THE Framer

Privacy Policy

Last updated: 7 July 2026

Who is responsible

The data controller is BAARS DESIGN, org. nr. 938 054 037, registered in Norway (baars.design). Privacy questions and data requests: [email protected].

What we collect and why

When you sign in with Google we store your Google account identifier, email address, display name and avatar URL (needed to provide your account — performance of contract). As you use the service we store the data you create: favourites, collections, households and their members, and slideshow settings. To reach your TV, the bridge you install reports your TV's local IP address and name, the name (SSID) of the WiFi network it is on, and the TVs it discovers on your network — this is used only to route artwork to the right TV. If you enable the weather widget, we store the approximate location coordinates you set for it. If you subscribe, we store your Stripe customer and subscription identifiers; your card details are held by Stripe, never by us.

What we don't collect

We do not sell data, run third-party advertising, or use tracking pixels. We do not store your Google password (authentication happens entirely with Google). The bridge on your home network talks only to The Framer's servers and to your TV; it does not inspect other traffic.

Who processes data for us

We use a small number of service providers: Google (sign-in), Stripe (payments and VAT calculation), Cloudflare (network routing in front of our servers, and encrypted off-site backup storage), and Open-Meteo (weather forecasts for the optional TV weather widget — if you enable it, your browser sends the approximate coordinates you set to api.open-meteo.com to fetch the forecast). Transactional email such as household invites is sent from our own mail server. Beyond these providers we do not share your data with anyone else, and no third party may use it for its own purposes.

Where data lives

Data is stored on The Framer's own server infrastructure in the EU/EEA. Artwork images are reproductions fetched from the source museums' public APIs and cached on our servers. Traffic is encrypted in transit via HTTPS.

Data retention and deletion

Your data is kept while your account is active. Deleting your account from the Settings page removes your profile, favourites, memberships, solely-owned households and bridge tokens. Encrypted server backups are retained for up to 30 days and then deleted automatically, so deleted data disappears from backups within 30 days. Billing records are kept as long as bookkeeping law requires.

Your rights

You can access, correct, export (Settings → Download my data) and delete (Settings → Danger zone) your data yourself, or email us to exercise any GDPR right — access, rectification, erasure, restriction, portability or objection. You may also complain to a data protection authority; for us that is Datatilsynet (Norway), but you can contact the authority in your own country. The service is not directed at children under 13.

Cookies

We use only the session cookie required to keep you signed in. No analytics or advertising cookies are set.

Contact

Privacy questions or data requests: [email protected] · BAARS DESIGN, org. nr. 938 054 037 (Norway) · baars.design.