Hold My Frame Search. Discover. Create.
Overview Pricing Legal
Overview Pricing Legal
Open app

Legal · Privacy policy

Privacy Policy

Last updated: July 15, 2026

On this page

  • Imprint
  • Privacy policy
  • Terms of use
  • Copyright & image rights
  • Refund policy

Sections

  • Controller
  • What data we collect
  • Cookies
  • Analytics
  • Legal basis
  • Third-party providers
  • Business transfers
  • Data retention
  • Children
  • Your rights
  • Changes to this policy
  • Contact

Controller

FADED Filmproduktion e.U. Hold My Frame Weyringergasse 13 1040 Vienna Austria Vienna, Austria
[email protected]

What data we collect

Account data: When you sign up, we store your email address and display name. If you use Apple or Google sign-in, we also store the OAuth provider and provider account ID needed to link the login to your account. Passwords, where used, are hashed using bcrypt and never stored in plain text.

Payment data: If you subscribe to a paid plan, payment is processed by Stripe. We store your Stripe customer ID and subscription status in our database. We do not store credit card numbers, bank account details, or other payment credentials — Stripe handles this directly. Stripe may collect additional data as described in their privacy policy.

Usage data: We log page views, search queries, clicks, feature usage, job provenance and technical errors to provide, secure and improve the product. These records are primarily stored on our own infrastructure. Selected feature inputs are sent to the processors described below only when the relevant feature is used.

Uploaded media and generated metadata: If you upload film material, we store the source file, generated stills, thumbnails, search embeddings, visual metadata and processing logs as needed to operate the service, secure the upload pipeline and support moderation or deletion requests.

External client reviews: If you open a client-review link without an account, we ask for your name so comments and overall feedback can be attributed to you. An email address is optional. If supplied, it is used to create a pseudonymous lookup key so we can locate, export or delete your review data after verifying a privacy request. Approvals and rejections are retained without your identity; names, emails, comments and overall feedback are removed on a verified deletion request or after the retention period, unless a legal hold applies. The organization that sent the review link may separately determine the purpose and content of the review and may therefore also be a controller for that project content.

AI-assisted features: Search language tools may send the current search query to OpenAI for normalization, translation or shot-list assistance. Pitch may send the brief or treatment text and selected reference context; Look Match review may send selected image inputs and server-built matcher context; Curate may send film/source/credit research context. An optional admin feedback summary is disabled by default and, when explicitly enabled, removes account email, URL queries, search queries, filters and visible-result details before sending feedback text. Brave Search may receive source-research queries from authorized Curate users or offline source-maintenance tools. Do not submit confidential third-party material unless you are authorized to use the relevant feature for that material.

Location data: We derive your approximate geographic location from your IP address (GeoIP lookup) for security purposes, including login anomaly detection. We do not store your raw IP address beyond the server access logs, which are retained for up to 30 days.

Email communications: We use Resend as our email service provider to send account verification and notification emails. Resend processes your email address solely for delivery purposes.

Cookies

We use the following cookies:

  • fd_session — required for authentication, expires after up to 30 days or when you log out. (Technically necessary, no consent required.)
  • fd_csrf — protects forms and API requests against cross-site request forgery, expires after up to 30 days. (Technically necessary.)
  • fd_oauth_state — temporary OAuth login protection, expires after 10 minutes. (Technically necessary.)
  • fd_device — recognizes your device for login security and anomaly detection, expires after up to 180 days by default. (Technically necessary.)
  • fd_admin_stepup — temporary admin confirmation cookie, expires after 10 minutes. (Technically necessary, admin users only.)
  • simulate_tier — temporary admin preview setting, expires after 24 hours. (Technically necessary, admin users only.)
  • hmf_preview — optional preview access cookie, expires after 30 days. (Technically necessary.)
  • hmf_consent — stores your cookie preference (accepted/rejected), expires after 1 year. (Technically necessary.)

The following cookies are only set if you accept analytics cookies via our consent banner:

  • _ga — Google Analytics client ID, expires after 2 years.
  • _ga_* — Google Analytics session data, expires after 2 years.

Analytics

We use Google Analytics 4 (GA4) on our landing page to understand how visitors find and interact with our website. GA4 is only loaded after you give consent via our cookie banner. If you reject analytics cookies, no tracking scripts are loaded and no data is sent to Google.

You can withdraw your consent at any time via Cookie settings. Withdrawal immediately disables analytics, removes existing Google Analytics cookies for Hold My Frame domain and path variants, and reopens the consent banner.

When GA4 is active, data is processed by Google Ireland Limited. Google may transfer data to the United States under the EU-US Data Privacy Framework (adequacy decision of July 10, 2023). For details, see Google's privacy policy.

Legal basis

We process your data based on:

  • Consent (Art. 6(1)(a) GDPR) — for analytics cookies (GA4). You can withdraw consent at any time.
  • Contract performance (Art. 6(1)(b) GDPR) — to provide the service you signed up for, process payments, and send transactional emails.
  • Legitimate interest (Art. 6(1)(f) GDPR) — to ensure security (login anomaly detection, rate limiting, GeoIP checks) and improve the product based on aggregated usage data.
  • Legitimate interest (Art. 6(1)(f) GDPR) — to provide requested project-review collaboration, attribute comments to the reviewer, preserve anonymous review decisions and prevent misuse of public share links. Reviewers may object where the statutory requirements are met.

Data processors and third-party providers

We use the following third-party service providers. Depending on the service and context, they may process data on our behalf or act as independent controllers for their own legally required processing, for example payment and sign-in providers:

  • Cloudflare, Inc. (US) — CDN, DDoS protection, DNS, WAF and R2 object storage for media. Data processed at edge locations worldwide. Privacy policy
  • Stripe, Inc. (US) — Payment processing for subscriptions. Privacy policy
  • Google Ireland Limited / Google LLC (IE/US) — Analytics (GA4), only with consent, and optional Google sign-in when you choose it. Privacy policy
  • Resend, Inc. (US) — Transactional email delivery. Privacy policy
  • Modal Labs, Inc. (US) — Bounded compute for GIF and ZIP generation using short-lived job manifests and exact object-key lists. Privacy policy
  • OpenAI, L.L.C. (US) — AI-assisted search language tools, Pitch analysis, Look Match review, Curate metadata work, optional redacted feedback summaries and film-pipeline metadata generation where those features are used. Privacy policy
  • Functional Software, Inc. (Sentry) (US) — Error monitoring and diagnostics. Default PII collection is disabled; authorization, cookie, token, body, URL-query and search-query fields are removed before events are sent. Privacy policy
  • Dropbox International Unlimited Company / Dropbox, Inc. (IE/US) — Encrypted operational backups, media mirrors and restore testing. Privacy policy
  • Apple Inc. (US) — Optional Apple sign-in when you choose it. Privacy policy
  • Brave Software, Inc. (US) — Source and metadata research for authorized Curate users and offline source-maintenance tools where enabled. Privacy policy

Where US-based providers are used, data transfers are covered by the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.

Business transfers

If Hold My Frame is involved in a merger, acquisition, restructuring, financing, sale of assets, transfer of the Service, or similar corporate transaction, personal data may be transferred as part of that transaction where permitted by law. Any successor will be required to respect this Privacy Policy or provide you with notice of any material changes.

Data retention

Account data is stored as long as your account is active. Login history is retained for up to 90 days for account security. Product usage, search logs and Look Match feedback are retained for up to 12 months to maintain and improve the service. External client-review names, optional emails, comments and overall feedback are retained for no more than 12 months unless they are deleted earlier or a legal hold applies. Approvals and rejections may remain as anonymous project decisions after reviewer identity and text are removed. Client/server error records are retained for up to 90 days. Server access logs are retained for up to 30 days. Support feedback and its attachments remain while needed for support and resolution and are included in account export/deletion. Uploaded media and generated metadata are retained until deletion, hiding, quarantine, account-level deletion handling, or a rights/moderation decision requires a different retention period.

You can export your account data and request deletion directly in Settings. The ZIP export includes active account data and available feedback attachments. Account deletion removes the active account, sessions, OAuth/reset records, login/security history, private tags, saved searches, pitch versions, owned project/version data, search/click events, feedback, error records, AI-job attribution and available feedback attachments from active stores. Attribution in shared records is removed or replaced with a non-identifying label. An active legal hold can temporarily block deletion. Shared library assets, provider records subject to a separate legal request, fraud-prevention records, billing/audit records and legal accounting records may be retained where required. Safety backups age out according to the backup retention schedule.

Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe that a child has provided personal data to us, contact us at [email protected] and we will take appropriate steps to delete it where required.

Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Request correction of inaccurate data (Art. 16).
  • Request deletion of your data (Art. 17).
  • Restrict processing (Art. 18).
  • Data portability (Art. 20).
  • Object to processing based on legitimate interest (Art. 21).
  • Withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3)).

To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before responding, especially for access, export or deletion requests. We will respond within 30 days unless a longer period is permitted by law.

External client reviewers can use the same contact address. Where an optional email was supplied with the review, we use it only after verification to locate the associated comments and feedback. Deletion removes reviewer identity and text from active stores and records a pseudonymous suppression marker so a later backup restore cannot reintroduce that data. Encrypted backup copies age out under the backup schedule.

If you use the Service through an agency, studio, company or other organization, that organization may also control some account, project or billing information and may be responsible for responding to requests about data it controls.

You also have the right to lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde):
Barichgasse 40–42, 1030 Vienna
www.dsb.gv.at

Changes to this policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. For significant changes, we will notify registered users by email.

Contact

For any privacy-related questions, reach us at [email protected].

Hold My Frame

Find, collect and present visual references.

Imprint Pricing Privacy Terms Copyright Refunds Cookie settings Contact
HOLDMYFRAME.COM
© 2026