Privacy policy
Last updated September 22, 2026.
Local media processing
Your camera-original videos, local previews, project selections, LUTs, and local exports remain on your computer during Framecraft’s local workflows. Framecraft does not upload those items merely because you open, review, grade, or export them. Framecraft may store preferences, source-profile selections, file paths, job-recovery information, and cached previews under the current Windows user’s local application-data folders.
Direct GPU playback keeps a local summary of the latest playback session’s numeric performance counters, dimensions, and renderer name. It contains no source filename, pictures, account details, or keys; it replaces the previous summary and is not automatically uploaded or attached to support reports.
Account information
Framecraft uses Google sign-in through Firebase Authentication for optional Framecraft account and direct-download license features. We store your Firebase user ID, email address, display name, profile image URL, and license status so we can provide and support your account. Administrator access uses the same Google sign-in with an additional server-controlled role. Core local frame selection and export do not require a Google account.
Google is our only sign-in provider. We never create, receive, or store a Framecraft password or your Google password. Google handles authentication and account recovery; Firebase verifies sign-in. Google/Firebase session tokens maintain your signed-in session. The Windows app keeps its revocable Firebase refresh token in Windows Credential Locker. Our backend keeps account, license, purchase, and credit records—not passwords.
Payments
Microsoft processes purchases made through the Microsoft Store under its own privacy and payment terms. Framecraft may receive the licensing, transaction, and reporting information Microsoft makes available to publishers, but does not receive your full payment-card number.
Stripe processes direct-download license purchases made on framecraftapp.com. Framecraft does not receive or store your full card number. We store Stripe customer, Checkout Session, payment, refund, dispute, product, and purchase identifiers needed to fulfill an order, prevent duplicate fulfillment, and provide support.
SeedVR2 local and cloud processing
Local SeedVR2 does not upload your photos. Its optional setup downloads software and model files from the documented sources. When you approve cloud SeedVR2, only the selected rendered stills and processing settings are uploaded to Framecraft's Google Cloud backend and sent to fal.ai. Your source video is not uploaded. The backend converts stills to 8-bit PNG for processing, and the AI PNG result is separate from your original local 16-bit TIFF master.
Stripe handles purchases of Framecraft cloud credits. We retain balances, reservations, consent, purchases, job IDs, status, and security records to fulfill work, avoid duplicate charges, reconcile uncertain jobs, and provide support. Cloud image objects are temporary and subject to our configured cleanup lifecycle; financial and job records may be retained longer. fal.ai processes and retains data under its privacy policy and API service terms. Cloud users must be adults and have the necessary rights and consent for uploads. The fal API key is stored only in Google Secret Manager on our server, never in the website or desktop app.
Optional Topaz upscaling
Your camera-original videos remain on your computer. If you explicitly select Topaz upscaling, Framecraft renders only the still image you selected and sends that still and the requested processing settings directly from your computer to the Topaz Labs Image API. The image does not pass through Framecraft’s Firebase or Google Cloud backend. Topaz processes the still and returns a separate derivative to your computer. Topaz may collect, use, and temporarily retain image and operational data under its own privacy policy and terms.
You obtain your Topaz API key directly from Topaz. Framecraft saves that key for the current Windows user in Windows Credential Locker. It is not written to Framecraft’s preferences file, included in exported images, sent to Framecraft, Firebase, Google Cloud, Microsoft, or Stripe, or exposed in ordinary application logs. The key is sent only to Topaz when needed to perform a request you initiate. You can remove the saved key in Framecraft, and you can revoke or replace it through your Topaz account.
Optional website analytics
If you choose “Allow analytics,” our website loads Google Tag Manager and Google Analytics 4 to measure website visits and when a visitor starts checkout for an upscaling credit pack. Analytics may use first-party cookies and browser/device information, approximate location, and a pseudonymous browser identifier. We send only allowlisted page addresses without query strings or fragments, referring-site origins without their paths or query strings, and the selected credit-pack size, listed price, and currency. A checkout-start event does not mean a payment was completed.
We do not send your name, email, Firebase account ID, API keys, payment or sign-in session identifiers, photo/video contents, filenames, or private download links to analytics. Desktop sign-in and payment-return visits are excluded. Google signals, advertising personalization, and automatic enhanced-measurement events are disabled. This website setup does not track activity inside the Windows app.
Analytics is off until you allow it. “Reject analytics” has no effect on your ability to use Framecraft, sign in, or buy credits. You can change your choice using Cookie preferences on the website. Rejecting after previously allowing analytics removes our accessible first-party Google Analytics cookies and reloads the website to stop its analytics code. It does not erase information already processed by Google. We remember your choice in this browser for up to 180 days using essential preference storage. Google describes its processing in its privacy policy and information about partner sites. Search Console separately provides search-performance reports; it does not require an analytics cookie on this website.
Security and service records
Optional bug reports and feedback
Framecraft can save a small local report after an error or an interrupted session, including a forced quit or power loss. Automatic diagnostics include the app version, operating-system family, architecture, exception type, error code and Framecraft code locations. They exclude raw logs, exception messages, memory dumps, screenshots, footage, media paths, API keys and authentication tokens.
Reports are sent only after you review and approve them. Help also provides feedback and feature-request forms. Sending requires Google sign-in and associates the report with your Firebase account ID and email for support and abuse prevention. Do not paste credentials or private customer information; common secret/path redaction is not exhaustive. Local drafts last saved more than 30 days ago are cleared on the next app launch. Submitted reports and notification records expire after 90 days and are deleted by daily cleanup. Authorized administrators can download reports for investigation, including with Codex. Notification emails contain a reference and private inbox link, not your message or diagnostics. The support inbox does not run website analytics.
Installer downloads use expiring links. We may record account, release, device-login, security, and error metadata needed to operate the service, investigate abuse, and provide support. Desktop sign-in stores a revocable Firebase refresh token in Windows Credential Locker; the website never receives your Windows password.
Sharing and service providers
We share information only as needed with service providers that operate authentication, hosting, payments, distribution, support, and user-directed processing; to complete a transaction or request; to protect users or services; during a corporate transaction; or when required by law. Providers process information under their own terms or contractual obligations. We do not sell personal information for money or use camera-original videos to train AI models.
Retention, choices, and rights
We retain account, transaction, support, and security records only as long as reasonably needed for the purposes above, legal obligations, dispute resolution, fraud prevention, and enforcement. Different records have different retention periods. Local files remain under your control. You may sign out, delete cached local data using Windows controls, remove a Topaz key inside Framecraft, revoke provider credentials with the provider, or request access, correction, or deletion of eligible account information.
Privacy rights vary by location and may include access, correction, deletion, portability, restriction, objection, or appeal. We may verify a request before acting and retain information that applicable law permits or requires us to keep.
Children and changes
Framecraft is not directed to children under 13 and we do not knowingly collect their personal information. We may update this policy as the product, providers, or law changes. Material changes will be identified by a new date and, when appropriate, additional notice.
Contact
Privacy questions or account-data requests may be sent to jd@wildwooddm.com.