Privacy
Frameboard is a tool for planning film and video productions. This page explains what it stores, why, and who else ever sees it. It is written to be read, not to be survived.
Who runs it
Frameboard is operated by Frameboard, registered in the Netherlands, Chamber of Commerce number 42157501. For anything on this page, write to info@useframeboard.com.
What is stored
- Your account. Name, email address, and your password stored only as a bcrypt hash. The plain password is never written down anywhere, which is also why it cannot be recovered, only replaced.
- Your work. The productions you create: reference images, notes, sketches, documents, shot lists, lighting plans and any clips you upload.
- Collaborators. The email addresses you invite to a production, so access can be granted when they sign in.
- Technical records. Our host keeps ordinary server logs, including IP addresses, to keep the service running and to detect abuse.
Cookies
One cookie is used to keep you signed in. It contains a random session token and nothing else, and it is marked HttpOnly so scripts on the page cannot read it. That one is necessary for the site to work and is set whether or not you agree to anything else.
Beyond that we use Google Analytics and PostHog to understand how people find and use Frameboard. Both store an identifier on your device, so neither is loaded at all until you have agreed on the banner. If you decline, nothing from either company is ever requested by your browser, and any identifier they had already set is deleted.
There are no advertising cookies and no ad networks. Nothing you make in Frameboard is ever sent to either of them: not your boards, images, shot lists or documents, and not the names of your productions.
How we know it is working
Separately from the two services above, and whether or not you agree to them, we record two things in our own database. Nothing about this leaves our servers, it sets nothing on your device, and it exists so we can tell whether the product is any good rather than to follow you.
- Milestones. The first time your account does one of a short, fixed list of things: created a production, turned a card into a shot, exported something, made a share link, invited someone. One row, the first time, and never again. It tells us whether people are getting to the useful part of the product. It does not record what you made, what it was called, or what was in it.
- Days you were active. A date, so we can tell whether people come back. Not a time, not a page, not a duration.
These two records do not include your IP address, your browser, where you came from, what you clicked, or the contents of anything you make. Both are tied to your account and are deleted with it.
Who else sees anything
- Vercel. Hosting. Serves the application and keeps request logs.
- Supabase. The database your account and productions are stored in.
- hCaptcha (Intuition Machines). Shown on the sign-in and sign-up forms to block automated abuse. It receives your IP address and interaction signals for that check.
- Resend. Sends the few emails the service needs, such as a password reset link or a notification that someone shared a production with you. It sees your email address and the message.
- Sentry. Error reporting, so crashes get found and fixed. It receives the technical details of a failure. We have deliberately turned off the options that would send cookies, headers or IP addresses, and we do not record screen sessions.
- Google Analytics and PostHog. Only if you agreed on the banner. They receive which pages you visited, an identifier stored on your device, and your IP address, which Google truncates before storing. Session replay is switched off in PostHog: the work on these screens is unreleased film, and recording it would be indefensible whatever the setting was called.
That is the whole list of outside companies. Your work is never sold, never used for advertising, and never sent to an AI model. There is no AI feature in Frameboard and nothing you make here is used to train one.
When we look at your work ourselves
We can open a production from a support tool. We use it for three things: helping with a request you have sent us, recovering work after something has gone wrong, and investigating abuse or a legal demand. We do not open productions out of curiosity, to look for examples, or for anything to do with marketing.
Access is limited to a short list of named company accounts, currently the founders, and that list is set in the deployment configuration rather than being something an account can be granted from inside the app. The tool is read only: it cannot edit your production. Every time it is used to open a production, that is recorded with who did it, which production, and when.
If you would like to know whether your account has ever been opened this way, ask us at info@useframeboard.com and we will tell you.
Sharing is your choice
A share link makes a production readable by anyone who has the link, without signing in. That is the point of it, so treat the link as the key: anyone you send it to can pass it on. You can revoke or regenerate it at any time, which takes effect immediately.
How long it is kept
Your productions stay until you delete them. Deleting your account removes the account and everything attached to it: productions, uploaded media and sessions. That deletion is immediate and cannot be undone. Backups held by our hosting providers age out on their own schedules.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, have it erased, or object to how it is handled. Two of these you can do yourself without asking: every production has a JSON export (that is your portability right), and your account page deletes the account outright. For anything else, email us and we will respond within one month. You can also complain to your national data protection authority, which in the Netherlands is the Autoriteit Persoonsgegevens.
How it is protected
Passwords are hashed with bcrypt. Traffic runs over HTTPS. Session cookies are HttpOnly and hold only a hash of the token, so a stolen database row cannot be replayed as a login. Every request for a production is checked against your account, so knowing its URL on its own grants nothing. Row Level Security is enabled on every database table. No system is perfect, and we will tell affected users promptly if something goes wrong.
Data processing terms, for companies
If you use Frameboard for a company and your own privacy obligations need a data processing agreement, this section is it, and it applies without anybody signing anything. Where you put personal data about other people into a production (a cast list, crew contacts, a location owner’s phone number), you are the controller of that data and Frameboard is your processor. In that role we:
- Process that data only to run the service for you, on your instructions as expressed by using the product, and for nothing else. Nothing in it is read by a model, used for training, or sold.
- Use only the sub-processors listed above under “Who else sees anything”: Vercel, Supabase, hCaptcha, Resend, Sentry, and, after consent only, Google Analytics and PostHog. The database lives in Supabase’s [DATABASE REGION] region. If we add or replace a sub-processor, this page changes and we tell you by email at least 30 days before it takes effect, and you may object by cancelling.
- Keep the people who work on Frameboard bound to confidentiality, and look at your work ourselves only in the cases described above.
- Apply the protections described under “How it is protected”, and tell you without undue delay, and in any case within 72 hours of becoming aware, if a breach affects your data.
- Help you answer requests from the people whose data it is: the JSON export is a complete copy, deleting a production or an account is immediate erasure, and for anything else you email us and we act within the month.
- Delete or return your data when the contract ends: your export is always available, and account deletion removes everything, subject only to provider backups ageing out.
- Allow you to check this. Ask and we will provide the information reasonably needed to show these terms are met.
These terms are governed by Dutch law and by the GDPR. If you need them as a signed document for a procurement file, email us and we will send one on our letterhead saying exactly this.
Changes
If this page changes in a way that matters, the date at the top changes and we will say so by email before it takes effect.