Privacy Policy
Starting Frame LLC, a New Jersey limited liability company ("Starting Frame," "we," "us," "our"), operates startingframe.com and the Frame workspace (the "Service"). This policy explains what we collect, why, and what we do — and explicitly do not do — with it. It applies wherever you are: the rights described below are offered to everyone who uses the Service, not only to people in a jurisdiction that requires them.
Who is responsible for your information. Starting Frame LLC is the data controller for the information described in this policy. Our contact details are at the bottom of this page, and that address reaches the person who decides how this information is handled — we are a small company and there is no separate department.
The short version: we don't want your information, and we have no interest in your work. Our apps are interfaces for working with files you keep in your own cloud (Google Drive, OneDrive, Dropbox) or on your own devices — your finished work and your source media stay yours. We hold your login, a small amount of setup you asked us to remember (your brand kit, your saved colours), and pointers to where your files live — not the files. There are two deliberate exceptions, both listed below: a logo you upload to Scene, and a signed media release, whose signature image we delete once the document reaches your storage. Everything we hold is listed below, and the list is meant to be short enough to read.
What we collect
- Account identity. Your email address. That is the only personal identifier we require.
- OAuth refresh tokens for connected storage providers. When you connect a cloud storage provider (Google Drive, OneDrive, or Dropbox), we store the OAuth refresh token issued by that provider, encrypted at rest. This token allows our apps to obtain short-lived access tokens so we can read and write within the narrow scope you authorized — files Frame creates or that you open from Google Drive, and files inside the
Apps/Framefolder of your OneDrive. - App preferences. Small per-user settings (for example, your default role view in Next App, your preferred teleprompter scroll speed) tied to your account.
- Access metadata for shared work. When a producer invites you to view a live show in Next App, we store the invitation record (your email, the show identifier, when access was granted or revoked). This metadata is the connection that lets us route the right people to the right show.
- Setup you asked us to save. Your brand kit (colours, fonts, and a logo image if you upload one) and any colour palettes you save in our tools, so they load next time. In Scene, a logo you upload is stored and served from a long, unguessable link, because live stream software cannot sign in to fetch it.
- Pointers to your own files, not the files. For teleprompter scripts we store the title, which storage provider it lives in, its file identifier, and your cue marks — not a word of the script itself, which stays in your own drive. For team projects we store an item's title and a link to it in your storage, not its contents.
- Media release records, including information about people who are not our users. If you use our release signer, we store the form you built and, for each person who signs, their name, the email address they give, the time, their IP address and browser, their signature image, their confirmation that they are 18 or older, and — where a parent or guardian signs on behalf of someone younger — the guardian's name and relationship. The signature image is deleted from our servers once the signed document has been delivered to your storage, and in any case within 90 days of signing — whether or not that delivery succeeded. The remaining record is kept as proof the release was given. If you use this feature, you are asking us to hold information about other people, and you are responsible for telling them so.
- Purchase records. What you bought and when. Card details are handled by Stripe and never reach our servers.
- Newsletter subscription, if you ask for it. If you enter your email address in a subscribe form on startingframe.com, we pass that address to Beehiiv, the service that sends our newsletter, along with the date you subscribed. We use it to send the newsletter and nothing else. Every issue carries an unsubscribe link, and unsubscribing removes you from the list.
- Anonymous usage statistics. We count page views on startingframe.com and in the Frame app, and a few simple tool events there (a tool was used, a file was exported and in which format). This is described in full under Analytics below. It sets no cookies, records no identifier that points back to you, and never records the content of your work.
- Error reports from the Frame app. When something breaks in one of our tools in your browser, the page sends us a short technical report so we can fix it: which tool, the error message, the file and line in our code where it failed, the page path (with anything after a
?or#removed), and a coarse browser label such as "Chrome 139 · Mac". The report carries no account identifier, we do not store an IP address with it, and it contains nothing you typed or made. We keep one record per distinct error and delete it 30 days after that error was last seen. It is not loaded on the stream-graphics page that plays inside your broadcast software. - Basic technical logs. Our servers log IP addresses, timestamps, and request paths for security, debugging, and abuse prevention. Retained for no longer than 30 days.
What we do not collect
We do not collect, store, or process:
- The content of your work. The words of your teleprompter scripts, your rundowns, the text you animate, your video and your images. These live in your own storage or on your own machine. Where we need to point at one, we store the pointer, not the file. (Note the exceptions listed above and be aware of them: a logo you upload to Scene, and signature images until they are delivered and deleted.)
- Files in your connected cloud storage. Our OAuth scopes (
drive.filefor Google,Files.ReadWrite.AppFolderfor Microsoft) are deliberately limited to a narrow slice of your storage. For Google Drive, that is files Frame has created or that you have explicitly opened in Frame. For OneDrive, that is files inside a dedicatedApps/Framefolder. We cannot list, scan, or browse the rest of your storage. - Live show content beyond the moments it is in transit. During a Next App live show, your rundown flows through a real-time channel (Ably) to authenticated invited viewers. It transits but is not persisted on our servers.
- Anything for our own gain. We do not read, analyse, mine, profile, sell or train anything on your work, and we do not build a picture of what you make. We are not an advertising business and we have no second use for your material.
How we use what we collect
- Email — to identify your account, send account verification and password reset messages, send multi-factor authentication enrollment and challenge messages where applicable, and notify you of material changes to the Service or this policy.
- OAuth refresh tokens — to obtain short-lived access tokens so our apps can read and write the narrow slice of your storage you authorized: files Frame creates or that you open from Google Drive, and files inside the
Apps/Framefolder of your OneDrive. - App preferences — to deliver a consistent experience across your sessions and devices.
- Access metadata (invitations) — to gate access to live shows to the right people.
- Technical logs — for security, debugging, and abuse prevention.
- Error reports — to find and fix things that break in our tools. A new kind of error sends one alert email to us; nobody else sees it.
We do not use your information for advertising, profiling, or any purpose other than operating the Service.
Third-party services we use
We rely on a small set of third parties to operate. Each receives only what it needs. Their privacy policies apply when you interact with them through the Service.
- Auth0 — handles authentication (email + password, Sign in with Google, Sign in with Microsoft) and multi-factor authentication for paid accounts. Receives your email address. For email + password accounts, Auth0 also stores a bcrypt hash of your password and any multi-factor credentials you enroll (such as a passkey or one-time-password seed). Starting Frame's own database never receives your password or your second-factor secrets. okta.com/privacy-policy
- Stripe — when you subscribe to a paid tier of any app. Handles payment method storage, billing, and the customer portal where you manage or cancel your subscription. Receives your email address, billing information you supply during checkout, and metadata identifying your subscription. We never receive or store your full payment card number — Stripe handles that on PCI-compliant infrastructure. stripe.com/privacy
- Google — when you sign in with Google or connect Google Drive. Receives the identity assertion or OAuth scopes you grant (limited to
drive.file). policies.google.com/privacy - Microsoft — when you sign in with Microsoft or connect OneDrive. Receives the identity assertion or OAuth scopes you grant. privacy.microsoft.com
- Ably — real-time pub/sub used for live show broadcast in Next App. Receives rundown content transiting through authenticated private channels during an active show. Does not persist project content beyond short-term message history (approximately 24 hours). ably.com/privacy
- Resend — transactional email delivery. Sends account verification, password reset, multi-factor authentication, billing, and material-change notification emails on our behalf. Receives the destination email address and the email body. resend.com/legal/privacy-policy
- Beehiiv — sends our newsletter. Receives only the email address you enter into a subscribe form and the date you subscribed. It is not used for anything but the newsletter, and it is a separate list from your Frame account. beehiiv.com/privacy
- DigitalOcean — our application servers run on infrastructure rented from DigitalOcean. Receives encrypted requests and responses. digitalocean.com/legal/privacy-policy
We do not use a third-party analytics company. Our page-view statistics run on software we host ourselves — see Analytics.
We do not sell, rent, or trade your personal information.
Cookies
We use cookies only as needed to operate the Service:
- Authentication session cookie (Auth0) — keeps you signed in to Frame across pages and tabs.
We do not use advertising cookies, retargeting cookies, or third-party analytics cookies. We do not use any cookie to build a profile of you or to follow you across other websites.
Analytics
We want to be direct about this, because "we don't use analytics cookies" is a narrow statement and it is not the whole answer: we do count visits to startingframe.com and to the Frame app. Here is exactly how.
- What it is. Umami, an open-source analytics program. We run it on our own server at
analytics.startingframe.com. The statistics are not sent to Google, to an advertising network, or to any analytics company — there is no third party in this at all. - What it records. The page visited, the referring site, and coarse signals derived from your request: browser, operating system, device type, and country. Umami is cookieless and does not store or transmit your IP address; it uses a rotating daily hash to tell one visit from another, which cannot be reversed and does not persist beyond the day. Inside the Frame app it also records a few named tool events — that a tool was used, that a file was exported and in which format, that a screen link was copied — with the tool's name attached.
- What it does not record. Your name, your email, an identifier that links a visit to your Frame account, anything you type, or anything you make. It cannot follow you to another website.
- Where it runs. On the public marketing site, startingframe.com, and inside the Frame app at frame.startingframe.com. It is not loaded on the stream-graphics page that plays inside your broadcast software. (An earlier version of this policy said it did not run inside the Frame app. That was wrong, and we have corrected it.)
- How long we keep it. Aggregate counts are retained for up to 24 months. There is nothing personal in them to delete, because nothing personal was recorded.
- Why we are allowed to. Our legitimate interest in knowing whether anyone is reading the site and using the tools — assessed as low-risk because the data is anonymous and never leaves our own server. If you would rather not be counted, any browser tracker-blocker or "Do Not Track" extension will block it, and nothing on the site will stop working.
Your rights
You can, at any time:
- Delete your account from Frame settings. Deletion removes your email, OAuth refresh tokens (which disconnects your linked drives; your files in those drives remain untouched), preferences, and access metadata. There is no project content to delete on our side because we never had it.
- Disconnect a storage provider from Frame settings. We immediately revoke and delete the stored OAuth refresh token. You may also revoke our app's access directly from your Google or Microsoft account settings.
- Request a copy of your data. This will consist of your email address, current preferences, and a list of your connected drives and access invitations. There is no project content to export from our side.
- Correct anything that is wrong. Write to us and we will fix it.
- Withdraw consent. Unsubscribe from the newsletter using the link in any issue, or disconnect a storage provider from Frame settings. Withdrawing consent does not undo anything that was lawful before you withdrew it.
- Object to our legitimate interests — including being counted in our page-view statistics. Write to us, or block the counter with any browser extension; nothing on the site will stop working.
- Complain to a regulator — see Complaints. You do not have to come to us first, though we would like the chance.
- Contact us with questions, concerns, or requests. There is one address, it reaches a person, and we do not charge for any of this.
We answer requests within 30 days. We will not refuse, delay, or degrade your service because you exercised a right.
If you are in the European Economic Area or the United Kingdom, you have additional rights under the GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. Contact us to exercise these.
If you are in California, you have rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of any sale or sharing of personal information. We do not sell or share personal information, and we do not use it for cross-context behavioural advertising — so there is nothing for a "Do Not Sell or Share My Personal Information" link to switch off. We do not process sensitive personal information for any purpose that would give you a right to limit it. We extend these rights to you as a matter of policy; Starting Frame is a very small company and does not currently meet the CCPA's thresholds for a covered business.
Our legal basis for using your information
If you are in the European Economic Area or the United Kingdom, the GDPR requires us to name the lawful basis for each thing we do. Ours are:
- Performing our contract with you (Art 6(1)(b)) — your email address, OAuth refresh tokens, app preferences, saved setup, file pointers, access invitations, and purchase records. We cannot run the account you asked for without them.
- Your consent (Art 6(1)(a)) — the newsletter, and connecting a cloud storage provider. You give it by asking, and you can withdraw it at any time by unsubscribing or disconnecting, with no effect on anything that happened before.
- Our legitimate interests (Art 6(1)(f)) — security logging, abuse prevention, error reports from the Frame app, and the anonymous usage counts described under Analytics. We have weighed these against your interests and consider them low-risk, because the data is minimal, short-lived, and never used to profile anyone.
- Legal obligation (Art 6(1)(c)) — retaining purchase records for tax and accounting.
Where you use our release signer to collect signatures from other people, you decide why those signatures are collected and what happens to them. In data-protection terms you are the controller of that information and we process it on your instructions. See Media releases below.
Complaints
If you think we have handled your information badly, please write to us first — the address is at the bottom of this page and it reaches a person, not a queue. You also have the right to complain to a data-protection authority without going through us:
- EEA — the supervisory authority in the country where you live or work. The list is at edpb.europa.eu.
- UK — the Information Commissioner's Office, ico.org.uk/make-a-complaint.
- Elsewhere — your national or state privacy regulator, where one exists.
Data retention
- Email, OAuth refresh tokens, app preferences: retained while your account is active. Deleted within 30 days of account deletion.
- Access metadata (invitations): retained for up to one year after the show date, or until the producer revokes access, whichever is sooner.
- Brand kits, saved palettes, Scene logos, script pointers and cue marks: retained while your account is active. Deleted within 30 days of account deletion.
- Media release records: signature images are deleted as soon as the signed document reaches your storage, and at the latest 90 days after signing regardless of delivery. The rest of the record is retained while your account is active, because it is the evidence the release was given, and deleted within 30 days of account deletion.
- Purchase records: retained as long as required for tax and accounting.
- Newsletter subscription: retained until you unsubscribe. Unsubscribing removes your address from the list.
- Anonymous page-view statistics: up to 24 months. Nothing in them identifies a person.
- Browser error reports: deleted 30 days after that error was last seen.
- Server logs: 30 days.
Security
- OAuth refresh tokens are encrypted at rest.
- All connections to the Service use TLS.
- Passwords for email + password accounts are stored by Auth0 as bcrypt hashes. Starting Frame's own database never receives passwords — in plaintext or hashed form.
- Paid (Pro) accounts additionally require multi-factor authentication. The second factor is either a passkey (WebAuthn) or a one-time-password seed in an authenticator app. Auth0 holds the second-factor credential. Starting Frame's own database never receives it.
- Access to production systems is limited to authorized personnel.
We cannot guarantee perfect security, but our architecture is deliberately designed to minimize the impact of any incident: there is no project content on our servers to leak.
Children and young people
The Service is a set of professional production tools. It is not directed at children, we do not market it to them, and it has no feature built to attract them — no social feed, no messaging between strangers, no public profiles, no streaks, notifications, or other mechanics designed to hold someone's attention.
Age requirement
You must be at least 13 years old to hold a Starting Frame account, or at least 16 if you are in the European Economic Area or the United Kingdom, matching the age of digital consent in your country. Where a higher minimum age applies where you live, that age applies to you. This is stated in our Terms of Service and you confirm it when you create an account.
We do not ask for your date of birth. That is deliberate. Collecting birthdays would mean holding a sensitive identifier about every user in order to police a rule that a simple confirmation already covers, and it would create exactly the file of children's information this policy is meant to avoid.
We do not knowingly collect information from children
We do not knowingly collect personal information from anyone below the applicable age. We do not ask about age in order to target anything, and we never use age — or any inference about age — to profile someone, to advertise, or to change what we show them. There is no advertising in the Service and we do not sell or share personal information for advertising.
If a child has given us information — how to reach us
If you are a parent or guardian and you believe a child has given us personal information, write to [email protected] with the subject line "Child privacy". Tell us the email address used and anything that helps us find the account. You do not need to prove anything first and you do not need an account of your own.
When we receive a report like that, or otherwise learn that an account belongs to someone below the applicable age, we will:
- Close the account and delete the information we hold for it — email address, storage tokens, preferences, saved setup, and file pointers — within 30 days, and sooner where we can.
- Confirm to you in writing when it is done.
- Not require a payment, an account, or a legal document from you in order to do it.
The same address works for any question about a young person's information, including a request to delete a signed media release. We answer these ourselves and we answer them first.
Signed media releases and minors
In most places a person under 18 cannot give legally binding consent to a media release — a parent or guardian has to. Our release signer therefore asks every signer to confirm they are 18 or older, and where they are not, it collects the consent of a parent or guardian instead of the young person's. This protects the person signing and it protects the customer relying on the release. See Media releases.
Media releases — information about people who are not our users
Our release signer is the one place we hold personal information about people who never signed up with us. We want it stated plainly.
- You are responsible for it. If you build a release form and send people to it, you decide why you are collecting those signatures and what you do with them. You must have the right to ask, and you must tell the people signing what you are doing. We hold the information on your instructions and for no purpose of our own.
- What is held. The signer's name, the email address they give if they want a copy, the time, their IP address and browser, and their signature image. Where a guardian signs for a young person, the young person's name and the guardian's name and relationship.
- The signature image is deleted from our servers as soon as the signed document has been delivered to your storage — and in any case within 90 days of signing, whether or not that delivery succeeded. Nothing we hold about a person who never agreed to our terms sits here indefinitely because our delivery broke. The rest of the record is kept as evidence the release was given, and is deleted within 30 days of your account being deleted.
- We never use it. Not for marketing, not for analysis, not for training anything. A signer's email address is used once, to send that person their own copy if they asked for it, and is never added to any list.
- Anyone who signed can write to us directly at [email protected] to ask what we hold about them or to have it deleted — they do not need an account, and we will tell the customer who collected it rather than quietly acting behind their back.
International transfers
We are based in the United States and our servers are in the United States. If you use the Service from anywhere else, your information is transferred to and processed in the United States, which may not give it the same protection as the law where you live.
Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where the UK GDPR applies), which are included in our agreements with the providers listed above. Several of those providers — including Stripe, Google, Microsoft and Auth0 — are additionally certified under the EU–US Data Privacy Framework. You can ask us for details of the mechanism covering any particular transfer.
The practical protection is the architecture rather than the paperwork: the material that would actually matter if it crossed a border — your scripts, your rundowns, your video and your images — is not transferred at all, because it stays in your own storage and never reaches our servers.
If you are outside the United States
We offer the rights described in this policy — access, correction, deletion, a copy of your data, objection, and withdrawal of consent — to everyone, wherever you live, rather than only where a law compels it. Some places give you rights beyond these; if yours does, write to us and we will honour them. We answer every request from the same address, and we do not charge for it.
Changes to this policy
If we update this policy, we will change the "Last updated" date above and, where the change is material, notify you by email.
Copyright complaints
Some parts of the Service hold material you upload — a Scene logo, a brand-kit logo or font, a signed release. If you believe something stored or displayed by the Service infringes your copyright, our designated agent is Brian Pilgrim, Starting Frame LLC, 1 Farrell Lane, Marlboro, NJ 07746, [email protected], (917) 331-3042 (U.S. Copyright Office registration DMCA-1079416). The full notice-and-counter-notice procedure is in our Terms of Service.
Contact
Email: [email protected]
Postal: Starting Frame LLC, 1 Farrell Lane, Marlboro, NJ 07746-1517