1. Scope and processing locations
A photograph, a person label, a face embedding, device biometric unlock and verified identity checking are different activities. Applicable law depends on the data and its actual use. This Notice supplements the Privacy Notice, AI Terms and Security Schedule and is not blanket consent to biometric processing.
Library face detection and recognition use the machine-learning service configured by the Library administrator, such as the local server or another customer-operated endpoint. Frameleaf Cloud does not provide face detection, face-template matching or a cross-customer face-identification service. Local people records, face relationships and other metadata can be included in a Library database backup; that transfer follows the distinct backup encryption and storage arrangement.
Cloud descriptions can analyze visible content in selected images and may include optional identity naming or medical-signal descriptions where separately enabled. These are text-generation features, not verification of identity, a medical diagnosis or proof that an individual consented. A description model can make sensitive inferences even when no reusable face template is generated.
Device biometric unlock, where supplied by the operating system, uses that system’s authentication process. It does not authorize Cloud face analysis or transfer the operating system’s biometric template to Frameleaf merely by unlocking the application.
2. Administrators, authority and consent
The Library administrator controls its recognition configuration, local people records and selected backup scope. Ask that administrator about the processing and available deletion controls. A person operating a Library for an organization must establish its lawful basis, required notices and appropriate safeguards.
Where law requires an individual’s written or electronic release for covered biometric processing, that release must be obtained before the covered collection, use or disclosure. Possessing a photograph or accepting these Terms does not provide consent for every adult depicted. Authority to act for a child or another person depends on applicable law, not merely on being the account holder.
Cloud processing requires the applicable separate feature authorization. Identity naming and medical-signal options are separate choices; turning on ordinary descriptions, backup or relay is not permission to enable every sensitive feature. Do not submit a collection for a use that cannot meet the required consent and lawful-basis conditions. Frameleaf may restrict a feature or workflow where those conditions cannot be met.
3. Purpose and prohibited secondary uses
Permitted purposes are the selected Library organization or expressly enabled Cloud processing functions. Frameleaf will not use private face information for advertising, generalized or cross-customer model training, public face search, unrelated identity verification or covert surveillance.
Frameleaf will not sell, lease or trade biometric identifiers or biometric information as a separate data asset. Disclosures within its responsibility are limited to the authorized service purpose, instructed processors and circumstances allowed by applicable law. A paid feature is not permission to monetize the resulting biometric data through unrelated disclosure.
Do not use the Services for unlawful public identification, covert biometric monitoring, prohibited mass surveillance or unlawful consequential decisions. Review generated names and local face matches; neither a similarity result nor fluent generated text proves identity.
4. Retention and deletion
Selected AI content is uploaded directly to an ephemeral processing worker. Uploaded content and container-local working data are deleted immediately when the job finishes, and the processing container is destroyed. Frameleaf does not retain a stopped container or a separate post-job upload archive. The destroyed container and its uploaded content cannot be recovered through the service. Frameleaf does not retain a reusable Cloud face-matching database as part of these Services. A generated description delivered to the Library remains under that Library’s control until its administrator changes or removes it.
Local recognition records and templates follow the administrator’s configuration and applicable law. Disabling future recognition does not necessarily remove existing records, derived descriptions or earlier backups. A rights request may require separate deletion of those categories by the responsible administrator.
Cloud Backup database dumps can contain local people and face data. The storage processor handles those dumps under SSE-C; Frameleaf’s Cloud coordination service does not hold the usable bucket key. Buddy Backup encrypts its recovery data before transfer to the peer. Removing one person’s record from the live Library does not individually rewrite every prior backup. The administrator must consider retention rotation, removal of affected recovery points or another lawful deletion method. Encryption is not an exemption from an applicable destruction deadline.
Where a law imposes a specific purpose-based or outside destruction deadline, that deadline prevails for covered data. Necessary evidence of a consent or rights request should be retained without an unnecessary template or private image. If the selected workflow cannot meet a mandatory deletion obligation, the affected processing must be restricted.
5. Safeguards and limitations
Frameleaf will apply reasonable care appropriate to sensitive information within its control, restrict access and keep readable templates out of ordinary support attachments and general telemetry. The Privacy Notice explains recipient and international-processing disclosures. The Backup Agreement explains why Cloud Backup and Buddy Backup have different encryption boundaries.
A local private-album label, hidden-person setting or PIN is not a cryptographic barrier against a server administrator. A restored database can contain previously captured people records; the administrator must reapply applicable deletion instructions after restoration.
6. Choices and requests
Disable future processing through the relevant Library or Cloud feature controls. Contact the Library administrator for local records and copies it controls. For Frameleaf’s processing, requests may be submitted through frameleaf.app or [email protected]. Frameleaf will authenticate requests proportionately and assist an organization customer under the DPA where applicable.
Withdrawal does not retroactively invalidate completed lawful processing or recall copies already independently distributed. It does require stopping future consent-based processing and addressing retained data where applicable law requires it. Frameleaf will not require unnecessary new biometric information merely to process an ordinary privacy request.
Postal correspondence: Frameleaf, Inc., Privacy Contact, 14 Wall Street, Suite 2000, New York, NY 10005, United States.
Telephone: +1 (332) 287-1911.