1. Scope
This Schedule governs Frameleaf’s commercial Services under the Master Terms. It distinguishes managed Cloud data from information on your independently operated Library, customer-provided storage or Buddy Backup peer. The Backup Agreement explains each destination’s encryption and recovery model. The DPA supplies additional duties for processing on an organization’s behalf.
Calendar days apply unless stated otherwise. A maximum retention period does not promise that a temporary file remains downloadable until its last day. Ending access, requesting deletion, starting erasure and completing storage removal are different events.
2. Security and shared responsibility
Frameleaf will maintain reasonable safeguards appropriate to the data and processing, including restricted administrative access, strong authentication, confidentiality obligations, audit records, tenant access controls, protected service credentials, encrypted transport, vulnerability handling, controlled changes and incident response. Staff access is limited to authorized functions and is not permission to browse private customer media. A supplier’s certification does not certify the complete Frameleaf service.
You maintain your server, devices, administrators, source files, network and customer-held secrets. Keep supported software, independent recovery material and appropriate permissions. A Library administrator may access local plaintext and locally stored keys regardless of a hidden-photo label or interface PIN. Frameleaf remains responsible for safeguards and service commitments within its own control.
3. Encryption boundaries
Cloud Backup uses storage-provider SSE-C encryption. The Library supplies the usable key over HTTPS to the storage endpoint when performing content operations. The Frameleaf Cloud coordination service does not receive that key in the ordinary protocol. Optional server-key escrow contains a passphrase-wrapped envelope and requires the customer’s recovery secret. The storage processor performs the encryption and decryption; this is not a claim that it never receives plaintext or the usable key.
Buddy Backup encrypts blocks and recovery metadata at the source before transfer to a peer. Cloud coordinates access and may retain an encrypted escrow envelope, but its ordinary protocol does not receive readable backup contents or usable vault keys.
Remote-access relay forwards the TLS session to the Library without decrypting its application payload. Cloud sign-in, billing, API and AI services have separate processing boundaries. Cloud AI receives readable selected inputs at the processing system. Enabling relay or backup is not AI consent.
4. Managed backup retention
During active service, the Library’s selected manifest-retention policy governs its recovery points. The default selects the newest point and the newest available points from seven daily, four weekly and twelve monthly periods. These are selections from completed runs, not a promise that every period contains a run. Required objects remain while referenced by retained manifests. The managed-storage cleanup removes object versions that have been noncurrent for more than 30 days; that is distinct from manifest history.
An ordinary owner unlink, explicit backup deletion request, lapse of the backup entitlement or commencement of account erasure starts a 30-day whole-bucket deletion hold. Storage becomes read-only or frozen. Unlinking revokes credentials, so recovery may require relinking or authorized support assistance. Data retention alone does not establish an accessible restore route.
After that hold, purge may begin. Final managed-bucket removal is scheduled within 90 days of the original trigger, not 90 days after the hold. Purge covers object versions, bucket access and related escrow. A routine reminder is sent seven days before the hold ends where an account contact remains available. This does not promise indefinite retrieval, preservation of already expired versions, or an automatic extension for a pending restore.
An ordinary account closure or staff suspension freezes managed backup access without scheduling whole-bucket deletion solely because of that event. Closure can be reversed only through support. Ordinary version cleanup remains separate. A specific lawful preservation requirement or approved preservation hold can delay removal; Section 8 applies.
Customer-provided storage and Buddy peer disks follow their own administrator-controlled lifecycle. Frameleaf cannot certify physical deletion from an independent system merely by revoking Cloud coordination access.
5. Other retention periods
| Information | Retention and treatment |
|---|---|
| Account export download | Temporary artifact, removed within 24 hours of generation. Download and retain your copy promptly. |
| AI processing containers, uploaded content and container-local working data | Content is uploaded directly to an ephemeral worker and deleted immediately when the job finishes; the container is destroyed. There are no retained stopped containers or separate post-job upload archives. The destroyed container and uploaded content cannot be recovered through the service. This is not a 24-hour retention window. |
| AI results delivered to the Library | Follow the receiving Library’s lifecycle. Worker destruction does not delete a result already delivered to customer-controlled storage. Non-content job and billing records follow the separate categories below. |
| Relay payload | Transient in-memory transport buffers, not a persistent photo archive. Session payloads are not retained for ordinary analytics. |
| Ordinary application and infrastructure logs | 30 days. Logs are intended to contain operational identifiers and measurements, not private media, prompts or keys. |
| Distributed traces | 7 days. |
| Audit events | 400 days from the event, then account, address, event detail and specific actor identifiers are removed from the audit row; action, actor category and time remain for operational history. This does not erase separate financial or case records. |
| Backup run telemetry | 90 days; this is distinct from stored recovery points. |
| Hourly backup usage samples | 35 days; daily and billing-period measurements needed for charges remain with the financial records. |
| Wallet statements | Seven years after the statement period, subject to an applicable legal preservation requirement. |
| Financial, subscription, wallet and payment records | Retained for applicable tax, accounting, payment-dispute and legal obligations. Unresolved transactions and usable balances require continuing records. These records do not require retention of underlying AI media. |
| Support, security investigations, abuse cases and legal correspondence | Retained while necessary for the specific request, investigation, legal duty or claim. Sensitive attachments are limited to the necessary scope and removed when their purpose ends. |
| Certificates, public hostname records and security observations | Retained as needed for certificate and routing security. Public DNS or Certificate Transparency records can remain outside Frameleaf’s control. |
A result delivered to your Library follows that Library’s lifecycle. A file separately captured in a backup follows the applicable backup lifecycle. The Cloud AI purge does not delete either customer-controlled copy.
6. Account closure
The account closure control makes the account inactive, ends sessions, unlinks servers and schedules direct subscription cancellation at the end of the paid period. Account identity, profile, consent and financial records remain, along with the wallet record and remaining balance. Managed backup storage is frozen. Closure itself sets no automatic date for erasing those records or whole buckets. Other ordinary lifecycle rules, including applicable credit expiry, still run.
A closed account cannot sign in; contact support to request reactivation or exercise privacy rights. Reactivation does not automatically relink the servers. Closing an account is not a deletion request, a refund request or cancellation of a store-billed subscription. The Billing and AI Terms explain financial consequences. Mandatory erasure and refund rights remain available through support.
7. Account deletion
7.1 Request and cancellation period
A deletion request starts a 30-day period in which you can withdraw it before erasure begins. The confirmation identifies the scheduled date. The account generally remains usable during that period, but new AI wallet top-ups and automatic top-ups are stopped. Closing the account instead requires canceling the pending deletion request first.
Export needed records and arrange backup recovery before erasure. Deleting the Cloud account does not erase your independently operated Library. App Store and Google Play subscriptions must be canceled separately in the relevant store.
7.2 Erased records
When erasure starts, Frameleaf ends account access and direct subscriptions and removes identity and sign-in information, profile and ordinary consent records, billing profile and saved payment methods, licences and activations, sharing and linking records, and identifying server settings. Any active Cloud AI processing is ended and its worker-held content is deleted. There is no completed-job upload archive to retain through the account-deletion period. Buddy coordination and escrow records are removed under the account lifecycle; this does not wipe a peer’s disks.
The managed backup 30-day hold begins when erasure starts, followed by purge within 90 days of that starting point. In an ordinary unheld request this can be up to 120 days from the initial account-deletion request. Cloud key escrow needed for managed backup administration follows the backup lifecycle.
7.3 Retained records
Records retained after account erasure include a minimal account and server reference, the deletion request, audit events, payment and tax records, subscription and purchase evidence, wallet ledger and refund or dispute records, relevant staff actions and case notes, service metering and job-cost records, and the backup records needed to complete retention and purge. Payment providers may retain their own customer, invoice and transaction records. Retention must be limited to an applicable purpose or legal obligation; it does not authorize new marketing or media analysis.
The service-use wallet balance is removed when erasure is carried out. Its removal does not extinguish the Refund Policy’s right to a refund of unused purchased value. Retained transaction and usage records support that claim, including where account sign-in is no longer available. Applicable prepaid-value and unclaimed-property rights also remain unaffected.
7.4 Deferred erasure
Erasure can wait while an account is suspended or inactive, a payment or wallet dispute remains open, the wallet is frozen, a backup preservation hold applies, or a wallet refund request is undecided. Approved refunds and payments still settling can also delay completion. These conditions do not establish an unlimited legal right to retain unrelated personal information. Frameleaf will assess the necessary scope, applicable response deadline and lawful basis, and provide required explanations and appeal information unless disclosure is legally restricted.
A deferred request remains pending. Where a hold ends, or access is restored after the customer could not cancel, a new erasure date is set with at least seven days’ notice. A customer who cannot sign in may ask support to withdraw the request before erasure begins. A deletion already in progress cannot be withdrawn through the ordinary controls.
8. Preservation and deletion limits
Frameleaf may preserve specifically identified information for a valid legal obligation, binding order, concrete dispute or necessary security investigation. It will restrict access and use, assess the basis and duration, and remove the hold when no longer justified. A supplier billing minimum is not a legal hold. A possible future dispute does not justify retaining all readable customer content indefinitely.
Ordinary managed backup versioning is not a customer-selectable immutable compliance archive. Any separately contracted retention lock must identify its scope, duration, cost and lawful deletion consequences before activation.
Deletion means removing active access and carrying out the applicable logical, object and key-removal processes. Frameleaf does not promise verification of physical overwriting on every supplier disk. Destroying a stored key is effective cryptographic erasure only to the extent no other usable copy permits decryption. Applicable deletion instructions must be reapplied when Frameleaf restores its own operational systems.
9. Incidents and contact
Frameleaf will investigate credible security and data-loss reports, contain harm, preserve proportionate evidence and provide notices required by law and the DPA. An inaccessible object, service outage and confirmed plaintext disclosure are different events. Notices will distinguish known facts from matters still under investigation.
Report security, restoration, deletion and privacy matters through frameleaf.app or [email protected]. Do not include usable encryption secrets. Postal correspondence: Frameleaf, Inc., 14 Wall Street, Suite 2000, New York, NY 10005, United States.
Telephone: +1 (332) 287-1911.