Legal
Privacy Policy
Last updated: August 4, 2026
This policy explains how FrameComment handles personal data, what we collect, why, and the rights you have. We built the Service for professional video work, and our approach is simple: your content is your business. We don’t sell data, we don’t run advertising, and we don’t use your content to train AI models.
1. Data controller
MINDQUB S.R.L.
Strada Vespasian nr. 47, Camera 2
Sector 1, București 011981, Romania
Company Registration No.: J2025022239001 · VAT / Tax ID: RO51533881
Contact: [email protected]
Note: when a company uses FrameComment to collaborate with its own clients and team, that company decides what content is uploaded and shared. For the content of those projects, the company acts as the data controller and MINDQUB S.R.L. processes it on the company’s behalf to provide the Service.
2. What we collect
Account data.Name, email address, and a password (stored only as a cryptographic hash, we never see or store the plain password). If you sign in with a passkey, we store the passkey’s public credential, never a private key.
Content you upload. Videos, images, documents, comments (including voice comments and attachments), project and folder names, and approval decisions. Guest reviewers on share links may leave a display name with their comments.
Billing data. Your company name, billing status and invoices. Card details are collected and processed directly by Stripe, they never touch our servers.
Usage and security logs. IP addresses, browser type, and security-relevant events (sign-ins, failed attempts, destructive actions). We use these to keep accounts safe, enforce rate limits and investigate abuse.
Cookies and local storage. We use only what is strictly necessary to operate the Service, session authentication and interface preferences (like your accent color). There are no advertising or cross-site tracking cookies.
3. Why we process it (legal bases)
We process personal data to provide the Service you signed up for (performance of a contract, Art. 6(1)(b) GDPR); to keep the Service secure, prevent abuse and improve reliability (legitimate interest, Art. 6(1)(f)); to meet legal obligations such as tax and accounting rules (Art. 6(1)(c)); and, where we ever ask for it, based on your consent (Art. 6(1)(a)), which you can withdraw at any time.
4. AI transcription
Transcripts are generated only when someone on your team explicitly requests one. In that case the audio of the selected video is sent to our AI transcription provider (currently OpenAI) solely to produce the transcript; the result is stored in your project as a document you can delete at any time. If you never request a transcript, your media is never sent to an AI provider.
5. Who we share data with
We do not sell or rent personal data. We share it only with processors that help us run the Service: Stripe (payments), our AI transcription provider (only on request, as above), and infrastructure providers for hosting and delivery. If your company connects its own storage backend (your server, Cloudflare R2, AWS S3), files stored there sit with the provider your company chose, under your company’s agreement with them. We may also disclose data where the law requires it, or to protect the rights and safety of our users and the Service.
6. International transfers
We aim to keep data within the European Economic Area. Some processors (for example Stripe and OpenAI) may process data in the United States; where that happens, transfers are protected by recognized safeguards such as the EU Standard Contractual Clauses or an adequacy framework.
7. How long we keep data
Account and content data are kept for as long as your company account is active. Deleted projects and files spend up to 30 days in a recoverable Trash, then are permanently removed. Deleting a company starts a 30-day cancellable countdown, after which the company’s data is permanently erased. Billing and invoicing records are retained for the periods required by Romanian fiscal law. Security logs are kept for a limited period needed to investigate abuse.
8. Security
All traffic is encrypted in transit (HTTPS/HSTS). Passwords are hashed; stored credentials for connected storage are encrypted at rest. Each company’s data is isolated at the database level using PostgreSQL row-level security, and destructive actions are protected by confirmations and time-delayed safety windows. No system is perfectly secure, but we treat security as a first-class feature and ship protections continuously.
9. Your rights
Under the GDPR you have the right to access, rectify, delete, restrict or object to the processing of your personal data, and the right to data portability. For any privacy-related requests, including access, rectification, deletion, or portability of your personal data, please contact: [email protected]. We respond within the timelines required by law. You also have the right to lodge a complaint with a supervisory authority, in Romania, that is ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, www.dataprotection.ro).
10. Children
The Service is intended for professional use and is not directed at children under 16. We do not knowingly collect personal data from children; if you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
If we change this policy in a material way, we will update the date above and notify active users before the change takes effect.