Privacy Policy
Who is responsible
The controller of your personal data is Lan Prijatelj s.p., Pahorjeva ulica 8, 1231 Ljubljana-Črnuče, Slovenia, registration number 9581162000, VAT ID SI82986932. Write to support@framely.si with any privacy question or request.
What we process
- Account data: email address, name and profile photo if you sign in with Google, whether your email is verified, and whether you passed the security check.
- Project content: your briefs, brand and product details, instructions, and the concepts, scripts, images and videos generated for you.
- Tokens and purchases: your token balance and its history, the jobs you ran, and purchase records from Stripe (amount, pack, payment reference). We never see your card details.
- Technical data: IP address, browser type and request logs, used for security, rate limits and fixing errors.
Why, and on what legal basis
- To provide Framely (Art. 6(1)(b) GDPR, performance of our contract with you): running your account, generating content, crediting tokens, and sending verification and password-reset emails.
- To keep the service secure and fair (Art. 6(1)(f), our legitimate interest): the Cloudflare security check, refusing disposable email addresses, rate limits, giving the free signup tokens only once per inbox, and error monitoring.
- To understand how the site is used (Art. 6(1)(f)): aggregated page-view counts from Vercel Analytics, which don't identify you.
- To meet legal duties (Art. 6(1)(c)): keeping accounting and tax records.
Who receives your data
We use these service providers, bound by data processing terms, and send each only what its task needs:
- Hetzner Online: Servers for the Framely API and database. Germany.
- Google (Firebase): Sign-in (Firebase Authentication) and file storage (Firebase Storage). Files in Frankfurt; sign-in data may be processed in the USA.
- Vercel: Hosting of the website and cookieless page-view analytics. USA.
- OpenAI: Writing concepts and scripts from your brief. USA.
- fal: Generating images and videos. Depending on the model, fal runs it itself or passes the request to the model's developer (currently OpenAI, Google and MiniMax). USA; MiniMax may process requests in Asia.
- Cloudflare: Turnstile security check against bots at signup and password reset. USA.
- Resend: Sending account emails (address verification, password reset). USA, sent from Ireland.
- Sentry: Error reports from the API and background workers. USA.
Payments are handled by Stripe and Link, the merchant of record, as independent controllers under their own privacy policies. We don't sell personal data, and we don't use your content or outputs to train AI models.
Transfers outside the EU
Some providers above process data outside the European Economic Area. Where they do, the transfer relies on the EU–US Data Privacy Framework if the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses.
How long we keep it
- Account data and projects: while your account exists. When you close your account they're deleted straight away, including your briefs, uploads and generated files.
- Database backups: overwritten within 30 days, which is how long deleted data can remain in a backup.
- Purchase and token records: these aren't deleted, because tax and accounting law requires them. When you close your account they're anonymised (your name, email and the link to your account are removed) and kept for up to 10 years.
- Rate-limit counters: at most 24 hours. Server logs and error reports: normally no more than 90 days.
Automated checks
Signup uses automated checks (the Cloudflare security check, the disposable-address list, one free bonus per inbox) to stop abuse. They don't produce legal effects, but if you think a check blocked you by mistake, write to support@framely.si and a person will look at it.
Cookies and browser storage
Framely doesn't use advertising or tracking cookies, so there is no cookie banner. Firebase keeps you signed in using your browser's storage, which is strictly necessary for the service. Vercel Analytics counts page views without cookies and without recognising you across sites or days. The Cloudflare security check processes your IP address and browser signals only to tell people from bots. Stripe Checkout runs on Stripe's own pages under Stripe's cookie policy.
Your rights
You can ask for access to your data, a copy in a portable format, correction, deletion or restriction, and you can object to processing based on our legitimate interests. Write to support@framely.si; we answer within one month.
You can also complain to the Slovenian data protection authority, the Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, ip-rs.si, or to the authority where you live.
Security
Connections are encrypted, files are reachable only through short-lived signed links, and access to production systems is restricted to us. Framely is meant for adults and businesses and isn't directed at children.
Changes
If we change this policy in a way that matters to you, we'll tell you by email or in the app before the change applies.