1. Service boundary
Frameleaf Cloud may provide account authentication, device and Library pairing, entitlement verification, connection coordination, remote-access routing, relay capacity, notifications and related transport services. Your Order identifies the enabled services and allowances. Frameleaf does not currently host the running Frameleaf Library, its operational database or the primary media collection. Your Library remains on equipment or hosting that you or your chosen administrator control.
A Cloud dashboard may show connection status, usage, billing and backup information. Its availability does not establish that your Library is online, backed up, healthy or accessible. A relay is a transport path, not a backup. Neither an app login nor a successful remote viewing session confirms that an off-site backup exists.
2. Connection paths and dependencies
2.1 Direct and relayed connections
A supported session may use a direct connection between authorized endpoints or a Frameleaf-mediated relay. Availability can depend on DNS, certificates, firewall rules, NAT traversal, endpoint permissions, your internet provider and software compatibility. We do not promise that every network will permit direct connections or that every function can traverse a relay. A relay may have different speed, resolution, concurrency and bandwidth limits from a direct connection, as disclosed in the Plan.
2.2 Your operational responsibilities
Maintain a supported Library version, reliable power and internet access, adequate local storage, correct clocks and certificates, and appropriate administrator permissions. Keep recovery and access credentials outside a single failing device where appropriate. Do not expose an unauthenticated Library to the internet. We may identify configuration issues, but a connection assistant is not a managed firewall, penetration test or security certification.
2.3 Offline and outage behavior
If your Library or home network is offline, remote browsing and operations requiring it may stop even while Frameleaf Cloud is functioning. Cached application files, where supported, are different from a running Library. Restoration requires an available target or supported export process and does not mean Frameleaf will start a temporary hosted Library for you. An account-service outage can prevent new connections or entitlement checks even where a local Library remains operational.
3. Authentication, authorization and pairing
A person pairing a Library, inviting a device, granting a share or authorizing an integration must have the necessary permission. Pairing is not proof of copyright ownership or consent from every person whose data the Library contains. Limit tokens to needed permissions; revoke lost devices and expired integrations. A user invited to view a shared album does not acquire administrative, backup or billing privileges merely by receiving that invitation.
Frameleaf may require step-up authentication for sensitive actions such as changing recovery settings, exporting backup credentials, adding administrators or deleting data. Recovery of the commercial account does not automatically recover Library passwords or customer-held encryption keys. We may deny a requested control change where authority cannot reasonably be verified, while preserving applicable rights and safe available retrieval options.
4. Encryption and transport visibility
4.1 Feature-specific protection
The remote-access relay forwards the encrypted TLS session between your browser or application and your Library. The Library holds the certificate’s private key and terminates that session; the relay routes traffic without decrypting the Library’s application payload. A direct connection bypasses the relay. The Cloud account, identity and API services are separate endpoints that process the information submitted to them, including sign-in and billing requests.
The relay can process routing hostnames, network addresses, server identifiers, connection times, traffic amounts and error information. Public hostnames and certificate records can also be visible through DNS and Certificate Transparency systems. Payload encryption does not conceal this metadata or protect plaintext from an authorized Library administrator or a compromised endpoint.
4.2 Buffers and logs
Relays may temporarily buffer traffic to transmit it reliably. They are not intended to keep an independently browsable media collection or durable recovery copy. Buffer and log deletion follow the Security, Retention and Deletion Schedule. We will not routinely retain the contents of private relayed media for analytics or advertising. Targeted incident evidence or a support capture requires an appropriate legal basis, authorization where required, and limited scope and retention.
4.3 No hidden processing permission
Enabling connectivity does not authorize Cloud AI analysis, model training, generalized content scanning or a change from customer-controlled to provider-controlled backup keys. If a selected feature requires us or an AI processing provider to receive readable content, the relevant disclosure and authorization must precede that processing.
5. Sharing and recipient risk
Where your Library supports sharing, you choose recipients, permissions and available expiry controls. A publicly accessible link can be forwarded, indexed, saved or used by someone other than the intended recipient. The interface must explain whether access is account-restricted or link-based. Revoking a link cannot remove screenshots, downloads or copies already made by recipients.
Review whether a share includes location metadata, person names, hidden assets, face labels, album membership or other sensitive information. A hidden designation is not a promise that a permitted export removes embedded metadata. A recipient’s app, browser, operating system or independently operated server may store information under that party’s control. Frameleaf remains responsible for its own processing, not every independent recipient’s conduct.
6. Limits, overload and misuse
The Order or accepted Plan disclosure identifies material relay limits and any authorized charge for additional usage. No charge arises simply because a direct connection falls back to a relay unless an applicable paid allowance or rate was disclosed and accepted. We may pause new sessions or proportionately throttle activity to address a genuine threat, overload or breach of a disclosed limit, with notice where practicable.
The relay is not a general-purpose VPN, public file-distribution network, anonymous proxy, outbound mail server, cryptocurrency-mining conduit or resale bandwidth pool. Do not use it to conceal unlawful conduct or attack other systems. Lawful high-volume use within an agreed allowance is not automatically abuse. We will seek a supported configuration or plan adjustment before withdrawing service for a remediable capacity issue where reasonably possible.
7. Third-party integrations
Integrations you enable may receive selected data and delegated permissions. Review the third party’s terms and privacy information. We will distinguish independently selected integrations from our own contracted subprocessors. An integrated AI provider engaged by Frameleaf to deliver a Frameleaf feature remains subject to Frameleaf’s contractual processor obligations; it is not reclassified as your independent provider merely to avoid those obligations.
An integration may stop functioning because of an external API change, expired credential or third-party restriction. We do not authorize circumventing another provider’s access controls. Import, synchronization and migration do not automatically preserve every proprietary edit, album structure, live-photo pairing or metadata field; supported scope must be disclosed for that feature. Do not delete originals until you have independently verified the intended result and backup status.
8. Client and protocol compatibility
We may require supported protocol versions for reliable and secure access to the paid network Services. Reasonable compatibility conditions do not prohibit modifying or redistributing AGPL software. We will not revoke a customer’s AGPL rights because they use a third-party client. Access may be limited where a client actually fails security, authentication, billing-integrity or interoperability requirements applicable to the commercial network service.
We ordinarily give 30 days’ notice of a material protocol retirement requiring customer action, except for urgent security, legal or operational necessities. A retirement notice will identify an available supported path where reasonably possible. Paid features withdrawn without an adequate replacement follow the Master Terms’ cancellation and refund protections.
9. Suspension, cancellation and local operation
Ending connectivity may stop remote routes, shared service URLs, token issuance and notifications. It does not authorize deletion of the independently hosted Library or local media. Turning off a remote-access feature is distinct from unlinking the server from Cloud. Unlinking revokes Cloud access credentials and can start the managed backup hold and deletion process described in the Backup Agreement. Canceling a separately purchased connectivity service does not by itself cancel an independently maintained backup subscription. Where a bundled plan ends, the cancellation confirmation must identify every affected service and the backup retrieval deadline.
During suspected compromise, we may revoke service tokens or disable risky sharing while retaining safe account and backup-recovery access. We will explain available review and recovery steps unless doing so would be unlawful or materially compromise security.
10. Support, measurements and remedies
We operate the connectivity Services with the reasonable skill, care and safeguards promised in the Master Terms and Security Schedule. There is no guaranteed latency, throughput, uninterrupted session or uptime percentage unless an accepted SLA expressly supplies one. A supplier’s own availability measure is not the availability of the complete customer-to-Library path.
Diagnostic information should omit unnecessary media, credentials and sensitive metadata. We may ask for redacted logs or a scoped test session, not unrestricted administrator access. Support: [email protected]. Security incidents: [email protected]. Privacy concerns: [email protected]. The Master Terms govern liability and disputes, subject to mandatory law.