Skip to content
RAWFRAME

Privacy Policy

What we collect, why, and how long we keep it.

Last updated 31 August 2026

Who is responsible for your data

RAWFRAME is responsible for the personal data described in this policy. For anything relating to your data — including the rights set out below — contact us at rawframebusiness@gmail.com.

What we collect, and why

Grouped by purpose, because that is what actually determines how long we keep it:

  • Account — your email address, an account identifier, and session data. To give you an account and keep you signed in.
  • Your content — the reference photos you upload, the images you generate, which scene and quality you chose, and technical metadata about each generation. To deliver the service you asked for.
  • Billing — your plan, subscription state, credit balance and ledger, and the Stripe customer, subscription and payment identifiers. To charge you correctly and keep accurate records.
  • Abuse prevention — hashed device and network signals, rate-limit counters, and a risk score. To stop free-trial farming and automated abuse.

Photos you upload

When you upload a reference photo, it is processed in your browser first: we detect the face and crop to it. Only that cropped version is sent to us.

On our side we re-encode the image, which removes all embedded metadata — including the GPS coordinates most phones attach to photos. The original full-size file is never stored.

Processed photos are held in private storage. There is no public URL. Access requires a short-lived link that only works for your signed-in account.

What we do — and do not do — with faces

Your browser may draw a box around the face in your photo to suggest a crop. Where your browser offers no face detection at all — Safari and Firefox do not — nothing is detected and we fall back to a simple portrait crop.

From that step we store exactly three values alongside your photo: whether a face was detected, a confidence score, and roughly how much of the frame the face fills. They are quality hints that tell us whether a reference is likely to produce a good result.

We do not create face embeddings, biometric templates, faceprints or facial landmark records. We do not run face recognition, and we never match one person’s face against another photo, another account, or any database. Your photo is stored as a private image and sent to our AI provider to generate your result — nothing more is derived from it.

Generated images

Your results are stored privately under the same rules. Only you can view or download them.

Retention — 30 days

Reference photos and generated images are deleted 30 days after they are created. This is strict: re-using a photo does not extend it.

Deletion removes the actual file from storage, not just its listing in the app. A record of what was charged is kept for accounting, without the image.

AI processing

To create an image we send your cropped reference photo, together with the scene’s instructions, to our AI provider (currently OpenAI). They process it to produce your result.

We send an anonymous account identifier for abuse monitoring. We do not send your name, email address, or payment details.

Payments

Payments are handled by Stripe. Card details go directly to Stripe and are never seen or stored by RAWFRAME. We keep a record of which plan you are on and what was purchased.

Preventing free-trial abuse

The one-time free credits are worth farming, so we check a few signals before granting them: a first-party cookie we set, a coarse browser fingerprint, and your network address.

Every one of these is hashed before it is stored. We do not keep your raw IP address or a raw fingerprint, and we do not use face recognition to link accounts.

If the checks suggest the free trial has already been used, the account still works normally — it simply starts with no free credits.

Cookies and storage

We use cookies to keep you signed in and to set the device identifier described above. There is no third-party advertising or cross-site tracking.

If you choose a photo before signing in, it stays in your browser and is not sent to us until you have an account and press Generate.

Deleting your account

You can delete your account at any time from Settings. This removes your photos, generated images, saved faces, and favorites, and stops any plan from renewing.

Records of completed payments are retained by Stripe under their own legal obligations.

One limited exception: we keep a pseudonymised device signal — a one-way hash of a first-party identifier we set in your browser, together with the fact that the one-time free-trial credit was claimed — for up to 365 days after deletion. This exists solely to stop the same device claiming the one-time free offer repeatedly by deleting and recreating accounts.

It contains no name, email address, photograph, or generated image, and it cannot be used to identify you or to recover your account. We do not use facial recognition or any biometric identifier for fraud prevention. After 365 days the record is deleted automatically and the device is treated as new.

Who processes data for us

These are the providers that handle data on our behalf:

  • Supabase — database, authentication and private file storage.
  • Netlify — application hosting and delivery.
  • OpenAI — image generation. Receives your cropped reference photo, the scene instructions, and an anonymous account identifier.
  • Stripe — payment processing. Receives your payment details directly; we never see or store card numbers.
  • Upstash — rate-limit counters, keyed on hashed identifiers.
  • Resend — transactional email, such as sign-in and password-reset messages.

We do not sell your data, and we do not share it for advertising.

Where your data is processed

Some of these providers operate outside the European Economic Area, including in the United States, so your data may be transferred and processed there under the safeguards those providers offer — typically the European Commission’s standard contractual clauses.

We do not claim that your data is stored only in the EU. If you would like to know which regions a particular provider handles your data in, ask us and we will tell you.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or erased, to object to or restrict how we use it, to receive a copy in a portable format, and to withdraw consent where our use rests on it.

You can exercise the most common of these yourself: your photos, generated images and account are deletable from Settings at any time. For anything else, contact us and we will respond within the time your law allows.

You also have the right to complain to your local data protection authority. We would rather you came to us first, but that right is yours regardless.

Our lawful bases are, broadly: performing our contract with you (delivering generations, billing), our legitimate interest in preventing fraud and abuse, and our legal obligations for financial records.

Contact

Questions about your data? Get in touch.