Back to homepage

Privacy Policy

Last updated: August 11, 2026

This Privacy Policy explains how FlowFrame, operated by Jeremy Lopes dos Santos (see our Contact page for full business details), collects, uses, and protects your personal data when you use flowframe.pro. We are the data controller for the personal data described here, under the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

1. Information We Collect

Account information

  • Email address and password (stored encrypted, never in plain text)
  • Account preferences and settings

Tool usage data

  • Content you upload or input into FlowFrame
  • AI-generated outputs and results
  • Usage timestamps, generation history, and credit consumption

Billing information

  • Subscription tier and plan details
  • Transaction history, payment method details are held by Stripe, not by us

Technical information

  • IP address, device and browser information
  • Session cookies and authentication tokens
  • Error logs and performance metrics

2. How We Use Your Information & Legal Basis

We process your data on these legal bases under GDPR Art. 6:

  • Contract (Art. 6(1)(b)): delivering the service, running generations, managing your subscription and credits, billing
  • Legitimate interest (Art. 6(1)(f)): keeping the service secure, preventing fraud and abuse, improving performance, aggregated analytics
  • Consent (Art. 6(1)(a)): marketing emails and non-essential tracking such as our advertising pixel, you can withdraw consent at any time
  • Legal obligation (Art. 6(1)(c)): keeping financial and tax records as required by Austrian law

3. Data Sharing & Subprocessors

We do not sell your personal data. We share data with the following subprocessors, each acting under a data processing agreement:

  • fal.ai (AI generation): your uploaded inputs and prompts are sent to fal.ai to run the generation you request. See fal.ai's terms.
  • Supabase (authentication, database, file storage)
  • Vercel (hosting and content delivery)
  • Stripe (payment processing and billing), see Stripe's privacy policy
  • TikTok Pixel (advertising measurement), only loaded where you have consented to non-essential cookies

We may also disclose data where required by valid legal process, law enforcement requests, or to protect our rights and the safety of our users.

4. International Data Transfers

Some of our subprocessors, including fal.ai and Stripe, are based outside the EU/EEA. Where we transfer personal data outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses or another valid transfer mechanism to protect your data.

5. Data Security

  • TLS/SSL encryption for data in transit (HTTPS)
  • Encryption at rest, encrypted password hashing
  • Access controls and authenticated sessions
  • Regular backups and security updates

No system is 100% secure. Keep your account credentials private, and contact support@flowframe.pro immediately if you suspect unauthorized access.

6. Cookies

We use essential cookies for authentication, security, and basic site functionality, these are required for FlowFrame to work. With your consent, we also use a TikTok advertising pixel to measure the performance of our marketing. You can manage or withdraw cookie consent at any time through your browser settings.

7. Your Rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure of your data ("right to be forgotten")
  • Request a copy of your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent at any time, without affecting past processing
  • Lodge a complaint with the Austrian data protection authority (Datenschutzbehörde), or the supervisory authority in your own EU country of residence

To exercise any of these rights, email support@flowframe.pro. We will respond within 30 days.

8. Data Retention

  • Your data is retained while your account is active
  • Generated content and account data are deleted within 30 days of account closure
  • Backup copies are purged within 90 days
  • Financial and transaction records are retained for 7 years as required by Austrian tax law

9. Children's Privacy

FlowFrame is not intended for children under 14. We do not knowingly collect data from children under 14. If you are between 14 and 18, you need parental or guardian consent to use FlowFrame. If we learn we have collected data from a child under 14, we will delete it. Parents can contact support@flowframe.pro with concerns.

10. AI Provider Data Usage

Your uploaded inputs and prompts are sent to fal.ai to generate your requested output. We do not control how fal.ai or the underlying AI models handle this data beyond our agreement with them, review fal.ai's terms if you have concerns. Avoid uploading highly sensitive personal information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will announce material changes by email or in-app notice at least 15 days before they take effect, and update the date at the top of this page.

12. Contact

For privacy questions or to exercise your rights, email support@flowframe.pro or see our Contact page for our full legal business details.