The short version
- Framiq can read only the repositories you choose, and its access is read-only. It never commits to, pushes to, or changes your repositories.
- Each video run happens on its own isolated cloud machine, which is discarded when the run ends, together with the copy of your code.
- Your code is used only to make your videos. It is not used to train AI models.
- Your videos and the other files from a run are deleted automatically 30 days after the run.
- We use Amplitude to understand how people use Framiq, including session replays (recordings of how you use the site). What you type into form fields is masked in those recordings.
- Payments are processed by Stripe. Framiq does not store your card number.
- Framiq does not sell your personal information, does not show ads, and does not use advertising or cross-site tracking cookies.
1. Who this policy covers
This policy applies to the Framiq website at www.framiq.app, the signed-in app there, and the Framiq Launch Videos GitHub App (together, the “Service”). “Framiq,” “we” and “us” mean the provider of the Service. Our Terms of Service describe the rules for using it. Questions and requests about this policy go to [email protected].
2. Information we collect
When you sign in with GitHub
You sign in through GitHub. GitHub tells us your:
- GitHub user ID and username;
- display name, if you have set one; and
- profile picture link.
GitHub also gives us an access token and a refresh token so the Service can see which repositories you have made available to Framiq. GitHub sets how long these tokens last, and the Service refreshes the access token when it expires. We keep your profile details and these tokens only inside your encrypted session cookie (see Cookies). We do not store your GitHub tokens on our servers.
The repositories you choose
When you install the GitHub App you choose which repositories Framiq can read, and you can change that choice in GitHub at any time. The Service lists those repositories (their names, whether they are private, and when they were last updated) so you can pick one. When you start a run, the Service gets a read-only GitHub token that works only for the repositories in that run and expires after one hour, and uses it only to copy them to the run machine.
What you tell us when you start a run
- the repository of the app to feature, and optionally your website’s address, whose public pages we read for your current logo, brand and wording;
- your brief, the short description of what to feature (up to 2,000 characters); and
- your video choices for later runs (style, voiceover and music), which we save as your defaults.
What a run produces
- your videos and their thumbnail images;
- the run’s details, status and the progress messages shown while it works;
- still frames of the video in progress, shown in the live view;
- the video plan: scenes, captions, the voiceover script, music descriptions and the voices used;
- the video project, kept so you can ask for changes to a video: the scene code Framiq writes (which can include markup, class names and import paths from your app), brand files it copies from your repositories (such as your logo and fonts), the voiceover, music and sound effects, and its working notes; and
- a technical log of the steps the run took, which can include file names and short excerpts from your repository. We use it to fix runs that fail.
Technical information
Like most websites, our hosting and network providers record basic request information, such as IP address, browser type, the pages requested and the time. Cloudflare also measures page views and page load performance without cookies (see Cookies).
How you use the Service
We use Amplitude, a product analytics service, to understand how people use the Service so we can fix problems and improve it. On the website and in the app, Amplitude records:
- the pages you view, when your visits start and end, how you arrived (the referring website and any campaign tags in the link), and basic device information such as your browser, operating system, language and approximate location based on your IP address;
- what you do in the app: clicking to sign in or to see how it works, signing in (and whether you just installed the GitHub App), submitting a form such as signing out, starting a run (with your style, voiceover and music choices, whether it is your first run and whether you added a website) or a run not starting, opening a run, a run finishing (with the number of videos) or not finishing, playing or downloading a video (with its style), and your purchases: starting, changing, cancelling, resuming or ending a plan (with the plan name) and buying a video pack (with the number of videos); and
- session replays: recordings of how the pages looked and changed while you used them, including mouse movements, clicks, scrolling and the text shown on the page, such as your repository names, your brief on the run page and Framiq’s progress messages. Videos, preview frames and thumbnails are left out of replays.
Session replays mask form fields by default: what you type into text boxes, including your brief while you write it, and the options you pick in menus are hidden before the recording leaves your browser. We use these default settings and have not turned masking off. When you are signed in, Amplitude links this activity to your GitHub user ID and username. Amplitude does not receive your code or your GitHub tokens.
Payments
Payments are processed by Stripe on its own checkout page. Your card details go to Stripe, and Framiq does not receive or store your card number. We give Stripe your GitHub user ID and username so a payment is linked to your account, and Stripe tells us whether a payment succeeded and what it was for. We keep your Stripe customer ID, your plan and its status, and how many videos you have used and have left. Stripe’s own privacy policy covers the information Stripe holds about you, such as your email address and billing details.
What we do not collect
The GitHub App also asks for read access to pull requests and to your email addresses. The Service does not currently read your pull requests or your email addresses. If we start using either, we will update this policy first.
3. How your code is handled
- Read-only access. Framiq’s GitHub access is read-only, so it cannot change your repositories. It never commits, pushes or opens pull requests.
- One machine per run. Each run starts on a fresh, isolated cloud machine on Google Cloud that is used for that run only and never shared with another customer’s run. The machine copies the latest version of the repositories in the run (or, when you ask for changes to a video, the version that video was made from), installs your app’s dependencies and runs parts of your app’s code so it can show your real screens. It adds its own working files only to that temporary copy.
- Sample data. The Service is designed to fill your screens with fictional sample data it writes itself, not with real names, email addresses or customer records found in your repository.
- Discarded after the run. When the run ends, the machine is shut down and discarded along with the copy of your code. Only the outputs listed in section 2 are kept, for the time described in section 6.
- Automated processing, including AI. The Service uses automated systems, including AI models from AI model providers, to understand your product from your code, your website and your brief, and to plan and build your video. Voice and music generation providers create the voiceover, music and sound effects; they receive the voiceover script and descriptions of the music and sound effects, not your code.
- Not used for training. Your code is used only to make your videos. Framiq does not use your code, briefs or videos to train AI models, and the AI model providers that process your code for us do so under business terms that do not allow them to train their models on it.
Please do not store passwords, keys or real customer records in repositories you connect. If your repository contains personal information about other people, you are responsible for having the right to share it with us for this purpose.
4. How we use information
- to sign you in and show you the repositories you have made available;
- to make your videos, show their progress and give you links to watch and download them;
- to remember your video choices, and to vary the voices and music between runs for the same app;
- to find and fix runs that fail, and to keep the Service secure and prevent misuse;
- to understand how people use the Service, through product analytics and session replays, so we can fix problems and improve it;
- to take payments; and
- to answer you when you contact us, and to meet legal obligations.
We do not sell your personal information, share it for targeted advertising, or use it to show you ads.
5. Who we share information with
We share information only with the service providers that run the Service for us, and only as needed for the purposes above:
- Google Cloud runs the machines that make your videos and stores run files, your list of runs and your saved choices, in the United States.
- Vercel hosts the website and the server that signs you in and passes requests to our other providers.
- Cloudflare provides our domain name service, protects the site from bots and abuse, and measures page load performance.
- GitHub handles sign-in and repository access. GitHub’s own privacy statement covers the information GitHub holds about you.
- Amplitude provides product analytics and session replays (see How you use the Service), in the United States.
- Stripe processes payments.
- AI model providers process your code, website and brief to plan and build your videos.
- Voice and music generation providers receive voiceover scripts and descriptions of music and sound effects to create audio for your videos.
These providers process information on our behalf under their own terms, and some may keep it for a limited time for security and abuse monitoring. We may also share information if the law requires it, to protect the rights, safety or security of our users, Framiq or others, or as part of a merger, acquisition or sale of the Service, in which case this policy will continue to apply to your information.
6. How long we keep information
- Your code: only on the run machine, which is discarded when the run ends.
- Run files (videos, thumbnails, run details including your brief, status and progress messages, live-view frames, the video plan, the video project and the technical log): deleted automatically 30 days after they are created. Google Cloud may keep deleted files recoverable for up to 7 more days before they are permanently removed. Download any video you want to keep within 30 days.
- Your list of runs (each run’s ID, repository name, brief and date) and your saved video choices: kept while you use Framiq, and deleted when you ask us to.
- Your session cookie: up to 30 days, or until you sign out.
- Billing records (your Stripe customer ID, plan, video balance and which runs used a video): kept while you use Framiq, and longer where the law requires us to keep payment records.
- Analytics events and session replays: kept by Amplitude for the period our Amplitude plan sets, and deleted when you ask us to delete your information.
- Operational logs in Google Cloud: 30 days. Our other providers keep their logs for their own standard periods.
7. Cookies
Framiq uses the cookies it needs to work, and Amplitude’s analytics cookies and browser storage. Amplitude’s cookies are set on framiq.app only and are not used to follow you across other websites. Framiq does not use advertising, social media or cross-site tracking cookies.
| Cookie or storage | What it does | How long |
|---|---|---|
framiq_session | Keeps you signed in. It is encrypted and holds your GitHub user ID, username, display name, profile picture link and GitHub tokens. | 30 days, or until you sign out |
framiq_oauth_state | A one-time security check that protects sign-in and app installation from forged requests. | 10 minutes for sign-in, 30 minutes for installation |
Cloudflare security cookies, such as cf_clearance or __cf_bm | Set by Cloudflare, when needed, to tell people from bots and protect the site from abuse. | Set by Cloudflare, usually 30 minutes to a year |
AMP_ followed by the start of our Amplitude project key | Set by Amplitude. A random ID for your browser, the current visit, your GitHub user ID once you sign in, and when your last event was recorded, so visits can be counted and linked together. | 1 year after your last visit |
AMP_MKTG_ followed by the start of our Amplitude project key | Set by Amplitude. How you arrived: the referring website and any campaign tags in the link, such as utm_source. | 1 year |
Amplitude browser storage (local storage and IndexedDB, not cookies), with names that start with AMP_ | Events waiting to be sent, Amplitude’s settings, when the current session replay started, and Amplitude’s own error diagnostics. | Until sent or replaced; replay start times are removed after 24 hours |
Cloudflare’s page load measurement does not use cookies or track you across other websites.
8. Your choices and rights
- Change repository access: in GitHub, go to Settings, then Applications, then Installed GitHub Apps, and configure or uninstall Framiq Launch Videos. Uninstalling removes Framiq’s access to your repositories.
- Revoke sign-in: in GitHub, go to Settings, then Applications, then Authorized GitHub Apps, and revoke Framiq Launch Videos.
- Sign out: signing out deletes your session cookie from your browser.
- Analytics: you can block or delete Amplitude’s cookies and site data in your browser settings. The Service works without them.
- Access or delete your information: email [email protected] from the email address on your GitHub account and tell us your GitHub username. We will delete your list of runs, your saved choices and any run files that remain, have Amplitude delete your analytics data, and respond within 30 days.
Depending on where you live, you may have rights to access, correct, delete or receive a copy of your personal information, to object to or restrict how we use it, and to complain to your local data protection authority. Email [email protected] to use any of these rights. We will not treat you differently for using them.
9. Security
We protect your information with measures that include an encrypted session cookie, short-lived and read-only GitHub tokens, a separate isolated machine for every run, credentials that are created for each run and expire within hours, and private storage for run files. Links to watch and download your videos expire after an hour, but anyone you share a link with can use it until then. No system is perfectly secure; if you believe your account or data has been exposed, email [email protected].
10. Where information is processed
Framiq and its providers process and store information in the United States. If you use the Service from another country, your information is transferred to and processed in the United States.
11. Children
The Service is not intended for anyone under 18, and we do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy as the Service changes. We will change the date at the top of this page, and if a change is significant we will give notice in the Service before it takes effect.
13. Contact
Questions, requests or concerns about privacy: [email protected].