Your privacy is central to Framekeep
Framekeep ("Framekeep," "we," or "us") provides a secure platform for delivering private galleries. This Privacy Policy explains how we collect, use, and safeguard information when you use our services and marketing site. By using Framekeep, you agree to this policy.
Last updated:
Information we collect
- Account details you provide, such as name, email, studio name, and login credentials.
- Content you upload or deliver through Framekeep, including images and gallery metadata.
- First-party product events and Web Vitals used to understand reliability and whether core gallery workflows succeed.
- Limited request information used for rate limiting, abuse prevention, and service security.
- Support communications and feedback you share with us.
How we use information
- Operate, maintain, and improve Framekeep services.
- Provide customer support and respond to requests.
- Secure accounts, prevent abuse, and enforce our policies.
- Send service-related updates; marketing emails are optional and you can opt out.
Sharing and disclosure
- We do not sell personal information.
- Cloudflare provides the Workers, D1, R2, KV, and network infrastructure used to operate Framekeep.
- We do not send gallery images to advertising networks or expose stored images through a public R2 custom domain.
- We may disclose information to comply with law, enforce our terms, or protect rights, property, and safety.
Data security and retention
Production traffic is redirected to HTTPS. Studio originals and free-gallery web-size viewing copies are stored in private R2 storage, account and gallery passwords are stored as salted hashes, and protected image routes require authorization or a time-bounded signed token. No system can prevent every forwarded link, screenshot, or device compromise. See the security and privacy controls page for implemented controls and limitations.
Data lifecycle
| Data | Current handling |
|---|---|
| Anonymous galleries | Client and edit access expires 14 days after creation. A browser-generated web-size copy is stored for viewing; photographers should keep full-resolution originals in their own archive. A scheduled cleanup process deletes expired gallery records and their stored objects; access ends at expiry even if cleanup has not yet run. |
| Studio accounts and galleries | Studio galleries close and move to a reversible archive 14 days after creation. Archiving ends client access and pauses uploads without deleting stored images. Contact support to request access, correction, export guidance, or deletion. |
| Feedback | Feedback submissions include the email, message, and a redacted page path. They are retained for up to 180 days for product improvement and support follow-up. |
| Security and operational records | Rate-limit records expire automatically. Other necessary operational records are retained only for service, security, abuse-prevention, support, or legal needs. |
First-party measurement
Framekeep records aggregate page, conversion, gallery-workflow, and Web Vitals events in its own database. Query strings and private tokens are removed or converted to route patterns before storage. Referrers are reduced to a coarse source category and the referring URL or domain is not stored. On eligible public page navigation, the server signs a random journey key with the redacted landing page and coarse source. A short-lived, first-party seed cookie copies that envelope into tab-scoped session storage and is then cleared; the journey expires within 24 hours. It is not an advertising identifier, account identifier, or cross-session profile. Analytics events do not contain raw search queries, IP addresses, email addresses, private gallery tokens, or user-agent text. Browser-reported upper-funnel and Web Vitals signals are rate-limited and treated as directional; gallery creation, upload, signup, favorite, and download events are recorded by the server. Conversion attribution is accepted only when the signed envelope verifies. Analytics events are deleted after 90 days by the scheduled cleanup process.
Your choices and rights
- Access, update, or delete your account data by contacting support or using in-product settings where available.
- Opt out of marketing emails using the unsubscribe link; we will still send essential service updates.
- Disable cookies in your browser; some features may not work without them.
Children
Framekeep is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us so we can delete it.
Contact
Questions or requests about this Privacy Policy? Email us at support@framekeep.com.