Privacy Policy
Last updated: July 20, 2026
Frame is an iOS app that helps you read a dating conversation and choose your next message. You paste a conversation (as text or screenshots) and Frame returns a read of the situation and a suggested next move. Handling that kind of content carefully is the whole job, so this policy is written to be read, not skimmed past.
The short version: no real email, no real name. Frame identifies you only through a pseudonymous Device Account with a random ID. Conversations you submit are processed to generate your read and deleted automatically after 30 days. Traits, useful facts, and per-person context saved to Memory stay available so later reads can use them; you can view, edit, or delete individual items, clear Memory, delete a profile, or delete all Frame data at any time. We never sell your data, never use it for advertising, and never allow it to be used to train AI models.
1. Who is responsible
The controller for data processing in connection with Frame is:
YANGOT Technologies UG (haftungsbeschränkt)
Fasanenstraße 67i
82008 Unterhaching, Germany
Managing director: Waldemar Panin
Email: frame@panin.de
2. What we collect and why
Pseudonymous Device Account
When you first open Frame, the app creates a pseudonymous Device Account with a randomly generated user ID. There is no visible login. Frame uses synthetic, app-generated credentials and does not ask for your name, real email address, phone number, or password. In releases that use protected account creation, Apple App Attest must first verify that the request comes from a genuine installation of Frame. Everything below is linked only to the random Device Account ID.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
Conversations you submit
The core feature. When you request a read, we process:
- the conversation text you paste, and/or
- screenshots you upload (up to 3 per read), from which we extract the message text.
Screenshots are processed to extract the conversation text and are not stored as images. Extracted transcripts and the reads generated from them are stored under your anonymous ID so the app can show you your results, and are deleted automatically after 30 days. You can delete them at any time before that (see section 6).
Conversations may include messages written by another person. We process this content solely on your request, solely to generate your read, with the short retention and no-training guarantees described here. Please only submit conversations you are personally part of.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for any third-party content, our legitimate interest in providing the service you requested (Art. 6(1)(f) GDPR), safeguarded by data minimisation, short retention, and no secondary use.
Onboarding answers, Memory, and profiles
During onboarding you answer a few questions about your dating situation. Frame may also save traits, preferences, useful facts, dating-interest profiles, and per-person context (together, "Memory") so later reads are more relevant. These items are stored under your anonymous ID and are separate from 30-day Read History. They remain until you edit or delete an item, clear Memory, delete the relevant profile, or delete all Frame data. Memory and profiles are visible and editable in the app.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
Purchases
Subscriptions are bought through Apple and managed by RevenueCat, our subscription infrastructure provider. We receive your anonymous user ID, the product you bought, and the subscription status — never your payment details, which stay with Apple.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
Subscription and usage abuse prevention
To stop deleting and recreating a Device Account from resetting paid usage limits, Frame stores a deployment-keyed hash derived from the verified App Store purchase scope and the time a Read was consumed. This record contains no raw transaction ID, Device Account ID, conversation, screenshot, or generated Read, and has no foreign key to account data. It expires after seven days and is scheduled for physical deletion by the daily cleanup worker, so it is retained for at most about eight days during normal operation. Deleting a Device Account does not delete this short anti-abuse record early because doing so would let deletion reset the usage allowance.
Legal basis: our legitimate interest in protecting paid service limits and preventing abuse (Art. 6(1)(f) GDPR).
Usage analytics
We collect first-party product events (for example: onboarding step completed, read requested, error shown) to understand whether the app works and where it fails. These events are linked to your anonymous ID and never contain your conversation content, screenshots, or names. The same events are mirrored to PostHog, our analytics processor (EU cloud hosting), under the same anonymous ID; your PostHog profile is deleted when you delete your data. We do not use advertising or cross-app tracking SDKs, and we do not track you across other companies' apps or websites.
Legal basis: our legitimate interest in improving and securing the service (Art. 6(1)(f) GDPR).
App and device integrity
Frame uses Apple's App Attest and DeviceCheck services to verify that requests come from a genuine copy of the app and to prevent reinstalling from resetting a one-time feature. We process cryptographic app-integrity keys, attestations, and Apple risk assessments linked to your pseudonymous Device Account. These records contain no conversation content. Verified integrity records remain with the Device Account until you delete your Frame data, except where a short security or legal retention requirement described below applies.
Legal basis: our legitimate interest in securing the service and preventing abuse (Art. 6(1)(f) GDPR).
Account-creation abuse prevention
For protected Device Account creation, requests go directly to Frame's account-bootstrap Edge Functions hosted by Supabase. Supabase necessarily processes the requesting network address, request metadata, and the short-lived app-integrity and account-bootstrap payload while routing and executing the request. These requests do not contain conversation text, screenshots, your name, real email address, or phone number.
During first-run account creation, Frame temporarily stores keyed hashes of an app-generated capability and network source together with short-lived App Attest challenge and receipt data. Frame's handler does not store the raw network address or raw capability in these controls. Challenges expire within two hours. An account-creation capability may provision an account only during its twenty-minute lifetime; if account creation committed during that window, its keyed control record may be used for up to one additional day solely to finalize that same authenticated account after an interrupted response. An expired capability cannot provision another account. These controls and keyed network rate-limit records are scheduled for deletion by the daily cleanup worker, so the finalization control is normally physically removed within about two days after its original expiry. A broker-created Device Account that is never completed is eligible for deletion after one day and is removed on the next successful cleanup run.
Legal basis: our legitimate interest in securing account creation and preventing automated abuse (Art. 6(1)(f) GDPR).
Notifications
If you opt in to notifications, iOS handles the permission. You can turn them off any time in system settings.
Legal basis: your consent (Art. 6(1)(a) GDPR).
3. AI processing
Frame uses large language models to extract the conversation you submit and to generate your read:
- Conversation extraction: Google Gemini API (Google LLC / Google Ireland Ltd.) receives the text and screenshots you submit.
- Read generation: models accessed via OpenRouter, Inc., configured to deny data collection and require zero-data-retention routing — providers that would store or log your content are excluded.
Screenshots are not stored as images. After Gemini extracts the transcript, Frame replaces recognized email addresses, links, social handles, phone numbers, and precise street addresses with stable placeholders before the transcript is stored or sent to OpenRouter. Names, workplaces or schools, and other conversation details remain because they can be necessary for meaningful advice and for referring clearly to the people involved. This reduces some direct contact and location data; it does not anonymize the conversation.
Your conversations are sent to these providers only to generate your read, and are not used to train their models. We send only what is needed for the read; your anonymous ID is not shared as part of the model input.
You can stop future AI sharing in Frame under Settings → AI providers → Stop sharing conversations with AI. Frame will not send another conversation to Google Gemini or OpenRouter unless you agree again. Stopping future sharing does not delete data already stored by Frame; use Settings → Delete my Frame data to erase it.
4. Service providers
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Backend and Edge Function hosting, database, pseudonymous Device Account authentication | EU/US (region-pinned hosting) |
| Google (Gemini API) | Extracting the conversation from submitted text and screenshots | EU/US |
| OpenRouter, Inc. | AI read generation (zero-data-retention routing enforced) | US |
| RevenueCat, Inc. | Subscription management | US |
| PostHog, Inc. | Product analytics (anonymous events, EU cloud hosting) | EU |
| Apple Inc. | App distribution, payment processing, notifications | US |
Where providers process data outside the EU/EEA, transfers rely on the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses (Art. 46 GDPR).
5. Retention
- Transcripts and reads: deleted automatically after 30 days.
- Screenshots: not stored; processed for text extraction only.
- Onboarding answers: kept while your Device Account exists, deleted when you delete your data.
- Memory traits, facts, profiles, and per-person context: kept until you edit or delete an item, clear Memory, delete the relevant profile, or delete all Frame data. These are not removed by the 30-day Read History cleanup.
- Analytics and purchase records: kept while your Device Account exists, deleted when you delete your data, except where a legal retention duty applies.
- Verified app-integrity records: kept with your Device Account until you delete your Frame data, except where a short security or legal retention requirement applies.
- Account-creation controls: challenges expire within two hours; provisioning capabilities expire after twenty minutes; an exact committed account may be finalized for one additional day; expired controls and keyed network rate-limit records are normally physically removed by the daily cleanup worker within about two days after expiry. An abandoned broker-created Device Account is eligible for deletion after one day and is removed on the next successful cleanup run.
- Subscription usage anti-abuse records: expire after seven days and are normally physically removed by the daily cleanup worker within about eight days. They are not deleted early when a Device Account is deleted.
- Records we are legally required to keep (e.g. for tax purposes) are retained for the statutory period.
6. Deleting your data
You can manage saved context at any time in Settings → Memory and Settings → Profiles. To erase everything, open Settings → Delete my Frame data. This permanently deletes your transcripts, reads, onboarding answers, Memory traits and facts, profiles and per-person context, analytics events, and credit records from our systems, and clears the app on your device. The short deployment-keyed subscription usage record described above is not linked by a foreign key to the Device Account and remains only until its scheduled expiry so deletion cannot reset paid usage limits. Because the Device Account contains no login identity, there is otherwise nothing left that identifies you afterwards.
7. Your rights
Under the GDPR you have the right to access, rectify, and erase your personal data, to restrict or object to processing, and to data portability (Art. 15–21 GDPR). You can exercise most of these directly in the app; for anything else, email frame@panin.de. Because Device Accounts contain no login identity, we may be unable to link you to stored data unless the request comes from your app installation.
You also have the right to lodge a complaint with a supervisory authority, for example the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.
8. Children
Frame is intended for adults and is not directed at anyone under 18. We do not knowingly process data of minors.
9. Changes
We will update this policy when our data practices change and post the new version here with an updated date. Material changes will be highlighted in the app.