Privacy Policy
How we handle personal data, in line with the EU GDPR.
Last updated: September 26, 2026
1. Who we are, and our two roles
Framvis, operated by an independent software developer based in Spain, is the controller for the personal data we need to run the Service: your account, sign-in and security events, support requests, and billing metadata. Contact: support@framvis.com.
For the material you capture and the leads your demos collect, you are the controller and we act as your processor — we handle that data to provide the Service to you. Those two roles are separate throughout this policy.
2. What we collect
Account & security. Your email address, a hashed password, and — if you enable it — an encrypted two-factor secret and hashed recovery codes. We also keep your time zone, used to show and interpret dates: your browser suggests it when you sign up, and you can change it in your account settings. We record sign-in attempts, session and “remember me” tokens (hashed), and rate-limit counters, which can briefly contain an IP address or a hashed email. For each device where you tick “remember me”, we also keep a coarse label of its browser and operating system, such as “Chrome on Windows”, and when it last signed you back in — never its IP address. You can see those devices, and sign them out, under Signed-in devices in your account settings. If you create API tokens, we keep each token’s name, a hash of it (never the token itself), its access level, its expiry and when it was last used — and, only if you list them, the IP addresses or address ranges it may be used from. That list is kept for as long as the token exists — including after it expires, until you revoke it — and cleared when the token is revoked, including when changing your password or signing out everywhere revokes it. It is deleted with your account.
Content you create. Captured walkthroughs, demo configuration, step text, translations, generated voiceover audio, personalisation variables and published demo versions. Captured recordings may contain personal data from your own product — see §6.
Leads. If you switch on the email gate, the visitor’s email address plus a random demo-session identifier. You may also define up to five extra fields (for example “Company”); those answers are stored with the lead and are yours.
Demo & site analytics. Cookieless counts of views, step progress, calls-to-action, traffic source and coarse replay-performance samples. No IP address is stored in these tables.
Support. Ticket text and any files you attach. Mail sent to our support address is read live from the mailbox and is not copied into the application.
Billing. Provider customer, subscription and price identifiers, and an append-only record of billing events. We never see or store your card details — see §5.
Activity record. A log of who did what, and when, to your demos, workspace and account — for example publishing a demo, revoking a share link, changing a member’s role, or a staff action such as suspending an account or granting a subscription. It names the accounts involved and holds short labels — such as a demo or project name — and counts, never the content itself.
Notifications. In-app notices for your account — for example that support replied to a ticket, that your role in a team changed, or that your API tokens were revoked — each with a short fixed title, a link inside the app and whether you have read it. They never repeat the content of a ticket or a message.
3. How & why we use it
To provide and secure the Service, process your subscription, answer support requests, and understand product usage in aggregate. Legal bases (GDPR Art. 6): performance of our contract with you, our legitimate interests in operating the Service securely and preventing abuse, your consent where we ask for it, and legal obligation for accounting records. Where we process your captured content and leads, we do so on your documented instructions as your processor. We do not sell personal data and we do not use it to train AI models.
4. Cookies & browser storage
What is necessary, and needs no consent. A session cookie keeps you signed in and carries the check that protects your account from forged requests. If you tick “remember me”, a separate persistent sign-in cookie is set on that device and expires at a fixed date. Viewing a password-protected or email-gated demo sets a short-lived access cookie scoped to that demo. The fv_consent cookie remembers your answer below — accepted or rejected, the version of this policy you answered, and when — for 12 months, with a copy in your browser’s local storage. A few preferences also stay in your browser’s storage: the team workspace you last used, whether demo narration is muted, and an announcement you dismissed.
What you can accept or reject. One thing: when you watch a demo on Framvis, your browser can keep a random identifier in its local storage. It groups the steps of your visit so the demo’s owner sees how far viewers get, lets a replay-performance sample count once per visitor, and is stored with your email if you submit it on an email-gated demo. It holds nothing about you and is not a cookie.
Nothing happens until you accept. Until you answer, and if you reject, pages on Framvis never create, store or send that identifier in this browser, and delete one that already exists; demos you watch here then send no viewing analytics at all. We still count visits to our public pages, anonymously: the date, the page and the referring website, with no identifier, no IP address and no cookie. If you accept, demos use the identifier as described. A demo embedded on another company’s website runs there, where this choice cannot reach it; that company decides how its demo is measured.
When you are signed in, your answer is also recorded against your account — the choice, the policy version, the time and whether you made it in the banner or on this page — so it appears in Download my data and is deleted with your account. When this policy changes, we ask again. You can change your answer here at any time; it applies to this browser.
Demos embedded on other websites. An embedded demo cannot use the access cookie. When you submit your email to an email-gated demo there, the access it gets is held only in that page’s memory, for at most one hour, and is never stored; if you reload the page, it asks again. An embedded demo also tells the website around it what happens in it: that it loaded, with the demo’s name; which step number you reached; that you clicked its call to action; that you submitted the email form; and that you finished. It never sends that website an identifier, your email or your form answers.
We use no advertising or third-party tracking cookies. Two third parties may set their own storage on the pages where they run: Cloudflare Turnstile on sign-in and support forms, and Paddle on the checkout page.
5. Who we share data with
We use a small number of sub-processors to run the Service. Each receives only what its function requires: our hosting provider (IONOS), on servers in Spain, hosts the application, database and private files; Cloudflare provides the anti-abuse check on our forms and stores our off-site database backups in a bucket restricted to the EU jurisdiction; Google Cloud (Vertex AI) processes demo text and generates voiceover when you use the AI features, configured to the EU region.
Paddle is our Merchant of Record. Paddle sells to you in its own right and is an independent controller for the transaction, not our processor — the relevant Paddle entity depends on where you are, and Paddle’s own buyer terms and privacy notice apply.
Recipients you choose. If you connect an integration, we send the events you select to that destination — a Slack channel, HubSpot, or any HTTPS endpoint you configure. Those are your instructions to us, and once delivered that data is governed by that provider’s terms.
A current list is kept at Sub-processors. We do not sell personal data.
6. Data in your recordings
When you capture a walkthrough of your own product, you decide what is recorded and you are the controller for any personal data it contains; we act as your processor. You must have a lawful basis and inform the people concerned.
What we do automatically: text typed into form fields is masked at capture and canvas content is not recorded. That is not a guarantee that a capture contains no personal data — ordinary page text and element attributes are recorded, so avoid capturing screens that show real customer data.
Two different correction tools, and the difference matters. A blur is a visual overlay only: the underlying text is still present in the stored recording. A data scrub irreversibly removes the text you name from the stored data, its translations, generated audio and every published version. Use the scrub, not the blur, when something must actually be gone. A scrub reports anything structural it could not safely rewrite, so you can rotate or revoke instead of assuming.
Replayed images load from wherever your product served them. If your captured pages referenced images on other hosts, a viewer’s browser contacts those hosts directly when the demo plays, which discloses their IP address and the time of the request to them. Those hosts are determined by the content you captured, not chosen by us.
7. Retention
Your account and content are kept while your account exists. Deleting your account removes your live content and your support tickets, then deletes the private files that belong to them; a file that cannot be deleted at that moment is normally retried automatically every day until it is gone. Three things outlive it, each with your account reference removed: demos and hubs you created in someone else’s team workspace, which stay with that team; the activity record of what happened (§2), which is kept for 24 months; and billing records, which we keep for as long as the law requires — pseudonymous rather than anonymous, since the payment provider holds its own record of the transaction. Backups rotate, so copies persist in them for a short period afterward. If you own a team workspace, deleting your account dissolves it, and its demos return to whoever created them.
You control your own content directly — delete a recording, revoke a share link, erase a lead, or scrub text from a capture at any time.
Operational data: abuse and rate-limit records are kept for days; delivery history for your integrations is pruned after 30 days; in-app notifications are removed 90 days after you read them, or after 180 days if you never do, and always when you delete your account; database backups rotate on roughly a weekly local cycle plus an off-site copy.
We are still finalising fixed expiry windows for demo leads and demo analytics; until those are agreed and published here, that data is kept while the demo it belongs to exists, and you can delete it yourself at any time.
8. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to your supervisory authority.
For your account data, most of this is self-service in your account settings: Download my data gives you a machine-readable copy of the data we hold about your account — staff-only notes on your support tickets, and the content of team workspaces you do not own, are left out — and Delete my account erases it; we then email you a confirmation. Both ask for your password first. You can change your address yourself in your account settings: we send a confirmation link to the new address, nothing changes until it is opened, and your current address is told about the request and again once the change is made. Write to us for anything else, including billing data. For personal data inside a customer’s demo or lead list — for example if you are a visitor who submitted an email — the Framvis customer running that demo is the controller and decides; contact them, and we will assist them as their processor. If you are not sure who that is, write to us and we will point you to the right party.
9. International transfers
The application, its database and its off-site backups are hosted in the EU. Some of the providers in §5 are, or are affiliated with, companies outside the EEA, and support or infrastructure access from outside the EEA is possible. Where that happens, those providers publish their own data-processing terms and transfer safeguards, which we rely on and which are linked from our Sub-processors page.
We do not claim that every party involved processes data exclusively inside the EEA. In particular, payments, the anti-abuse check, any integration you connect, and the third-party hosts referenced by your own captured pages may involve processing elsewhere.
10. Changes
We may update this policy; material changes will be notified in-app or by email. This version reflects the Service as built and is maintained by its developer rather than reviewed by external counsel.
Questions about this document? Contact support@framvis.com.