Privacy Policy
Starting Frame LLC, a New Jersey limited liability company ("Starting Frame," "we," "us," "our"), operates startingframe.com and the Frame workspace (the "Service"). This policy explains what we collect, why, and what we do — and explicitly do not do — with it.
The short version: we don't want your information. Our apps are interfaces for working with files you store in your own cloud (Google Drive, OneDrive, etc.) or on your own devices. We never see, store, or process the content of your projects. We hold the minimum information needed to identify you as the account holder and connect you to your own storage.
What we collect
- Account identity. Your email address. That is the only personal identifier we require.
- OAuth refresh tokens for connected storage providers. When you connect a cloud storage provider (Google Drive, OneDrive — and Dropbox / Box in a future release), we store the OAuth refresh token issued by that provider, encrypted at rest. This token allows our apps to obtain short-lived access tokens so we can read and write within the narrow scope you authorized — files Frame creates or that you open from Google Drive, and files inside the
Apps/Framefolder of your OneDrive. - App preferences. Small per-user settings (for example, your default role view in Next App, your preferred teleprompter scroll speed) tied to your account.
- Access metadata for shared work. When a producer invites you to view a live show in Next App, we store the invitation record (your email, the show identifier, when access was granted or revoked). This metadata is the connection that lets us route the right people to the right show.
- Basic technical logs. Our servers log IP addresses, timestamps, and request paths for security, debugging, and abuse prevention. Retained for no longer than 30 days.
What we do not collect
We do not collect, store, or process:
- The content of your projects — teleprompter scripts, rundowns, typography text, video plans, or anything else you create or edit in our apps.
- Files in your connected cloud storage. Our OAuth scopes (
drive.filefor Google,Files.ReadWrite.AppFolderfor Microsoft) are deliberately limited to a narrow slice of your storage. For Google Drive, that is files Frame has created or that you have explicitly opened in Frame. For OneDrive, that is files inside a dedicatedApps/Framefolder. We cannot list, scan, or browse the rest of your storage. - Live show content beyond the moments it is in transit. During a Next App live show, your rundown flows through a real-time channel (Ably) to authenticated invited viewers. It transits but is not persisted on our servers.
- Anything we do not list explicitly above.
How we use what we collect
- Email — to identify your account, send account verification and password reset messages, send multi-factor authentication enrollment and challenge messages where applicable, and notify you of material changes to the Service or this policy.
- OAuth refresh tokens — to obtain short-lived access tokens so our apps can read and write the narrow slice of your storage you authorized: files Frame creates or that you open from Google Drive, and files inside the
Apps/Framefolder of your OneDrive. - App preferences — to deliver a consistent experience across your sessions and devices.
- Access metadata (invitations) — to gate access to live shows to the right people.
- Technical logs — for security, debugging, and abuse prevention.
We do not use your information for advertising, profiling, or any purpose other than operating the Service.
Third-party services we use
We rely on a small set of third parties to operate. Each receives only what it needs. Their privacy policies apply when you interact with them through the Service.
- Auth0 — handles authentication (email + password, Sign in with Google, Sign in with Microsoft) and multi-factor authentication for paid accounts. Receives your email address. For email + password accounts, Auth0 also stores a bcrypt hash of your password and any multi-factor credentials you enroll (such as a passkey or one-time-password seed). Starting Frame's own database never receives your password or your second-factor secrets. okta.com/privacy-policy
- Stripe — when you subscribe to a paid tier of any app. Handles payment method storage, billing, and the customer portal where you manage or cancel your subscription. Receives your email address, billing information you supply during checkout, and metadata identifying your subscription. We never receive or store your full payment card number — Stripe handles that on PCI-compliant infrastructure. stripe.com/privacy
- Google — when you sign in with Google or connect Google Drive. Receives the identity assertion or OAuth scopes you grant (limited to
drive.file). policies.google.com/privacy - Microsoft — when you sign in with Microsoft or connect OneDrive. Receives the identity assertion or OAuth scopes you grant. privacy.microsoft.com
- Ably — real-time pub/sub used for live show broadcast in Next App. Receives rundown content transiting through authenticated private channels during an active show. Does not persist project content beyond short-term message history (approximately 24 hours). ably.com/privacy
- Resend — transactional email delivery. Sends account verification, password reset, multi-factor authentication, billing, and material-change notification emails on our behalf. Receives the destination email address and the email body. resend.com/legal/privacy-policy
- DigitalOcean — our application servers run on infrastructure rented from DigitalOcean. Receives encrypted requests and responses. digitalocean.com/legal/privacy-policy
We do not sell, rent, or trade your personal information.
Cookies
We use cookies only as needed to operate the Service:
- Authentication session cookie (Auth0) — keeps you signed in to Frame across pages and tabs.
We do not use third-party advertising, retargeting, or analytics cookies.
Your rights
You can, at any time:
- Delete your account from Frame settings. Deletion removes your email, OAuth refresh tokens (which disconnects your linked drives; your files in those drives remain untouched), preferences, and access metadata. There is no project content to delete on our side because we never had it.
- Disconnect a storage provider from Frame settings. We immediately revoke and delete the stored OAuth refresh token. You may also revoke our app's access directly from your Google or Microsoft account settings.
- Request a copy of your data. This will consist of your email address, current preferences, and a list of your connected drives and access invitations. There is no project content to export from our side.
- Contact us with questions, concerns, or requests.
If you are in the European Economic Area or the United Kingdom, you have additional rights under the GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. Contact us to exercise these.
If you are in California, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete it, and the right to opt out of any sale of personal information. We do not sell personal information.
Data retention
- Email, OAuth refresh tokens, app preferences: retained while your account is active. Deleted within 30 days of account deletion.
- Access metadata (invitations): retained for up to one year after the show date, or until the producer revokes access, whichever is sooner.
- Server logs: 30 days.
Security
- OAuth refresh tokens are encrypted at rest.
- All connections to the Service use TLS.
- Passwords for email + password accounts are stored by Auth0 as bcrypt hashes. Starting Frame's own database never receives passwords — in plaintext or hashed form.
- Paid (Pro) accounts additionally require multi-factor authentication. The second factor is either a passkey (WebAuthn) or a one-time-password seed in an authenticator app. Auth0 holds the second-factor credential. Starting Frame's own database never receives it.
- Access to production systems is limited to authorized personnel.
We cannot guarantee perfect security, but our architecture is deliberately designed to minimize the impact of any incident: there is no project content on our servers to leak.
Children
Frame is not directed at children under 13 (or under 16 in the EEA and UK). We do not knowingly collect personal information from children.
International transfers
If you access Frame from outside the United States, your information may be processed in the United States, where our servers are located.
Changes to this policy
If we update this policy, we will change the "Last updated" date above and, where the change is material, notify you by email.
Contact
Email: [email protected]
Postal: Starting Frame LLC, 1 Farrell Lane, Marlboro, NJ 07746-1517