Privacy
Frame, Inc. ("Frame," "we," "us," or "our") operates an AI-powered video generation platform at frame.so. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over your data.
We keep this policy plain and specific. If something is unclear, email us at privacy@framer
This policy applies to:
The Frame website (frame.so)
The Frame web application
The Frame API
All related services and communications
It does not apply to third-party services we link to. Those are governed by their own privacy policies.
1. DATA WE COLLECT
We collect data in three ways: data you give us directly, data generated by your use of the Service, and data from third parties.
1.1 Data you provide directly
Account data
When you create an account, we collect your name, email address, and password (hashed — we never store it in plain text). If you sign up via Google or another OAuth provider, we receive your name and email from that provider.
Profile and billing data
If you subscribe to a paid plan, we collect your billing address and payment method details. Payment card data is processed and stored by our payment processor (Stripe) and is never stored on our servers.
Input content
Product images, text prompts, brand assets (logos, color codes, fonts), and any other files you upload to generate videos. See Section 4 for how we handle this specifically.
Communications
If you contact us by email or through our support system, we retain those communications to help resolve your issue and improve our support.
Team and collaboration data
If you use a Team plan, we collect the names and email addresses of team members you invite, and any approval workflow activity.
1.2 Data generated by your use of the Service
Usage data
Pages visited, features used, videos generated, prompts submitted, export formats selected, time spent in the application, and actions taken within the platform.
Device and technical data
IP address, browser type and version, operating system, device type, screen resolution, referring URL, and general geographic location (country and city level, derived from IP address).
Log data
Server logs recording requests made to our platform, including timestamps, request types, and error events. Logs are retained for up to 90 days.
Cookies and tracking
See Section 6 for full details on our use of cookies.
1.3 Data from third parties
OAuth providers
If you sign in via Google, we receive your name, email address, and profile picture from that provider.
Payment processors
Stripe provides us with limited transaction metadata (plan purchased, amount, date, last 4 digits of card, billing country). We do not receive full card numbers.
Analytics providers
We use analytics tools that may process anonymized usage data. See Section 6.
2. WHY WE COLLECT YOUR DATA (LEGAL BASIS)
We only process your data when we have a lawful reason to do so. The reasons we rely on are:
Contract performance
Processing necessary to provide the Service you signed up for — generating videos, managing your account, processing payments, and delivering exports.
Legitimate interests
Improving the Service, detecting and preventing fraud and abuse, maintaining security, and understanding how users interact with the platform — in ways that do not override your rights.
Legal obligation
Retaining records required by tax, accounting, or other applicable law.
Consent
Where we ask for your permission specifically — such as sending marketing emails or using your content as a case study. You can withdraw consent at any time.
3. HOW WE USE YOUR DATA
We use the data we collect to:
Operate the Service
— Create and manage your account
— Process your prompts and generate video outputs
— Deliver and store your exports
— Apply your brand presets to generated videos
— Process payments and manage your subscription
Improve the Service
— Analyze usage patterns to fix bugs and improve features
— Understand which features are used most and least
— Test new features and interface changes
Communicate with you
— Send transactional emails (receipts, password resets, export notifications, account alerts)
— Send product update emails if you have opted in
— Respond to your support requests
Maintain security and prevent abuse
— Monitor for unusual activity, fraud, and policy violations
— Enforce our Terms and Conditions
— Protect the security of our infrastructure
Comply with legal obligations
— Retain records as required by applicable law
— Respond to lawful requests from authorities
4. YOUR CONTENT — HOW WE HANDLE IT
This section is specific to the product images, prompts, brand assets, and video outputs you create on Frame.
4.1 We do not train our AI on your content
We do not use your Input Content (uploaded images, prompts, brand assets) or your Output Content (generated videos) to train, fine-tune, or improve our AI models. Your content is yours. It is processed only to generate the outputs you requested.
4.2 Storage and retention
Your uploaded files and generated videos are stored securely on encrypted cloud infrastructure. We retain your content for as long as your account is active. If you delete a file or video from your account, it is removed from our active storage within 30 days and from backup systems within 90 days.
If you close your account, all associated content is deleted within 30 days of closure and from backups within 90 days.
4.3 Access to your content
Only you and authorized Frame team members with a specific operational need (such as investigating a reported bug or security incident) can access your content. We do not browse user content routinely.
4.4 No selling of your content
We do not sell, license, or share your Input Content or Output Content with any third party for their own use.
4.5 Prompts and metadata
Aggregated, anonymized data about prompt patterns (for example, what types of scenes are commonly requested) may be used to improve prompt suggestions and templates. This data is stripped of any identifying information before analysis.
5. HOW WE SHARE YOUR DATA
We do not sell your personal data. We share it only in the following limited circumstances.
Team plan sharing
If you are on a Team plan, account administrators can see the names, email addresses, activity logs, and generated content of team members within the shared workspace.
Legal requirements
We may disclose your data if required by law, court order, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of Frame, our users, or the public. Where permitted, we will notify you before complying with such a request.
Business transfers
If Frame is acquired, merges with another company, or sells substantially all of its assets, your data may be transferred as part of that transaction. We will notify you in advance and you will have the option to delete your account before any transfer.
With your consent
We may share your data in other ways if you explicitly authorize us to do so — for example, as part of a case study or testimonial.
6. COOKIES AND TRACKING
6.1 What we use
Strictly necessary cookies
Required for the Service to function. These include session cookies that keep you logged in and security tokens. These cannot be disabled.
Functional cookies
Remember your preferences (such as language and display settings). Can be disabled without affecting core functionality.
Analytics cookies
Help us understand how the Service is used. We use Posthog for product analytics. Data is anonymized and aggregated. Can be disabled via cookie settings.
We do not use advertising or tracking cookies. We do not participate in cross-site tracking or retargeting.
6.2 Managing cookies
You can control cookies through your browser settings. Note that disabling cookies beyond strictly necessary ones may affect some features of the Service. A cookie preference panel is available at frame.so/cookies.
6.3 Do Not Track
We honor Do Not Track (DNT) browser signals. If DNT is enabled, we disable all non-essential tracking for your session.
7. DATA RETENTION
We retain your data for as long as your account is active or as needed to provide the Service. Specific retention periods:
After the applicable retention period, data is securely deleted or irreversibly anonymized.
8. DATA SECURITY
We take security seriously and implement measures appropriate to the sensitivity of the data we handle.
Technical measures include:
— Encryption in transit (TLS 1.2+) for all data
— Encryption at rest (AES-256) for stored files
— Hashed passwords (bcrypt)
— Access controls limiting who can access production data
— Regular security audits and penetration testing
— Automated vulnerability scanning
Organizational measures include:
— Background checks for employees with data access
— Security training for all staff
— Incident response plan with defined notification windows
— Data access logging and anomaly detection
No security system is perfect. In the event of a data breach that affects your personal data, we will notify you and relevant authorities as required by applicable law, within 72 hours of becoming aware of the breach.
If you discover a security vulnerability, please report it responsibly to security@framer