Privacy Policy
Last updated: August 2026
Your photos stay on your device and go straight to your TV over your own Wi-Fi, unless you switch on a cloud yourself (see “Cloud sync” below for what changes when you do). The Apple app can collect privacy-scrubbed anonymous usage analytics, which you can turn off in Settings. The current Android app sends no analytics or in-app issue reports.
1. Who is responsible
The data controller for personal data processed by the Frame Photos app and this website is:
Siebrand Dijkstra
Email: privacy@framephotos.app
2. What data we collect
2.1 Anonymous usage analytics in the Apple app (PostHog)
On iPhone, iPad, and Mac, Frame Photos uses PostHog Cloud (EU instance, eu.i.posthog.com) to collect anonymous product analytics. The current Android app does not use PostHog or another analytics service. Apple-app analytics can include:
- App lifecycle events (opened, closed, foregrounded, backgrounded)
- Feature interactions (uploads, album sync, mount changes, slideshow configuration)
- Onboarding progression (completed, skipped, page reached)
- TV pairing outcomes (success, failure, error type), without IP or hostname
- Device class (model, OS version, app version, locale) and TV firmware generation
- A random anonymous identifier (distinct ID) generated locally on first launch, not linked to your name, email, Apple ID, or Google account
We do not use Apple’s Identifier for Advertisers (IDFA) or Android’s advertising ID, and we do not track you across other apps or websites.
2.2 Issue reports in the Apple app (only when you tap Send)
On iPhone, iPad, and Mac, when you submit a report through Settings → Report an Issue, the following is sent to PostHog along with the report. The current Android app does not provide this upload flow:
- The description you typed
- Your email address, only if you choose to provide it so we can reply
- App version, OS version, device model, locale
- Up to 32 KB of the current session’s log file and 32 KB of the previous session’s log file
- Connected TV firmware generation and Samsung API version (if available)
These logs may contain technical information such as your TV’s local IP address, the TV’s MAC address (used by the Wake-on-LAN feature), filenames of photos you have uploaded, photo dimensions, and Samsung-internal content identifiers. We treat issue reports as a support service and only use them to investigate and reply.
Issue reports are sent even when analytics is turned off in Settings. Otherwise we couldn’t respond to your problem. Submitting a report is always a deliberate, manual action you take.
2.3 What stays on your device
As long as you do not switch on a cloud, your photos, photo metadata, albums, edits, and TV pairing tokens are stored locally inside the app’s sandbox. The Apple app uses SwiftData; Android uses local app storage. Photos are transferred directly between your device and your TV over your local Wi-Fi network. Nothing in this list ever reaches our servers or any third party unless you turn on Cloud sync yourself; see section 3.
2.4 What we don’t collect
- Your name (unless you put it in an issue report)
- Your email address, except if you voluntarily provide one when contacting support, or when you sign in to Frame Cloud
- Apple ID, Google account, or iCloud account information
- Advertising identifiers (IDFA or Android advertising ID)
- Precise location data
- Anything from your photo library beyond the photos you explicitly pick to upload
- The content of your photos. We never analyse it, and outside of a Frame Cloud you switch on yourself, we never receive it at all
- Health, financial, or biometric data
- Contacts, calendar entries, or other apps’ data
3. Cloud sync, only if you switch it on
Cloud sync is off by default and chosen per album. There are two separate clouds, and you decide if and which one an album uses.
3.1 iCloud Sync (Apple)
When you turn on iCloud Sync for an album, its metadata, edits, TV definitions and (if you also enable it) full-resolution original photos are stored in your own iCloud account, in the app’s private CloudKit database. This data is subject to Apple’s own terms and counts against your personal iCloud storage quota. We cannot read this data and never receive a copy of it. You can invite up to 5 other people to a shared album using Apple’s native sharing; participants in a shared album can see each other’s Apple ID.
3.2 Frame Cloud (Frame Photos Plus)
Frame Cloud is started from an Android phone and can then be joined from Android, iPhone, iPad, or Mac. Unlike iCloud Sync, Frame Cloud runs on our infrastructure: Google Firebase (Cloud Firestore and Cloud Storage), hosted in the europe-west4 region (Netherlands). When you use Frame Cloud, we store:
- Original photos, 4K renders, and thumbnails
- Album and photo metadata: names, ordering, crop and matte settings, TV definitions, and which photo is on which TV
- Your Google sign-in identity (a user id plus your display name or email), which is visible to the other members of the same Frame Cloud
Only the Frame Cloud owner and their invited members (up to 5) can read this data. It is encrypted in transit (TLS) and encrypted at rest by Google. We never look at your photos and never use them to train any model. If you leave a Frame Cloud, photos you already downloaded to your device stay there. If the owner deletes the Frame Cloud, its contents are deleted.
4. Purchases
Purchases run entirely through the App Store or Google Play. We never see your card details, billing address, Apple ID, or Google password. Our purchase-management provider, RevenueCat, receives the store receipt plus a pseudonymous app user identifier and returns only which entitlement (feature unlock) your install owns, not your payment information. When you use Frame Cloud, that pseudonymous identifier is your Frame Cloud account id, so a subscription follows your account across devices and platforms rather than being tied to a single phone.
5. Legal basis for processing (GDPR Art. 6)
- Anonymous analytics in the Apple app: our legitimate interest in improving the product (Art. 6(1)(f)). You can object to this processing at any time by toggling off “Send anonymous usage data” in Settings.
- Issue reports in the Apple app: performance of the support service you requested by tapping Send (Art. 6(1)(b)).
- Cloud sync (iCloud Sync and Frame Cloud): performance of the contract you enter into when you switch on cloud sync: storing and sharing your album across your devices and invited members is the service you asked for (Art. 6(1)(b)).
- Purchases: performance of the purchase contract (Art. 6(1)(b)) and compliance with our legal obligations around billing and tax records (Art. 6(1)(c)).
6. Who processes the data
- PostHog Inc.: analytics and issue-report intake. We use PostHog’s EU instance (eu.i.posthog.com), so your data is stored on servers located in the European Union and is not transferred outside the EEA. PostHog acts as a data processor on our behalf. PostHog privacy policy.
- Google Ireland Ltd.: hosts Frame Cloud on Firebase (Cloud Firestore and Cloud Storage), europe-west4 (Netherlands). Used only when you or someone else switches on Frame Cloud. Firebase privacy and security policy.
- RevenueCat, Inc.: validates purchase receipts and tracks entitlements. Receives the store receipt and a pseudonymous app user identifier only, never your payment details. RevenueCat privacy policy.
- Apple Inc.: App Store purchase, download, and delivery, and (if you turn on iCloud Sync) storage of your album data in your own iCloud account. Apple processes this data under its own privacy policy. We have no access to your Apple ID, payment information, billing address, or iCloud-stored content.
- Google LLC: Google Play download, delivery, and purchases. Google processes store metadata under its own privacy policy. We do not receive your Google password or full payment details.
We do not sell, rent, or share your data with advertisers, data brokers, or any other third party.
7. International data transfer
Analytics and issue-report data from the Apple app is stored on PostHog’s EU instance and remains within the European Economic Area. Frame Cloud data is stored in Google’s europe-west4 region (Netherlands). Two of our processors are US companies (RevenueCat, and Google LLC as the parent of the EU Firebase entity), and transfers to them are covered by the European Commission’s standard contractual clauses. RevenueCat only ever sees purchase receipts and a pseudonymous identifier, never your photos or personal profile. Store providers process download and purchase metadata under their own privacy terms.
8. How long we keep data
- Anonymous analytics events: retained for up to 12 months, then automatically deleted by PostHog
- Issue reports: retained for up to 24 months or until the issue is resolved, whichever is longer
- Local data on your device: kept until you delete the app or clear its data in your device’s Settings
- Frame Cloud content: kept for as long as the Frame Cloud exists and its subscription is active. If the subscription lapses, the Frame Cloud becomes read-only for 30 days, is then suspended, and its contents are deleted after 90 days of suspension. Leaving a Frame Cloud, or the owner deleting it, removes your access sooner; photos you already downloaded to your device stay there.
- Purchase records: kept for as long as needed to restore your purchase, and as required by tax and accounting law.
9. Your rights (GDPR Art. 15-22)
You have the right to:
- Request access to the data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Request restriction of processing
- Receive your data in a portable format
- Object to processing based on legitimate interest (also available as the in-app analytics toggle)
Because we use anonymous identifiers, we may not be able to locate events linked to a specific person without additional information from you (such as your distinct ID, visible in PostHog dashboard or available on request). To exercise any of these rights, email privacy@framephotos.app. We respond within 30 days.
10. Right to lodge a complaint
If you believe we are not handling your personal data lawfully, you can lodge a complaint with the Dutch Data Protection Authority Autoriteit Persoonsgegevens or with your local supervisory authority within the EU.
11. Children
Frame Photos is not directed at children under 16. We do not knowingly collect data from children. If you are under 16 and have submitted an issue report containing personal data, ask a parent or guardian to contact us at privacy@framephotos.app and we will delete it.
12. Changes to this policy
If we update this policy, the “Last updated” date at the top will change. Material changes will also be communicated through an in-app notice.
13. Contact
Privacy questions: privacy@framephotos.app
Other questions: see our support page.