37/36 FRAME
LEGAL

Privacy Policy

LAST UPDATED: 17 JULY 2026

Frame 37 is a camera app. Cameras see a lot, so this page says plainly what we store, why, where it lives, and how to make it go away. No dark patterns, no data brokers.

The short version. We store your photos so we can develop them, and an account so they come back to the right person. We do not sell your data, we do not use your photos to train anything, and we do not show you ads. Deleting your account really deletes your photos.

01Who we are

Frame 37 (“Frame 37”, “we”, “us”) is the Frame 37 mobile app and this website, operated by Evgenii Isupov, an individual developer based in Portugal, who is the data controller for the data described here.

Contact: [email protected] — email is the fastest way to reach us, and the right address for any privacy request. If you need a postal address for a formal notice, ask and we will provide one.

02What we collect

DataWhy we have itLegal basis (GDPR)
Your photos — the frames you shoot, plus the developed versions we render To develop a roll and give it back to you. This is the product. Performance of a contract (Art. 6(1)(b))
Account identifier — email address, or an Apple / Google sign-in identifier, or an anonymous guest ID To tie rolls to an account and let you sign back in on a new device. Performance of a contract
Roll and frame metadata — film type, frame numbers, timestamps, processing status To run the counter, the develop timer and the darkroom queue. Performance of a contract
Push token and basic device info (platform, app version) To tell you a roll is ready. Only if you allow notifications. Consent (Art. 6(1)(a)) — you can revoke it in system settings
Subscription and usage records — which plan you have, how many rolls you developed To apply your plan's limits and handle billing questions. Performance of a contract; legal obligation for tax records
Technical logs — IP address, request time, error traces Security, abuse and rate limiting, debugging. Legitimate interests (Art. 6(1)(f)) — keeping the service up and unabused

WHAT WE DO NOT COLLECT

03How your photos are handled

When you shoot a frame, the app uploads the original directly to our private storage over an encrypted link. The original is not written to your device's photo gallery, and it is not visible to you before the roll is developed — that is the point of the app.

When the roll is finished, our darkroom worker renders the developed frames and stores them next to the originals. Access is private: images are served only to your account, only over short-lived signed links.

Photos are processed automatically by our own software. We do not look at your photos, we do not sell them, and we do not use them to train machine-learning models. We may access an individual image only if it is strictly necessary to fix a fault you reported to us, or if we are legally compelled to.

COLLECTING A ROLL

When you collect a developed roll, it is downloaded to your device and then deleted from our servers. After that, your device holds the only copy — so keep your own backups. We cannot restore a collected roll for you.

04Who else touches the data

We use a small number of processors, each bound by a data processing agreement and each doing only what we instruct:

Beyond those, we disclose data only when the law requires it, or to establish or defend legal claims. If Frame 37 is ever acquired, your data may transfer with the service; you will be told before that happens.

05Where the data lives

Our servers and database are in the European Union (Amsterdam). Cloudflare R2 and push delivery may involve transfers outside the EEA; those are covered by the European Commission's Standard Contractual Clauses.

06How long we keep it

07Deleting your account

You can delete your account from inside the app (Settings → Account → Delete account). This starts a real erasure: we delete your stored images and then purge or anonymise your database rows, leaving only an anonymous tombstone and any records we are legally required to keep. Erasure runs as a background job and normally completes within minutes; it can take up to 30 days if something needs retrying. It cannot be undone — uncollected rolls are gone.

If you cannot reach the in-app option, email [email protected] from your account address and we will do it for you.

08Your rights

If you are in the EEA or the UK you have the right to access, correct, delete, export (portability), restrict, and object to our processing, and to withdraw consent at any time (withdrawal does not affect processing already carried out). If you are in California, you have the rights to know, delete, correct, and to opt out of sale or sharing — we do not sell or share personal data, so there is nothing to opt out of.

To exercise any of these, email [email protected]. We answer within 30 days and will not charge you or degrade your service for asking. You can also complain to your local data protection authority.

09Children

Frame 37 is not directed at children under 13 (or under 16 where local law sets that age), and we do not knowingly collect their data. If you believe a child has given us data, write to us and we will delete it.

10Security

Data is encrypted in transit (TLS) and at rest. Storage buckets are private, object names are generated by our servers, and access happens only via short-lived signed links. No system is perfect: if a breach ever affects your data, we will notify you and the relevant authority as the law requires.

11This website

This site sets no cookies and runs no analytics or tracking. It loads fonts from Google Fonts, which means your IP address reaches Google when the page opens. Our host may keep standard server logs for security.

12Changes

If we change this policy we will update the date above, and for material changes we will tell you in the app or by email before the change takes effect.

Questions? [email protected] — a person reads that inbox.