← Framepulse

Privacy Policy

Last updated August 12, 2026

This policy explains how LIMINAL BLUES LTD ("LIMINAL BLUES", "we", "us" or "our"), a company registered in the United Kingdom, handles personal data when you use the Framepulse app, widgets, notifications, and framepulse.app.

LIMINAL BLUES LTD is the data controller. Contact us at support@framepulse.app.

1. Data we handle

  • Account and sign-in data: Firebase account identifier, Apple or Google sign-in provider, email address (including an Apple private relay address), name and profile image when supplied by your provider, Framepulse user ID, username, and country or region code.
  • Profile and settings data: Profile image, biography, location text, social handles, profile theme, display preferences, notification preferences, streaming-service preferences, widget settings, and whether your profile is public.
  • Library and viewing data: Followed films, shows, people and studios; watchlist and watched status; ratings; watched dates; favourites; custom lists and list items; and related media metadata.
  • User and social content: Notes, reviews, comments, reactions, likes, follows, blocks, reports, list titles and descriptions, and the privacy choices attached to that content.
  • Letterboxd import data: When you choose to import an export, Framepulse processes its filename and fingerprint, watched and watchlist entries, ratings, likes, reviews, dates, lists, and title-matching decisions. Framepulse does not sign in to your Letterboxd account.
  • Personalisation and AI data: Search or DeepSearch text, spelling-correction queries, titles and ratings used for recommendations, followed people, generated taste-profile information, and AI token-usage totals.
  • Community search trend data: The TMDb identifier and type of a film, show, person or studio opened from an organic search, together with the Framepulse user ID needed to count each account once.
  • Subscription data: A Framepulse user ID linked to RevenueCat, App Store receipt and transaction information, product and entitlement status, purchase dates, renewal or expiry status, and subscription-management information. We do not receive payment-card or bank-account details.
  • Device, notification and security data: APNs device token, app version, limited device or operating-system information supplied by providers, IP-derived security fingerprints, authentication and session data, App Check or App Attest signals, and information needed to rate-limit requests and prevent abuse.
  • Support data: Information you include when contacting us for help or making a privacy request.

Visual Search uses Apple's on-device text recognition. The captured camera image is not uploaded to Framepulse; recognised text is handled like another search query. Images deliberately selected as profile pictures are uploaded and stored.

Framepulse does not use advertising SDKs, sell personal data, or use personal data to track you across other companies' apps or websites for advertising.

2. How we receive data

  • Directly from you when you use Framepulse features.
  • From Apple, Google Firebase and Google Sign-In when you authenticate or use device-integrity services.
  • From Apple and RevenueCat when you purchase, restore or manage a subscription.
  • Automatically when your device communicates with Framepulse for authentication, security, request routing and notifications.

3. Why we use data and our lawful bases

  • To create and authenticate accounts, sync libraries, provide social features, process imports, personalise Framepulse and deliver subscriptions, as necessary to perform our contract.
  • To provide taste profiles, recommendations, spelling correction and natural-language entertainment searches when enabled.
  • To calculate aggregate community search trends from results that people choose to open and improve discovery in Framepulse.
  • To send notifications you have enabled.
  • To secure accounts, prevent fraud and cost abuse, maintain reliability, moderate content and defend legal claims, based on our legitimate interests in operating a safe service.
  • To comply with legal obligations.
  • On the basis of consent where consent is required for optional processing. Consent can be withdrawn, although the related feature may stop working.

We do not use AI to make solely automated decisions that produce legal or similarly significant effects about you.

4. AI features

Framepulse uses Google Firebase AI Logic and Vertex AI for DeepSearch, spelling correction, "Worth watching?" recommendations, and taste-profile generation. These features are disabled until you allow AI-powered features and can be disabled again in Settings.

  • Search text or entertainment descriptions may be sent to Google.
  • Personalised features may send selected viewing history, ratings, genre preferences, standout titles, credits and followed people.
  • Framepulse stores generated taste-profile data and token totals, but not raw DeepSearch or spelling-correction prompts in its database.
  • DeepSearch can use Grounding with Google Search. Google states that grounded prompts, context and output may be retained for up to 30 days. Other processing may use limited abuse-monitoring logs and temporary in-memory caching.
  • Google states that Vertex AI customer data is not used to train or fine-tune models without the customer's permission or instruction.

Do not include confidential personal information in an AI prompt.

5. When data is visible to other people

New accounts begin with Public Profile enabled. Other people may be able to find your username and see information or content made public, including your biography, profile image, favourites, public lists, public notes, ratings attached to public notes, follower information, and interactions. You can disable Public Profile in Framepulse settings.

Private profiles, private lists and private notes are excluded from public profile and community responses. Previously public content may remain briefly in device, search-engine or web caches outside our immediate control. Reports are available only to authorised Framepulse administrators for moderation and safety work.

Text you attempt to publish may be screened before it becomes visible. Text rejected immediately by a high-confidence rule is neither published nor stored. Text requiring human review is held privately for up to 30 days and is available only to authorised administrators. If an administrator rejects reviewed content, it remains hidden and may be retained with the moderation record for safety, enforcement and dispute-resolution purposes. Framepulse also keeps anonymous aggregate counts describing the category, rule, language, surface and safety-engine version so we can measure accuracy.

Blocking prevents the affected accounts from viewing or interacting with each other through supported community features.

The underlying account-level records used to calculate community search trends are not publicly accessible. Only aggregate popular- search results may be displayed in Framepulse.

6. Service providers and recipients

  • Apple: sign-in, App Store purchases and subscriptions, push notifications, device services and distribution.
  • Google Firebase and Google Cloud: sign-in, authentication, profile-image storage, App Check, App Attest integration, Firebase AI Logic and Vertex AI.
  • RevenueCat: purchase validation, subscription history, entitlement status and subscription analytics.
  • Railway: API, scheduled processing and PostgreSQL database hosting.
  • Vercel: website, public profile and legal-page hosting.
  • TMDb and MDBList:entertainment and external-rating metadata.

TMDb and MDBList requests are made through Framepulse-controlled services and are not intentionally supplied with your email or profile identity. We may also disclose data where required by law, to protect users or the service, or during a corporate transaction subject to appropriate safeguards.

7. International transfers

Providers may process data outside the United Kingdom, including in the United States or European Economic Area. We rely on an applicable UK adequacy regulation or contractual safeguards made available by the provider, such as the UK International Data Transfer Agreement, UK Addendum, or equivalent lawful safeguards. Contact us for more information relevant to your data.

8. Retention

  • Account, profile, library, social, settings and current taste-profile data remain while your account exists, unless deleted sooner.
  • Letterboxd import staging sessions and source candidate data expire after 30 days. Imported Framepulse records then follow normal account retention.
  • Pulse notification and activity events are removed after 90 days.
  • Taste-profile evolution history is limited to the newest 50 snapshots per account.
  • Account-level community search trend records are automatically removed after seven days and are not retained as a long-term search history.
  • Raw DeepSearch and spelling-correction prompts are not retained in the Framepulse database; Google's provider retention above still applies.
  • Text awaiting automatic moderation review is held privately for no more than 30 days. Text rejected before storage is not retained, while reviewed moderation records and hidden content follow the normal account, safety and legal retention periods. Non-identifying aggregate moderation-rule statistics may be retained to measure the safety controls.
  • Production application logs are configured not to retain user IDs, titles, list names, notification subjects, request contents or error messages. Infrastructure providers may retain limited security and operational metadata under controlled schedules.
  • Data needed for a dispute, fraud investigation, legal claim or legal obligation may be retained as reasonably required.

9. Account and data deletion

You can permanently delete your account in Settings after a recent Apple or Google sign-in confirmation. Successful deletion removes associated data from the live Framepulse database, the Firebase Authentication account, Framepulse profile images in Firebase Storage, and the linked RevenueCat customer record. Short-lived community search trend records may remain until their automatic seven-day expiry; they are not publicly accessible.

Deleting Framepulse does not cancel an App Store subscription. Billing is controlled by Apple, so cancel an active subscription in your Apple ID subscription settings. Apple and payment providers may retain records they are legally required to keep.

10. Security

Measures include encrypted HTTPS transport, authenticated APIs, short-lived and revocable sessions, Apple Keychain storage, Firebase App Check and App Attest, access controls, private caching rules, rate limits, request and input validation, production-log minimisation, and restricted administrative actions. No internet service can guarantee absolute security.

11. Your UK data-protection rights

Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing of your data; receive certain data in a portable format; withdraw consent; and complain to the Information Commissioner's Office.

You have a right to object to processing based on legitimate interests.

Email support@framepulse.app to exercise a right. We may verify your identity. You can also contact the ICO.

12. Your choices

  • Keep Public Profile disabled and use private content settings.
  • Allow or disable AI-powered features in Settings.
  • Change or disable notification categories.
  • Decline camera access and use text search instead.
  • Choose whether to import a Letterboxd archive.
  • Edit or delete supported profile and user content.
  • Delete your account in Settings.

13. Changes to this policy

We may update this policy when Framepulse, our providers or legal requirements change. We will update the date above and provide additional notice where a change materially affects personal-data use.

14. Contact

LIMINAL BLUES LTD
United Kingdom
support@framepulse.app