FamFrame← back home

a small note

privacy policy

Effective 28 May 2026 - last updated 4 September 2026.

at a glance

FamFrame is a place to draw your family and make frames of the moments that mattered. To do that, we keep the things you save - your account, the people you add, the photos you upload, the frames you make. We use a small set of trusted services to run the product. We do not sell your data, we do not use your photos to recognise you or anyone else against any outside database, and we do not use your photos or the face signatures we derive from them to train general-purpose or foundation AI models, and we only load analytics or marketing cookies if you say yes.

To actually make your frames we do carry out automated face processing on the photos in a frame - this is a form of biometric processing, it is explained in “A note on photos and faces” below, and we do it only with your explicit consent.

This page explains what we collect, why, who else sees it, how long we keep it, and what you can ask us to do with it. If anything is unclear, write to admin@thebaio.com.

1. Who we are

FamFrame is operated by Alon Mittelman, trading as Mimona Technologies, a sole proprietor registration number 300171220, with a place of business at 24 Hertzl Street, Ramat Gan, Israel. In this policy “we”, “us”, and “FamFrame” mean that person, acting as the controller of your personal data.

For privacy questions, requests to exercise your rights, or any other matter described here, contact us at admin@thebaio.com.

You also act as a controller of the personal data of other people whose photographs you choose to upload; we process that data on your instructions and on the basis described in this policy.

2. Who this applies to

This policy applies to everyone who uses FamFrame at thefamframe.com or any related domain. FamFrame is open to people aged 16 and over. If you are under 16, you may not create an account; if you have done so, please ask a parent or guardian to write to us at the address above and we will delete the account.

Although FamFrame is operated from Israel, this policy is written to meet the requirements of the EU General Data Protection Regulation (GDPR) for users in the European Economic Area and the UK, the Israeli Privacy Protection Law 1981 (as amended, including Amendment 13), and the biometric-privacy rights of users in Illinois (BIPA) and Texas (CUBI) where applicable.

3. What we collect

From you, when you sign up and use the product

  • Account. Your email address and, if you sign in with Google, your Google account name and profile picture.
  • Profile. A display name and theme preference. You may change these at any time.
  • Family tree content. The people you add (their names, approximate years of birth or passing, short bios and memories you choose to write), the relationships between them, and the photos you choose to upload of those people.
  • Frames. The frames you make in the app - including the cast (who is in the frame), the photographic style you chose, an optional title and description, and the resulting image.
  • Credit ledger. A record of frame credits you have received, earned, purchased, or spent.

Some of the bios, memories, and photos you choose to add may reveal special categories of data (for example health, religious or ethnic information). Where they do, we process that data on the basis of your consent and to provide the service you asked for, and only as needed to run FamFrame.

From you, when you pay us

Frame purchases are processed by LemonSqueezy, which acts as the merchant of record. LemonSqueezy collects your billing information and processes the payment under its own privacy policy. We receive a confirmation that the purchase succeeded, the products purchased, a transaction identifier, and limited billing metadata (for example the billing country) that we keep for tax and accounting purposes. We do not see or store your full card number.

Automatically, when you use the site

  • Technical data. Your IP address, browser user-agent, approximate location derived from the IP, the pages you visit and the actions you take, and the time of each request. We use this to keep the service running, to detect abuse, and to debug problems.
  • Session cookies. A database-backed session cookie set by NextAuth so you stay logged in. See section 8.
  • Product analytics and analytics cookies (only if you consent). If you accept the analytics category in our cookie banner, we record a small set of first-party product milestones (such as starting sign-up, uploading a photo, starting or completing a frame, and opening or completing checkout), the page path, an anonymous 30-minute session identifier, device category, and campaign source. These events may be linked to your account after sign-in. We do not put names, email addresses, family details, photos, photo links, prompts, or image content in these events. We also load the Meta (Facebook) Pixel and Google Ads conversion tag to measure our advertising. If you decline, none of this analytics processing takes place.

A note on photos and faces

Photos you upload of family members are personal data, and they are sometimes photos of people other than yourself. To place each person in a frame and make the result resemble them, FamFrame performs automated face processing on the photos in a frame’s cast: it detects faces, computes a numerical “face signature” (a facial-geometry embedding) for each person, and uses it to match and blend that person’s likeness into the image. These face signatures are a form of biometric data. We use them only to make and improve your frames - never to identify strangers, and never for advertising or profiling.

To be precise about what this is and is not: the processing is “one-to-one” - we match and blend a person’s likeness within your own frames. We do not run “one-to-many” facial recognition to identify a person against any external database or watch-list, and we do not use your photos or face signatures to train general-purpose or foundation AI models. Our schedule for retaining and destroying this biometric data is set out in “How long we keep it” and section 9, and serves as our publicly available written retention-and-destruction policy for the purposes of the Illinois Biometric Information Privacy Act.

The photos themselves are stored for display in your tree and for the cast you choose when you make a frame. By uploading a photo of another person you confirm that you have the right to do so and, where the law requires it, that you have their consent to this face processing, including any written release that a biometric-privacy law requires, and - if the person is a child - the consent of their parent or guardian. If you are the subject of a photo on FamFrame and want it removed, write to admin@thebaio.com and we will remove it.

4. Why we use your data and our legal basis

Under the GDPR we must have a legal basis to process your data. Under Israeli law we must use the data only for the purpose for which it was collected and as reasonably understood from the circumstances. Here is how that breaks down for FamFrame:

What we do with itGDPR legal basis
Create your account, sign you in, run the app, store and display the people and photos you save, deliver the frames you make.Performance of a contract
Detect faces, compute a per-person face signature (facial-geometry embedding), and use it to match and blend each person’s likeness into a frame (see “A note on photos and faces”).Your explicit consent for special-category biometric data (Art. 9(2)(a)), given when you upload photos for face processing. You can withdraw it at any time (see “How long we keep it”).
Process payment for frame credits and keep tax records.Contract (Art. 6(1)(b)) and compliance with a legal obligation under Israeli tax law (Art. 6(1)(c)).
Keep the service secure, detect abuse, prevent fraud, and debug problems.Our legitimate interests in operating a safe service (Art. 6(1)(f)).
Send you transactional email (magic-link sign-in, receipts, important account notices).Contract (Art. 6(1)(b)).
Record limited first-party product milestones, and load the Meta Pixel and Google Ads conversion tag, to understand where people get stuck and measure how the site and advertising are used.Your consent, given through the cookie banner (Art. 6(1)(a) and ePrivacy Directive Art. 5(3)). You may withdraw consent at any time.
Respond to legal requests, defend legal claims, comply with court orders.Legal obligation and our legitimate interests (Arts. 6(1)(c) and 6(1)(f)).

We do not carry out any solely-automated decision-making that produces legal or similarly significant effects about you within the meaning of Article 22 of the GDPR. And, to repeat the point because it matters: we do not use your photos or face data to train general-purpose AI models for us or for anyone else.

FamFrame uses automated AI models to create and edit the frames you request from the photos you provide.

5. Who we share it with

We do not sell your data. We do not share it for advertising other than the limited Meta Pixel and Google Ads signals described above (and only if you have consented). Our first-party product events stay in the same hosted database used to operate FamFrame and are not sent to another analytics provider. We use a small set of trusted service providers (“processors”) to actually run the product. Each is bound by a data-processing agreement and is listed below.

ProviderWhat it doesWhere
Amazon Web Services (AWS S3)Stores uploaded photos and frame images.United States / EU (see note below).
fal.ai (Features & Labels, Inc.)Runs the image-making models: composes a frame from the photos in your chosen cast and upscales finished frames. Receives those photos.United States.
RunPod, Inc.Runs the face-refinement step: detects and matches faces and blends each person’s likeness into the frame, computing the face signatures described in “A note on photos and faces.” Receives photos and face crops.United States.
BrevoSends transactional email, including magic sign-in links.France (EU).
Google LLCOAuth sign-in (only if you choose “continue with Google”). Google sees your sign-in event; we receive your Google email, name, and profile image.United States.
LemonSqueezyProcesses frame-credit purchases as merchant of record.United States.
Meta Platforms, Inc. (Pixel)Receives page-view and conversion events only if you accept analytics cookies.United States / Ireland.
RenderHosts the FamFrame application and the Postgres database that stores your account and tree.United States.
Sentry (Functional Software, Inc.)Error monitoring: receives technical reports when something in the app breaks. Reports are scrubbed - no email addresses, photos, or photo links - and IP addresses are not collected.United States.
Google LLC (Google Ads)Receives page-view and conversion events only if you accept analytics cookies.United States / EU.

We may also disclose data when required by a binding legal request, to enforce our Terms of Service, or to protect the rights, safety, or property of FamFrame or others. If FamFrame is ever transferred to a new operator (acquisition, restructuring), we will tell you before your data is transferred and you will have a reasonable opportunity to delete your account first.

6. International transfers

FamFrame is operated from Israel. The European Commission has formally recognised Israel as providing an adequate level of data protection, so personal data may flow freely from the EU/EEA to FamFrame on that basis. This adequacy recognition is subject to periodic review by the European Commission; if it were to change, we would put alternative safeguards (such as Standard Contractual Clauses) in place.

Several of our processors are based in the United States. We rely on the EU-US Data Privacy Framework where the provider is certified, on the Standard Contractual Clauses approved by the European Commission, or on the equivalent UK and Swiss safeguards. These safeguards also cover the onward transfer of your data from Israel to those US processors. You can ask us for a copy of the safeguards in place by writing to admin@thebaio.com.

7. How long we keep it

  • Account, tree, photos, and frames: for as long as your account is active. If you delete your account, we delete your account and related data from the active database. Limited residual copies may remain temporarily in backups or restricted technical storage, except where we are required to keep data longer.
  • Face signatures: the facial-geometry embeddings we derive for a person, including per-photo embeddings and a per-person matching centroid, are deleted when you delete that person or your account. They are not kept separately from the photos they were derived from, except for limited residual copies in routine backups for the period described below.
  • Payment records and invoices: we keep transaction records for the period required by Israeli tax law, which is generally seven (7) years.
  • Server logs and security data: hosting runtime logs are generally kept for no longer than 30 days. Error-monitoring and security-incident records may be kept longer where reasonably necessary to investigate an incident, protect the service, establish or defend legal claims, or comply with law.
  • First-party product analytics: consented milestone events are automatically deleted after 90 days.
  • Backups: our hosted database backups are retained for a rolling window (currently up to 30 days) and then overwritten.

In every case, a person’s face signature is permanently destroyed at the earliest of: when you delete that person or your account, when the purpose for which it was collected is satisfied, or three (3) years after your last interaction with us. Together with “A note on photos and faces”, this is the written retention-and-destruction schedule required by the Illinois BIPA.

8. Cookies and similar technologies

FamFrame uses two categories of cookies and local-storage entries.

  • Essential. A database-backed NextAuth session cookie that keeps you logged in, a CSRF token, and a small localStorage entry that records your cookie-banner choice so we do not ask again. These are always on; the site cannot run without them.
  • Analytics & marketing. A 30-minute first-party analytics session stored in localStorage, the Meta (Facebook) Pixel, the Google Ads conversion tag, and related cookies are only used if you accept the analytics category in the cookie banner. You can change your mind at any time from the “cookie preferences” link in the footer.

9. Your rights

Wherever you live, you can write to admin@thebaio.com to ask about, correct, or delete your data. If we cannot do what you ask we will explain why.

If you are in the EU/EEA or the UK, the GDPR gives you the right to: access the personal data we hold about you and receive a copy of it; ask us to correct inaccurate data; ask us to delete your data (“right to be forgotten”); ask us to restrict how we use it; receive your data in a portable, machine-readable format; object to processing that we base on our legitimate interests; withdraw any consent you have given (which does not affect processing that already happened on the basis of that consent); and lodge a complaint with your national supervisory authority.

If you are in Israel, the Privacy Protection Law (as amended) gives you the right to inspect the data we hold about you, to ask for it to be corrected or deleted, and to complain to the Israeli Privacy Protection Authority.

If you are in Illinois or Texas (biometric laws). The face signatures described in “A note on photos and faces” are biometric identifiers/information under the Illinois Biometric Information Privacy Act (BIPA) and the Texas Capture or Use of Biometric Identifier Act (CUBI). We collect and use them only to make and improve your frames, with your consent; we do not sell, lease, trade, or otherwise profit from biometric data; and we permanently destroy a person’s face signature when you delete that person or your account, when the purpose for which it was collected has been satisfied, or within three (3) years of your last interaction with us - whichever occurs first.

10. Security

Connections to FamFrame are encrypted with TLS. Photos and frame images are stored encrypted at rest in AWS S3. Passwords are not used - sign-in is by magic link or Google OAuth, and session tokens are stored in our database and expire automatically. Access to the production database is limited to the operator and protected by individual credentials. No system is perfectly secure; if we discover a breach that affects you, we will notify you in accordance with Israeli law and Article 33 of the GDPR, and, where the Protection of Privacy (Data Security) Regulations, 2017 apply, we will report a serious security incident to the Israeli Privacy Protection Authority as those regulations require.

11. Children

FamFrame is for people aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has created an account, write to admin@thebaio.com and we will delete it. If you upload a photograph of a child as part of your family tree, you confirm that you are entitled to do so, and that you are the child’s parent or guardian - or have their consent - for the automated face processing described above. We do not knowingly create a face signature of a child under 13 without verifiable parental consent; the child or their guardian can ask us to remove it at any time using the same address.

12. Changes to this policy

If we make a material change to this policy - adding a new processor, changing the legal bases, adopting new tracking - we will update the effective date at the top and, when the change is significant, give you notice in the app or by email before the change takes effect. Continuing to use FamFrame after the change means you accept the updated policy. Where a change materially affects how we process your biometric data, we will ask for your renewed explicit consent rather than rely on your continued use.

13. How to complain

We hope you will always come to us first at admin@thebaio.com so any problem can be solved.


This page is the privacy policy. The companion document - what you can and cannot do with the service, and what we will and will not do for you - is the Terms of Service.

FamFrame · a small studio for family pictures
family frame·contact·privacy·terms·