1. Who is responsible
FrameFetch is operated by Ke Wang. For privacy questions, account deletion requests or rights requests, email keke19870699@gmail.com.
This notice covers the public FrameFetch website at framefetch-web.onrender.com and the official FrameFetch Companion for Windows and macOS.
2. Data we process
Account data
Display name, email address, a one-way password hash, account creation time, Pro entitlement and internal account identifiers.
Payment data
Stripe customer and checkout identifiers, payment status and the entitlement purchased. Stripe receives the card and billing data entered in its checkout.
Download-job data
Source URL, requested quality, job status, output title, cloud storage key, bounded error text, timestamps and the associated user or guest identifier.
Technical data
Network and request metadata needed for hosting and security. The application creates a secret-keyed hash from a guest IP address to enforce the guest allowance without storing that address in the download table.
Do not submit confidential, private, credential-bearing or sensitive-media URLs. FrameFetch rejects URLs containing embedded usernames or passwords and blocks private-network destinations, but a submitted public source URL is still part of the service record.
3. What the local companion does
FrameFetch Companion runs on 127.0.0.1:18765 and performs extraction and download work on your computer using yt-dlp and FFmpeg. Its normal workflow is:
- The public website requests a short-lived, single-use authorisation ticket from FrameFetch.
- The companion exchanges that ticket for the authorised source URL, quality and maximum permitted resolution.
- The companion contacts the source website and saves the resulting media and selected sidecar files into your chosen folder.
Your downloaded media file is not uploaded to FrameFetch when using the companion. The public service still receives entitlement and quota records, and the source website receives the network requests made by yt-dlp.
Browser-cookie access is optional and off by default. If you deliberately select a supported browser, yt-dlp reads those cookies locally to contact the source website. FrameFetch does not automatically read browser cookies and the companion does not send those cookie values to the FrameFetch public service.
Active companion task status and recent logs are held in local process memory. Optional features may write an archive, subtitles, thumbnails, descriptions or info.json beside your download. Those files remain on your computer until you delete them.
4. Why we use data
- Provide the service
- Create accounts, inspect URLs, run downloads, deliver temporary links and connect the official companion.
- Manage entitlements
- Apply the guest allowance, three-download free-member trial and Pro allowance of 100 downloads per 24 hours.
- Process payment
- Create a CNY ¥18.90 Stripe checkout and activate Lifetime Pro after verified payment confirmation.
- Protect the service
- Prevent abuse, validate public URLs, rate-limit inspection, investigate failures and secure account sessions.
- Support users
- Respond to support, refund, privacy, copyright and acceptable-use enquiries.
Depending on the context, the legal basis may be performance of a contract, legitimate interests in operating and securing FrameFetch, compliance with legal obligations, or consent where the law requires it.
7. Retention
Account and payment-entitlement records are retained while the account is active and afterwards where reasonably needed for payment records, disputes, security and legal compliance. Download records may be retained to enforce allowances, diagnose jobs and prevent abuse.
Cloud download links expire after one hour. The expiry controls access to the signed link; it does not itself guarantee immediate deletion of the object or associated job record. Cloud objects and operational records are retained only as long as reasonably necessary for delivery, reliability, abuse prevention and operational cleanup.
To request account or personal-data deletion, email the contact address above. Some payment, fraud-prevention or legal records may need to be retained after deletion.
8. Your data-protection rights
Subject to applicable law and exceptions, you may ask to access, correct, erase, restrict or port your personal data, or object to certain processing. You may also complain to the UK Information Commissioner’s Office.
Send requests to keke19870699@gmail.com. FrameFetch may ask for proportionate information to verify that the request concerns your account.
Never email a password, full payment-card number, browser-cookie export or private media file. A support request normally needs only your account email, operating system, approximate event time and the exact on-screen error.