Privacy Policy
Last updated: August 1, 2026
FrameQ (frameq.ai) is operated by QuneticLabs LLC, 1021 E Lincolnway #10578, Cheyenne, WY 82001, USA. This policy explains what data the service collects, why, and the control you have over it. For anything in this document, write to [email protected].
What we collect
- Account data — your email address and sign-in credentials, held by our authentication provider (Supabase). We never see or store your password in plain text.
- Content and workspace data — the topics, scripts, videos, uploads and settings you create. When you upload your own footage you attest that you hold the rights to it, and we record that attestation with a timestamp and the IP address it was made from.
- Connected platform data — when you connect a channel (YouTube today; TikTok and Instagram when those integrations launch) we store the channel's identifier and handle, the OAuth tokens the platform issues (encrypted — see Security), the identifiers of videos we publish for you, and the performance metrics the platform reports for those videos.
- Usage and billing data — a ledger of credit grants and spends, job and render history, and error diagnostics.
- Cookies — essential only: your sign-in session and a locale preference (fq-locale). There are no advertising or cross-site tracking cookies.
How we use it
To provide the service: generating scripts, rendering videos, scheduling and publishing to the channels you connected, and showing you how those videos perform.
To send transactional email (render results, publish failures, channel reconnection notices, workspace invites). We do not send marketing email without a separate opt-in.
To keep the service safe: enforcing rate limits, investigating abuse, and meeting legal obligations. We do not sell your data.
YouTube and Google data
FrameQ uses YouTube API Services. By using the YouTube features of the service you also agree to be bound by the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy.
When you connect a YouTube channel we access it only to upload and schedule the videos you approve, set their metadata, and read their analytics. FrameQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke FrameQ's access at any time from your Google security settings or by disconnecting the channel inside FrameQ. When a channel is disconnected, its stored tokens are deleted.
TikTok and Instagram data
When the TikTok integration is available and you connect a TikTok account, we will store the account identifier and the encrypted access tokens TikTok issues, and use them only to deliver the videos you approve to your TikTok account and, where you grant it, to read their performance. We do not read your messages, contacts, or anything beyond the scopes you approve. You can revoke access inside FrameQ or in TikTok's own settings at any time; revocation deletes our stored tokens.
The same applies to Instagram: the connection is limited to the professional account you authorize, publishing the content you approve, and reading its performance metrics.
Who processes data for us
These providers process data on our behalf, strictly to run the service:
- Supabase — database, authentication and API hosting
- Railway — application and worker compute
- Cloudflare R2 — media file storage
- Anthropic — AI text generation (receives topics, scripts and metadata prompts; never your credentials or platform tokens)
- ElevenLabs — voice synthesis for premium voices (receives script text)
- fal.ai — AI image and video clip generation (receives visual descriptions)
- Resend — transactional email delivery
- Sentry — error monitoring
- Google/YouTube — and TikTok and Meta once those integrations launch — publishing and analytics for the channels you connect
How long we keep it
- Account, workspace and content data: for as long as your account exists.
- Platform tokens: until you disconnect the channel or delete your account, at which point they are deleted.
- A record of recently used stock footage is kept for about 90 days, so the service can avoid repeating the same clips in your videos.
- Operational logs and error reports: for a limited period, then deleted or anonymized.
Your rights
You can ask us to export or delete your data at any time by emailing [email protected] from your account address; we respond within 30 days. If you are in the EU/EEA or the UK you additionally have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to your supervisory authority. QuneticLabs LLC is the data controller.
Security
Platform tokens are encrypted at rest with AES-256-GCM using a key held outside the database. Transport is TLS. Access to production data is restricted, and the database enforces row-level security so one workspace can never read another's data.
Children
The service is not directed at children and may not be used by anyone under 13, or under the higher minimum age of your country.
Changes to this policy
Changes are posted on this page with an updated date above; material changes are announced in the app or by email.