How Framestory handles your data
This notice explains what personal data Framestory collects, why we collect it, how long we keep it and which rights you can exercise. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR).
Last updated: August 1, 2026
1. Who is the data controller
Framestory SASU, a simplified joint-stock company established in Paris, France, is the controller of the personal data described in this notice. You can reach us at contact@framestory.digital for any question about privacy or to exercise your rights. We have not appointed a Data Protection Officer; privacy requests are handled directly by the company.
2. What we collect and why
We collect the minimum needed to run the service. Every category below has a defined purpose and a legal basis under Article 6 GDPR.
| Data category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | Email address, hashed password or provider identifier, interface language | Create and secure your account, sign you in, send service emails | Performance of a contract (Art. 6(1)(b)) |
| Shoot content | Photos you upload, the context you type, and the generated write-ups, captions and alt-texts | Produce the Shoot Story Package you asked for and show your history | Performance of a contract (Art. 6(1)(b)) |
| Usage and quota data | Number of runs in the current month, plan tier, timestamps of runs | Enforce plan limits fairly and keep the free tier available to everyone | Performance of a contract (Art. 6(1)(b)) |
| Demo anti-abuse data | A one-way hash of your IP address, run timestamp | Limit the no-signup demo to two live runs per visitor per day | Legitimate interest in preventing abuse (Art. 6(1)(f)) |
| Lead and contact data | Email address, form source, chosen language, message topic | Answer your message and send the newsletter you asked for | Consent (Art. 6(1)(a)); you can withdraw it at any time |
| Technical logs | Error messages, request timestamps, coarse request metadata | Diagnose failures and keep the service secure and available | Legitimate interest in service security (Art. 6(1)(f)) |
3. How long we keep it
| Data | Retention period |
|---|---|
| Account data | For the life of the account, then deleted within 30 days |
| Shoot content (photos, packages) | Until you delete it, or 30 days after account closure |
| Usage and quota records | 13 months, then deleted |
| Demo IP hashes | 24 hours |
| Newsletter and contact leads | Until you unsubscribe or ask for deletion, and at most 3 years after last contact |
| Technical logs | 90 days |
| Accounting records for paid plans | 10 years, as required by French commercial law |
4. Your eight rights
Write to contact@framestory.digital to exercise any of them. We answer within one month and never charge for a first request. You can also delete your content and your entire account yourself from the Settings page.
- 01
Right of access
Ask for a copy of the personal data we hold about you and the details of how we use it.
- 02
Right to rectification
Ask us to correct inaccurate data, or fix it yourself from your account settings.
- 03
Right to erasure
Ask us to delete your data. The Settings page performs the full deletion immediately.
- 04
Right to restriction of processing
Ask us to freeze processing while a dispute about accuracy or lawfulness is resolved.
- 05
Right to data portability
Receive your account data and generated packages in a structured, machine-readable format.
- 06
Right to object
Object to processing based on our legitimate interests, including anti-abuse measures.
- 07
Right to withdraw consent
Withdraw consent for the newsletter or non-essential cookies at any time, without affecting past processing.
- 08
Rights around automated decisions
We take no decision producing legal effects about you by automated means. Generated text is a draft, never a decision about you.
5. Who processes data on our behalf
We use a small set of processors, each bound by a data processing agreement: our cloud database and authentication provider (hosting inside the EU), our model provider, which processes uploaded photos and context solely to return the generated text, and our email delivery provider for account and newsletter emails.
Uploaded photos are sent to the model provider only for the duration of a run. They are not used to train models, and we do not sell or rent personal data to anyone.
6. International transfers
Where a processor operates outside the European Economic Area, transfers rely on the European Commission's Standard Contractual Clauses together with technical measures such as encryption in transit and at rest.
7. Security
Data is encrypted in transit with TLS and at rest by our hosting provider. Access to your rows is enforced at database level by row-level security policies, so one account cannot read another's shoots. Administrative access is limited to what is needed to operate the service, secrets are held in a managed store and never shipped to the browser, and passwords are stored only as salted hashes.
8. Children
Framestory is a professional tool and is not directed at children under 16. We do not knowingly create accounts for them.
9. Complaint to the CNIL
If you believe we have mishandled your data, please contact us first — we would rather fix it. You also have the right to lodge a complaint with the French supervisory authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or on www.cnil.fr. If you live in another EU country, you may complain to your local supervisory authority instead.
Framestory SASU · Paris, France · contact@framestory.digital · © 2026