Back to home

Privacy Policy

Version 1.0 privacy policy explaining FingerFrame AI account, local and hosted media, AI safety, payment, analytics, retention, transfer, and privacy practices.

Last updated: 2026-08-12

Version 1.0

Effective and last updated: 12 August 2026

1. Data Controller and Contact

The data controller for FingerFrame AI is:

Evan Reed handles privacy matters directly. Email is the supported correspondence channel for privacy requests and complaints.

This Privacy Policy explains how we collect, use, store, disclose, transfer, and delete personal data when you visit FingerFrame AI, create an account, use local or hosted AI features, submit a content-safety appeal or report, contact support, or purchase a subscription.

2. Data We Process

The data depends on the feature you choose.

2.1 Local mode

Camera frames, uploaded media, gesture landmarks, selection boxes, and local visual effects are processed in your browser. FingerFrame AI's servers do not receive or store that media in local mode. Browser permissions control access to your camera. When you first use gesture tracking, your browser downloads the MediaPipe software files from jsDelivr and the hand-landmark model from Google's static storage. Those asset hosts receive ordinary technical request data such as IP address, user agent, requested asset, and request time, but we do not send them your camera frames, uploaded media, landmarks, prompts, or generated results.

2.2 Hosted AI generation

For hosted generation, we receive the source photo or short video, prompt, requested settings, account identifier, age and regional consent confirmation, and the technical information required to perform the request.

  • After prompt approval, the exact source bytes are hashed and stored under a random private Cloudflare R2 preflight key with a 15-minute access lease so Evolink-routed visual safety checks can inspect them. A rejected or inconclusive source is deleted without task creation or credit reservation. Only an allowed source object's lease is extended so Evolink and the applicable upstream generation model can process that same object.
  • Evolink processes prompts and media using Nano Banana 2 Lite or Gemini Omni Flash, depending on the selected supported feature.
  • After strict provider-URL, size, and media-type validation, generated bytes are ingested into a lease-scoped private R2 quarantine object that users cannot access. We calculate the SHA-256 of the actual bytes there. The same object becomes deliverable only after the required safety decisions, audit writes, and atomic task-state transition succeed. We do not expose the provider's original result URL as the user-facing download URL.
  • Media bytes are not stored in our application database. The database stores task state and metadata, as described below.

2.3 Content-safety processing

Hosted prompts, source media, and outputs are subject to a two-stage framework: input scanning before generation, followed by the applicable output check before delivery:

  1. Before task creation: we normalise the prompt and check it against a mandatory local baseline blocklist. Administrator rules cannot disable, remove, or replace that baseline; they can only extend it. If the local check matches, the request is blocked without sending the prompt to Waffo. Otherwise, we send the prompt text, locale (en or zh), and enforcement mode to Waffo Prompt Sift. We create the task only when Waffo returns an explicit allow and the required audit record is written. Evan Reed, as operator, is responsible for the active local rules. We review them at least monthly and when a relevant law, provider rule, credible report, or observed abuse event changes, keeping a dated change record of the trigger, reviewer, affected category, stable non-descriptive rule IDs, and outcome without storing the prohibited term in the safety audit log.
  2. Before generation from source media: after prompt approval, the exact source bytes are written to the short-lived private preflight object described above and re-hashed at the provider-facing URL. The original prompt and that immutable object are sent through Evolink for input-media moderation. A source image requires explicit allows from both evolink-moderation-1.0 and Qwen3.8-Max; a source video requires an explicit allow from Qwen3.8-Max. Every required input audit must be written successfully. A non-allow or system failure deletes the preflight object and prevents task creation, credit reservation, and generation-model processing.
  3. Before delivery of a generated image: after quarantine ingestion and actual-byte hashing, we create a short-lived HMAC-authorised URL bound to the task and exact output SHA-256. The original prompt and this URL for the same immutable object are sent through Evolink for two required checks. Evolink's evolink-moderation-1.0 must return unflagged, low-risk, and no violation; Qwen3.8-Max (qwen3.8-max) must independently return a strict structured allow decision with no matched category. Qwen evaluates sexual/NSFW, violence/gore, hate, CSAM, deepfake/impersonation, copyright/trademark, self-harm, terrorism/violent extremism, and weapons/WMD assistance. Both checks must pass.
  4. Before delivery of a generated video: we use the same quarantine, actual-byte hashing, and task-plus-hash URL binding. The original prompt and exact immutable video are sent through Evolink to Qwen3.8-Max for the same strict, structured categories. Only an explicit allow with no matched category passes.

A single lease-backed output claim covers provider retrieval, quarantine ingestion, moderation, audit, and delivery transition; concurrent non-owner work defers. All required checks and audit writes, followed by an atomic task-state transition, must succeed before the quarantined object becomes user-accessible. Any review, block, flagged or non-low-risk result, matched category, missing safety configuration, unavailable safety provider, timeout, malformed or inconsistent moderation response, or audit-write error fails closed. The output is not delivered and the task is failed. An explicit prohibited-content block records a safety strike and remains charged; review outcomes and safety-service, response, or audit failures restore reserved credits and do not record a user strike. Transport or private-storage errors before a moderation decision retain the charge and may be retried up to three times.

Our own safety audit record stores only hashes and limited verdict metadata: prompt SHA-256, output SHA-256 where applicable, user/task references, stage, safety provider, action, reason code, bounded categories or rule identifier, provider request identifier, semantic or risk projection, and timestamp. It does not store prompt text, matched blocklist terms, media, or output/delivery URLs, and it is retained for 12 months. The original prompt may separately appear in the ordinary generation record described below.

Safety scanning is an automated decision about whether a particular generation request can proceed or be delivered. It does not by itself produce legal or similarly significant effects beyond access to that generation. You can request a human review using the appeal process in our Acceptable Use Policy.

2.4 Account and authentication data

When you sign in with Google, we receive the authorised profile fields needed for the account, such as name, email address, avatar, Google account identifier, authentication records, and OAuth tokens where Google returns them and they are needed to maintain sign-in. We never receive your Google password. We also store account roles, status, sign-in timestamps, and security-related account records.

2.5 Usage, generation, consent, and credit records

We store the model and mode selected, prompt, task and provider identifiers, timestamps, task status, error code, output type, temporary output-expiry metadata, credits reserved, consumed or restored, subscription entitlement, and safety audit metadata. We also keep the version, status, timestamp, and regional information associated with hosted-AI age and processing consent. Application logs are designed not to contain media bytes, full provider credentials, or full payment-card data.

2.6 Payment and subscription data

Waffo Pancake is the merchant of record and an independent controller for payment, tax, fraud, refund, chargeback, and merchant-of-record transaction data. Waffo and its payment partners collect payment-card and billing details directly. FingerFrame AI receives only the order, product, amount, currency, subscription status, payment status, limited purchaser information, transaction identifiers, and signed event information needed to provide the plan and support the purchase. Full card numbers never pass through or reside on our servers.

2.7 Technical, security, and regional data

We and Cloudflare may process IP address, country or approximate region derived from the network request, request time, URL, referrer, browser and device type, operating system, language, performance and error data, and security events. We use this information to deliver the site, determine hosted-feature regional eligibility, protect accounts and systems, apply rate limits, investigate abuse, and diagnose failures. We do not request precise GPS location.

2.8 Analytics data

Plausible Analytics loads on production pages for cookie-free aggregate traffic measurement. It measures hostname and page path, referral source, browser, operating system, device type, and country/region/city derived from the request IP address. According to Plausible's Data Policy, it does not set cookies, create persistent identifiers, track people across websites/devices/days, or store raw IP addresses or full user agents; visitor analytics is processed and stored in the European Union.

Google Analytics 4 and Microsoft Clarity load only after you affirmatively accept optional analytics in our consent control. They may process online identifiers, IP-derived approximate location, device and browser details, referrer and navigation data, page views, session duration, feature interactions, clicks, scrolling, pointer or touch movement, and performance data. Clarity can reconstruct sessions and create heatmaps. We pass Clarity explicit analytics consent with advertising storage denied, and mark both the local Studio and authenticated application shell for content masking. We do not intentionally send camera frames, uploaded media, prompt or result content, or full payment-card data to analytics providers. We do not use advertising or targeted-marketing cookies.

2.9 Support and reports

When you contact us, request a refund, report unsafe content, or appeal a decision, we process your email address, message, task or order identifier, correspondence, and any attachment or evidence you choose to provide. Do not email illegal imagery, passwords, API keys, full card numbers, or private media unless we first arrange an appropriate channel.

3. Purposes and Legal Bases

Where applicable law uses the legal bases below, we rely on them as follows:

PurposeData involvedLegal basis
Provide accounts, local interfaces, hosted generation, credits, subscriptions, downloads, cancellation, and supportAccount, media, prompt, task, consent, credit, subscription, and support dataPerformance of a contract; steps requested before entering a contract
Complete checkout, grant paid entitlements, administer renewal, cancellation, refund, tax, and accountingAccount, order, subscription, transaction, and limited purchaser dataPerformance of a contract; legal obligation
Scan prompts, source media, and outputs; prevent CSAM and other prohibited content; enforce our Terms; and investigate reportsPrompt, temporary source/output URL, media and prompt hashes, safety decision, task/user identifiers, and report dataLegitimate interests in safe and lawful operation; legal obligation where applicable
Authenticate users, secure systems, apply age and region controls, prevent fraud, abuse, or intrusion, and diagnose failuresAccount, OAuth, consent, IP/region, request, device, error, and security dataPerformance of a contract; legitimate interests in security and fraud prevention; legal obligation
Send receipts and service, billing, security, support, or policy noticesName, email, account, order, and support dataPerformance of a contract; legitimate interests; legal obligation
Measure aggregate site traffic with cookie-free Plausible AnalyticsPage/referrer and coarse browser, device, and location statisticsLegitimate interests in understanding and improving aggregate site usage, where a legal basis is required
Measure and improve the site with Google Analytics and Microsoft ClarityOptional analytics dataYour consent
Establish, exercise, or defend legal claims and respond to valid legal processRelevant account, transaction, safety, support, and technical dataLegitimate interests; legal obligation

We may create aggregate or de-identified statistics that cannot reasonably identify you. We do not use your media to train our own models.

4. Cookies, Browser Storage, and Analytics Choices

CategoryExamples and purposeCan you decline?
Strictly necessarySession and OAuth security, fraud prevention, routing, service operationNo, if you want the affected account feature to work
FunctionalLanguage, theme, consent record, and feature preferencesYes, although the related preference or feature may not persist or work
Cookie-free site analyticsPlausible aggregate page, referral, browser, device, and coarse location statisticsIt stores no cookie choice; browser or network blocking can prevent it
Optional analyticsGoogle Analytics 4 and Microsoft Clarity measurement, heatmaps, and session reconstructionYes; they do not load until accepted

You can decline GA4 and Clarity in the analytics consent prompt. Clearing this site's browser data removes the saved choice and causes the prompt to appear again. To withdraw after accepting, clear the site's analytics consent/browser data; those optional services then stop on a future page load. Plausible does not set a consent cookie or persistent identifier and is not controlled by that choice; browser content blocking, DNS filtering, or equivalent network controls can block it. Withdrawal does not affect earlier lawful processing. See our Cookie Policy.

The analytics providers' own notices are available in the Plausible Data Policy, Google Privacy Policy, and Microsoft Privacy Statement.

5. Service Providers and Disclosures

We disclose only data reasonably necessary for the stated service:

  • Cloudflare provides DNS, network delivery, security, Workers compute, D1 database, private R2 media storage, and email routing. It can process request, technical, account, database, and temporary media data on our behalf.
  • jsDelivr delivers the MediaPipe browser software used for optional local gesture tracking. It receives ordinary asset-request technical data, but not local Studio media or landmarks from us.
  • Google provides Google OAuth sign-in, the hand-landmark model file used for optional local gesture tracking, applicable upstream model processing for Evolink-routed generation, Google Analytics after consent, and support-mail delivery where configured. Google's static asset host receives ordinary request technical data when the model file is downloaded, but we do not send it local Studio media or landmarks.
  • Evolink receives hosted prompts, input media URLs or media, requested model settings, generated output, and output-moderation context to route Nano Banana 2 Lite and Gemini Omni Flash generation, evolink-moderation-1.0 image safety checks, and Qwen3.8-Max structured image and video safety checks.
  • Waffo Pancake receives hosted custom prompts and locale for Prompt Sift only after the mandatory local baseline check does not match. Separately, as merchant of record, it and its payment partners process checkout, card, billing, tax, fraud, subscription, refund, and dispute data as independent controllers.
  • Plausible Analytics processes cookie-free aggregate page, referral, browser, device, and coarse location statistics on our behalf on production page visits. It does not receive prompts, Studio media, generation results, account identifiers, or payment-card data from us.
  • Microsoft Clarity receives optional analytics and session-interaction data only after analytics consent.

These providers may use subprocessors under their terms. Their policies apply when they act as independent controllers, including Google for your Google account, Waffo for merchant-of-record data, and analytics providers for their services.

We may also disclose limited information:

  • when required by applicable law, court order, or valid regulatory or law-enforcement process;
  • to protect users, child safety, the public, our rights, or the security of the service;
  • to professional advisers bound by duties of confidentiality; or
  • as part of a genuine merger, reorganisation, financing, or transfer of the service, with appropriate notice and continuing safeguards.

We do not sell personal data for money. We do not "sell" or "share" personal data for cross-context behavioural advertising as those terms are used in applicable US state privacy laws. We do not serve targeted advertising.

6. International Data Transfers

FingerFrame AI is controlled from Singapore. Plausible states that its visitor analytics is processed and stored in the European Union and does not leave the EU. Cloudflare operates a global network, and jsDelivr, Google, Microsoft, Waffo, Evolink, and their subprocessors may process other data in Singapore, the United States, Hong Kong, or other countries where they operate. Those countries may have privacy laws different from yours.

For transfers for which a specific safeguard is required, we use the lawful mechanism available for the relationship, such as contractual data-protection terms incorporating the European Commission's Standard Contractual Clauses, an applicable adequacy decision, or another legally recognised transfer mechanism. We also use data minimisation, encrypted transport, access restrictions, short-lived media URLs, and vendor security review as appropriate. Singapore's transfer-limitation rules require overseas recipients to provide protection comparable to the PDPA, subject to applicable exceptions.

Hosted Evolink processing is not offered in the EEA, United Kingdom, or Switzerland at launch. This regional limit does not prevent ordinary website, account, cookie-free aggregate, or consented optional analytics data from being processed where lawful.

7. Retention

We use the following operational retention schedule. A longer period applies only when reasonably necessary for a legal hold, fraud or safety investigation, payment dispute, tax duty, or other legal requirement; we then isolate the affected data and delete or anonymise it when the exception ends.

Data categoryRetention periodEnd-of-period action
Local-mode mediaNever received by FingerFrame AI serversRemains under your browser/device control
Hosted input mediaUntil task completion/failure; its access lease expires no later than 24 hours after creationDeleted promptly at terminal state where possible, then by the hourly expiry sweep or R2 lifecycle backstop
Hosted generated quarantine and delivery mediaIts access lease expires no later than 24 hours after creationBecomes inaccessible at expiry, then is removed by the hourly sweep or R2 lifecycle backstop
Generation prompt and ordinary task metadata12 months after the task finishesDeleted or anonymised, except records needed for an active account dispute or legal obligation
Credit grant, use, expiry, and entitlement ledgerWhile the account is active and up to 5 years after closure or the related paid transaction, whichever is laterDeleted, anonymised, or legally archived through the verified account/records process
Safety audit metadata, including prompt/output hashes and verdict metadata but no prompt text, matched terms, media, or URLsUp to 12 months after the safety scanDeleted or anonymised; verified closure may cause earlier removal unless a documented safety or legal hold applies
Account/profile/authentication dataWhile the account is active, then up to 90 days after a closure request is verifiedDeleted or anonymised through the account-closure process, subject to the separate records below
Age, region, consent, policy-acceptance, withdrawal, and enforcement evidence5 years after the relevant record or account closure, whichever is laterDeleted or anonymised unless legally required longer
Orders, subscriptions, refunds, disputes, tax, and accounting records we control5 years after the relevant transaction or assessment periodDeleted, anonymised, or legally archived
Support, safety-report, and appeal correspondenceUp to 24 months after the matter closesReviewed and deleted or anonymised operationally unless a legal or safety hold applies
Application security, access, and error logs under our controlUp to 12 months after creationRotated, deleted, or aggregated operationally
Plausible aggregate site analyticsWhile the Plausible site/account remains active, unless deleted earlierDeleted through Plausible's site/account process; no raw IP address or full user agent is stored
Google Analytics user- and event-level exploration dataNo more than 14 months under our property retention settingDeleted by Google under its service process; standard aggregate reports may follow Google's service rules
Clarity playback/session reconstructionOrdinarily 30 days; labelled, favourited, sampled sessions and heatmap/click data may remain up to 13 monthsDeleted by Microsoft under Clarity's service process

Plausible, Waffo, jsDelivr, Google, Microsoft, Evolink, Cloudflare, and other providers maintain their own retention schedules for data they control. Deletion from our active systems may leave protected residual copies in provider backups until the provider's normal backup cycle completes; such copies remain isolated from ordinary use and are overwritten or deleted under that cycle.

Media access expiry is enforced at every read and an hourly sweep removes expired private objects; a provider lifecycle rule is the final backstop and may complete later under Cloudflare's process. Task, generation, and safety-record expiry is enforced by the service's daily scheduled database-retention process. Account closure, credit-ledger, correspondence, consent, transaction, and legal-hold records are handled through verified requests and an operator-run review process; we do not represent those manual workflows as automatic in-app deletion.

8. Security and Breach Notification

We use measures appropriate to the service, including TLS/HTTPS transport, private object storage, short-lived signed media access, server-only provider credentials, encryption of configured secrets, role-based administration, OAuth security controls, request validation, rate limiting, webhook signature verification, least-privilege access, and safety audit records that hash rather than repeat prompt text. No online service can guarantee absolute security.

If a personal-data incident occurs, we will investigate, contain it, assess notification duties, and document our response. Where a law requires notice within 72 hours, we will notify the competent authority within that period after becoming aware, to the extent required by that law. For a breach notifiable under Singapore's PDPA, we will notify the Personal Data Protection Commission as soon as practicable and no later than three calendar days after determining that the breach is notifiable, and notify affected individuals as soon as practicable where required. Other affected people and regulators will be notified within the deadline and in the manner required by their applicable law.

Protect your Google account and device, do not share API keys, and report suspected unauthorised access to support@fingerframeai.com.

9. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

  • be informed about the personal data we collect, use, disclose, and retain;
  • access personal data we control and receive information about its use or disclosure;
  • correct inaccurate or incomplete data;
  • request deletion where there is no overriding legal or operational reason to retain it;
  • restrict processing in specified circumstances;
  • receive eligible data in a structured, commonly used, machine-readable format;
  • object to processing based on legitimate interests;
  • withdraw consent at any time where processing relies on consent, including optional analytics;
  • challenge a prompt or output safety decision and request human review;
  • opt out of sale or sharing for targeted advertising—although we do neither; and
  • complain to the data-protection authority where you live or work. In Singapore, this is the Personal Data Protection Commission.

Send a request from the account email to support@fingerframeai.com and describe the right you wish to exercise. We may request proportionate information to verify your identity and protect other users. We will respond within 30 calendar days, or sooner if applicable law requires. If a lawful extension is needed, we will explain the reason and expected date. Exercising a right will not result in unlawful discrimination, although deleting data or withdrawing processing essential to a feature may make that feature unavailable.

You can also revoke FingerFrame AI's Google access in your Google Account settings and manage Waffo-controlled payment information through Waffo's customer tools or privacy channels.

10. Service Notices and Marketing

We may send necessary account, generation, billing, renewal, cancellation, receipt, security, support, and policy messages. These are service communications, not marketing, and some cannot be disabled while the affected account or subscription remains active.

We do not currently send optional promotional marketing messages. If we introduce them, we will use any consent required by law and include a working unsubscribe path. Opting out of future marketing will not stop necessary service communications.

11. Children and Hosted AI

FingerFrame AI is not intended for children under 13, and we do not knowingly collect their personal data. Users aged 13–17 may use local mode only with permission from a parent or legal guardian; local-mode media remains on the device through FingerFrame AI. Hosted AI, cloud media processing, accounts used for hosted generation, and paid cloud-model features require the user to be at least 18.

If you believe a child has provided personal data contrary to this policy, contact us. After appropriate verification, we will restrict the account and delete the data as required, subject to child-safety evidence-preservation duties.

12. Third-Party Links and Services

This policy governs personal data controlled by FingerFrame AI. Third-party websites and independently controlled services have their own practices. Review their notices before using local gesture assets, Google sign-in, Waffo checkout, model-provider services, analytics, or any external link.

13. Changes and Version History

We may update this policy as the product, providers, safety practices, or law changes. We will update the version and effective date above. For a material change that affects how we collect, use, or disclose personal data, we will provide at least 15 days' advance notice through the registered email address or a prominent service notice, unless urgent security, fraud, child-safety, provider, or legal requirements require faster action. Earlier versions and their effective dates will be retained in our policy records and can be requested by email.

14. Contact and Complaints

Email is the supported correspondence channel for privacy requests and complaints. If we do not resolve your concern, you may complain to the Singapore Personal Data Protection Commission or the competent privacy authority in your jurisdiction.