How Frameow handles account, cat photo, portrait, payment, and service data
2026/09/16
Frameow is an independent developer project maintained by the Frameow team. The team handles service and privacy requests at support@frameow.com.
This Privacy Policy explains how Frameow collects and uses information when you visit the website, create an account, upload cat photos, generate portraits, make a payment, or contact support.
Accounts, portrait creation and purchases are for people aged 18 or older. We record your age confirmation time and the version of that declaration, not your date of birth or an identity document. Contact support if you believe a person under 18 has created an account.
Depending on how you use Frameow, we may handle:
Frameow does not ask for your password or email verification code in support messages.
We use this information to provide authentication, process portrait generations, store and deliver your content, manage credits and billing, send requested or required emails, respond to support requests, prevent abuse, and improve service reliability.
When you choose a photo, a smaller preview is sent through OpenRouter to check whether it contains one cat, including before you sign in. Frameow does not save this check preview or include it in logs; OpenRouter and its model provider process it under their own policies. Your original photo stays on your device until you confirm creation after signing in. Starting sign-in temporarily saves your selection in this browser so it can be restored when you return. The draft is cleared after restoration, or discarded after 30 minutes when the draft store is next accessed. Saving the original photo and generating a portrait begin only when you confirm creation after signing in.
Uploading a photo or creating a portrait does not automatically publish it in Frameow’s public gallery. Public style examples are separate from your account’s photos and generated portraits. The source photos selected for a generation are sent to the AI service provider to produce your result; private account access does not mean the photos are processed only on your device.
After you allow optional analytics, we record style views, signed-in visits, photo-selection actions and checkout starts, together with campaign labels and random visit and session identifiers. Signed-in observations are associated with your account to understand the creation and purchase journey. These measurement records do not contain uploaded photos, portrait text, email addresses, full referring URLs, or payment credentials. Generation, payment, and download or sharing-link milestones are also recorded as part of providing those services, independently of optional analytics.
When enabled, Google Analytics 4 receives consented page and interaction events and related server-confirmed generation and payment events, using random identifiers to associate activity within a visit. We disable advertising storage and personalization. Microsoft Clarity receives masked recordings of selected public browsing pages to help us understand navigation and usability; creation forms, sign-in, account and artwork pages are excluded. Public static example images may remain visible, but uploaded photos, portrait text, cat names, email addresses and signed image links are excluded from both tools.
Optional collection starts only after you allow analytics and respects Do Not Track and Global Privacy Control. You can decline or withdraw consent using Privacy settings at the bottom of the website. Withdrawal stops future optional collection and cancels associated pending deliveries; it cannot recall data already sent. See our Cookie Policy for browser storage and controls.
Account-linked analytics details are deleted with the account. Anonymous daily image totals, which contain no account or artwork identifiers, can remain for aggregate reporting.
TikTok advertising measurement requires a separate opt-in in Privacy settings. It shares public style views and confirmed registration, checkout and positive payment events, with event identifiers, product information and payment amount/currency where applicable. Matching uses available IP address, user agent, TikTok click ID and browser cookie. Email, phone, account ID, uploaded images, portrait text and private artwork links are excluded. Attribution and associated delivery records are retained for up to 30 days, and account-linked records are deleted with the account. You may withdraw consent at any time. See the Cookie Policy for details.
Frameow uses service providers to operate the product. These may include Google for sign-in and optional analytics, Microsoft for optional Clarity analytics, Resend for email delivery, Waffo for payment services, KIE.ai and OpenRouter for GPT Image 2 generation, OpenRouter and Google for the initial cat-photo check, DeepSeek for image/text safety checks, Qiniu for image storage and delivery, Cloudflare for domain and network services, and hosting or database providers used to run Frameow.
Waffo Pancake acts as merchant of record for Waffo transactions. Full card numbers and card security codes are entered into its hosted payment flow, not stored by Frameow. We receive order references, billing status and information needed to match your purchase to your account.
Each provider handles data under its own terms and privacy practices. We share only the information reasonably needed for that provider to perform its role.
Before generation, the selected photos and applicable template text are checked for prohibited content; the final output is checked before it is made available. These checks send the necessary content to DeepSeek through its official API. They are separate from optional analytics. Reports and appeals are reviewed by the Frameow team, who may access the content needed to resolve the case.
Our audit table records internal account/job links, a content digest, template and policy versions, decision categories, timestamps and any human review outcome. It does not contain image copies, raw prompts, signed image URLs or raw model responses. Ordinary audit records are retained for 90 days and then scheduled for deletion. A specific unresolved dispute or legal obligation may require limited longer retention with a recorded reason and end date. Account deletion removes the account/job links from retained audit records.
Unreleased intermediate generation files are held in private staging storage, normally for no more than 24 hours. Rejected results are scheduled for removal promptly. They are not exposed through the ordinary media download API. This does not extend the retention of your source photos.
Temporary source photos that are not saved to a cat profile are scheduled for deletion after seven days. Photos saved to a cat profile and generated portraits remain available until they are removed through the product or the associated account is deleted.
Account deletion is requested by email and has a 30-day waiting period. When the request is completed, the account and its online product data are removed. Deleting an account does not create eligibility for repeated new-account credits.
We apply the following retention rules to data under Frameow’s control. Deletion of your online account is separate from rotation of restricted backups and records needed for a specific unresolved case.
| Record | Retention and removal rule |
|---|---|
| Routine support emails and attachments | Keep while the request is open, then for up to 12 months after closure to handle follow-up questions. Remove unnecessary attachments earlier. The team checks closed cases monthly. |
| Billing complaints, refund or dispute correspondence | Keep the minimum case evidence for up to 24 months after closure to support transaction disputes. An unresolved case or applicable legal requirement may need a longer, documented period. This is not a promise to retain all account data after deletion. |
| Application diagnostic logs | Use for incident investigation and service reliability. Logs are rotated by the hosting system; the team reviews retained logs monthly and removes diagnostic copies no longer needed. An active incident may require an isolated evidence copy until the investigation and follow-up are complete. We do not represent size-based log rotation as a guaranteed number of days. |
| Restricted database backups | Keep to restore the service and recover from failed releases. At each release and at least monthly, review backup copies; remove superseded copies after a newer backup has been validated and the associated rollback need has ended. A backup retained for an incident has a recorded reason and next review date. Backups are not used for routine customer access or analytics. |
| Account-linked activity, credit and payment-reference records in the live product database | Keep while needed to operate your account and resolve transactions. The online account deletion process removes the linked product records. Specific support or moderation evidence retained for a dispute is governed by the separate rules above. |
| Anonymous daily totals | May remain for reporting because they contain no account, artwork or photo identifiers. |
For a specific legal obligation or unresolved dispute, the team records the reason for extended retention, the responsible person and the next review or expiry date. It reviews these exceptions monthly and removes the retained copy when that reason ends. A restricted deletion record containing only the internal account identifier and deletion time is kept until backups containing that account have been retired. Restoring a backup requires reapplying completed account-deletion requests before normal service resumes, so a restore does not reactivate a deleted account.
Payment, email, hosting, analytics and AI providers control their own service logs, backups and legally required records. Their retention may differ from Frameow’s schedule. We do not promise that every provider deletes a copy when Frameow does, or that API content is never retained or used by an upstream provider. See KIE’s privacy policy and Waffo’s privacy policy. Contact us for questions about a specific record or provider.
Email support@frameow.com from your account address to request access, correction or deletion, or to raise an objection about processing. We verify only the information needed to match the request to your account. Applicable rights and exceptions depend on your location and the purpose for which the record is retained. Optional analytics can be withdrawn through Privacy settings without deleting your account.
New style summaries, generation results, site activities, and product feature updates can be managed in email preferences when those controls are available. Account security messages are required and cannot be turned off while an account exists.
We use reasonable technical and organizational measures to protect information. No internet service can guarantee absolute security, so please use a secure email account and contact us if you believe your Frameow account has been accessed without permission.
We may update this policy as Frameow changes. The date at the top shows the latest published version.
The Frameow team handles requests by email, replies within two business days, and aims to complete an initial review of ordinary cases within five business days. Complex cases receive a progress update. For privacy questions or an account deletion request, email support@frameow.com.