Skip to content
Privacy

How Framestory handles your data

This notice explains what personal data Framestory collects, why we collect it, how long we keep it and which rights you can exercise. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR).

Last updated: August 1, 2026

1. Who is the data controller

Framestory SASU, a simplified joint-stock company established in Paris, France, is the controller of the personal data described in this notice. You can reach us at contact@framestory.digital for any question about privacy or to exercise your rights. We have not appointed a Data Protection Officer; privacy requests are handled directly by the company.

2. What we collect and why

We collect the minimum needed to run the service. Every category below has a defined purpose and a legal basis under Article 6 GDPR.

Data categoryExamplesPurposeLegal basis
Account dataEmail address, hashed password or provider identifier, interface languageCreate and secure your account, sign you in, send service emailsPerformance of a contract (Art. 6(1)(b))
Shoot contentPhotos you upload, the context you type, and the generated write-ups, captions and alt-textsProduce the Shoot Story Package you asked for and show your historyPerformance of a contract (Art. 6(1)(b))
Usage and quota dataNumber of runs in the current month, plan tier, timestamps of runsEnforce plan limits fairly and keep the free tier available to everyonePerformance of a contract (Art. 6(1)(b))
Demo anti-abuse dataA one-way hash of your IP address, run timestampLimit the no-signup demo to two live runs per visitor per dayLegitimate interest in preventing abuse (Art. 6(1)(f))
Lead and contact dataEmail address, form source, chosen language, message topicAnswer your message and send the newsletter you asked forConsent (Art. 6(1)(a)); you can withdraw it at any time
Technical logsError messages, request timestamps, coarse request metadataDiagnose failures and keep the service secure and availableLegitimate interest in service security (Art. 6(1)(f))

3. How long we keep it

DataRetention period
Account dataFor the life of the account, then deleted within 30 days
Shoot content (photos, packages)Until you delete it, or 30 days after account closure
Usage and quota records13 months, then deleted
Demo IP hashes24 hours
Newsletter and contact leadsUntil you unsubscribe or ask for deletion, and at most 3 years after last contact
Technical logs90 days
Accounting records for paid plans10 years, as required by French commercial law

4. Your eight rights

Write to contact@framestory.digital to exercise any of them. We answer within one month and never charge for a first request. You can also delete your content and your entire account yourself from the Settings page.

  1. 01

    Right of access

    Ask for a copy of the personal data we hold about you and the details of how we use it.

  2. 02

    Right to rectification

    Ask us to correct inaccurate data, or fix it yourself from your account settings.

  3. 03

    Right to erasure

    Ask us to delete your data. The Settings page performs the full deletion immediately.

  4. 04

    Right to restriction of processing

    Ask us to freeze processing while a dispute about accuracy or lawfulness is resolved.

  5. 05

    Right to data portability

    Receive your account data and generated packages in a structured, machine-readable format.

  6. 06

    Right to object

    Object to processing based on our legitimate interests, including anti-abuse measures.

  7. 07

    Right to withdraw consent

    Withdraw consent for the newsletter or non-essential cookies at any time, without affecting past processing.

  8. 08

    Rights around automated decisions

    We take no decision producing legal effects about you by automated means. Generated text is a draft, never a decision about you.

5. Who processes data on our behalf

We use a small set of processors, each bound by a data processing agreement: our cloud database and authentication provider (hosting inside the EU), our model provider, which processes uploaded photos and context solely to return the generated text, and our email delivery provider for account and newsletter emails.

Uploaded photos are sent to the model provider only for the duration of a run. They are not used to train models, and we do not sell or rent personal data to anyone.

6. International transfers

Where a processor operates outside the European Economic Area, transfers rely on the European Commission's Standard Contractual Clauses together with technical measures such as encryption in transit and at rest.

7. Security

Data is encrypted in transit with TLS and at rest by our hosting provider. Access to your rows is enforced at database level by row-level security policies, so one account cannot read another's shoots. Administrative access is limited to what is needed to operate the service, secrets are held in a managed store and never shipped to the browser, and passwords are stored only as salted hashes.

8. Children

Framestory is a professional tool and is not directed at children under 16. We do not knowingly create accounts for them.

9. Complaint to the CNIL

If you believe we have mishandled your data, please contact us first — we would rather fix it. You also have the right to lodge a complaint with the French supervisory authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or on www.cnil.fr. If you live in another EU country, you may complain to your local supervisory authority instead.

Framestory SASU · Paris, France · contact@framestory.digital · © 2026