Framewalk

← Framewalk

GDPR Compliance

Last updated: July 19, 2026

This page summarizes how Framewalk handles personal data under the General Data Protection Regulation (GDPR) for users in the European Economic Area, the UK, and similar jurisdictions. It supplements our Privacy Policy.

1. Data controller

nheek (operating Framewalk) is the data controller for personal data collected through the Service.

For GDPR-related inquiries: [email protected].

2. Your rights

Under GDPR, you may have the following rights (subject to conditions and exceptions in law):

  • Right of access — request a copy of your personal data (Settings → Your data → Download my data in the app, or contact us). We prepare the export in the background and notify you when the download is ready.
  • Right to rectification — correct inaccurate or incomplete data (edit profile and hunt/post details in-app, or contact us).
  • Right to erasure — delete your account in Settings → Your data → Delete account, or contact [email protected]; you can also stop using Sign in with Apple for Framewalk in your Apple ID settings.
  • Right to restriction — ask us to limit certain processing.
  • Right to data portability — request a ZIP export (account data + your frame photos) from Settings → Your data → Download my data (background prepare + download when ready), or via [email protected].
  • Right to object — object to processing based on legitimate interests where applicable.
  • Right to withdraw consent — where we rely on consent (for example push alerts, camera/library access, or location when you enable a trail), you can turn it off in device or app settings without affecting prior lawful processing.

You may also lodge a complaint with your local data protection supervisory authority.

3. Legal basis for processing

We process personal data on one or more of these grounds:

  • Contract — to provide the Service you signed up for (account, hunts, frames, feeds, follows, likes, reposts, subscriptions).
  • Legitimate interests — to secure the Service, prevent abuse (including report, block, automated prompt safety, bans, and appeals), improve the product, and communicate important service notices, balanced against your rights.
  • Consent — where required (for example push notifications, camera/photo library, or optional GPS trails).
  • Legal obligation — where we must retain or disclose data to comply with law.

4. What we collect (summary)

See the Privacy Policy for detail. Categories include account and profile data (including preferred app language); Sign in with Apple identifiers and first-sign-in email/name; photos and hunt drafts you create; prompts and theme links (including stored embeddings used for similarity matching when AI is configured); optional GPS trails and map settings; social activity (follows, likes, reposts, notifications, reports, blocks); moderation records (prompt flags, bans, appeals); payment metadata from app stores; device and session data; push tokens if enabled; support messages; and, when you use Translate, caption or prompt text sent for optional machine translation (with cached results).

5. Cookies and similar technologies

On the website, we use essential cookies and storage for session login and security when applicable. The marketing site may also use local storage for appearance (for example light/dark preference).

On mobile apps, we use secure storage for login sessions and preferences. Push notifications require a device token if you opt in. Camera, photo library, and location are requested only for features you use (capturing frames, attaching media, recording a trail). Map tiles are rendered by Apple or Google on your device.

6. Processors and international transfers

We use trusted service providers (hosting, object storage, app store billing, push delivery, Sign in with Apple when you choose it, map tile providers when you open a trail map, and optional AI providers for prompt generation/moderation, theme similarity embeddings, and optional on-demand UGC translation) who process data on our instructions. Where data is transferred outside the EEA/UK, we use appropriate safeguards such as standard contractual clauses where required.

We do not sell your personal data.

7. Retention

We retain data while your account is active and for a limited period afterward for backups, security, or legal compliance. Discarded hunts are purged after the plan retention window described in-product (7 / 30 / 90 days). Access, deletion, and portability requests: [email protected].

8. Data breach notifications

If a personal data breach is likely to result in risk to your rights and freedoms, we will notify affected users and relevant authorities as required by GDPR, typically within 72 hours of becoming aware where feasible.

9. Contact

For GDPR requests or questions: [email protected].