FrameOS Scenes

FrameOS Cloud is in beta

The cloud is new and still changing. It works — frames enroll, scenes deploy — but expect rough edges, and expect things to move around.

  • It is free while in beta. Limits (frames, storage, logs) exist so one account cannot crowd out the rest; they may change.
  • Your data stays yours. Scenes, backups and frame settings can be exported from your account at any time, every frame keeps working on its own if the cloud is unreachable, and easy cloud ↔ self-hosted migrations are coming.
  • Self-hosting is not going anywhere. The cloud is an option next to the self-hosted FrameOS backend, not a replacement for it. The cloud itself is open source too — you can run your own, though we do not recommend it yet.
  • Tell us what breaks. Bugs and ideas are welcome on GitHub or Discord.
Legal
Sign in
Terms of ServicePrivacy PolicyImprint

Privacy Policy

Last updated: 15 August 2026. This explains what FrameOS Cloud does with your data, in plain language. The short version: we collect what the service needs to work, we sell nothing, and you can take your data and leave at any time.

Who is responsible

The controller is Raaven BV, Grauwmeer 1/70 bus 78, 3001 Leuven, Belgium. For anything in this policy — including the requests described under “Your rights” — write to [email protected]. A real person reads that address.

We have not appointed a Data Protection Officer: we are not a public body, our core activity is not large-scale monitoring, and we do not process special categories of data at scale, so art. 37 GDPR does not require one.

What we collect, and why

Your account

Your email address, an optional display name, and a hash of your password (or, if you sign in with Google, your Google account identifier instead). We need this to have an account at all, so the legal basis is performance of a contract (art. 6(1)(b) GDPR). Without it there is no service. We verify the email address because password resets and security notices have to reach the real owner of the account.

Your frames, scenes and files

Whatever you put into the service: the frames you link, the scenes you write or install, the images and files you upload, your device settings and schedules, backups of your FrameOS installations, and the logs and metrics your frames report. The legal basis is again performance of a contract: storing and serving this content is the service. Private scenes stay private; a scene becomes public only when you publish it.

Security and abuse prevention

We record an audit trail of security-relevant actions (sign-ins, device approvals, token rotations, scene publishing, deletions) with the IP address the request came from, and we rate-limit by IP address. The signup and password-reset forms run an anti-abuse check. The legal basis is our legitimate interest (art. 6(1)(f)) in keeping accounts from being taken over and the service from being flooded — an interest you share.

Analytics and error reports

If — and only if — you agree to it, we record which pages you visit and what you click, plus automatic reports when something goes wrong in your browser. The legal basis is your consent (art. 6(1)(a)), which you can withdraw at any time from the cookie banner without giving a reason and without losing anything else. Decline and the analytics code never loads.

Even with consent, we deliberately strip the parts that would be sensitive: URLs that carry a token (a password-reset link, a private scene’s share link) are redacted before they leave your browser, element attributes are never captured, and pages that list other people’s email addresses are excluded entirely.

Errors that happen on our servers are logged and reported without your consent and without your identity attached, on the basis of our legitimate interest in the service working at all. Those reports contain the error and the operation that failed, not your content.

Cookies and similar storage

We use the following:

  • Session cookie — proves you are signed in. Strictly necessary; no consent needed, and it disappears when you sign out.
  • Theme and consent preferences — remembers dark mode and remembers what you answered on the cookie banner, so it does not ask again. Strictly necessary for a function you asked for.
  • Analytics storage — set by PostHog only after you accept. Declining leaves it unset.

Who else sees your data

We do not sell your data and we do not share it for anyone else’s advertising. We do use a small number of service providers who process data on our behalf, under contract (art. 28 GDPR), and only on our instructions:

ProviderWhat it doesWhat it seesWhere
Hetzner Online GmbHHosting of the servers and the encrypted off-site backups.Everything you store: account, frames, scenes, uploaded files, backups.Germany (EU)
PostHogProduct analytics and error tracking — how the service is used and what breaks.Pages visited, clicks, and error reports. Never page URLs that contain a token, and never element attributes.EU region (eu.i.posthog.com)
Postmark (ActiveCampaign)Sending account email: address verification and password resets.Your email address and the message body.United States
CloudflareContent delivery and the anti-abuse check on the signup and password-reset forms.Your IP address and a challenge token. No account data.Global network
OpenAI
only for the feature described
Moderating and categorising scenes published to the Scene Store, and answering AI chat requests you start.The text and images you submit for publication, and your prompts.United States
Google
only for the feature described
Sign-in with Google — only if you choose that button instead of a password.Your Google account identifier and email address.United States

Your account and everything in it is stored in the EU. Where a provider above is outside the EEA, the transfer is covered by the European Commission’s Standard Contractual Clauses and, for US providers, by the EU-US Data Privacy Framework where they are certified.

We will also disclose data if a law or a valid court order requires it. If that ever happens and we are allowed to tell you, we will.

Public by your choice

Scenes you publish to the Scene Store are public: their name, description, preview images, contents, and your display name as the publisher are visible to everyone and downloadable by anyone. Your email address is never shown. Unpublishing removes a scene from the store, but copies other people already downloaded are theirs.

How long we keep things

  • Account data — until you delete your account. Then it goes, along with your frames, scenes, files and backups.
  • Sessions — until they expire or you sign out.
  • Security audit trail — kept after account deletion with your account identifier removed, so it no longer identifies you. A security log that could be erased on request would not serve its purpose.
  • Backups — the off-site backups roll over on a 30-day cycle, so deleted data survives in them for up to 30 days before being overwritten. We do not restore backups to recover deleted accounts.
  • Analytics — retained by PostHog under their standard retention.

Your rights

Under the GDPR you have the right to access your data, correct it, have it erased, restrict or object to how we use it, receive it in a portable format, and withdraw any consent you have given. Two of those do not need to involve us at all:

  • Export — download everything on your account as a JSON file from your account security page, any time.
  • Deletion — delete your account from the same page. It is immediate and permanent; nothing waits on us.

For anything else, email [email protected]. We answer within one month, as art. 12(3) requires. There is no charge.

If you think we have got this wrong, you can complain to a supervisory authority — for us that is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), or the authority where you live. We would rather you told us first.

Automated decisions

We do not make decisions about you by automated means with legal or similarly significant effects. Scenes submitted to the Scene Store are screened automatically for illegal and abusive content, and a rejection there can be appealed by writing to us — a human will look.

Children

FrameOS Cloud is not directed at children and we do not knowingly create accounts for anyone under 16. If you believe a child has an account here, tell us and we will remove it.

Security

Passwords are stored hashed, never in plain text. Traffic is encrypted in transit. Credentials for your linked FrameOS installations are encrypted at rest. Backups are encrypted in transit and stored on access-controlled infrastructure in the EU. No system is perfect; if we ever suffer a breach that puts you at risk, we will notify you and the supervisory authority as arts. 33-34 require.

Changes

If we change this policy in a way that matters, we will tell you by email or in the app before the change takes effect. The date at the top always says when it last changed.

TermsPrivacyImprint