Unframed is a private shared album for your group — a trip, a wedding, a birthday, a random Tuesday — operated by 14923626 Canada Inc.. This policy explains what we collect, why, and the controls you have. The short version: your album is only ever visible to the group it belongs to, face matching is opt-in, and you can delete your photos, your face data, or your entire account at any time.
This document is also available in the languages listed above. Where the law allows, this English version governs if a translation differs from it. The French version is provided for users in Quebec under the Charter of the French language.
Account information. When you sign in with Apple, Google, or email we receive your name (if you share it), your email address, and an account identifier. Email sign-in also stores a salted hash of your password, never the password itself. We use this to create and secure your account, to link you to your albums, and to send you the emails described in section 2. We also keep your email preferences (such as whether you want reveal emails).
Age. Unframed is for people 13 and older. We ask you to confirm this once and keep only the fact that your account confirmed it; we don't use app-store age signals and we don't ask for your date of birth.
Photos and videos. The photos and short videos (with their sound) you choose to add to an album are uploaded to our servers and stored so the album's group can view and download them. Photo metadata may include the time of capture and, while location tagging is on, the location where a photo or video was taken (used for the album's map, Places and Wrapped). Location tagging is on by default and takes effect only once you allow the app to access your location: it uses your location only while you're taking photos, and a photo or video you add from your device's library keeps the place where it was taken only while tagging is on and location access is allowed. You can turn tagging off at any time in Profile. The app asks for location access when you first open it after signing in. Where a photo or video was taken is shown to everyone in its album — on the map, in Places and in Wrapped — once the album's photos are revealed; photos and videos added while tagging is off carry no location, and whoever added them still sees the map and where everyone else's were taken. A file can also carry metadata of its own from the camera, such as where it was taken: we remove it from photos as they are uploaded, and from videos a few moments later, once the video has finished processing on our servers. A video's picture and sound are never changed by this — only the file's metadata is removed, and in the rare case where a video cannot be processed it is kept exactly as it was sent.
Profile photo (optional). You can add a profile photo. It is shown next to your name to the members of the albums you are in (in member lists, comments, reactions and the like). We keep it as a small square picture (at most 512 pixels) with no metadata: no location and no camera details. It is not used for face matching and is never compared with anyone's face. You can change or remove it at any time, in Profile in the app or in Account settings on this site, and members can report it to us.
Face data (opt-in). You are never identified unless you enroll. If you choose to enroll in face matching (the person filter), you give us a selfie and we create a face signature from it — a set of numbers that describes your face; the selfie itself is not stored. Face matching turns on once you add your reference photos this way, and can't be turned on without them. You can turn matching off, or delete the signature, at any time. When matching is off, you aren't tagged in any album, and your existing tags are removed; turn it back on and new photos, and the photos already in your albums, can tag you again. When a photo is added to an album where someone uses face matching, the faces in it are compared with the face signatures of people who use face matching on Unframed. Only matches with members of that album who have it turned on are kept. No one else is identified, and nothing about other faces is stored. In detail: when a photo is added to an album in which at least one member has enrolled and has face matching on, the whole photo is analyzed and every face in it is detected. Each face large and clear enough to recognize (at most 24 per photo) is then compared with the face signatures enrolled on Unframed, and a face is identified only if it matches a member of that album who has enrolled and has face matching on. The only thing we keep is that tag: which member appears in which photo, and how close the match was. Nobody else in the photo is identified or stored — not people who have not enrolled, not members who have turned matching off, and not enrolled people outside the album: no face signature is made for them, and face positions, face crops and comparison results are discarded as soon as the photo is processed, never stored, shown or logged. Photos in an album where no member has enrolled with matching on are not scanned; they may be scanned later, if a member enrolls or turns matching back on, or someone who has enrolled joins the album. Photos already scanned are scanned again when a member turns matching back on, enrolls, or joins the album already enrolled, so that member can be tagged in them. Videos are never scanned, and whoever adds a photo in the app can turn matching off for it.
Scanning is bounded by allowances: free albums include a one-time allowance of a set number of photos so you can try it (an album is free while no upgrade or subscription pays for it); an album upgrade gives that album a one-off allowance that includes any photos it already had matched; and an album a subscription covers matches from the Unframed Plus or Max subscriber's monthly allowance instead, shared across the albums they cover and refreshed each month. Service-wide limits, such as a daily limit per uploader, also keep matching within our capacity; a photo they hold back is matched later. When an allowance runs out, photos and videos still upload normally; photos are simply not matched until more allowance is available. Face data is used only to power the person filter inside your own albums. It is never used for advertising, never sold, and never shared with other users, and it identifies you only in albums you are a member of. You can delete your face signature at any time — in the app under Profile → Face recognition, or on this site in Account settings → Face signature (or by deleting your account) — and it is removed from our systems, along with the tags it produced.
Comments, reactions and album names. The comments and reactions you post on photos and videos, the names you give albums, and any report you make about a photo, video or comment are stored with your account. Comments, reactions and album names are shown to the album's members. You can delete your comments and reactions at any time, and deleting your account removes them and your reports.
Purchases. Payments are processed by Apple (App Store) or Google (Google Play), depending on where you bought. We receive purchase receipts or purchase tokens (never your card or payment details) to grant what you bought, and the store sends us subscription lifecycle notices — renewal, lapse, refund — so entitlements stay in step with what you are actually paying for.
Device and usage data. Push notification tokens (with the device's language and platform, so a notification arrives in the right language on the right service), basic device information, a short allowlist of in-app activity events (app opened, paywall viewed, an invite shared, opened or declined, and the like — never the contents of your photos), a record of the days your account was active, crash and error reports (the error text, the screen it happened on, app version, and device or browser), and server logs needed to run and secure the service (e.g. rate limiting, abuse prevention). Activity events, active days and crash reports are stored with your account identifier.
Usage records. Our servers also record key moments in how the service is used: creating your account (and whether you signed up with Apple, Google or email); creating an album (whether it is sealed and for how long, and how many albums you have created); joining one (with who invited you, who hosts it, how many members it then has and how long you had had your account); your first photo or video in an album; reaching a plan limit (which limit, and whether you host the album or joined it); an album's reveal (how many members and contributors it has and how many photos and videos it holds) and how soon after it you first looked; covering an album with your subscription, or an album that was waiting for a plan being removed unfunded; and purchases, renewals, auto-renew changes, refunds (and a refund the store later reverses) and the end of a subscription (the product, the store, its price and currency, how long a subscription lasted, and whether you bought for an album you host or one you joined). These records are linked to your account, and refer to albums and to other members only by codes, never by name. They never contain an email address, the contents of your photos or videos, comments or album names. When an account is deleted, one record with no identifier at all, dated only to the day (not the time), notes that an account was deleted, how long it existed, whether it was paying, how many albums it hosted, and whether you or we deleted it.
To provide the service: storing and delivering your group's album, running the reveal countdown, sending the notifications your group expects by push and email (for example, an email when an album you're in is revealed, sent to a verified address only if you turn reveal emails on in the app's settings; they are off unless you do, and you can turn them off again there or with the one-click unsubscribe link in any of them), telling you about your data (such as an album that is going to be deleted or trimmed — these notices are sent even if you have turned other notifications or reveal emails off), powering the opt-in person filter, processing upgrades, and keeping the service safe. We also use your account identifier, the activity events, active days and usage records above, and purchase records for our own analytics: counting active accounts, seeing which features people use, how albums grow and how long people keep using Unframed, and adding up sales, renewals and refunds, so we can make better decisions about the product and its prices. Our analytics provider, PostHog, processes these records for us (section 4). They are never used for advertising, and never combined with data from other companies. Crash reports are used to fix what breaks. We do not sell your personal information, and we do not use your photos or face data for advertising or to train unrelated models.
Only members of the album a photo belongs to. There are no public profiles, feeds, or search. While an album's seal is on, nobody can see anyone else's photos and videos until the reveal moment set by the album's admin; each member can see and delete only what they added themselves, under Your uploads, and can save it on this website, signed in on a computer (not every version of the phone apps can save it before the reveal). An album's admins can remove members and delete any photo or video in the album. Your profile photo, if you add one, is shown only to members of the albums you are in.
When you leave an album, the photos and videos you added to it are permanently deleted from it, along with the face-match tags that mark you in its other photos; your comments and reactions stay. When an admin removes a member, that member's photos and videos stay in the album unless the admin also chooses to delete them.
We use Amazon Web Services to host the service, store media (Amazon S3), run opt-in face matching (Amazon Rekognition), and send emails — verification and password-reset codes, reveal emails, and notices about your albums and data (Amazon SES). These providers process data on our behalf under data-processing agreements. Sign-in is provided by Apple and Google when you choose those options; push notifications are delivered through the Apple Push Notification service on iPhone and iPad and through Firebase Cloud Messaging (Google) on Android; purchases are processed by Apple (App Store) or Google (Google Play); and product analytics is provided by PostHog (below). Photos and videos are delivered through Amazon CloudFront, which keeps short-lived cached copies in North America and Europe for up to 7 days; those copies cannot be retrieved without a link that expires within 2 hours.
Maps. The album map in the Android app loads its map images from OpenFreeMap (openfreemap.org), a free third-party map service. Only while you have the map open, your phone asks OpenFreeMap for the pieces of the map on screen, and each request reveals your device's IP address and the approximate area of the map being viewed. Nothing about your account, your albums or your photos is sent, and we have no agreement with OpenFreeMap about that data; its own terms and privacy policy apply. On iPhone the album map is Apple Maps, and Apple handles those requests under its privacy policy. The web app shows no map.
Face matching (Amazon Rekognition). Enrollment selfies, and the album photos that face matching scans, are processed by Amazon Web Services on our behalf, only to find and match faces. AWS's terms allow content processed by its AI services to be used to improve them unless the account opts out; our AWS account is opted out of that use. What is stored is a face vector for each enrollment selfie (a set of numbers that describes a face, not an image of it) in a face collection in our own AWS account. Album photos are compared against those vectors and are never added to the collection. The vectors are deleted when you delete your face signature or your account, or after 3 years without account activity.
Product analytics (PostHog). We use PostHog as our product-analytics provider, on PostHog Cloud US, which stores the data in the United States. Only our servers send it anything: the apps and this website contain no PostHog code and never contact it. It receives the in-app activity events (except those about face matching) and the usage records described in section 1, including purchase prices, linked to a code computed from your account identifier rather than the identifier itself, along with how and on what date you signed up, which plan you are on, and whether you use iOS, Android or the web; records from the test accounts we mark as ours say so. It never receives your name, email address, photos or videos or their location, comments, album names, face data (not even whether you set up face matching), your age, device identifiers or push tokens, crash reports, or your IP address, and PostHog's own IP collection and location lookup are turned off for our project. PostHog processes this data only on our behalf and on our instructions, under a data-processing agreement we have signed, and never for advertising. Because it is stored in the United States, it is processed outside Canada and can be accessed by the courts, law-enforcement and national-security authorities of the United States under the laws there.
How long an album collects. An album's reveal date can be set up to 10 years after the album is created. A free album collects for a bounded time: a sealed one stops accepting new photos and videos 14 days after its reveal or 365 days after it was created, whichever comes first, and one without a seal stops 14 days after the 90-day mark from its creation. On the free plan, sealing an album again with a new reveal date can reopen it, but never past 365 days after it was created — so the window in which a free album collects anything is bounded from the start, and is never longer than a year. An album that is upgraded, or covered by an Unframed Plus or Max subscription, keeps accepting new photos and videos for as long as it stays upgraded or covered, even if its free-plan window has passed, unless an admin of the album sets an end date or stops new uploads; when a cover ends, the free plan's limits apply again to an album that is not upgraded. An album's admins can set an end date or stop new uploads at any time.
After a subscription ends. Albums and media beyond the free plan limits are kept for at least 30 days after paid access and any billing grace end. After that, excess hosted albums and their contents are permanently deleted, keeping the two most recently active eligible free albums. Kept albums and albums the subscription covered for another host are trimmed to free photo, video and storage limits, removing newest uploads first. Albums that account only joined, permanent one-time album upgrades or earlier paid originals unlocks, and albums covered by another member's active subscription are protected. An album that is still sealed when those 30 days begin is held: nothing in it is deleted under this rule until 30 days after its reveal. Renewing, upgrading an album or covering it before its deadline protects it. Profile → Usage shows the current deadlines and affected albums.
Who is told. We send cancellation and retention notices by email (to a verified address) and push when data is at risk: to the account whose subscription ended, and to every member of each album that would be deleted or trimmed, who also see a notice on the album in the app. A member's notice names the album, the album's host and the date, says that the album is no longer covered by a plan and what will be removed, and explains how to save, upgrade or cover it. It does not say whose plan it was or why it ended, though members may infer that the plan behind the album has ended. Members of a held album are first told at its reveal. When an album we warned about is saved by a renewal, an upgrade or a cover, we tell the people we warned.
Full-quality originals. Free albums also have a separate originals-only cleanup: 30 days after an album's reveal date, original files are removed unless the album has a permanent upgrade, an earlier paid originals unlock or an active Plus or Max cover. Standard-quality copies and thumbnails that remain within the retention rules above are kept. We send reminders roughly 7 days and 1 day beforehand to members who have album notifications enabled. An album upgrade keeps its originals for as long as we operate the service.
A cover only holds an album's originals while that subscription is active (including any store billing grace period). When it ends and nobody else in the group covers it, the album goes back on the schedule above: its originals are removed 30 days after the reveal or 30 days after the cover ended, whichever is later or the extended deadline shown in Usage, with the same reminders roughly 7 days and 1 day before.
Purchase records. When you delete your account, we keep the record of each App Store or Google Play purchase made with it — what was bought, when, the store's transaction reference and the account it was applied to — for as long as we operate the service. We keep it so the same purchase can't be redeemed again on another account, so a store refund can still be matched to what it paid for, and for our financial records. It holds no photos and no payment details.
Everything else. Photos you delete, a profile photo you change or remove, and deleted accounts, are removed from production systems promptly (PostHog's analytics copy follows its own schedule, below). A deleted account's remaining records age out of our rolling database backups within 35 days; those backups hold account data, not photo or video files. Deleted or removed photos, videos and profile photos can remain in encrypted storage backups for up to 30 days before they are permanently purged. Crash and error reports are kept 30 days; in-app activity events and the record of active days are kept 90 days in our own systems. Face signatures are not part of the backup tail — deleting one is immediate and complete (see below).
Analytics (PostHog). The records we send to PostHog wait on our servers only until they are delivered, normally within minutes and at most 7 days: one PostHog has not taken by then is never sent, and is deleted from our servers instead (the deletion itself can take a few more days). On the PostHog plan we use, we can look at only the last 1 year of these records, but PostHog does not promise to erase older ones at that point, so they stay with PostHog until you delete your account. When you delete your account, anything still waiting to be sent is discarded, and shortly afterwards we ask PostHog to delete your analytics profile and every event recorded under your code, whatever its age. PostHog removes the profile, usually within a few minutes, and deletes the events in the background, typically within a week; we repeat the request a day later to catch anything that was still on its way. After that, nothing about your own use of Unframed is sent to PostHog: for 400 days after the deletion completes, our servers keep a deletion marker holding only your code and the day the deletion happened (not the time), so that any late record for that code is discarded instead of sent, and then delete the marker, usually within a few days. Records of other members joining an album you created, or through an invite you made, before your deletion began name your code as that album's host or as the person who invited them; they belong to those members, so they stay until those members delete their own accounts. A join recorded once your deletion has begun never names you. The one record about the deletion itself has no identifier (section 1).
Logs and support records. Server and application logs are kept 60 days; access logs and our cloud audit trail are kept 90 days. We also keep a record of support actions taken from our internal console — what changed and the internal account id it applied to — for as long as we operate the service. Neither holds photos, contact details or payment details. To check that the service works as described, we also count what happens in it, per day and per album (for example how many people joined an album, or how many reveal emails were sent); these counts name no one and hold no content. The running daily counts are kept 90 days; each day's totals are also copied into our daily service summary, which we keep for as long as we operate the service. The per-album counts are kept until 400 days after they last changed, including after the album is deleted.
Face data — retention and destruction schedule. Your face signature is kept only while you are enrolled in person filtering, and is permanently destroyed when you delete it (Profile → Face recognition in the app; Account settings → Face signature on this site) or delete your account — whichever comes first. It is never retained after that for any purpose, including to improve the service.
You never have to ask: if you stop using Unframed, your face signature is destroyed automatically after 3 years without any account activity, even if you never open the app again. A daily job enforces this, and we do not extend the window.
Turning person filtering off is a separate control: while it is off you aren't tagged in any album, and your existing tags are removed from every album, but your signature is kept so you can turn matching back on; from then on new photos, and the photos already in your albums, can tag you again. Deleting the signature is the removal path for your face data: it destroys the signature, so no new photo can be matched to you, and the person tags it already applied to past photos (which enrolled members appear in which photo) are removed from those photos shortly afterwards, in the background.
When you delete your account, your face signature is destroyed before the rest of your account data, and if that destruction cannot be completed the deletion stops and retries rather than continuing without it — so your face data can never outlive your account. Unlike photos, face signatures leave no backup tail: they exist only in the live matching index, so destroying them is immediate and final.
You can, at any time, from the app — or from this website, signed in on a computer:
Unframed is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
Media is transferred over encrypted connections and stored encrypted at rest. Access to an album's media requires authentication and membership of that album. No system is perfectly secure, but we design for least access and audit our practices regularly.
We'll post any changes to this policy here and, for material changes, notify you in the app. Questions or requests: support@scientsolutions.ca.