Privacy Policy
Last updated: 1 August 2026
SC NEVERBOTS SRL is the data controller for personal data collected through FrameCraft. This page explains exactly what we hold and why. It is short because we hold very little.
Your videos are not collected
FrameCraft runs on your own computer. Your footage, audio, subtitles and projects stay there. They are never uploaded to us and we have no way to reach them.
Subtitles never leave your machine at all. Speech to text runs locally, so your audio is not sent anywhere for transcription.
Some features do call an outside service, using an API key you create and enter: B-roll and its keywords, sticker and emoji suggestions, music suggestions and AI voices send the necessary text to OpenRouter, and stock searches go to Pexels and Freesound. Those requests go directly from your computer to that provider under your own account. They never pass through us, we cannot see them, and we hold no record of them.
What we do store
- Your email address: to send your licence key and to let you recover it later.
- Your licence key and whether it is active or revoked.
- A device fingerprint: a one-way SHA-256 hash calculated on your own machine from hardware identifiers, plus a device name such as “Windows DESKTOP-ABC”. It exists only to enforce the limit of one computer at a time. It cannot be reversed and tells us nothing about what is on your computer.
- A payment reference from Stripe, so a purchase can be matched to a licence.
We never see or store your card details. Stripe handles payment entirely and we receive only a reference and the result.
Why we are allowed to hold it
To perform the contract you entered when you bought a licence: issuing your key, letting you activate it, and letting you recover it. We do not use your address for marketing and we do not sell or share data with anyone for their own purposes.
Analytics and advertising measurement rest on a different basis: your consent, given on the cookie banner and withdrawable at any time. Nothing about your purchase or your licence depends on it.
Who processes it for us
- Stripe: payment processing.
- Brevo: sending your licence key and sign-in links.
- Cloudflare: serving this website.
- Google Analytics: visitor statistics, only if you accept the cookie banner.
- Meta (Facebook and Instagram): measuring which of our adverts lead to a purchase, only if you accept the cookie banner. Meta is a joint controller for this, not our processor.
- TikTok: the same measurement for adverts on TikTok, and on the same condition. TikTok is likewise a joint controller, not our processor.
- Our server in the EU, where the licence database is held.
Cookies, analytics and advertising
We use Google Analytics to see how many people visit and which pages they read, and the Meta and TikTok pixels to see whether an advert we paid for led to a sale. All of them are switched off by default: nothing is loaded and no cookie is set until you press Accept on the banner. Decline and they all stay off, with no loss of functionality. You can change your mind at any time by clearing this site’s data in your browser, which removes the stored choice and brings the banner back.
If you accept, Google receives your IP address, the pages you view and basic device information, acting as our processor.
If you accept, Meta and TikTok each receive two events: one when you open the checkout page (Meta calls it Lead, TikTok calls it InitiateCheckout) and a Purchase when a payment succeeds. Each carries your IP address, your browser type, the identifiers that platform sets itself (_fbp and _fbc for Meta, _ttp and the click id from an advert link for TikTok), and for a purchase the amount paid.
These events are sent twice, once from your browser and once from our server through Meta’s Conversions API and TikTok’s Events API, and each platform merges its pair into a single event. The server copy exists because browsers increasingly block the first one. It is sent from the payment confirmation, so for a purchase it also includes your email address, first name, surname, city and country, hashed with SHA-256 before they leave our server. The platforms compare those hashes against their own; they never receive the plain values. To make the server copy possible, those advert identifiers from your browser are stored alongside the payment record at Stripe.
If you press Decline, none of this happens, including the server side: your choice is recorded with the payment, and the confirmation code checks it before reporting anything. Buying is never conditional on accepting.
Aside from those, the only cookies are functional: a short-lived sign-in cookie when you open your licence page, and an administrator session cookie that applies to us, not to you.
The editor itself contains no analytics or advertising code at all. They exist only on this website. The copy of FrameCraft installed on your computer loads nothing from Google, Meta or TikTok and reports nothing to anyone. This is not a setting you have to trust us about: the identifiers those scripts need are only compiled into the build that runs this website, so there is nothing in your copy for them to attach to.
How long we keep it
For as long as your licence exists, since it is what makes your licence work. Sign-in links expire shortly after they are issued. Records connected to a payment are kept as long as accounting law requires.
Your rights
You can ask for a copy of your data, correction of it, or its deletion. Email [email protected] and we will respond within 30 days. Deleting your data means deleting your licence, so it will stop working, so we will say so before doing it.
If you are unhappy with how we handle your data you can complain to the Romanian data protection authority, ANSPDCP.
Seller
SC NEVERBOTS SRL
CUI: 52184682
ONRC: ROONRC.J2025053476008
B-dul Mihai Viteazu, Nr. 28, Ap. 5A, Municipiul Timișoara, Județul Timiș, România