Skip to content
Frameleaf
    • Library & timelineEvery photo and video, in order
    • Search & AIFind anything by describing it
    • People & petsFaces recognised on your server
    • Memories & placesRediscover moments and maps
    • SharingPartners, spaces and links
    • Photo editorNon-destructive, with versions
    • StudioA full video editor, built in
    • For photographersIngest, proof, edit and deliver
    • Library careDuplicates, repairs and trash
    • PrivacyLocked content and what stays home
  • Demo
    • iPhone & iPadNative, written in Swift
    • AndroidNative, written in Kotlin
    • Web appThe full library in any browser
    • NAS appsUnraid, Synology and TrueNAS
    • Frameleaf CloudOptional services for your server
    • Remote accessReach home without open ports
    • Cloud backupEncrypted off-site copies
    • Buddy backupBack up to a friend's server
    • Cloud GPUHeavy AI jobs, paid by use
    • Sign inManage and open your servers
  • Pricing
  • Docs
  • Sign in to Frameleaf Cloud
  • Get Frameleaf
Sign inGet Frameleaf
Legal and policiesPrivacy and data

Privacy Notice

Last updated October 3, 2026

On this page
  1. 1. Who we are and what this Notice covers
  2. 2. Our role and an administrator’s role
  3. 3. Information involved in each service
  4. 4. Purposes and legal bases
  5. 5. Recipients and disclosures
  6. 6. International processing and residency
  7. 7. Retention, closure and deletion
  8. 8. Security and encryption limits
  9. 9. Choices and rights
  10. 10. Children, sensitive data and automated decisions
  11. 11. Regional disclosures and updates

1. Who we are and what this Notice covers

Frameleaf, Inc., a Wyoming corporation, provides Frameleaf Cloud and the proprietary Frameleaf applications. Contact us at [email protected] or Frameleaf, Inc., Privacy Contact, 14 Wall Street, Suite 2000, New York, NY 10005, United States. Frameleaf Canada Inc. may assist with support, administration and service delivery. These entities remain responsible for their respective obligations under applicable privacy law; Canadian administrative involvement does not mean all processing occurs in Canada.

This Notice concerns our websites, commercial accounts, applications and services. It does not govern a separate Library administrator’s use of information on their own server, an independently selected integration, or an unrelated hosting provider. Frameleaf does not currently host your operational photo or video Library. The Library, database and primary media storage are operated by you or your chosen administrator. Our Cloud service provides separately enabled connectivity, encrypted backup and AI functions, not a replacement running Library.

2. Our role and an administrator’s role

For account administration, our billing records, website security and our own legal obligations, Frameleaf ordinarily determines the purposes and means of processing and acts as the responsible organization or controller under applicable law. For content processed solely on an organization’s instructions, Frameleaf acts as a processor or service provider as described in the Data Processing Addendum. Those roles are determined by actual activities, not simply by the labels in this Notice.

An organization or household administrator may manage users, permissions, selected backup content, retention and shared balances. The administrator of your self-hosted Library may be able to access its media, metadata and database. Ask that administrator about their privacy practices. A Frameleaf interface control cannot prevent an independent server owner from exercising access available through their own systems.

3. Information involved in each service

3.1 Account, purchase and support information

Account information may include your email address, chosen name, authentication identifiers, account settings, subscription entitlements, organization membership and security-recovery information. Purchase records may include billing contact and address, currency, tax information, plan, payment status, transaction identifiers and limited payment-method details supplied by the payment processor or marketplace. For direct card purchases, payment details are submitted to the payment processor; Frameleaf receives payment-method references and limited details such as brand, last four digits and expiry, rather than full card numbers or security codes. Do not send full payment credentials to support.

Support information includes your communications and diagnostic material you choose to provide. Avoid sending private keys, passwords, full card details or unnecessary private photographs. We will ask for the minimum reasonably necessary to investigate a problem and explain any request for readable media.

3.2 Self-hosted content and mobile permissions

A local Library can contain originals, videos, thumbnails, face labels, albums, descriptions, location and other metadata. The mere use of that self-hosted software does not transfer all such information to Frameleaf Cloud. Transfers depend on enabled features, selected content, connection settings and permissions.

Applications may use device permissions for selected photos, camera, microphone, notifications, background transfer, location or local-network access. Local caches and downloaded content may be stored on the device. Permission settings and cache controls are explained in the Application. Revoking a permission can interrupt the associated feature without deleting copies already transmitted or exported elsewhere.

3.3 Connectivity and relay

Cloud processes linked-server and account identifiers, endpoints and hostnames, software and status reports, authorized connections, traffic totals and security events. The remote-access relay routes the encrypted TLS session to the Library without decrypting its application payload. Routing hostnames, network addresses, timing and byte counts remain visible to the transport infrastructure. Cloud sign-in, account and API requests are separate and are processed at those services.

3.4 Backup and recovery

Managed Cloud Backup stores supported files, database dumps and manifests at the storage processor using server-side encryption with a key supplied by the Library over HTTPS for content operations. The processor performs encryption and decryption and therefore receives the usable key and readable content during those operations. The Cloud account and coordination services do not receive that usable key in the ordinary backup protocol. They can list object identifiers, content-hash names, sizes and timestamps and record usage, run status and lifecycle information.

Server-generated and customer-provided stored-key modes keep a local key copy; memory-only mode requires unlocking again after restart. Optional server-key escrow sends Cloud a passphrase-wrapped envelope. It is not a staff-recoverable plaintext key. Customer-provided buckets use your selected provider and its separate terms.

Buddy Backup encrypts blocks and recovery metadata on the source server before transfer to the paired peer. Cloud receives pairing, server, account, authorization and operational information and any separately enabled encrypted escrow envelope. Its ordinary coordination protocol does not receive plaintext backup media, manifests or usable vault keys. Peer storage is controlled by the peer administrator. These encryption boundaries do not protect against a compromised source endpoint or an authorized person with the key.

3.5 Cloud AI

Cloud descriptions use prepared previews with embedded location and device metadata removed. Other enabled media jobs can send a prepared image, video, audio segment or full render input, along with the authorized settings and text needed for the operation. The processing system can read those inputs. Removing embedded metadata does not remove visible faces, signs, locations, voices or other information present in the content itself.

Face detection and recognition use the Library’s configured local or customer-operated machine-learning service; they are not Cloud face-matching services. Optional identity naming and medical-signal descriptions require separate feature choices. Job records include the operation, estimate, reservation, usage, status and charge. Backup or relay enrollment does not authorize an AI job or model training.

Selected AI content is uploaded directly to an ephemeral processing worker. Uploaded content and container-local working data are deleted immediately when the job finishes, and the processing container is destroyed. Frameleaf does not retain a stopped container or a separate post-job upload archive. The destroyed container and its uploaded content cannot be recovered through the service. A result delivered to your Library has its own local lifecycle. Non-content job, usage and billing records follow the Security Schedule and do not preserve the uploaded media.

3.6 Website and application diagnostics

Necessary technical information can include IP address, device and browser type, software version, session identifiers, language, request timing, errors and security events. The Cloud account site uses sign-in cookies and browser storage for the chosen display theme. Payment and optional billing-address search have separate third-party processing described in the Cookie Notice. Additional optional diagnostics or analytics, if introduced, require the applicable disclosure and choice. We will not intentionally place private images, secrets or unnecessary full file paths into general analytics events.

4. Purposes and legal bases

We use information to provide requested features, authenticate users, process purchases, maintain accounts and entitlements, transport authorized data, preserve and restore selected backups, run authorized AI jobs, provide support, secure systems, prevent misuse, meet legal obligations and handle disputes. We also use minimized operational information to understand performance and correct defects.

Where a lawful-basis framework applies, processing necessary to provide a requested service may be based on contract; security and proportionate service administration may be based on legitimate interests after assessing individual rights; legally required records or disclosures rely on the relevant obligation; and optional marketing, non-essential tracking, sensitive processing or other activities requiring consent use an appropriate separate consent. Contract necessity is not used to justify optional advertising or processing unrelated to the service. Special-category or biometric processing requires any additional legal condition that applies.

We do not sell private photographs or videos, use private media to target advertising, or train generalized or cross-customer AI models on private inputs or outputs as part of the ordinary Services. We do not authorize our service providers to do so on our behalf. Any genuinely optional future data-contribution program will require a separate, intelligible choice and cannot obtain another person’s rights merely through the account holder’s click.

5. Recipients and disclosures

We disclose information only as reasonably needed for the stated purposes to authorized infrastructure, storage, communications, support, security, payment and AI providers; authorized personnel and assisting affiliates; people you choose to share with; and lawful recipients described below. Service providers processing on our behalf are subject to appropriate confidentiality, security and use limitations. Payment marketplaces or independently selected integrations may act under their own privacy terms for their separate activities.

The Subprocessor and Processing Location Register applicable to your service is available through frameleaf.app or by contacting [email protected]. We will make the applicable provider identities, functions, processing locations and material data categories available before processing where required. The recipient categories in this Notice do not replace those specific disclosures. For organization processing, new subprocessors are also subject to the DPA’s notice and objection procedure.

We may disclose information to comply with valid legal process, protect against a concrete threat or fraud, establish or defend legal claims, or address unlawful material, subject to necessity and applicable law. Legal requests undergo internal-counsel review under the Law Enforcement and Subpoena Policy. Our policy is to notify affected users before disclosure unless a court order or other binding law prohibits notice, with only the narrowly defined life-safety emergency delay described in that Policy. Delayed notice follows when the restriction or emergency basis ends. We cannot provide plaintext or keys we do not possess or control.

In a merger, financing, reorganization or business transfer, relevant information may be reviewed or transferred under safeguards and continuing privacy obligations. A transaction is not permission to disregard existing restrictions on private-media use. A materially different purpose requires the notice and legal basis that the law requires.

6. International processing and residency

Cloud account, identity, entitlement, billing and operational coordination records are processed by the global control plane in the United States. A selected regional backup or AI destination is a separate setting; it does not make the account record resident exclusively in that region. Remote-access routing can use infrastructure in the United States or Canada, and payment, email, edge-network and other supporting providers can process data in their disclosed locations.

Managed backup storage is selected according to the account’s supported data region. Cloud AI jobs require an available regional gateway and processing destination. A region appearing in a setting is not a promise that every feature is available there or that all account and support information stays there. Country-exclusive processing applies only to an expressly agreed scope with identified exceptions. Buddy Backup data resides on the peer storage you select; you are responsible for considering the peer’s location and authority.

Information may be subject to lawful access in a processing country. Where a transfer requires an approved mechanism, Frameleaf will establish it before that transfer and provide relevant information on request, subject to lawful security and confidentiality limits. A provider’s participation in a certification or adequacy framework is not automatically Frameleaf’s participation.

7. Retention, closure and deletion

The Security, Retention and Deletion Schedule provides the applicable lifecycle. Ordinary logs are kept for 30 days, traces for seven days, temporary account exports for 24 hours and audit identifiers for 400 days before the stated de-identification process. AI content uploaded to a processing worker is deleted immediately when the job finishes; it is not kept for a 24-hour retrieval period. Financial and case records can outlast deletion when an applicable purpose or legal duty requires them.

Closing an account makes it inactive; it does not erase it. Sessions end and servers are unlinked, but account records and the remaining wallet balance stay, and managed backup storage is frozen without an automatic whole-bucket deletion date solely from closure. Other ordinary lifecycle and applicable credit-expiry rules continue. Support is required for reactivation or rights requests when you cannot sign in.

Requesting deletion starts a 30-day cancellation period. Once erasure starts, sign-in and identified account data are removed, direct subscriptions end, any active AI processing is ended and its worker-held content is deleted, and managed backup storage enters a further 30-day deletion hold with final removal scheduled within 90 days of erasure starting. Financial, audit, dispute and necessary lifecycle records remain as described in the Schedule. The AI Terms and Refund Policy explain the remaining wallet value: removing account access or the service-use balance does not extinguish the right to a refund of unused purchased value.

A dispute, refund, suspension, frozen wallet or preservation hold can delay erasure. We must assess the lawful basis and necessary scope and respond to rights requests within applicable legal deadlines; a technical hold does not create an unlimited right to retain everything. Where a hold ends, a revised date is provided with at least seven days to act before erasure.

Canceling renewal, deleting an app, unlinking a server, closing an account and requesting erasure have different consequences. Store-billed subscriptions must be canceled in the store. Cloud account deletion does not erase the independently operated Library or certify deletion from a Buddy peer. Contact support for an explanation, an available export, a deletion request or a challenge to retention.

8. Security and encryption limits

We apply the safeguards committed in the Security Schedule and, for business processing, the DPA. Access is limited by role and legitimate need. Encryption does not prevent every endpoint compromise, stolen session, authorized misuse or loss of a customer-controlled key. A PIN or hidden-photo screen is not a substitute for cryptographic protection. A provider’s certification does not automatically certify the whole Frameleaf service.

Where a breach affects information for which we are responsible, we will investigate, mitigate and make required notifications. Organization customers receive the DPA’s additional incident notices. Communications will identify what is known and avoid implying that an encrypted event exposed plaintext unless the evidence supports that conclusion.

9. Choices and rights

Depending on applicable law, you may have rights to know or access personal information; obtain a usable copy; correct inaccuracies; request deletion; restrict or object to processing; withdraw consent; opt out of legally defined sale, sharing, targeted advertising or certain profiling; limit qualifying sensitive-information use; and appeal a denied request. You may complain to the competent privacy regulator. We will not unlawfully discriminate against you for exercising those rights.

Submit a request through available account controls or [email protected]. We will verify identity proportionately, request only necessary information, and respond within the period required by applicable law. An authorized agent may act with appropriate proof. Where a legal right to appeal applies, reply with an appeal request and we will provide reconsideration and the applicable regulator route.

For organization-controlled content, we may direct a request to the responsible administrator and assist it under the DPA. We will not redirect a request concerning our own account-processing responsibilities to avoid answering it. For data we cannot decrypt, our response may involve available metadata, encrypted export or deletion rather than readable photographs we cannot access.

Consent withdrawal stops future consent-based processing, subject to lawful limitations; it does not retroactively invalidate lawful completed processing. A request does not automatically erase valid financial records, legal preservation or information needed to resolve a dispute. We will explain any material refusal or retention exception unless law prevents it.

10. Children, sensitive data and automated decisions

Independent commercial accounts are not offered to children under 18. Any supported managed family access requires the protections described in the service and applicable parental authorization. A photograph depicting a child does not mean the child has created an account. We do not knowingly use children’s private media for behavioral advertising or generalized model training. Contact [email protected] about an unauthorized child’s account or processing.

Face recognition and similar sensitive features are addressed in the separate Biometric and Sensitive Features Notice. No account holder may consent for every adult depicted merely by uploading a group photograph. AI labels and recommendations are not verified identity findings. We do not offer the ordinary photo service as a system for making legally significant automated decisions about individuals. Security or anti-fraud restrictions can use automated signals; affected users can seek review through the support or privacy channels.

11. Regional disclosures and updates

For United States residents with applicable state privacy rights, the categories, purposes, recipients and retention described above also serve as the relevant category disclosures; sensitive information is used only for the requested functions and other permitted purposes, not as blanket authorization for secondary use. For Canadian individuals, Frameleaf remains accountable for processing within the scope of applicable Canadian law and for appropriate arrangements with service providers. Mandatory provincial rights and language obligations remain unaffected.

Where European, United Kingdom, Swiss or other laws require a local representative, additional notice, assessment or transfer instrument, Frameleaf will provide it and establish it before offering the relevant processing in scope. This Notice alone is not a representation that every jurisdiction is enabled. Material changes will be announced through appropriate notice; a new consent will be obtained where required rather than inferred from a retroactive edit to this page.

Questions: [email protected]. United States correspondence: Frameleaf, Inc., Privacy Contact, 14 Wall Street, Suite 2000, New York, NY 10005, United States. All enquiries, including Canadian privacy enquiries, may be submitted through frameleaf.app or the email address above.

Telephone: +1 (332) 287-1911.

More in Privacy and data

  • Cookie and Similar Technologies NoticeNecessary and optional technologies, and how to set your preferences.
  • Biometric and Sensitive Features NoticeFace recognition on your server and in the cloud, consent, purpose limits and destruction.
  • Security, Retention and Deletion ScheduleOur security baseline and how long backups, AI jobs, relay data, logs and account data are kept.
  • Data Processing AddendumProcessing for organisations: security, subprocessors, incidents, audits, deletion and transfers.

All legal documents

Frameleaf

A photo and video library for home servers. The Frameleaf Library community edition is open source under AGPLv3.

GitHub

Features

  • Library & timeline
  • Search & AI
  • People & pets
  • Memories & places
  • Sharing
  • Photo editor
  • Studio
  • For photographers
  • Library care
  • Privacy

Apps

  • iPhone & iPad
  • Android
  • Web app
  • NAS apps

Cloud

  • Frameleaf Cloud
  • Remote access
  • Cloud backup
  • Buddy backup
  • Cloud GPU
  • Pricing
  • Sign in to Frameleaf Cloud
  • Status

Get started

  • Get Frameleaf
  • Try the demo
  • Switch to Frameleaf
  • Install guide
  • Documentation
  • FAQ
  • Open source
  • Photo credits

Legal & policies

  • All legal documents
  • Terms of Service
  • Privacy Notice
  • Acceptable Use
  • Refund Policy
  • Security Policy
  • Cookies
© 2026 Frameleaf. Frameleaf Library community edition licensed under AGPLv3.