Finger Frame
Legal

Privacy Policy

Last updated 11 August 2026 · Applies to Finger Frame for iPhone and to fingerframeapp.com

The short version

Who is responsible for your data

Finger Frame ("the app") is provided by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("we", "us"). We are the controller of the personal data described in this policy for the purposes of the UK and EU General Data Protection Regulation.

Privacy questions, requests and complaints: founders@fingerframeapp.com. [EU/UK REPRESENTATIVE, IF REQUIRED BY GDPR ART 27]

What the camera is used for

The app needs the camera because the camera is the interface. Every video frame is analysed on your iPhone to locate the joints of your hands, so the app can tell when your thumbs and index fingers have closed a rectangle and where its corners are. That analysis uses Apple's on-device Vision framework. It happens inside the app on your device, produces coordinates rather than pictures, and sends nothing over the network.

The live preview you see is composited on your device's GPU. If you have chosen one of the five on-device styles (Pixel, Glow Up, Noir, Chroma, Negative) the app makes no network connection for rendering at all — those styles are arithmetic running on your phone, and they work in aeroplane mode.

Recordings are written to your device's private app storage, and a copy of every finished recording is also uploaded to our own storage in the background — whatever style you used, and without asking you each time. Being uploaded is not being published. An uploaded recording stays private to you until you choose to share it, and it is deleted after 30 days whether you ever share it or not. Section 4 is exactly what is stored, who can reach it, and how to have it removed sooner.

Microphone

A recording's soundtrack is either the app's own music track or no sound at all, so nothing you say is recorded — no soundtrack option captures the microphone, and no audio from you is mixed into the file. The app does still ask for microphone permission when you open it, because the recorder keeps the ability to use it; refusing changes nothing about what you can record today. Audio is never sent to an AI provider either — the generative models receive video only.

What is sent to AI providers, and when

The generative styles (Anime, Clay, Sketch, Oil Paint, and any style you write yourself) cannot run on a phone. They run on a third party's accelerators, which means your video has to be sent there while you record. This is the single most significant thing this policy has to tell you, so it is spelled out precisely.

Nothing is sent until you pick a generative style and start a session. Two different providers are used, depending on the style:

ProviderWhat it receivesRoute
fal.ai
(runs the FLUX.2 [klein] model)
Still images taken from your camera feed, roughly 8 per second, downscaled to 768 × 768 pixels and JPEG-compressed, for as long as your session is open. Through our own relay server, which exists so that our API key is not shipped inside the app. The relay passes each image straight through and does not write it to disk.
Decart
(runs the Lucy 2.5 model, via fal.ai)
A live video stream from your camera for the duration of the session. Directly from your iPhone to Decart's media servers over WebRTC. Our relay only helps the two ends find each other (it passes connection details, never the video).

Be aware of what is in the picture. The image sent to the provider is the camera's view, and the app crops down to the inside of your finger frame after the restyled result comes back. So the provider receives more of the scene than the part you framed — including your face, other people, and the room around you. Point the camera accordingly, or use an on-device style, which sends nothing.

These images and streams are sent so that the provider can render the frame you are looking at and return it. They are processed to produce that output and, per our arrangement with each provider, are not used to train their models. We do not keep a copy of any frame sent for rendering: the relay passes each one through without writing it to disk, and there is no archive of the frames a session sent. The finished recording is a different thing from the frames that rendered it, and that one is uploaded to us — section 4.

Each provider's own handling of the data is governed by its terms: fal.ai privacy policy and Decart privacy policy.

We send no identifier alongside the frames. The provider receives the imagery and the style prompt, and nothing that names you.

Your recordings, and the ones you share

When a recording finishes, the app uploads a copy of it to our storage in the background. It does this for every finished recording, whatever style you used, and it does not ask you each time. The upload is what makes a share link work the moment you want one instead of after a wait on whatever connection you happen to be on. An upload that is interrupted is retried later, so it may complete some time after you recorded.

Uploading is not publishing. An uploaded recording is stored unshared, and while it is unshared it has no working web address at all: there is no page to open, for you or for anyone else. Sharing is a separate, deliberate action in the app. When you share, that one video becomes readable by anyone holding a link of the form www.fingerframeapp.com/c/<slug>. The slug is a short random string; it is not derived from anything about you and cannot be guessed by counting upwards.

The three optional collections

Beyond making the app work, there are three things we collect that are not needed to make it work. Analytics is on from the moment you install the app. This app is not on the App Store for anyone to download: it is given out privately, and everyone who is given it has already agreed to analytics as a condition of getting it, so the app does not ask a second time. The other two — the prompts you write, and hand-position numbers — are off until you turn them on, and we ask in a prompt that explains the specific purpose; "carrying on using the app" is never taken as agreement.

You can turn any of the three off at any time, including analytics, by writing to founders@fingerframeapp.com. That stops the collection from that moment and lets you have what was already gathered deleted — section 9 is what to send and what we do. There is no switch inside the app yet, for any of the three. The app is fully functional with all three off, and turning them off costs you no feature and no credits.

a. Product analytics (on by default)

Analytics is on when you install the app. The app sends us events about how the app is used — which screens are opened, which style was chosen, how long a session ran, whether a recording completed, and credit balance changes — together with your app version, the major version of iOS, and which iPhone model you have. The model is there because hand detection behaves differently on different generations, so "the gesture does not work" can turn out to mean "the gesture does not work on an iPhone 12". Events are deleted after 90 days. To have analytics turned off and the events we hold deleted, ask us — section 9.

Events carry a random install identifier: 128 random bits generated on first launch and stored only in the app's own storage. It is not Apple's advertising identifier, not your device's serial number or IDFV, and not anything that survives deleting the app — delete the app and that identifier is gone, and a fresh install is an unrelated one as far as this data is concerned. There is no button in the app for resetting it while keeping the app; what we can do on request is delete the events themselves. Your IP address is not stored alongside events, and the connection sets no cookies, so there is no second identifier that could outlive it.

What analytics deliberately does not include: no crash reporting or session replay, no screenshots, no camera images, recordings, audio or prompt text, no location, locale or time zone, no screen size, and no third-party analytics SDK of any kind. Nothing is shared with an advertising network, because there is no advertising.

b. The prompts you write

A prompt is something you wrote, not a measurement, and people type names into free-text fields. So this one is asked for at the moment you type — a tick box under the field, unticked — rather than once in a settings screen, and what leaves the phone is screened on the phone first:

Prompt reports carry no install identifier and are deliberately not linkable to your analytics events or to each other, so the prompt collection cannot become a record of what one person types. We use it only to find which looks are popular enough to become proper built-in styles. Text that no one has reviewed is deleted after 30 days.

Two honest caveats. First, no automatic check can tell a famous name from your friend's name — "in the style of Studio Ghibli" and "make Sarah look like a puppet" look identical to it — which is why the cautious branch is the default. Second, because a report carries no identifier, we cannot pick out yours to delete on request; what we can do is delete a specific prompt if you tell us the wording, and the 30-day window means unreviewed text does not sit around. Please still avoid typing anything confidential.

c. Hand-position data for training a model

The app's gesture detection is built on a general-purpose hand model that was not designed for this gesture, and it is the part of the app most likely to be frustrating. To improve it we would like to collect examples.

If you turn this on, what we collect is numerical landmark coordinates only — the positions of hand joints as x/y numbers, the app's own confidence values, which iPhone model and which camera, and a timestamp rounded to the hour so the set cannot become a record of when you are at home. We deliberately do not collect the image or any crop of it. No frame, crop, thumbnail or pixel buffer leaves your phone for this purpose — the code that writes these samples cannot accept an image at all.

Samples wait on your phone for at most 14 days before being destroyed whether or not they were ever uploaded, in a file that is encrypted whenever the device is locked and excluded from iCloud and device backups. Nobody's hand geometry should end up silently copied into a backup they cannot see.

This option, and only this option, uses a second identifier: a contributor reference, a random value created when you agree and destroyed when you withdraw. It is not your install identifier and it does not survive a reinstall; withdrawing and agreeing again produces an unrelated value. It exists because without some handle we could not find your samples in order to delete them.

Landmark data is used only to train and evaluate our own gesture-detection model. It is not sold, not shared with advertisers, and not used to identify anybody. Uploaded samples are destroyed 180 days after upload at the latest — see section 7 for the full published schedule and the biometric-specific notice that applies here.

Turning on either of the two optional collections requires you to confirm that you are 16 or older. Analytics does not ask, because it is already on — if the app is being used by someone under 16, write to us and we will turn it off and delete what was collected. See section 11.

Other data

WhatWhyNote
Purchases of credits To sell you credits Handled entirely by Apple through the App Store. We never see your payment card, and Apple does not give us your name or address. What we do keep is a record of the purchase: Apple's transaction identifier, which credit pack it was, and how many credits it granted. That record is what stops the same purchase being credited twice, and it is what lets us put your credits back if something goes wrong.
Your credit balance So the credits you paid for are still there Your balance is kept on our server as a list of movements — credits added by a purchase or a referral, credits used by a recording — attached to your account: a random identifier for your app install, plus the Apple Account identifier from signing in. Not to your name, which we never ask for. The app keeps its own copy so it works offline, and the two are reconciled when you have a connection. We keep the list rather than a single number so that a mistake can be traced and corrected rather than argued about.
Sign in with Apple (required) To hold your credits, to carry them to another device, and to reach you about a purchase Signing in is how the app opens, and it asks again on every launch until it succeeds. Apple gives us a stable identifier for your Apple Account and an email address — the latter only on the first authorization you ever give this app, which is why we keep it rather than ask again. Apple lets you hide your real address, in which case what we receive is a @privaterelay.appleid.com alias that forwards to you and that you can switch off at any time. Your credit balance is attached to that identifier, which is what lets an unspent balance follow you to a second device or survive a reinstall. The address is used only for messages about your purchases or your account. We do not use it for marketing and we do not pass it to anyone.
Waitlist answers To know whether people want a feature before it is built, and to tell you when it opens When the app asks whether you want early access to something, your answer is recorded either way — yes and no are both useful, and being asked is the measurement. Stored with it: anything you typed in the box, and the address Apple released to us so we can tell you when it opens. Deleted after 30 days.
A recording queued to be re-rendered To finish a render that failed part-way If the AI provider fails while you are recording, the recording still happens and the take is queued to be processed again when the model is back. The queued job holds its length, the style, and your prompt if you wrote one — a prompt is kept here because it is the instruction needed to run the render again, and this is not the optional prompt collection in section 5b. Your email address is on the job only if you asked to be told when it is ready. Deleted 30 days after it finishes or fails.
Referral links To credit the person who invited you An invite link carries a random referral code belonging to the sender's install. When a referred install records its first video we record that one install referred another. No names are involved.
Server logs Security, abuse prevention, keeping the service up Our relay and web server record connection metadata, including IP address, timestamp and which route was used. Retained for 30 days, then deleted. Not joined to analytics and not used to build a profile of you.
Emails you send us To answer you Kept for as long as needed to deal with your query, and up to 24 months for a record of what was asked.

This website does not use cookies, does not embed third-party fonts, scripts, analytics or social widgets, and loads nothing from another company's servers.

Legal bases, and where biometrics law applies

If you are in the UK, EU or EEA, we rely on the following bases under Article 6 GDPR:

PurposeBasis
Rendering the style you chose, including sending frames to the AI providerPerformance of a contract (Art 6(1)(b)) — it is the service you asked for and cannot be delivered any other way
Hosting and serving a video you chose to sharePerformance of a contract (Art 6(1)(b))
AnalyticsConsent (Art 6(1)(a)), given before the app is handed over as a condition of receiving it, withdrawable at any time
Prompt collection, hand-landmark collectionConsent (Art 6(1)(a)), given separately for each in the app, withdrawable at any time
Server logs, fraud and abuse prevention, referral integrityLegitimate interests (Art 6(1)(f)) — keeping the service available and stopping people from manufacturing free credits
Answering support email, meeting legal obligationsLegitimate interests / legal obligation (Art 6(1)(f), 6(1)(c))

Faces, hands, and what counts as biometric data

A camera pointed at a person records their face. Under Article 9 GDPR, imagery becomes "biometric data" in the special-category sense when it is processed for the purpose of uniquely identifying a natural person. We do not do that: the app has no face recognition, no identity matching, no face database and no way to tell one user from another. Hand tracking locates joints in order to place a rectangle, and the restyling models redraw pixels. Nothing in the app attempts to work out who anybody is.

Even so, hand and face imagery is sensitive and some US state laws define biometric identifiers more broadly than "used to identify". We therefore treat the optional hand-landmark collection (section 5c) as if it were biometric data, and give it the following specific notice.

Notice for Illinois, Texas and Washington residents

This notice concerns the optional hand-landmark collection only. If you have not enabled it, none of it applies to you, and no other part of the app collects or stores a biometric identifier.

Who else processes data

We use as few third parties as we can. Each one below acts on our instructions under a written data processing agreement, or, where marked, as an independent controller of its own.

WhoRoleDataWhere
fal.aiAI inference providerCamera frames during a generative session; the style promptUnited States
DecartAI inference provider (realtime model, reached through fal.ai)Live camera video during a Lucy sessionUnited States and Israel
[HOSTING PROVIDER, e.g. Railway]Hosting for our relay, share pages and shared-video storageShared videos; server logs; optional analytics, prompts and landmark data[REGION]
AppleIndependent controllerApp Store distribution, payment for credits, and any crash reports you have allowed iOS to sharePer Apple's own privacy policy

Your rights, and how to get data deleted

Depending on where you live you have some or all of the following rights: to know what we hold, to get a copy, to have it corrected, to have it deleted, to restrict or object to processing, to withdraw consent, and to complain to a regulator. Exercising any of them is free and we will not treat you differently for it.

Deleting your data

Deletion needs a handle. Because signing in with Apple is required, the address Apple released to us is one, so a single email is enough:

  1. What to send. Write to founders@fingerframeapp.com from the Apple Account address you signed in with. If you chose to hide your real address, the @privaterelay.appleid.com alias is the one we hold, and writing from it reaches us the same way. Add the /c/ links of any shared videos if you want those named specifically.
  2. What we do. We mark your account deleted, and from that moment it stops working: nothing reads it any more, so it has no balance, no credits, no waitlist answer and no queued render. We turn off all three collections, delete the optional data held for you, and delete every video we hold for you — the ones you shared and the ones you never did. We reply within 30 days. Recordings kept on your phone are yours; delete them like any other file.
  3. One exception, stated plainly. Prompt reports (section 5b) carry no identifier by design, so there is nothing to look you up by and we cannot single out yours. If you tell us the wording we will delete that prompt; otherwise the 30-day window on unreviewed text is the protection. Everything else — analytics, landmark samples, shared videos — we can and will delete.
  4. What stays, and why. A deleted account is not an erased one, and the difference is worth stating rather than burying. Your credit and purchase records stay — they are financial records we are required to keep, section 10. One of those records is the credits you were given for signing in, and its key contains the identifier Apple gave us for your Apple Account; the deleted account row keeps that identifier too. That is deliberate. It is the only thing that stops an account being deleted, made again, and paid the joining credits a second time, and there is no version of this where we both keep that defence and hold nothing. It is not a password and not a way in — signing in needs a token from Apple that we cannot produce — and it is used for nothing except refusing to pay the same grant twice.

Deleting the app is not a deletion request. It removes the app's own copy of your data and ends that install, but it does not reach anything we hold, and afterwards there is no identifier left on your phone to quote at us. If you want our copy gone, ask us first.

In the UK you may complain to the Information Commissioner's Office; in the EU/EEA, to your national supervisory authority.

How long things are kept

DataKept for
Camera frames sent for renderingNot retained by us. Processed in transit and discarded; the relay never writes them to disk.
Recordings on your deviceUntil you delete them or delete the app. We cannot reach them.
Videos uploaded from the app — which is every finished recording30 days from upload, then deleted automatically, whether or not it was ever shared. Sooner on request — see section 9.
Analytics events (on by default)90 days
Custom prompt text (opt-in)30 days unless a human has reviewed it and kept it as a candidate style
Hand-landmark samples (opt-in)14 days on the device; 180 days after upload. Full schedule in section 7.
Waitlist answers (the answer, anything you typed, your email address)30 days
A recording queued to be re-rendered (its style, your prompt if you wrote one, your email address if you asked to be told)30 days after it finishes or fails for good. A job still waiting is kept until it is one or the other — deleting it would throw away a recording we said we would re-render.
Server logs30 days
Support emailUp to 24 months
Credit and purchase recordsSeven years. This is the one thing on this page we cannot delete on request — see below.
Apple Account identifier and email addressKept as long as the credit and purchase records they belong to, i.e. seven years. A deletion request stops the account working but deliberately does not clear them — section 9, "What stays, and why", and "The exception is money" below.

Anything derived from the data in this table that no longer relates to an individual — an aggregate count, or a trained model's weights — may be kept after the source data has been deleted. We cannot reconstruct your data from it.

The exception is money. Records of purchases and of credits added or used are financial records, and we are required to keep them — for tax and accounting purposes, and to be able to answer a chargeback or a refund. They are kept for seven years and are outside the deletion request in section 9. What they contain is deliberately thin: Apple's transaction identifier, the pack, the number of credits, a timestamp, and the account they belong to. No name, no address, no payment details.

What that means for a deletion request. The record of the credits you were given for signing in carries a key that contains the identifier Apple gave us for your Apple Account, and the deleted account row keeps that identifier as well. A deletion request does not clear either, for the reason section 9 gives: that key is the only thing that stops the joining credits being collected again by deleting an account and making a new one. We would rather tell you it is there than claim these records cannot be traced back to you.

Children

The app is rated 12+ and is not directed to children. We do not knowingly collect personal data from a child under 13 (or under the equivalent age where you live). The two optional collections in section 5 require you to confirm you are 16 or older before they can be enabled, and they stay off otherwise. Analytics is on from installation and is not asked for in the app, so nothing confirms an age for it; if the app is being used by someone under 16, write to us and we will turn it off and delete what was collected.

If you are a parent or guardian and believe a child has enabled one of them or shared a video, email founders@fingerframeapp.com and we will delete it. A child can use the app's five on-device styles without any video going to an AI provider, and we would rather they did. The finished recording is still uploaded to us and deleted after 30 days (section 4), and analytics still records that the app was used; ask us and we will turn analytics off and delete what it collected.

Security and international transfers

Traffic between the app and our servers uses TLS. Our AI provider API keys live only on our relay and are never shipped in the app, which is why the relay exists. Access to stored data is limited to the people who need it. No system is perfect, and we would rather hold less data than defend more of it — that is why almost everything here is optional or transient.

We are based in [COUNTRY] and our providers are largely in the United States, so personal data may be transferred outside the UK/EEA. Where it is, we rely on the UK Addendum and the European Commission's Standard Contractual Clauses, or on an applicable adequacy decision.

US state privacy rights

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act and comparable state laws. There is no advertising in the app and no advertising identifier is collected. We do not engage in profiling that produces legal effects, and we do not use personal information to make automated decisions about you.

California, Colorado, Connecticut, Virginia, Texas, Utah and other state residents may exercise the access, correction, deletion, portability and opt-out rights their law provides using the routes in section 9. We will not discriminate against you for doing so, and you may use an authorised agent.

Changes, and how to reach us

If we change this policy we will update the date at the top. If a change means collecting something materially new, or using what we hold for a genuinely different purpose, we will ask you again in the app rather than relying on you re-reading this page — and if that new purpose needs consent, the answer stays "no" until you say otherwise.

founders@fingerframeapp.com  ·  support@fingerframeapp.com  ·  [POSTAL ADDRESS]