Fullframe — Privacy Policy
Publisher: Appy Nation · App: Fullframe
(com.appynation.fullframe)
1. What we collect, and why
Fullframe's basic editing tools — filters, adjustments, crop, retouch, background removal, text and collage — run entirely on your device. Your photos never leave your phone to use them. This is not a limited trial; it is the permanent, free tier of the app.
Fullframe has no user accounts. You do not create a login, and we do not ask for your name, email address, or any other personal identifier to use the app.
AI tools (optional)
Some tools are labelled as AI tools — for example erase object, expand photo, upscale, AI headshot, hairstyle try-on, beard try-on, and AI makeup style. These are the only place a photo you are editing leaves your device. When you choose to run one of these tools, the photo you are working on is sent to our server, which forwards it to our AI processing provider (Google, via its Vertex AI service) to carry out the specific operation you requested, and the result is sent back to your device.
- We only send a photo when you explicitly start an AI operation. The app tells you this before you run one.
- The photo and the result are held only long enough to complete your request — 15 minutes at the outside — and are then automatically deleted from our processing systems. We do not keep a copy.
- We do not store the contents of your photo, and we do not store any text describing what the operation should do, in our own database. Our database records only bookkeeping information about the operation itself — which tool ran, how long it took, whether it succeeded, and byte counts — never the image, never a prompt.
- Our AI provider's own terms for this service state that data sent through it is not used to train their models. That is their commitment, not a technical guarantee we can verify ourselves, which is why we describe it exactly as their terms state it.
Reporting an AI result
If you believe an AI-generated result is inappropriate, you can report it from inside the app. Reporting sends only a reference to the specific operation and the reason you selected — never the image itself, which by the time a report is possible has typically already been deleted under the retention window above. The reporting system is built so that it could also carry a short optional note, but the app currently offers no place to type one — so today a report never contains anything you wrote. If we add a note field in a future version, we will update this section to say so before it ships.
Subscriptions and purchases
Fullframe offers optional paid subscriptions (Pro, Pro AI+, Pro AI Max) through Google Play (and, in the future, the Apple App Store). Payment is handled entirely by the store — we never see or store your payment card details. To confirm your subscription is active, our server receives an opaque reference token from the store (not your payment information) and checks it against the store's own systems.
Camera and photo access
If you take a photo inside the app, that photo is handled exactly like any photo you open from your device. If you choose a photo from your library, the app only ever sees the one file you selected — using your device's own picker, not a scan of your library. Saving an edited photo writes it to your device's gallery; the app does not read your existing gallery to do this.
On-device face detection
Some editing tools (retouch, reshape, makeup) use face detection that runs entirely on your device to locate facial features so the tool can be applied accurately. No face data, biometric template, or detection result is ever transmitted anywhere by Fullframe — it exists only transiently on your device while you are editing. The detection itself is performed by Google's on-device ML runtimes, whose own diagnostic telemetry is described in section 2 below; that telemetry never contains your photo or anything derived from it.
Abuse prevention on the AI service
Running an AI operation costs us real money, so the server has to be able to tell one connection apart from another — otherwise a single script could spend a day's capacity in minutes and leave paying subscribers unable to use the feature. To do that, and only for that, the server counts operations per connection:
- We do not store your IP address. We compute a short, non-reversible hash of it and store a counter under that hash. The address itself is never written down.
- That counter holds nothing but a number of operations, expires automatically within about 48 hours, and is never linked to your identity, your subscription, or any photo — we have no account system to link it to.
- Our hosting provider (Cloudflare) also sees the connection's IP address in the ordinary course of serving the request, as any web host does, and applies its own rate limiting.
2. What we do not do — and the one thing we cannot switch off
- We do not run advertising in the app, and we do not use any advertising SDK.
- We do not run analytics or crash-reporting software of any kind — Fullframe's own code measures nothing about your use of the app and transmits nothing about it to us.
- Your photos never leave your device on the free tier — the only exception, at any tier, is an AI operation you explicitly start (section 1).
- We do not sell, rent, or share your data with data brokers.
- We do not require an account, and we do not track you across other apps or websites.
One caveat we state because it is true. The on-device face and feature detection in some editing tools is powered by Google's ML runtimes (ML Kit and MediaPipe), which run on your phone. Those runtimes send Google their own anonymous diagnostic and performance telemetry — things like model-load events and processing-latency statistics about the runtime itself. This telemetry never includes your photo, your face data, or anything derived from your image content; it is not sent to us and we cannot read it; and it is built into Google's runtime in a way we cannot disable. We would rather tell you this than claim a zero we do not control.
3. Who we share data with
The only party we ever share a photo with is our AI processing provider (Google, via Vertex AI), and only for the single operation you explicitly requested. Our server itself runs on Cloudflare, which as our hosting provider handles the network connection carrying that request. Once you have a subscription, Google Play (or, later, Apple) processes your payment and subscription status as the platform you purchased through — we do not share your data with any other company.
4. Data retention and deletion
Because we do not require an account and do not store your photos or AI prompts on our servers, there is generally nothing to delete beyond what has already expired automatically within 15 minutes of an AI operation. If you have questions about a specific operation or want to confirm nothing was retained, contact us at the address below.
5. Children
Fullframe is not directed at children and does not knowingly collect data from children.
6. Changes to this policy
If how Fullframe handles data changes — for example, when a new feature or a new AI provider is introduced — this policy will be updated, and the "last updated" date below will change accordingly.
7. Contact us
Support email: ticketappynation@outlook.com