1. Scope
This Privacy Policy explains how [LEGAL ENTITY NAME], doing business as DropFrame and Momentous ("DropFrame," "we," "us"), collects, uses, shares and protects personal information when you visit dropframe.ai, purchase or use a membership, install a Drop, connect the DropFrame Connection to an AI client, or take part in The Lab (together, the "Service"). It also describes the choices and rights you have. Capitalized terms not defined here have the meaning given in our Terms of Service.
We act as a controller (or "business" under California law) for account, billing, marketing and usage data, and as a processor (or "service provider") for the content you submit to the Drops on behalf of your business and your clients, which we handle only on your instructions.
2. Information we collect
2.1 Information you give us
- Account and membership: name, email, company, role, plan, seat assignments and community profile, collected through our community platform.
- Billing: handled by our payment processor. We receive your name, email, plan, billing status, the last four digits and brand of your card and the billing country. We never receive or store full card numbers.
- Your Content: briefs, treatments, voice samples, rate cards, line items, crew and cast contacts, client names and contacts, schedules, actuals, onboarding documents, uploads and anything else you send through a Drop or the DropFrame Connection. This may include personal information about your clients, crew and talent, which you are responsible for having the right to share with us.
- Communications and community: support emails, survey answers, votes, posts, comments and office-hour participation in The Lab.
2.2 Information collected automatically
- Connection and usage logs: which Drops and tools you call, timestamps, request metadata, error logs, render counts and the AI client type (for example, that a request came from a Claude or ChatGPT client). We log tool calls to operate, secure and meter the Service.
- Device and site data: IP address, browser and device type, pages viewed, referrer and approximate location derived from IP, collected through server logs and the cookies described in Section 9.
2.3 Information from third parties
Our community platform and payment processor send us membership and payment status so we can turn your access on and off. If you connect a third-party tool (for example a budgeting, scheduling or storage app) we receive the data you choose to import.
2.4 Your AI client is not us
When you use a Drop, your prompts and the results are processed by the AI client and model provider you chose (Claude, ChatGPT, Cursor, Grok or another). Those providers receive that data under their own privacy terms, which you should review. The DropFrame Connection receives only the data the Drop sends to our tools, such as the brief to render or the line items to price.
3. How we use information
- To provide, operate, secure and support the Service, including verifying your entitlement, rendering documents, storing your job records and running The Lab.
- To process payments, manage renewals and send transactional messages (receipts, renewal reminders, security notices, changes to terms).
- To improve the Service, develop new Drops and produce aggregated, de-identified benchmarks that cannot reasonably be linked to you or your clients.
- To send product news, drop announcements and marketing you can opt out of at any time (Section 8).
- To prevent fraud, abuse and violations of our policies, and to comply with law.
We do not sell your personal information, we do not "share" it for cross-context behavioral advertising, and we do not use Your Content or Outputs to train machine-learning models.
Legal bases (EEA, UK and similar jurisdictions)
We process personal information to perform our contract with you (providing the Service), for our legitimate interests (securing and improving the Service, communicating with customers) balanced against your rights, to comply with legal obligations, and with your consent where required (for example, non-essential cookies and certain marketing). You may withdraw consent at any time.
4. How we share information
We share personal information only with:
- Subprocessors and service providers who help us run the Service under written contracts that limit their use of the data to our instructions (Section 5).
- Other members of The Lab, to the extent you post content there.
- Your organization, if you use a seat on a Studio or Agency plan; the plan administrator can see seat assignments and shared job records.
- Professional advisers, authorities and others when required by law, legal process or to protect rights, safety or the integrity of the Service.
- A successor in a merger, acquisition, financing or sale of assets, subject to this policy.
5. Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Heartbeat (Heartbeat Chat, Inc.) | Community platform, membership and billing front end | United States |
| Stripe, Inc. | Payment processing | United States |
| Vercel, Inc. | Website hosting | United States |
| Cloudflare, Inc. | DNS, network security | United States |
| [Hosting / database provider for the DropFrame Connection] | Server hosting, job-record storage, backups | [Region] |
| [Email provider] | Transactional and marketing email | [Region] |
| [Analytics provider, if any] | Privacy-respecting site analytics | [Region] |
We will update this list when subprocessors change and, for customers on a data processing agreement, give notice as that agreement provides.
6. Retention
- Job records and Your Content: for as long as your subscription is active, plus a 30-day export window after cancellation, after which they are deleted from production systems. Encrypted backups are purged on a rolling basis within 90 days.
- Account and billing records: for the life of the account and up to 7 years afterward for tax, accounting and dispute purposes.
- Usage and security logs: typically 12 months, longer if needed for an investigation.
- Marketing data: until you unsubscribe or 2 years of inactivity.
You can delete individual job records at any time from within the Service or by asking us.
7. Security
We use administrative, technical and physical safeguards appropriate to the sensitivity of the data, including encryption in transit (TLS) and at rest, access controls and least-privilege access, authenticated and metered API access, logging, and vendor review. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you and any regulator as required by law, including Nevada NRS 603A and, where applicable, the GDPR and UK GDPR.
8. Your rights and choices
8.1 Everyone
You can access and update your account details through the community platform, unsubscribe from marketing using the link in any email (transactional messages continue), export your job records, delete job records, and cancel your membership. Email privacy@dropframe.ai for anything you cannot do yourself.
8.2 California (CCPA/CPRA)
California residents have the right to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of sale or sharing (we do neither); to limit use of sensitive personal information (we do not use it for purposes requiring that right); and not to be discriminated against for exercising rights. In the past 12 months we have collected the categories listed in Section 2 (identifiers, commercial information, internet activity, professional information, and the content you submit) for the purposes in Section 3, and disclosed them to the service providers in Section 5. We honor Global Privacy Control signals. Submit requests to privacy@dropframe.ai; we will verify your identity through the account email and respond within 45 days. You may use an authorized agent with written permission.
8.3 Nevada
Nevada residents may direct us not to sell covered information. We do not sell it; you may still submit a request to privacy@dropframe.ai.
8.4 EEA, UK and Switzerland
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent and to lodge a complaint with your supervisory authority. Contact privacy@dropframe.ai. Where we transfer data outside your region we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful mechanism.
8.5 Other U.S. states
Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and others) have similar rights of access, correction, deletion, portability and opt-out, and may appeal a decision by replying to our response. We will handle those requests as described above.
9. Cookies and similar technologies
dropframe.ai uses strictly necessary cookies and local storage for things like remembering a tab or preference, and, if we enable analytics, privacy-respecting analytics that do not build cross-site profiles. We do not use advertising cookies. Our community and payment platforms set their own cookies when you use them. You can control cookies in your browser; blocking essential cookies may affect the Service. We honor Global Privacy Control; we do not currently respond to other "Do Not Track" signals because no common standard exists.
10. Data processing agreement for business customers
If you submit personal information about your clients, crew or talent and need a data processing agreement under GDPR, UK GDPR or U.S. state law, email privacy@dropframe.ai and we will provide our standard DPA, which incorporates this policy, the subprocessor list and Standard Contractual Clauses where required.
11. Children
The Service is for adults running businesses. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
12. International users
We are based in the United States and process information there and in the locations of our subprocessors. By using the Service you understand your information may be transferred to and processed in the United States, which may have different data-protection laws from your country.
13. Changes
We may update this policy. Material changes will be announced by email or in the Service at least 14 days before they take effect; the "Last updated" date shows the current version.
14. Contact
[LEGAL ENTITY NAME] (DropFrame / Momentous)
[MAILING ADDRESS], Las Vegas, Nevada [ZIP]
Privacy requests: privacy@dropframe.ai