1. Who we are
FrameBind (“FrameBind”, “we”, “us”) is operated by ALGO Strategy, a sole trader (eenmanszaak) established in the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under no. 42079860, and contactable at contact@framebind.com. For the purposes of the GDPR, we are the data controller for the personal data described in this policy.
2. The data we collect
We collect only what we need to run the service:
- Account data— your name, email address, and (if you sign in with a profile picture provider) an avatar URL. We use email “magic links” to sign you in; we never store a password.
- Sign-in & security data — the IP address and approximate session timing of your logins, used to keep your account secure and detect abuse.
- Your content — the prompts you type, the documents you upload (PDF, DOCX, or a PowerPoint template), and the slides and .pptx files we generate for you. These may contain personal data if you choose to include it.
- Billing data — your purchase history and credit balance. Card details are handled by our payment processor (see §4) and are not stored on our servers.
We do not use third-party advertising or analytics trackers, and we set only the cookies strictly necessary to keep you signed in (see §6).
3. Why we use it, and our legal basis
- To provide the service — creating your account, generating and storing your decks, and taking payment. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
- To keep the service secure and prevent abuse — e.g. logging sign-ins, rate-limiting. Legal basis: our legitimate interests (Art. 6(1)(f)).
- To send you optional progress emails — telling you when your plan, draft, and finished deck are ready. You can switch these off at any time. Legal basis: consent (Art. 6(1)(a)), and our legitimate interest in transactional service emails.
- To meet legal obligations — e.g. keeping invoices and tax records. Legal basis: legal obligation (Art. 6(1)(c)).
4. Who we share it with (our processors)
We use a small set of trusted providers to run FrameBind. Each acts as our processor and only handles your data to provide their service to us:
- Anthropic(USA) — the AI model that turns your prompt and uploaded documents into a deck. Your content is sent to Anthropic's API to generate your slides. Anthropic does not use data submitted through its API to train its models.
- Resend (USA) — sends your sign-in links and progress emails.
- Cloudflare R2 — stores your uploaded files and generated decks.
- Stripe — acts as our merchant of record: it sells the credits to you, processes the payment, and stores your card details. We receive only the result of the transaction, never your full card number.
- Our database and application servers, hosted in the European Union.
We do not sell your personal data and do not share it with anyone else except where required by law.
5. International data transfers
Some of our processors (notably Anthropic and Resend) are based in the United States, so providing the service involves transferring your data outside the EU/EEA. Where that happens, the transfer is protected by the European Commission's Standard Contractual Clauses (or another valid safeguard under GDPR Chapter V). You can ask us for more detail using the contact above.
6. Cookies
We use only strictly necessary cookies — a session cookie that keeps you signed in after you click your magic link. We use no advertising, analytics, or cross-site tracking cookies, so no cookie consent banner is required. Your browser can block or delete cookies, but sign-in will not work without the session cookie.
7. How long we keep your data
- Your account, uploads, and decks are kept until you delete them or close your account — we keep your work available to you for as long as you have an account.
- When you delete a deck or your account, we remove the associated content from our active systems promptly and from routine backups within the normal backup-rotation period.
- Invoices and tax records are kept for as long as tax law requires us to (typically several years), even after account closure.
- Limited security logs (e.g. sign-in IPs) are kept for a short period for fraud and abuse prevention.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased (“right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable format and have it transferred;
- withdraw any consent you've given, at any time.
To exercise any of these, email contact@framebind.com. We'll respond within one month. You also have the right to lodge a complaint with your local data protection authority — in our case, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
9. Security
We protect your data with encryption in transit, access controls, and reputable infrastructure providers. No online service is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data and will notify you and the relevant authority of a qualifying data breach as required by law.
10. Children
FrameBind is a paid service intended for adults. It is not directed at children, and we do not knowingly collect data from anyone under 18.
11. Changes to this policy
We may update this policy as the service evolves. We'll change the “Last updated” date above and, for material changes, notify you by email or in the app.