In short — three things worth knowing
- Your photographs are never sent to any AI model. The service integrates no external AI provider whatsoever. All image processing runs on our own servers, and every recommendation is produced by local computation.
- There is no analytics, tracking, or advertising pixel anywhere in the service. We do not track you and we do not sell data to anyone. Ever.
- The photographs remain yours alone. FrameGrid acquires no rights in them and uses them for nothing other than publishing on your behalf, at your instruction.
Who we are and how to reach us
The service is owned and operated by Klimovitch Alexander, Israeli Licensed Dealer no. 308978956, based in Netanya, Israel.
For any privacy matter — access, correction, or deletion — contact info@framegrid.art. We respond within 14 days.
What we collect about you, the photographer
We collect the following because the service cannot function without it:
- Account details — your email address and an encrypted password. These are managed on our behalf by Supabase; we never see your password.
- Profile details — your full name, business name, and time zone.
- Publishing preferences — posts per week, preferred days and hours, a standing signature caption, and carousel size limits.
- The photographs you upload — the files themselves, plus the original filename, image dimensions, the capture date from the camera data, and a mathematical fingerprint of the file used to detect duplicates.
- The posts you create — caption, tags, scheduled time, and the resulting Instagram post identifier.
- Your Instagram connection — username, business account id, Facebook Page id, profile picture, and an access token issued by Meta.
- Instagram performance data — follower count, reach, profile views, likes and comments, retrieved from Meta and used for your reports and recommendations.
- Notifications — if you enable browser notifications, the notification identifier for that device is stored.
- Financial planning data — only if you choose to use that section. See the dedicated section below.
We do not collect or store your phone number, your postal address, or any payment card details. No such field exists in our database.
Information about your clients
FrameGrid is a tool for you. Your clients have no account, no access, and no interface in the service. We are not a client-facing photo gallery and we never contact your clients.
That said, in order to publish on your behalf, the service holds certain information you entered that relates to other people:
- The name of the couple or client, as you entered it or as contained in your Lightroom collection name.
- The date of the shoot or event.
- The photographs themselves, in which your clients appear.
- Instagram usernames you asked us to tag — the couple, the venue, the makeup artist, the dress designer. These are transmitted to Meta on every publication, because that is the only way tagging works.
- The public profile picture of accounts you tagged, as returned by Meta, shown in the interface.
With respect to this information you are the responsible party, not us. We hold and process it solely on your instruction and make no independent use of it. It is your responsibility to ensure you hold the necessary consents from the people photographed, in line with your own client agreements and applicable law.
Location data: every uploaded photograph is converted to a social-ready version, and that conversion removes the EXIF metadata, including the GPS coordinates of where the photo was taken. We never read, decode, or store GPS coordinates in our database at any stage. The only EXIF value we retain is the capture date and time.
Where data is stored and who can reach it
All data and photographs are stored with Supabase, a database and storage infrastructure provider. The site itself is hosted on Vercel. Both operate servers outside Israel, so data is transferred to and stored outside the country.
Your photographs have a stable web address. That address contains a long random identifier that cannot be guessed, but it is not password-protected — this is a technical requirement of Meta, which must be able to download the image in order to publish it. Anyone holding the exact address can open it. We do not publish these addresses anywhere.
Your access to data is restricted to your own account through database-level authorization rules.
Administrator access
The operator of FrameGrid has an administration panel. It exists for two purposes: running the business — how many photographers are registered, how much storage is in use, and what it costs — and providing customer support when something breaks.
In that capacity the operator has the technical ability to see the list of photographers, their email addresses, galleries, photographs, and storage usage. This is used strictly for operations and support, and never to browse your work without cause.
Your financial data is not reachable from the administration panel. No administrative code path reads the financial tables.
For support purposes, the operator can log into your account and act within it on your behalf — including uploading, editing, styling and publishing — strictly for operations and support, and never for independent use of your content. Even during such access, the financial section remains fully blocked and inaccessible. In the future we will add an explicit approval step on your part before such access.
Such access may include your connected Instagram and Facebook account and the data obtained from Meta, including publishing content on your behalf. This data is used solely to provide the service and support, and is never sold or shared with any third party for any other purpose.
The financial section
The service includes a personal financial planning area — income, expenses and targets. Using it is entirely your choice; if you do not use it, it stays empty.
The area is protected by an additional passcode that you set, separate from your login password. The passcode is stored as a one-way hash and cannot be recovered — not even by us. If you forget it, we cannot restore it for you.
To be precise: the passcode is an access gate, not encryption of the underlying data. We do not access your financial data, but we do not represent it as encrypted at rest.
Who we share data with
We do not sell data and we do not share it with advertisers. The only transfers are the following, all of which are necessary to operate the service:
- Meta (Instagram / Facebook) — when you publish, we send the photographs you selected, the caption, and the usernames you asked to tag. We also retrieve your account performance data from them.
- Supabase — database storage, image files, and authentication. Verification emails are also sent through them.
- Vercel — website hosting. Every request to the site passes through them.
- Your browser vendor’s push service (Google, Apple, or Mozilla, depending on your browser) — only if you enabled notifications. They receive an encrypted message containing a short headline.
And for complete clarity, the service contains none of the following: analytics tooling, advertising pixels, third-party error monitoring, or any artificial intelligence service.
Artificial intelligence — a clarification
The service produces automated recommendations: layout template selection, post suggestions, and ranking of images by performance. These features may sound "smart", so precision matters here.
They are not based on artificial intelligence. They are arithmetic scoring that runs on our own servers over your performance data and your previous choices.
No photograph, no caption, and no detail about your clients is sent to any AI provider. Should we add an AI-based capability in future, we will update this document in advance and ask for your consent.
How long we keep data
Data is retained for as long as your account is active. Galleries and photographs remain until you delete them — we do not delete your content on our own initiative.
In-app notifications are deleted automatically after 24 hours. The Instagram access token expires on its own after roughly sixty days, after which reconnection is required.
When your account is deleted, all data and files are permanently erased. See the Data Deletion page for details.
Your rights
Under the Israeli Protection of Privacy Law, 5741-1981, as amended, you have the following rights:
- To review the information held about you.
- To request correction of inaccurate or outdated information.
- To request deletion of your data and your account.
- To receive a copy of your data.
- To disconnect your Instagram connection at any time from the settings page.
To exercise any of these rights, contact info@framegrid.art. We will handle your request within 14 days. If our response does not satisfy you, you are entitled to contact the Israeli Privacy Protection Authority at the Ministry of Justice.
Security
Traffic to the site is encrypted. Passwords are stored hashed and cannot be recovered. Database-level rules restrict each photographer to their own data. The Lightroom plugin key is stored only as a one-way hash and is shown to you exactly once, at the moment it is created.
The access token issued by Meta is stored in our database and protected by authorization rules, but is not separately encrypted. We are working to improve this.
No system is perfectly secure. If a security incident occurs that may affect your data, we will notify you and the competent authorities as required by law.
Minors
The service is intended for business owners and is not intended for use by anyone under 18. We do not knowingly collect information about minors as users of the service.
Changes to this policy
If we make a material change to this document — for example adding a new provider that receives data — we will notify you in the app or by email before it takes effect. The date of the most recent revision appears at the top of this page.