Framera

Legal

Privacy Policy

Last updated 13 September 2026

1. Who we are

Bytefold operates Framera and is responsible for the personal data described here.

This policy explains what we collect, why, who we share it with, and the choices you have.

2. What we collect

Account details:

  • your email address, your name if you give it, and a securely hashed version of your password — never the password itself;
  • your Google account ID, if you sign in with Google;
  • a public profile — handle, display name, bio and avatar — if you create one.

Your content:

  • prompts, uploaded images and audio, and saved elements with their photos;
  • the videos, images and audio you generate, and your projects, canvases and Agent chats.

Billing and usage:

  • your plan, subscription status and credit history. Card and payment details go to Paddle, our payment provider; we never see or store them.

Security and technical data:

  • the IP address and browser of each signed-in session;
  • server logs of requests to our service;
  • a record of the prompts our safety screening checks, and whether each was allowed.

Messages: what you send through the contact form, and reports you make about published content.

3. How we use it

  • to run the service: create your generations, keep your library and projects, and keep you signed in;
  • to charge credits and manage your plan;
  • to keep the service safe: prevent abuse and fraud, screen prompts and enforce our rules;
  • to email you about your account, billing, team and requests you make — service emails, not marketing;
  • to answer your messages;
  • to meet our legal obligations.

We don't sell your personal data, show you ads, or use your content to train AI models.

Where data protection laws such as the GDPR apply, we rely on performing our contract with you (running the service), our legitimate interests (security, abuse prevention and reliability) and legal obligations (tax and accounting records).

4. Who we share it with

We use these service providers, each only for the job described:

  • Paddle — checkout, payments, tax and invoices. As merchant of record, Paddle handles payment data under its own privacy notice.
  • Hetzner — hosts our servers and our database, in Finland.
  • Cloudflare R2 — stores uploads and generated files.
  • fal.ai, with Replicate as a backup — run the AI models, and receive the prompt and inputs for each generation.
  • Anthropic — powers the Cinema Studio director, the Agent and the Help Center assistant, and receives the text you send those features.
  • Brevo — sends our emails.
  • Google — only if you choose to sign in with Google.

Other people see your data only when you choose: posts you publish are public with your profile, and a post's prompt is shown only if you allow it. In a team workspace, the owner and admins can see members' email addresses, usage and credits spent.

We may disclose data when the law requires it, to protect people from harm, or as part of a sale or reorganisation of our business, in which case this policy continues to apply.

5. International transfers

Our providers process data in several countries, including the United States. Where the law requires it, transfers rely on recognised safeguards such as standard contractual clauses.

6. How long we keep it

We keep your account and content while your account is open. When you close your account, or delete files, we delete that data within a reasonable period, except what we must keep.

Billing and credit records are kept as long as tax and accounting law requires. Safety records, such as blocked prompts and reports, are kept as long as needed to protect the service and meet legal duties.

Sign-in sessions expire 30 days after they were last used. Password reset links expire after one hour.

7. Your rights

Depending on where you live, you can ask to access, correct, export or delete your personal data, object to or restrict how we use it, and withdraw consent where we rely on it. Use our Contact page, or email support@bytefold.io. We will respond within the time the law requires. You can also complain to your local data protection authority.

8. Security

Passwords are stored as salted hashes, sign-in sessions use secure cookies, connections are encrypted, and our database and file storage providers encrypt data at rest. No system is perfectly secure, so please use a strong password you don't use elsewhere.

9. Children

The service is for people aged 18 and over. We don't knowingly collect data from children. If you believe a child has an account, contact us and we will remove it.

10. Cookies

We use a small number of essential cookies, listed in our Cookie Policy.

11. Changes to this policy

We will post changes here and, if they are significant, tell you by email before they take effect.

12. Contact

Questions about your privacy? Use our Contact page, or email support@bytefold.io.

See also Trust & Safety and Contact.

We use essential cookies to keep you signed in. We don't use advertising cookies, and any analytics we add will only run if you accept. Cookie policy