Back to FoundFrame

Privacy Policy

Last updated: April 3, 2026

1. Introduction

FoundFrame ("we," "us," or "our") respects your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information when you use our Service at foundframe.com.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and an encrypted password. Authentication is handled by Supabase Auth. We do not store your password in plaintext; Supabase manages credential security.

2.2 Usage Data

We record your search queries, the number of credits consumed, the effort level selected, timestamps of searches, and results returned. This data is stored in our database and associated with your account for usage tracking and service improvement.

2.3 Saved Clips

If you save clips to your library, we store the video metadata (video ID, title, channel, timestamps, description) associated with your account.

2.4 Billing Information

Payment processing is handled by Stripe. We do not store your full credit card number. Stripe may collect your name, billing address, and payment details in accordance with their Privacy Policy. We receive a customer ID, subscription status, and transaction history from Stripe.

2.5 Analytics Data

We use PostHog for product analytics. PostHog collects anonymized usage events such as page views, feature interactions, search events, and error occurrences. This data helps us understand how the Service is used and improve the experience. PostHog may collect your IP address (which is anonymized), browser type, device type, and referring URL.

2.6 Cookies and Local Storage

We use cookies and browser local storage for authentication session management and user preferences. PostHog may also set cookies for analytics purposes. You can configure your browser to refuse cookies, though this may limit Service functionality.

3. How We Use Your Information

  • To provide, operate, and maintain the Service.
  • To authenticate your identity and manage your account.
  • To process payments and manage subscriptions.
  • To track credit usage and enforce tier limits.
  • To improve the Service through analytics and usage patterns.
  • To communicate with you about your account, billing, or Service updates.
  • To detect and prevent fraud or abuse.

4. Third-Party Services

We share data with the following third-party services:

  • Supabase Auth: Email and authentication credentials for user sign-in.
  • Stripe: Billing and payment information for subscription management.
  • PostHog: Anonymized usage events and analytics data.
  • Google Gemini API: Search queries and video content are sent to Google's Gemini API for AI analysis. Google's data handling is governed by their Privacy Policy.
  • YouTube Data API: Search queries are sent to YouTube for video discovery. Subject to the Google Privacy Policy.

We do not sell your personal information to third parties.

5. Data Retention

We retain your account information and usage data for as long as your account is active. Search history and saved clips are retained until you delete them or close your account. Upon account deletion, we will remove your personal data within 30 days, except where we are required to retain it for legal or compliance purposes.

Anonymized analytics data may be retained indefinitely for aggregate statistical purposes.

6. Data Security

We implement industry-standard security measures to protect your data, including encrypted connections (HTTPS/TLS), secure password handling via Supabase, and access controls on our infrastructure. However, no system is completely secure, and we cannot guarantee absolute security.

7. Your Rights

7.1 General Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and personal data.
  • Export your data in a portable format.
  • Opt out of non-essential analytics tracking.

7.2 GDPR (European Economic Area)

If you are located in the EEA, you have additional rights under the General Data Protection Regulation, including the right to lodge a complaint with your local data protection authority. Our legal basis for processing your data is (a) performance of a contract (providing the Service), (b) legitimate interest (improving the Service, fraud prevention), and (c) your consent (analytics).

7.3 CCPA (California)

If you are a California resident, you have the right to know what personal information we collect and how it is used, to request deletion of your personal information, and to opt out of the sale of personal information. We do not sell personal information.

8. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. Your continued use of the Service after changes constitutes acceptance.

10. Contact

For privacy-related questions or to exercise your rights, contact us at support@foundframe.com.