Skip to content
FinalFrame

Privacy Policy

Last updated: September 12, 2026

FinalFrame is an AI-powered photography critique service built for photographers. We know photographers care deeply about how their images are handled, so this policy is written in plain language. It explains exactly what data we collect, why, where it goes, and how you can control it.

1. Who We Are

FinalFrame is operated by Crypto Brains DOO, a company registered in Serbia. For any privacy-related questions, you can reach us at:

For the purposes of the EU General Data Protection Regulation (GDPR), Crypto Brains DOO acts as the data controller for the personal data described in this policy.

2. Data We Collect

2.1 Account Data

When you create an account, we collect and store:

2.2 Photographs and Image Data

When you upload a photograph for critique, we process and store:

2.3 EXIF Metadata We Extract and Retain

We extract a limited set of photographic metadata from your images to provide better critique. Specifically:

We do not extract or store GPS coordinates, camera serial numbers, or other personally identifying EXIF fields. GPS data is actively stripped from all stored copies of your images.

2.4 AI Critique Data

When the AI analyzes your photograph, we store the full critique results, including:

2.5 Curation Data

If you use the photo curation feature (selecting your best images from a set), we store the session data including individual image scores, rankings, strengths and weaknesses, cohesion analysis, and sequence reasoning.

2.6 Content Moderation Data

Every image uploaded to FinalFrame is screened through OpenAI's content moderation endpoint (omni-moderation-latest) before critique. For any moderation outcome that matches a monitored category (“soft_block,” “hard_block,” and any “pass” that still flagged a category), we log the verdict, the flagged categories, and their confidence scores for audit and threshold calibration purposes. A clean “pass” with no flagged category is not logged. For hard-blocked content (severe policy violations), we additionally log: a cryptographic hash (SHA-256) of the image, your IP address, user agent, and the timestamp. This metadata is retained for law enforcement cooperation and platform safety. The image itself is deleted immediately and is not retained in any form. Non-hard-block moderation logs do not include IP addresses or image hashes.

Third-party content databases: moderation metadata (image hashes, flagged categories, scores) is stored only in our own Supabase database for the purposes described above. We do not forward image hashes or moderation metadata to NCMEC, PhotoDNA, GIFCT, StopNCII, or any other external hash-matching database. We may cooperate with law enforcement authorities upon lawful request: in that case, hashes or metadata would be disclosed only in response to a specific legal process.

Automated detection scope (transparency disclosure). Our automated content moderation uses OpenAI's omni-moderation-latest model, which evaluates images for adult sexual content (sexual), violence (violence, violence/graphic), and self-harm content (self-harm, self-harm/intent, self-harm/instructions). It does NOT provide automated detection specific to child sexual abuse material; the sexual/minors category in the moderation API is text-only and is not evaluated against image content. We rely on user reporting (see Section 9.4 of our Terms of Service) and the adult sexual category with an admin review queue for borderline scores (0.50–0.75 band) as proximate signals. We may add a dedicated image-CSAM detection partner in the future and will update this section before doing so.

2.6a Automated Decision-Making (GDPR Art. 22)

Image uploads are screened by automated content moderation before any AI critique begins. These automated decisions can have a significant effect on you: they may restrict public sharing of your image, or, in the case of severe policy violations, result in your account being suspended and any active subscription being cancelled. We rely on automated screening because the volume and sensitivity of the material (including adult sexual content, graphic violence, and self-harm imagery) make pre-review by a human infeasible and unsafe.

Your right to human review. You have the right to obtain human review of any automated moderation decision that affects your account or your ability to share content. To request a review:

2.6b AI Transparency (EU AI Act Art. 50)

The critique, score, tier, editing instructions, and any narrative text generated by FinalFrame are produced by AI models in OpenAI's GPT-5 family, operating on your image and optional EXIF metadata. The output reflects algorithmic analysis, not human judgement. It is intended as educational feedback, not as a professional appraisal, competition verdict, or legal document. The results may be incorrect, incomplete, or biased for reasons outside our control. You should use your own judgement when acting on any critique.

When you choose to publish an image to the public gallery (Section 6 of the Terms), its FinalFrame Score and tier are displayed publicly alongside the image, may appear on your public photographer profile, and can be shown in an embeddable badge you place on third-party websites you control. These scores remain an algorithmic assessment as described above; publishing is optional and reversible: unpublishing removes the public display, and the badge stops showing your statistics within approximately one hour.

OpenAI processes your image as a sub-processor on our behalf. See Section 5 (Third-Party Sub-Processors) for the specific processing role and data protection terms. Our data processing agreement with OpenAI is available on request.

2.6c Retention Periods for Moderation Actions

We retain data related to content-moderation actions for the following periods:

2.7 Payment Data

If you subscribe to a paid plan (Pro at $19/month or Premium at $36/month) or purchase credit packs, payment processing is handled by Paddle (“Paddle”), who acts as our Merchant of Record. Paddle contracts through more than one legal entity and the one that is your counterparty depends on where you purchase from; see Terms Section 11.5. This means Paddle is the legal seller of the subscription; they process payments, collect applicable taxes (VAT, sales tax, GST), and handle chargebacks on our behalf. We store:

We never see or store your full credit card number, CVV, or banking details. That data lives entirely within Paddle's PCI-compliant infrastructure. Invoices and receipts are issued by Paddle, not by FinalFrame.

2.7a Payment Retry Handling

When a subscription payment fails, we record the failure timestamp on your profile and retry the charge through Paddle for up to 30 days. During this retry window we send you up to three operational emails about the failure (first notice, midpoint reminder, and final notice before plan loss) so you can update your payment method. We also pause monthly credit refills beginning on the failure date: already-granted credits remain spendable, and credit balances are restored on successful payment. If all retries fail within the retry window, your plan reverts to Free and a final notice email is sent. We send these emails as part of our contract with you (GDPR Art. 6(1)(b), contract performance); they do not respect marketing-email opt-outs. The payment-failure timestamp is cleared when payment succeeds, when you cancel, or when a refund/chargeback is processed; otherwise it is purged after 180 days of account dormancy. We may also send you a pre-expiry notice up to 14 days before your card expires under the same legal basis.

Specific dunning email types we may send under this section:

2.7b Subscription Pause State

When you pause your subscription, we process pause-state data: pause scheduled date, pause start date, pause end date, and reminder-sent flag. Lawful basis: Art. 6(1)(b) GDPR (contract performance). We retain pause-state until the cap-enforcement window naturally expires (rolling 6 months) plus a 12-month dispute window.

2.8 Usage and Quota Data

We track:

2.9 Referral Program Data

If you participate in the referral program, we store:

To prevent self-referral abuse, we normalize email addresses (stripping Gmail +alias suffixes) and compare them during referral processing. This normalized form is not stored; it is computed transiently during the check.

2.10 Public Gallery and Sharing Data

FinalFrame has an opt-in public gallery. If you choose to publish a project or curation session, the following becomes publicly accessible:

You can also generate share links (tokens) that make individual critique results accessible to anyone with the link. You can unpublish projects or revoke share links at any time.

After you revoke a share link, the link becomes inaccessible immediately. However, cached previews on third-party platforms (WhatsApp, Facebook, X, Discord) may persist for 1–7 days. FinalFrame does not control third-party caching behavior.

Image URL expiry after revocation. When a viewer loads a share page, their browser receives a time-limited signed URL pointing directly to the image file. If you revoke the share link or delete the critique after a viewer has already opened the page, the share page itself stops loading for new visitors immediately, and the viewer can no longer obtain a fresh signed URL. However, a signed URL already issued to a browser remains fetchable from our storage provider until it expires: at most 3 hours for images served on shared and public gallery pages, and at most 1 hour for images on private account surfaces. After that window closes, the image file is no longer reachable by any previously issued URL.

2.11 Challenge Data

If you participate in photography challenges, we store your entries, constraint scores, and feedback linked to the challenge.

2.12 Progress Insights and Coaching Data

As you use FinalFrame over time, we generate personalized progress insights and coaching briefs. These include a narrative assessment, focus areas, shooting and editing missions, patterns observed in your work, and a photographer identity label. This data is derived from your critique history and stored in your account.

2.13 Feedback Data

If you submit feedback through the in-app feedback form, we store your message, a screenshot (if you choose to include one), the page URL you were on, and your browser user agent string.

If you cancel your subscription, we ask for an optional reason (selected from a preset list, with an optional free-text field). This is stored alongside your feedback data to help us improve the service.

Lawful basis: We collect optional cancellation reasons to improve the product, under GDPR Art. 6(1)(f) legitimate interest. Our interest in understanding churn does not override your rights, because the data is minimized (enumerated category by default) and the free-text portion is purged automatically.

Retention: The enumerated reason code (e.g. “too_expensive”, “not_using_enough”, “other”) is retained with your account for as long as the account exists. Any free-text response you provide in the “Other” field is automatically purged after 90 days.

Right to object (GDPR Art. 21): You can request immediate purge of your cancellation free-text by emailing support@finalframe.photo. We will process the request within 30 days, and typically within a few business days.

2.13a Mid-Cycle Plan Change Consent Records

When you change your plan mid-cycle in a way that places an immediate charge, such as upgrading to a higher tier (for example, Pro to Premium, which unlocks the Coaching Brief as an additional digital-content feature), or changing your billing frequency (for example, monthly to annual, which commits you to a new, longer minimum term), we write a dedicated consent record to our consent_events table capturing your acknowledgment that the change is performed immediately and that the 14-day withdrawal right under EU Directive 2011/83/EU Art. 16(m) is waived for it.

Purpose. Record of your express consent to immediate performance of the upgraded digital-content services (for example, Coaching Brief on Premium). Required under GDPR Art. 7(1) accountability and the Consumer Rights Directive 2011/83/EU Art. 16(m) disclosure regime. This is a separate consent moment from the waiver you gave when you first subscribed (recorded under action “withdrawal_waiver_accepted”) and from the cookie- consent log described in Section 9.

Data retained. The action type “withdrawal_waiver_upgrade”, the timestamp, your IP address, your user agent string, the from-plan identifier, the to-plan identifier, and the price amount shown to you on the order screen at the moment of consent (retained as evidence that the price you consented to is the price you were charged). No payment-card data, no image data, and no critique content is written to this row.

Retention. 6 years from the consent event, aligned with the German Handelsgesetzbuch § 257 commercial record-keeping requirement (which applies to Crypto Brains DOO in respect of EU customer-facing contracts and may be invoked to prove that the waiver was obtained before immediate performance began). After 6 years, the record is purged.

Lawful basis. GDPR Art. 6(1)(c): legal obligation to record consumer consent under Art. 7(1) GDPR together with the national transpositions of Consumer Rights Directive 2011/83/EU Art. 16(m) (for example, § 356 Abs. 5 BGB in Germany, Art. L221-28 Code de la consommation in France).

Your rights. You can request a copy of your upgrade-consent records through the self-service data export in Account Settings (which covers the consent_events table under Section 8.1), or by emailing support@finalframe.photo. Because this record is retained under a legal obligation, we cannot delete it before the 6-year retention period ends, even on an Art. 17 erasure request; we will restrict processing on request instead (Art. 18).

2.14 Demo Session Data

If you try a demo critique without an account, we store a demo session linked to your IP address, the critique results, and the demo image. Demo images are cleaned up separately from account data. If you create an account, a demo critique you ran on this device may be linked to your new account so it appears in your dashboard.

Lawful basis. We process your demo image and the IP address under our legitimate interest (GDPR Art. 6(1)(f)) in providing the free trial you requested and in preventing abuse of it. Because the demo is a transient, one-off critique you initiate, we rely on legitimate interest rather than consent; there is no standing relationship to manage and no consent-withdrawal mechanism for data this short-lived; you can instead ask us to delete a demo session at any time (see below).

Sub-processor. Before we generate the critique, your demo image is sent to OpenAI (US) for content moderation and AI analysis, exactly as it is for account critiques. OpenAI acts as our sub-processor for this step; the transfer safeguards (Standard Contractual Clauses and the EU-U.S. Data Privacy Framework) are described in Section 5 (Third-Party Sub-Processors) and Section 6 (International Data Transfers).

EXIF metadata. As with account uploads, we read a limited set of photographic metadata from your demo image (camera make and model, lens, and exposure settings) to inform the critique. GPS location data is always stripped and is never stored. See Section 2.3 for the full list of EXIF fields we read.

IP address retention. What happens to the IP address recorded with a demo session depends on whether you go on to create an account:

2.15 Cookies and Local Storage

FinalFrame uses localStorage (not traditional cookies) to store your cookie consent preference (“accepted” or “rejected”). Supabase Auth uses its own cookies/storage for session management. See Section 9 for full details.

2.15a Telemetry and Analytics Stream

FinalFrame uses PostHog (EU Cloud instance at eu.i.posthog.com, hosted in Frankfurt, Germany) to log structured product-analytics events. This subsection discloses the specific event types, the data fields transmitted per event, the lawful basis for each, and your rights relating to this data.

Event types and lawful basis

EventData fieldsLawful basis
signup_completed (service fields only)user_id, locale, hours_since_clickArt. 6(1)(b): contract performance
signup_provisioned (acquisition fields)acquisition_source, acquisition_medium, acquisition_campaign (marketing parameters from the link you arrived through), landing_referrer_host (the host name of the referring site only, e.g. news.ycombinator.com; never the full address, path, or query)Art. 6(1)(f): legitimate interest. We record which marketing channel brought you to FinalFrame, read once from the page URL and the referring site at the moment you sign up, so we can measure which acquisition channels are effective. We store the referring site’s host name only, never the full referrer URL. We do not profile you or make any automated decision from this data, and we do not set a tracking cookie to collect it. Our interest is understanding how people find the product; it is proportionate given the data is minimal and internal-only. You have the right to object to this processing at any time (Art. 21(1)): see Section 8 (Your Rights).
email_verifieduser_id, hours_since_signupArt. 6(1)(b): contract performance
critique_submitteduser_id, tier, genre, lane, is_first, cost_usd, tokens_in, tokens_outArt. 6(1)(f): legitimate interest. We log per-critique AI cost fields (cost_usd, tokens_in, tokens_out) server-side to monitor unit economics and detect cost anomalies. These fields are never exposed to users or included in any user-facing output. Our interest is maintaining a financially sustainable service without over-charging users; this interest is proportionate given the data is aggregated and internal-only.
subscription_activateduser_id, tier, is_annual, days_since_signupArt. 6(1)(b): contract performance
subscription_reneweduser_id, tier, months_activeArt. 6(1)(b): contract performance
subscription_canceleduser_id, tier, reason_code (enumerated category), months_activeArt. 6(1)(f): legitimate interest (churn analysis). Free-text cancel reasons are not forwarded to PostHog: only the enumerated reason code is sent (e.g. “too_expensive”).

New profile columns

As part of the analytics pipeline, we store the following additional fields on your profile record:

AI call cost tracking

We maintain an internal ai_calls table that logs per-request AI cost data (model, token counts, computed cost in USD, call type, success/failure). This table is used exclusively for internal cost monitoring and is never exposed to users via any API or export. It is subject to column-level access controls that prevent any authenticated user from reading it via the database API. Lawful basis: Art. 6(1)(f): legitimate interest in monitoring operational costs. Retention: 24 months, a period we set ourselves for this internal table. It is separate from, and not tied to, the period that applies to our PostHog analytics (see the “Retention” subsection below). Rows that age past this window are purged automatically by a daily background job. These internal cost-monitoring rows are not financial accounting records: Paddle, our payment processor and merchant of record, holds the invoices and financial records subject to longer statutory retention.

PostHog as recipient and data residency

PostHog Inc. (US-domiciled) is our analytics sub-processor. We use PostHog's EU Cloud instance (eu.i.posthog.com), which stores all event data in Frankfurt, Germany. A Data Processing Agreement (DPA) and Standard Contractual Clauses (SCCs) are in place to cover any US-domiciled data access by PostHog staff.

Retention

We retain PostHog event data for no longer than 12 months, the retention period of the PostHog Cloud plan we have chosen for that purpose, after which PostHog deletes it. Our internal AI cost-monitoring data has its own, separately stated period (see the “AI call cost tracking” subsection above), which is not tied to this one.

Right to erasure (§5 cross-reference)

When you submit a deletion request under GDPR Art. 17 (available in Account Settings or by emailing support@finalframe.photo), we delete:

See Section 8.1 (Right to erasure) and Section 7.4 (Account Deletion) for the full deletion cascade.

Regulatory references

Our marketing-attribution capture reads UTM parameters and the referring host from page navigation, not from device storage, so it falls outside the consent gate of ePrivacy Art. 5(3) (EDPB Guidelines 2/2023 on technical storage and access); the processing of that data rests on legitimate interest (Art. 6(1)(f)). CJEU Planet49 (C-673/17) governs cookie storage and access, which this navigation-read path deliberately avoids. The legitimate-interest basis is documented in our internal Legitimate Interest Assessment (LIA) referenced in the DPIA §11.

2.16 Newsletter Subscribers

If you sign up for our newsletter waitlist or subscribe to email updates (e.g., from the demo result page), we collect:

Lawful basis: Your explicit consent (GDPR Art. 6(1)(a)). You can withdraw consent at any time by clicking the one-click unsubscribe link in any email, or by toggling off email categories in your account's Email Preferences settings.

We use double opt-in for newsletter subscriptions: after you enter your email, we send a confirmation email. Only after you click the confirmation link will you receive marketing emails. Unconfirmed signups are automatically purged after 7 days.

Newsletter subscriber data is stored separately from your FinalFrame account. If you later create an account with the same email, the two records are not automatically merged. You can request deletion of your newsletter subscription at any time by contacting support@finalframe.photo or by using the unsubscribe link.

2.16a Monthly Recap (Existing Customers)

Monthly progress recap email: a once-a-month summary of your critique activity and progress, sent only to existing paying customers who are drifting: users on a Pro or Premium plan who were active in the last 60 days but not in the last 14 days. This is lifecycle mail about the paid service you already use, not a general newsletter, so it does not use double opt-in.

Lawful basis (two layers). The permission to send it rests on the existing-customer “soft opt-in” under the ePrivacy Directive 2002/58/EC Art. 13(2) (and its UK PECR Reg. 22(3) equivalent), which applies where (a) we obtained your contact details in the course of a sale of a similar product, (b) every message markets only our own similar photography-critique service, and (c) you are offered a simple, free means to refuse this use both when we collect your details and at any time afterwards. The processing of your contact details to prepare and send it rests on our legitimate interest (GDPR Art. 6(1)(f); Recital 47 expressly recognises direct marketing as a legitimate interest). As in Section 2.17, legitimate interest is the basis for processing your data, not a licence for the marketing send itself: the send is permitted by the soft opt-in above.

On by default; opt out at any time. Because it relies on the soft opt-in rather than your explicit consent, this email is on by default (opt-out) for the eligible paying cohort. You were first given a simple, free way to refuse marketing email when you created your account, before any recap is sent, and you can turn this email off at any time thereafter using the emailMonthlyRecap toggle in your account's Email Preferences settings, or the one-click unsubscribe link in every recap email; under GDPR Art. 21(2) an objection to direct marketing is always upheld at once. The email is also suppressed automatically for users on a content-moderation pause, and for any address on our email suppression list, regardless of preference state.

2.17 Win-Back Email Consent

When you cancel a paid subscription, we offer an optional checkbox to receive a short series of win-back emails (up to 3 messages over 60 days). We only send these emails if you explicitly tick the opt-in checkbox at the cancellation confirmation screen: pre-ticked boxes are never used.

Lawful basis: Explicit consent (GDPR Art. 6(1)(a)). This is a separate consent moment from the cancellation-reason retention described in Section 2.13, which relies on legitimate interest (Art. 6(1)(f)) to analyse churn patterns. The win-back program is marketing; the reason retention is product analytics. We keep them legally distinct.

Data we log: A timestamp of when you opted in, the IP address and user agent at the moment of consent (for Art. 7(1) demonstrability), and each win-back email we send to you via our standard email event log. We also record each time you withdraw win-back consent (the date and time of the withdrawal), so that both the start and the end of your consent are demonstrable.

How to withdraw consent: Click the unsubscribe link in any win-back email (ends the entire 3-message series instantly), toggle off win-back emails in your account settings, or click the global unsubscribe link in any of our marketing emails. Per GDPR Art. 7(3), withdrawing consent is as easy as giving it.

Involuntary (failed-payment) churn: soft opt-in basis. If your paid subscription ends not because you actively canceled but because we could not collect payment after the full dunning retry cycle, we may send the same short win-back series to the email address you gave us when you subscribed. For this cohort the lawful basis is not explicit consent and is not legitimate interest (GDPR Art. 6(1)(f) does not license a direct-marketing send): it is the existing-customer “soft opt-in” under the ePrivacy Directive 2002/58/EC Art. 13(2) (and its UK PECR Reg. 22(3) equivalent). That exemption requires that (a) we obtained your contact details in the course of a sale of a similar product, (b) every message markets only our own similar photography-critique service, and (c) you are offered a simple, free means to refuse this use: available at any time via your account settings, the global marketing-unsubscribe link, and a one-click unsubscribe in every message we send.

How you can refuse: at signup and at any time: The simple, free opportunity to refuse these emails is offered to you at the point of signup: when you create your account we tell you we may send occasional marketing emails about the FinalFrame service and give you a one-step way to opt out before any is sent. That same refusal also covers this win-back series. You can additionally opt out at any later time via the win-back toggle in your account settings, the global marketing-unsubscribe link, or the one-click unsubscribe link in every win-back message. Opting out at signup, or using the global unsubscribe at any time, stops this series together with all our other marketing email. The footer of win-back emails to this cohort identifies you as a former FinalFrame subscriber rather than claiming you opted in, so the basis is never misrepresented.

Right to object (GDPR Art. 21(2)): immediate opt-out. You have an absolute right to object to direct marketing at any time. For the soft opt-in cohort, exercising that right via any of the routes above stops the entire win-back series immediately and with no further messages; we do not require a reason and there is no balancing test: an objection to direct marketing is always upheld at once.

2.18 Onboarding and Activation Emails

When you create a FinalFrame account, we send a short series of onboarding emails over your first few days (currently up to three messages within roughly 72 hours): getting-started guidance, a walkthrough of core features, and an explanation of what the Premium tier and Coaching Brief add. Their purpose is to help you activate and get value from the service you signed up for.

Lawful basis. These are first-party service and activation communications about the product you registered for: not a generic newsletter and not third-party marketing. We rely on performance of a contract (GDPR Art. 6(1)(b)) and our legitimate interest in helping new users successfully adopt the service (Art. 6(1)(f)). We do not rely on the existing-customer “soft opt-in” (ePrivacy Directive Art. 13(2)). That basis applies only where contact details were obtained in the course of a sale, and a free signup is not a sale. We do not treat the default-enabled state as your consent under Art. 6(1)(a).

How to opt out (at any time, before or after any message). Toggle off Getting started emails in your account's Email Preferences settings, click the one-click unsubscribe link in any onboarding email, or use the global marketing-unsubscribe link. Opting out stops the remaining series immediately. These emails are also suppressed for any account on a content-moderation pause, regardless of preference state.

Right to object (GDPR Art. 21(2)). You have an absolute right to object to direct marketing at any time. Exercising it via any route above stops the onboarding series at once: no balancing test, no reason required.

Data we log. Each onboarding email we send is recorded in our standard email event log (the message type and a timestamp), used to sequence the series and to honour your opt-out.

2.19 Contact Email and Messages to Photographers

If you are a photographer. Your profile has an optional contact email field. It is never displayed on the page itself. Setting it enables two separate things, and you can control each one:

We email the address to confirm it belongs to you. When you save a contact email, we send a short message to that address asking whoever reads it to confirm. Until someone does, the contact form does not appear on your profile and we relay nothing: so an address entered by mistake, or by someone else, never receives forwarded messages. The confirmation link is valid for 7 days, and saving the address again sends a new one. We limit how many of these confirmation messages any one address can receive per day.

If you received a confirmation request you did not expect. Someone entered your address on a FinalFrame profile. Ignore the message and nothing happens: no messages are relayed to you and no account of yours is created or changed. The message tells you only that an address was entered; it does not disclose who entered it.

If you are writing to a photographer. When you submit the contact form we collect and store your name, your email address, your message, your IP address, and the time of submission. Your name, email address and message are passed on to the photographer: your email address is placed in the message's reply field so that they can answer you directly, and their reply comes from their own address, not through FinalFrame. We do not verify that the address you enter belongs to you, we do not send you anything at that address, and we do not add you to any mailing list. The IP address is retained for abuse prevention only.

Lawful basis. Legitimate interest (GDPR Art. 6(1)(f)) in operating a correspondence channel that both parties want: the sender chose to write, and the photographer chose to publish a contact address and to leave the channel open. This is correspondence delivery, not marketing; we do not use a message, or a sender's address, to send FinalFrame's own promotional email.

Retention. Relay records, including refused submissions, are permanently deleted after 90 days (Section 7.7). The delivered message itself lives in the photographer's own mailbox after that point and is outside our control. Reporting a message does not extend that window: the relay record is deleted on the same schedule either way, and the copy you forward to support@finalframe.photo is what we work from.

Abuse. Automated bot checks, per-sender and per-recipient rate limits, and content limits apply to every submission. To report an abusive message, forward it to support@finalframe.photo: do not reply to it, since replying discloses your own address to the sender.

3. How We Use Your Data

We use the data described above for the following purposes:

We do not use your images to train AI models. Your photographs are sent to the OpenAI API solely for real-time critique. Under OpenAI's API data usage policy, API inputs and outputs are not used to train their models.

We do not sell your personal data. We do not share your data with third parties for their own marketing purposes.

4. Lawful Basis for Processing (GDPR)

If you are in the European Economic Area, the United Kingdom, or another jurisdiction where lawful basis is required, we rely on the following legal grounds:

5. Third-Party Sub-Processors

Your data is shared with the following service providers, each for a specific purpose. We have data processing agreements in place where required.

6. International Data Transfers

FinalFrame is operated by Crypto Brains DOO from Serbia. Most of our sub-processors listed above are US-based companies. If you are accessing the service from within the EEA or UK, your data will be transferred to and processed in the United States and Serbia.

For transfers from the EEA/UK, we rely on:

If you have concerns about international data transfers, please contact us at support@finalframe.photo.

7. Data Retention

Retention periods depend on your plan:

7.1 Free Plan

7.2 Pro Plan ($19/month) and Premium Plan ($36/month)

7.3 Purchased Credit Packs

7.4 Account Deletion

7.4a Billing Communications and Paddle (Merchant of Record)

Billing is processed by Paddle (“Paddle”) acting as our Merchant of Record. Paddle issues transaction receipts directly to the payment method on file and is responsible for VAT, sales tax, and GST collection and remittance. FinalFrame does not send a separate billing receipt for renewal charges.

Billing records (subscription_events, and the billing-tied rows of admin_audit_log as defined in Section 12.1) are retained for 10 years after the related transaction, in line with the Serbian rules for our billing books and records (Law on Accounting Art. 28: journal and general ledger kept ten years; Law on Tax Procedure and Tax Administration Art. 114: the ten-year absolute tax-limitation period). Paddle, as our Merchant of Record and the issuer of your invoice, is separately subject to its own invoice-retention obligations (including the EU One-Stop-Shop ten-year rule, Art. 369k of the VAT Directive), which attach to Paddle, not to us. This retention is a legal obligation under GDPR Art. 17(3)(b): even if you delete your account, the billing records described above are retained for the full 10-year window, but personal identifiers (your user_id) are dissociated from those rows at deletion time so the rows persist as pseudonymous accounting records. As with the moderation records in Section 7.4, these are pseudonymous rather than anonymous: the row keeps the Paddle transaction and event identifiers alongside a one-way hash of your email address, so we can re-link it to you for finance, audit or chargeback-defence purposes. They therefore remain personal data under Art. 4(5) GDPR, and the rights set out in Section 8.1 apply to them. Because this retention is mandated by law, we cannot delete these rows before the 10-year period ends, even on an Art. 17 erasure request; we will restrict processing on request instead (Art. 18). Administrative audit rows that are not part of the billing record, such as moderation actions, appeal outcomes, reinstatements, regenerating your share tokens, threshold changes, and administrative reads of your data, are not covered by this ten-year obligation: they are retained for 36 months from the action, as set out in Section 12.1. If you delete your account before that period ends, your user ID is set to null on those rows, but the record itself persists until the 36 months elapse, as described in Section 7.4. Your rights over that processing, including the right to object, are set out in Section 8.1. Our billing_webhook_failures log is a separate short-lived operational record used to detect and resolve failed payment-provider webhooks; resolved entries are automatically purged 30 days after they are recorded. An entry that is still unresolved is retained until the underlying payment-provider failure is resolved, and is then purged on that same 30-day schedule: it is not deleted on a timer, because an unresolved payment failure is the record we need in order to correct your billing. It is not a statutory accounting record subject to the 10-year period. Paddle, our Merchant of Record, retains separate billing data under its own retention policy: see Paddle's privacy policy for their specifics.

If your account is paused for a content-moderation review, we suppress our own billing-related communications (including upgrade prompts and plan-change confirmations) to avoid sending conflicting signals while the review is open. Paddle, as the legal seller of your subscription, may continue to send tax documents, receipts, or regulatory notices directly to your payment-method email address. You can request an export of the Paddle-held transaction history at any time by contacting privacy@paddle.com.

7.5 In-App Deletion (Soft Delete)

When you delete individual comparisons or projects within the app, the data is soft-deleted and retained for 30 days to allow recovery in case of accidental deletion. After 30 days, soft-deleted records are permanently purged. Full account deletion (Section 7.4) bypasses the soft-delete period and permanently removes all data immediately.

7.6 Demo Sessions

7.7 Portfolio Contact Messages

8. Your Rights

8.1 Rights Under GDPR (EEA/UK Residents)

If you are in the EEA or UK, you have the following rights under GDPR Articles 15–22:

To exercise any of these rights, email us at support@finalframe.photo. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection supervisory authority.

8.2 Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the right to:

To exercise these rights, email us at support@finalframe.photo or use the account deletion feature in Account Settings.

9. Cookies and Tracking Technologies

FinalFrame takes a consent-first approach to tracking:

9.1 Essential (Always Active)

9.2 Analytics and Performance (Consent Required)

The following are only activated after you click “Accept” on the cookie consent banner:

If you click “Reject,” none of the consent-gated technologies are activated. You can change your preference at any time using the “Manage cookie preferences” option in the page footer or in your account settings.

10. Children's Data

FinalFrame is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child under 16 has created an account, please contact us at support@finalframe.photo and we will promptly delete the account and all associated data.

11. Biometric Data

Photographs you upload may contain images of people. We want to be clear about what our AI does and does not do:

Our AI analyzes photographs for composition, lighting, color, technical quality, and artistic merit. When people appear in photographs, the AI may assess compositional elements (e.g., subject placement, posing, expression as it relates to mood) but does not perform any biometric measurement or identification.

This distinction matters under laws like the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and similar state laws. Since we do not collect, capture, or store biometric identifiers or biometric information, these laws do not apply to FinalFrame's image analysis.

12. Security Measures

We take the following measures to protect your data:

No system is perfectly secure. If you discover a security vulnerability, please report it responsibly to support@finalframe.photo.

12.1 Administrative Access and Audit Trail

Where administrative access is exercised, the following controls apply:

Our internal Data Protection Impact Assessment (DPIA), referenced in Section 2.15, contains the underlying analysis for these controls (DPIA §1.4 administrative-access scope and §3.5 moderation-threshold authority).

12.2 Personal Data Breach Notification

Despite the safeguards above, no system is immune to security incidents. If we become aware of a personal data breach (the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to your personal data), we will respond in accordance with our internal incident-response procedure as follows:

The detection, assessment, containment, and reporting workflow that governs this commitment is documented in our internal Data Protection Impact Assessment (DPIA §4.3).

13. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, our sub-processors, or applicable law. When we make material changes, we will:

We encourage you to review this policy periodically. Your continued use of FinalFrame after changes take effect constitutes acceptance of the updated policy.

14. Contact Us

For any questions, concerns, or requests related to this privacy policy or your personal data, please contact:

We aim to respond to all privacy-related inquiries within 30 days.


This privacy policy was drafted for attorney review and is not a substitute for formal legal advice. If you have specific legal concerns, we recommend consulting a qualified attorney in your jurisdiction.