Legal

Privacy Policy

Last updated: 17 September 202611 min read

FrameGrid is a social-media management tool for professional photographers. This document explains exactly what data the service collects, why, where it goes, and what you can do about it. It was written against an actual audit of the system, not from a template.

The service is operated by Klimovitch Alexander, Israeli Licensed Dealer no. 308978956.

01

In short: three things worth knowing

  • There is no analytics, tracking, or advertising pixel anywhere in the service. We do not track you and we do not sell data to anyone. Ever.
  • The photographs remain yours alone. FrameGrid acquires no rights in them and uses them for nothing other than publishing on your behalf, at your instruction.
  • No data is ever sent to an AI service automatically. Data is sent only when an AI feature is enabled and you are actively using it, and it is not used to train models. If you do not use these features, no data is sent. Full details are in the "Artificial intelligence" section.
02

Who we are and how to reach us

The service is owned and operated by Klimovitch Alexander, Israeli Licensed Dealer no. 308978956, based in Netanya, Israel.

For any privacy matter, including access, correction, or deletion, contact info@framegrid.art. We respond within 14 days.

03

What we collect about you, the photographer

We collect the following because the service cannot function without it:

  • Account details: your email address and an encrypted password. These are managed on our behalf by Supabase, and we never see your password.
  • Profile details: your full name, business name, and time zone.
  • Phone number: only if you chose to provide it at sign-up or when activating a subscription. It is used solely to contact you about your account and subscription.
  • Invoicing details: business or full name, business or ID number, and an invoice email. You provide them when activating a subscription, or earlier at sign-up if you choose, and they are used to issue a tax invoice/receipt as required by law.
  • Subscription status: whether the account is on a trial or a paid subscription, and the date until which access is active.
  • Publishing preferences: posts per week, preferred days and hours, a standing signature caption, and carousel size limits.
  • The photographs you upload: the files themselves, plus the original filename, image dimensions, the capture date from the camera data, and a mathematical fingerprint of the file used to detect duplicates.
  • The posts you create: caption, tags, scheduled time, and the resulting Instagram post identifier.
  • Your Instagram connection: username, business account id, Facebook Page id, profile picture, and an access token issued by Meta.
  • Instagram performance data: follower count, reach, profile views, likes and comments, retrieved from Meta and used for your reports and recommendations.
  • Notifications: if you enable browser notifications, the notification identifier for that device is stored.
  • Financial planning data: only if you choose to use that section. See the dedicated section below.

We do not collect your home address and we do not store any payment card or payment method details. Payment itself does not take place inside the service.

04

Information about your clients

FrameGrid is a tool for you. Your clients have no account, no access, and no interface in the service. We are not a client-facing photo gallery and we never contact your clients.

That said, in order to publish on your behalf, the service holds certain information you entered that relates to other people:

  • The name of the couple or client, as you entered it or as contained in your Lightroom collection name.
  • The date of the shoot or event.
  • The photographs themselves, in which your clients appear.
  • Instagram usernames you asked us to tag, such as the couple, the venue, the makeup artist or the dress designer. These are transmitted to Meta on every publication, because that is the only way tagging works.
  • The public profile picture of accounts you tagged, as returned by Meta, shown in the interface.

With respect to this information you are the responsible party, not us. We hold and process it solely on your instruction and make no independent use of it. It is your responsibility to ensure you hold the necessary consents from the people photographed, in line with your own client agreements and applicable law.

Location data: every uploaded photograph is converted to a social-ready version, and that conversion removes the EXIF metadata, including the GPS coordinates of where the photo was taken. We never read, decode, or store GPS coordinates in our database at any stage. The only EXIF value we retain is the capture date and time.

05

Where data is stored and who can reach it

All data and photographs are stored with Supabase, a database and storage infrastructure provider. The site itself is hosted on Vercel. Both operate servers outside Israel, so data is transferred to and stored outside the country.

Your photographs have a stable web address. That address contains a long random identifier that cannot be guessed, but it is not password-protected. This is a technical requirement of Meta, which must be able to download the image in order to publish it. Anyone holding the exact address can open it. We do not publish these addresses anywhere.

Your access to data is restricted to your own account through database-level authorization rules.

06

Administrator access

The operator of FrameGrid has an administration panel. It exists for three purposes: running the business (how many photographers are registered, how much storage is in use, and what it costs), managing subscriptions, and providing customer support when something breaks.

In that capacity the operator has the technical ability to see the list of photographers, their email addresses, galleries, photographs, and storage usage. To manage subscriptions the operator also sees your subscription status, your phone number and the invoicing details you provided, and can extend a subscription after payment. This is used strictly for operations and support, and never to browse your work without cause.

Your financial data is not reachable from the administration panel. No administrative code path reads the financial tables.

For support purposes, the operator can log into your account and act within it on your behalf, including uploading, editing, styling and publishing, strictly for operations and support and never for independent use of your content. Even during such access, the financial section remains fully blocked and inaccessible. In the future we will add an explicit approval step on your part before such access.

Such access may include your connected Instagram and Facebook account and the data obtained from Meta, including publishing content on your behalf. This data is used solely to provide the service and support, and is never sold or shared with any third party for any other purpose.

07

The financial section

The service includes a personal financial planning area for income, expenses and targets. Using it is entirely your choice, and if you do not use it, it stays empty.

The area is protected by an additional passcode that you set, separate from your login password. The passcode is stored as a one-way hash and cannot be recovered, not even by us. If you forget it, we cannot restore it for you.

To be precise: the passcode is an access gate, not encryption of the underlying data. We do not access your financial data, but we do not represent it as encrypted at rest.

08

Who we share data with

We do not sell data and we do not share it with advertisers. The only transfers are the following, all of which are necessary to operate the service:

  • Meta (Instagram / Facebook): when you publish, we send the photographs you selected, the caption, and the usernames you asked to tag. We also retrieve your account performance data from them.
  • HookMyApp: our Instagram publishing partner. Some accounts are connected through them, and for those, publishing to Meta passes through their service. In that case they receive, at the moment of publishing, the image URL, the caption and the usernames to tag, and performance data is retrieved through them as well. They get no access to our database, to your galleries, or to your account details. Under their privacy policy, content passing through them is deleted from their database after seven days. Settings states explicitly whether your account is connected this way.
  • Supabase: database storage, image files, and authentication. Verification emails are also sent through them.
  • Vercel: website hosting. Every request to the site passes through them.
  • Anthropic: our AI provider. It receives data only when you use one of the AI features, as described in the next section.
  • Your browser vendor’s push service (Google, Apple, or Mozilla, depending on your browser): only if you enabled notifications. They receive an encrypted message containing a short headline.

And for complete clarity, the service contains none of the following: analytics tooling, advertising pixels, or third-party error monitoring.

09

Artificial intelligence

Some recommendations in the service, such as layout template selection, post suggestions and ranking images by performance, are arithmetic scoring that runs on our own servers. They do not use artificial intelligence and send data to no provider.

In addition, the service has three optional features that use Anthropic’s AI service. Nothing is sent to it automatically or in the background: data is sent only when a feature is enabled and you are actively using it. If you do not use it, nothing is sent. This is the data each one sends, and only while it is in use:

  • Gallery photo analysis: a reduced copy of each photograph (up to 512 pixels) is sent to identify what it shows, so posts can be ordered by content. The feature is off by default and runs only after you approve it.
  • Spellcheck in the Premiere plugin: the caption text of the project you chose to check.
  • Translation in the editor chat: the messages and notes you and your editor write during an editing job, so each side reads them in their own language.

Anthropic processes the data only to return a response and, under its commercial terms, does not use it to train models. We keep only the result on our side, for example the photo description or the translated message.

No detail about your clients beyond what appears in the photograph or text you chose to process is sent to an AI provider. Should we add a new AI feature that receives a different kind of data, we will update this document in advance.

10

Cookies

The service uses exactly three cookies, all strictly necessary. There are no advertising or tracking cookies, and therefore no consent banner:

  • A session cookie that keeps you signed in across pages.
  • A security cookie used during Instagram connection. It lives for ten minutes and prevents request forgery.
  • A financial-section cookie that keeps that area unlocked for 12 hours after you enter your passcode.
11

How long we keep data

Data is retained for as long as your account exists. Galleries and photographs remain until you delete them, and we do not delete your content on our own initiative. Even when a subscription is not active, your content is kept and waiting for you.

In-app notifications are deleted automatically after 24 hours. The Instagram access token expires on its own after roughly sixty days, after which reconnection is required.

When your account is deleted, all data and files are permanently erased. Invoices issued for payments are kept in the business’s accounting records for the period required by law. See the Data Deletion page for details.

12

Your rights

Under the Israeli Protection of Privacy Law, 5741-1981, as amended, you have the following rights:

  • To review the information held about you.
  • To request correction of inaccurate or outdated information.
  • To request deletion of your data and your account.
  • To receive a copy of your data.
  • To disconnect your Instagram connection at any time from the settings page.

To exercise any of these rights, contact info@framegrid.art. We will handle your request within 14 days. If our response does not satisfy you, you are entitled to contact the Israeli Privacy Protection Authority at the Ministry of Justice.

13

Security

Traffic to the site is encrypted. Passwords are stored hashed and cannot be recovered. Database-level rules restrict each photographer to their own data. The Lightroom plugin key is stored only as a one-way hash and is shown to you exactly once, at the moment it is created.

The access token issued by Meta is stored in our database and protected by authorization rules, but is not separately encrypted. We are working to improve this.

No system is perfectly secure. If a security incident occurs that may affect your data, we will notify you and the competent authorities as required by law.

14

Minors

The service is intended for business owners and is not intended for use by anyone under 18. We do not knowingly collect information about minors as users of the service.

15

Changes to this policy

If we make a material change to this document, for example adding a new provider that receives data, we will notify you in the app or by email before it takes effect. The date of the most recent revision appears at the top of this page.