How we handle your data.
Last updated: September 28, 2026
FrameSaver is built to be simple and respectful of your privacy. This page is the plain-language version of what that means in practice.
This policy is a draft for transparency, not a substitute for legal advice. Review it with a qualified attorney before relying on it as legally binding.
What we collect
To run the service, we store:
- Your email address: used to sign you in via a one-time code. We don't use it for marketing.
- Photos you upload: stored privately in your account. Only you can see them.
- Your settings: screensaver duration, transition style, selected photo sources.
- Your favorites: photos you've marked as favorites while browsing.
- A session cookie: set by our authentication provider to keep you logged in.
Optional usage analytics
We use PostHog to understand whether people successfully display photos, how much the player is used, and which browsers encounter failures. During visible playback we send a small summary approximately every five minutes and, when possible, when you leave. Display time is an estimate; it does not tell us whether anyone is watching.
On public pages such as the homepage, guides, and FAQ, we record which page was viewed, the referring website, and campaign tags, so we can tell which guides help people find FrameSaver. Signed-in pages do not send page views.
Signed-in usage uses an account identifier so we can count returning accounts. It is not anonymous. Analytics events exclude your email address, photo contents, filenames, image URLs, and folder identifiers. We do not record your screen, clicks, or keystrokes automatically. Reports focus on aggregate usage and reliability.
You can turn optional analytics off below or in the dashboard. This preference applies to this browser, including analytics generated by its requests to our server. Set it separately on other devices. We also honor Do Not Track and Global Privacy Control. Operational account records and server logs needed to run the service are separate.
Usage analytics
Help us understand whether FrameSaver displays photos reliably and gets used. We measure approximate display time and basic failures, without recording your screen or collecting photo contents or filenames. This choice applies to this browser. Do Not Track and Global Privacy Control turn analytics off.
What we don't collect
No passwords (we use one-time email codes instead). No ad-tracking pixels. No cross-site profiling. No sale of data to third parties. Ever.
Third-party services
FrameSaver runs on a small set of trusted infrastructure providers:
- Supabase: hosts your account, photos, and settings.
- Vercel: hosts the website and processes requests and operational logs needed to serve it.
- PostHog: processes the optional usage measurements described above.
- Smithsonian Open Access and Wikimedia Commons: read-only public APIs we query to fetch photography for the screensaver. Collection requests are proxied through our server. Images can load directly from the source host, which receives the network information needed to deliver them.
Your rights
You can delete your account at any time. Email us and we'll remove your email, photos, settings, and favorites from our databases. We don't keep backups beyond what our hosting providers use for their own disaster recovery.
If you're in the EU, UK, or California, you have additional rights under GDPR and CCPA, including access, correction, portability, and deletion. To exercise any of these, email us.
Changes to this policy
If we materially change what we collect or how we use it, we'll update this page and the “last updated” date above. For significant changes, we'll also send a note to your account email.
Contact
Questions or requests? ericfriedman@gmail.com.