Trust & data

Privacy, without guesswork.

This notice explains what FrameFetch processes when you use the public website, create an account, pay for Lifetime Pro, or connect the local companion.

Last updated 23 July 2026 Operator: Ke Wang Contact: keke19870699@gmail.com

Plain-language summary

1. Who is responsible

FrameFetch is operated by Ke Wang. For privacy questions, account deletion requests or rights requests, email keke19870699@gmail.com.

This notice covers the public FrameFetch website at framefetch-web.onrender.com and the official FrameFetch Companion for Windows and macOS.

2. Data we process

Account data

Display name, email address, a one-way password hash, account creation time, Pro entitlement and internal account identifiers.

Payment data

Stripe customer and checkout identifiers, payment status and the entitlement purchased. Stripe receives the card and billing data entered in its checkout.

Download-job data

Source URL, requested quality, job status, output title, cloud storage key, bounded error text, timestamps and the associated user or guest identifier.

Technical data

Network and request metadata needed for hosting and security. The application creates a secret-keyed hash from a guest IP address to enforce the guest allowance without storing that address in the download table.

Do not submit confidential, private, credential-bearing or sensitive-media URLs. FrameFetch rejects URLs containing embedded usernames or passwords and blocks private-network destinations, but a submitted public source URL is still part of the service record.

3. What the local companion does

FrameFetch Companion runs on 127.0.0.1:18765 and performs extraction and download work on your computer using yt-dlp and FFmpeg. Its normal workflow is:

  1. The public website requests a short-lived, single-use authorisation ticket from FrameFetch.
  2. The companion exchanges that ticket for the authorised source URL, quality and maximum permitted resolution.
  3. The companion contacts the source website and saves the resulting media and selected sidecar files into your chosen folder.

Your downloaded media file is not uploaded to FrameFetch when using the companion. The public service still receives entitlement and quota records, and the source website receives the network requests made by yt-dlp.

Browser-cookie access is optional and off by default. If you deliberately select a supported browser, yt-dlp reads those cookies locally to contact the source website. FrameFetch does not automatically read browser cookies and the companion does not send those cookie values to the FrameFetch public service.

Active companion task status and recent logs are held in local process memory. Optional features may write an archive, subtitles, thumbnails, descriptions or info.json beside your download. Those files remain on your computer until you delete them.

4. Why we use data

Provide the service
Create accounts, inspect URLs, run downloads, deliver temporary links and connect the official companion.
Manage entitlements
Apply the guest allowance, three-download free-member trial and Pro allowance of 100 downloads per 24 hours.
Process payment
Create a CNY ¥18.90 Stripe checkout and activate Lifetime Pro after verified payment confirmation.
Protect the service
Prevent abuse, validate public URLs, rate-limit inspection, investigate failures and secure account sessions.
Support users
Respond to support, refund, privacy, copyright and acceptable-use enquiries.

Depending on the context, the legal basis may be performance of a contract, legitimate interests in operating and securing FrameFetch, compliance with legal obligations, or consent where the law requires it.

5. Service providers and international transfers

FrameFetch may disclose limited data to providers that perform necessary functions:

  • Render for application hosting and operational network logs.
  • Database and Redis services for accounts, job state, quotas and short-lived companion tickets.
  • Cloudflare R2 or compatible object storage for cloud-generated media objects.
  • Stripe for checkout, payment processing, receipts, fraud controls and payment records.
  • Source websites that receive requests required to inspect or retrieve the URL you supplied.
  • Professional advisers, courts, regulators or law enforcement where disclosure is legally required.

Some providers may process data outside the United Kingdom. Where required, FrameFetch relies on the provider’s lawful transfer mechanism and contractual safeguards.

6. Cookies and browser storage

  • framefetch_session is an essential, signed, HTTP-only account-session cookie with a maximum age of 30 days. In production it is marked Secure and SameSite=Lax.
  • framefetch-language is stored in browser local storage to remember the selected language.
  • The current FrameFetch application does not intentionally set advertising cookies. Stripe, the hosting provider or a source website may apply their own cookies under their own notices.

7. Retention

Account and payment-entitlement records are retained while the account is active and afterwards where reasonably needed for payment records, disputes, security and legal compliance. Download records may be retained to enforce allowances, diagnose jobs and prevent abuse.

Cloud download links expire after one hour. The expiry controls access to the signed link; it does not itself guarantee immediate deletion of the object or associated job record. Cloud objects and operational records are retained only as long as reasonably necessary for delivery, reliability, abuse prevention and operational cleanup.

To request account or personal-data deletion, email the contact address above. Some payment, fraud-prevention or legal records may need to be retained after deletion.

8. Your data-protection rights

Subject to applicable law and exceptions, you may ask to access, correct, erase, restrict or port your personal data, or object to certain processing. You may also complain to the UK Information Commissioner’s Office.

Send requests to keke19870699@gmail.com. FrameFetch may ask for proportionate information to verify that the request concerns your account.

Never email a password, full payment-card number, browser-cookie export or private media file. A support request normally needs only your account email, operating system, approximate event time and the exact on-screen error.