Privacy Policy
Last updated: September 2, 2026
This Privacy Policy explains how Pureframe AI collects, uses, retains, and shares information when you visit our website or use our API and SaaS product.
1. Information we collect
Account and contact information, such as name, email address, phone number, company, industry, and messages you send to us.
Customer content, such as videos, images, transcripts, metadata, search queries, prompts, and other files or information submitted to the service.
Derived data, such as extracted frames, transcripts, embeddings, labels, indexes, scene metadata, and other data generated to make video content searchable.
Usage and technical data, such as pages viewed, actions taken, device information, browser type, IP address, logs, referral pages, and approximate location derived from technical data.
Analytics data collected through PostHog (currently in active use, gated behind cookie consent) to understand product usage, conversion funnels, errors, and drop-off points. We configure session replay to mask form inputs and sensitive fields.
Performance data collected through Vercel Speed Insights (currently in active use) to monitor page load times and site performance. This tool is cookieless and does not collect personal information.
Marketing and advertising data, such as campaign source, ad click identifiers, pages viewed, button clicks, conversion events, hashed contact identifiers, cookie IDs, pixel IDs, and similar online identifiers collected through advertising tools such as Meta Business Tools, Google Ads, LinkedIn Ads, or similar platforms, if and when we use those tools. We do not currently use any advertising or remarketing tool — see Section 7 for current status.
Security and bot-prevention data, such as IP address, user agent, browser or device signals, network or TLS signals, Cloudflare Turnstile sitekey and origin information, and challenge results. We use Cloudflare Turnstile to protect our contact form from spam and automated abuse — see Section 8 for details.
Billing and payment-related data, such as Stripe customer identifiers, billing address, payment method metadata, transaction history, credit balance, credit transactions, invoices, tax information, and chargeback or dispute records. We do not store full card numbers.
2. How we use information
To provide, operate, maintain, and improve Pureframe AI.
To process, index, search, and retrieve customer content as requested by users.
To respond to inquiries, provide support, and communicate about the service.
To monitor performance, prevent abuse, debug issues, and understand how visitors and users interact with the product.
To protect Pureframe AI, users, forms, signups, logins, uploads, APIs, and other workflows from spam, bots, automated attacks, credential abuse, fraud, and other misuse, including by using Cloudflare Turnstile in invisible or managed modes.
To detect prohibited content: content processed through the service — including frames, audio, and transcripts generated during indexing — may be automatically scanned by content-safety systems, including hash-matching against databases of known illegal material and machine-learning classifiers for content categories prohibited by our Terms. Flagged content is reviewed by a person before enforcement action, except where the law requires otherwise. Where the law requires it, we report identified child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC) or other appropriate authorities.
To measure advertising performance, attribute signups or inquiries to campaigns, build or exclude advertising audiences, and show relevant ads on third-party platforms such as Facebook, Instagram, Google, LinkedIn, or similar services, where permitted by law and your choices.
To enforce our Terms and comply with legal obligations.
3. Our roles: controller and processor
For account, billing, website, analytics, marketing, and security data, Pureframe AI acts as a data controller — we decide how and why that information is processed as described in this policy.
For customer content and data derived from it (frames, transcripts, embeddings, indexes), Pureframe AI acts as a data processor (or service provider) on behalf of the account owner: we process that content only to provide the service to the account owner and its authorized users, plus the content-safety scanning and legal-compliance processing described in this policy.
If you need a Data Processing Agreement for your organization, contact us at support@pureframe.ai.
4. Customer content and uploader responsibilities
Users and organizations that upload content are responsible for ensuring they have the rights, notices, permissions, and consents required to upload and process that content through Pureframe AI.
Customer content may contain personal information about people who appear in videos, images, audio, transcripts, metadata, or other submitted materials. We process that information as needed to provide the service to the account owner and authorized users.
If we receive a privacy, deletion, access, takedown, or rights request involving customer content, we may ask the requester for additional information, direct the requester to the relevant account owner, or take reasonable action where required by law or our Terms.
5. Retention
Uploaded videos and derived data such as frames, transcripts, embeddings, metadata, and indexes are retained until you delete the source content, close your account, or request deletion, unless a longer period is required for legitimate operational or legal reasons.
Search queries and product usage logs are generally retained for up to 12 months.
Security, diagnostic, and server logs are generally retained for up to 90 days.
If you request account deletion, we may apply a 30-day grace period before hard deletion so the request can be cancelled, subscriptions can be handled, and deletion jobs can complete.
Backups may retain deleted content for up to 30 days before they are overwritten or removed.
Contact form submissions and sales inquiries may be retained for up to 24 months.
Analytics data is retained according to our analytics provider settings and used to understand product usage and improve the service.
Advertising and conversion data is retained according to our advertising platform settings and campaign needs, unless a shorter period is required by law or your choices.
Billing, payment, tax, credit transaction, and dispute records may be retained for up to 7 years or longer where required for accounting, tax, legal, fraud-prevention, or financial recordkeeping obligations.
Content flagged by content-safety systems, and records of related review decisions, may be retained longer where reasonably necessary for legal compliance, evidence preservation, or protection against repeat abuse.
When an account is closed, we retain an anonymized record that includes aggregate metrics such as account tenure, plan, and total usage, along with a one-way cryptographic hash of your email address used for fraud prevention. This record contains no reversible personal information and is retained indefinitely.
6. Sharing information
We do not sell personal information.
We may share information with service providers that help us host, operate, analyze, secure, bill for, and support Pureframe AI, including providers for authentication, database storage, object storage, vector search, compute, payments, email delivery, analytics, advertising measurement, and bot prevention.
We may share website events, conversion events, device identifiers, cookie identifiers, hashed contact information, and similar marketing data with advertising and measurement partners such as Meta, Google, LinkedIn, and similar platforms, if and when we use those tools. We do not currently use any advertising or remarketing tool.
We share security and bot-prevention signals with Cloudflare through Cloudflare Turnstile, which protects our contact form from spam and automated abuse. If we extend Turnstile or similar tools to other workflows, we will update this section.
Our current infrastructure and service providers include Supabase, Cloudflare, Qdrant, Modal, Stripe, Resend, PostHog, Vercel, and cloud hosting providers. The exact providers may change as the service evolves.
We may share content and related account information with child-safety organizations and authorities, such as NCMEC, where we are required or permitted by law to report identified illegal material.
We do not use customer-uploaded videos, images, transcripts, embeddings, search indexes, or other customer content to build advertising audiences, run retargeting campaigns, or train third-party advertising systems.
We may disclose information if required by law, to protect rights and safety, or in connection with a business transaction such as a merger, acquisition, financing, or sale of assets.
7. Advertising, cookies, and tracking technologies
Current status: the cookie- or browser-storage-based tracking on this website consists of PostHog product analytics and Google Analytics 4. These services measure page views, scroll depth, referral information, device and browser characteristics, approximate location derived from network information, and interaction events. They only run after you enable the "Product analytics" category through the cookie banner or Cookie Preferences in the footer. We also use Vercel Speed Insights to monitor page load performance; it is not gated by cookie consent.
We do not currently run Meta Pixel, Meta Conversions API, Google Ads tags, LinkedIn Insight Tag, or any other advertising, retargeting, or conversion-measurement tool on this website. The "Marketing measurement" category in Cookie Preferences is reserved for these tools and stays off — no such tool loads — until we turn it on.
If we start using advertising or marketing-measurement tools, we will update this Privacy Policy and enable the "Marketing measurement" category first. Where required by law, those tools will not run for a visitor until they've actively consented through that category. Once active, such tools may collect or receive information about your visits and actions on our website for conversion measurement, campaign attribution, frequency capping, fraud prevention, audience creation, audience exclusion, and remarketing.
You can change your cookie choices at any time using "Cookie Preferences" in the footer, through your browser settings, or — once any advertising partner is active — through platform-level controls provided by that partner.
Browser settings, private browsing modes, ad blockers, and global privacy signals may limit some tracking technologies, but they may not block every analytics or measurement event.
Depending on your location, sharing data with advertising platforms for cross-context behavioral advertising may be considered a sale, sharing, or targeted advertising activity once such tools are active. You may contact us to opt out of such use, and we will honor legally required opt-out signals where we are able to detect and process them.
8. Bot prevention and Cloudflare Turnstile
Current status: we use Cloudflare Turnstile to protect our contact form from spam and automated abuse. It is not used anywhere else on this website today.
When you submit the contact form, Cloudflare may process client-side signals such as IP address, user agent, browser or device characteristics, network or TLS signals, sitekey and origin information, and similar technical data for bot detection, abuse prevention, and Turnstile improvement. Cloudflare's processing of Turnstile data is described in the Cloudflare Turnstile Privacy Addendum at https://www.cloudflare.com/en-gb/turnstile-privacy-policy/.
We use Turnstile for security and abuse prevention only, not for advertising or cross-site behavioral advertising by Pureframe AI.
If we extend Turnstile or a similar bot-detection tool to other forms or workflows, we will update this section to reflect what's active.
9. Security
We use reasonable technical and organizational measures to protect information, as described on our Security page. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
You are responsible for keeping your account credentials and API keys secure.
10. Your choices and rights
You may request access, correction, deletion, or export of your personal information by contacting us at support@pureframe.ai.
Depending on where you live, you may have statutory rights over your personal information — such as access, correction, deletion, portability, restriction, or objection under the GDPR or UK GDPR, rights under the India Digital Personal Data Protection Act, or rights under US state privacy laws — and the right to complain to your local supervisory authority. We honor these requests as required by applicable law. For requests concerning customer content, we may direct you to the account owner, who controls that content.
You may delete content through product controls when available or contact us for assistance.
You can control cookies and similar technologies through your browser settings, though some features may not work correctly without them.
You may opt out of marketing emails by using the unsubscribe link in those emails. Transactional or service-related messages may still be sent when necessary.
You may use ad platform controls, such as Meta ad preferences, Google ad settings, LinkedIn ad settings, and industry opt-out tools, to limit personalized advertising on those platforms.
You may contact us at support@pureframe.ai to opt out of targeted advertising, sale, or sharing activities where those rights apply.
11. Children
Pureframe AI is a business service and is not intended for anyone under 18. We do not knowingly collect personal information from children.
12. International use
Your information may be processed in countries other than where you live. Those countries may have data protection laws that differ from your local laws.
Pureframe AI infrastructure and service providers may process data in the United States, India, and other countries where we or our providers operate. We do not currently offer a dedicated EU data residency option.
13. Third-party links
Our website and product may contain links to third-party websites, plugins, and services that we do not own or control, such as payment processors, documentation hosts, or social media platforms. We are not responsible for the privacy practices or content of those third parties. Visiting a linked site is subject to that site's own privacy policy, and we encourage you to review it.
14. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users, such as posting an updated version on this page.
15. Contact
For privacy questions or requests, contact us at support@pureframe.ai.