FrameRoam

Who we are and how to contact us

FrameRoam is operated by Makoto Kumasaka under the developer brand Made by Mako (“we”, “us”). This policy explains how information is handled by the FrameRoam iPhone app and this product website.

For privacy questions, access requests, corrections or deletion requests, email thingsmadebymako@gmail.com. You can also find this contact on our support page, without installing the app or signing in.

Projects and scenes on your device

FrameRoam V1 has no sign-in or cloud project backup. The app stores projects, shot names and notes, scene references, camera settings and positions, camera moves, shot order, preferences and rendered reference images on your device. Reference images are rendered from the 3D scene; they are not photographs taken by your phone camera.

Files imported through Files or incoming sharing are copied into app-managed local storage. Incoming shared copies wait on your device until you open FrameRoam and import or remove them. Projects and imported source scenes are not uploaded to a FrameRoam cloud backup. Bundled scenes can open without downloading scene files.

App removal, clearing storage and operating-system storage management can affect local data. Device backups or migration may include app data according to your platform settings. Keep separate copies of important original files and exports.

Camera permission and motion tracking

If you enable Magic Window on a supported iPhone, the app requests camera permission so Apple’s ARKit can estimate device motion. FrameRoam uses position, orientation and tracking status to move the virtual camera. This feature does not record, store or upload the camera feed.

A virtual camera pose that you save becomes part of your local project and selected exports. It is not a continuous recording of your movement. Touch controls work without motion tracking, and you can manage camera permission in iOS Settings.

Local-only V1 and earlier accounts

V1 does not offer FrameRoam account creation, sign-in or cloud project backup. The mobile release does not initialize Firebase Authentication or Firestore. This does not remove records created in earlier account-enabled test builds. If you used one of those builds, contact us about access to or deletion of those records. Local files remain separate from any earlier cloud copies.

Purchases and RevenueCat

FrameRoam uses Apple’s App Store and RevenueCat to process supported purchase requests, determine Pro access and restore purchases. The RevenueCat SDK may communicate with its service when the app opens, before you make a purchase.

RevenueCat processes app-user identifiers, purchase and transaction history, entitlement status, and technical request, app and device information needed to operate its service. V1 uses an anonymous app-user identifier for purchase access and restoration; it does not require or send a FrameRoam sign-in identity. Earlier account-enabled test builds may have associated purchases with a Firebase user identifier. These identifiers can be linked to you; “anonymous” does not mean that no data is processed.

The app does not send your email address or display name as RevenueCat customer attributes. Apple handles payment details; the FrameRoam purchase interface does not request your payment-card number. RevenueCat provides purchase reporting and analytics to us. See RevenueCat’s privacy policy and Apple’s privacy information.

FrameRoam Pro is a one-time, non-consumable purchase, not a subscription. Restore Purchases restores purchase access, not deleted projects. Local-only storage does not mean zero network traffic or erase earlier provider records.

Exports and sharing

PNG shot sheets and supported MP4 video previews are generated on your device. They can include rendered scene content, project and shot names, notes, camera settings and scene attribution. Review your export before sharing.

When you share, the app passes the prepared files to the destination you choose in the system share menu. That app, service or recipient controls its copy. Deleting a project cannot erase copies you exported or shared.

Native sharing writes temporary export files to app cache. Files retained after a share attempt become eligible for cleanup 24 hours after the latest attempt; cleanup occurs during a later file-preparation operation, not necessarily at exactly 24 hours. Unshared prepared files are removed when their preparation is disposed of where cleanup can complete. iOS may also manage cached files.

Website, online scenes and support

Our product website uses Google Firebase Hosting. It has no app-added advertising, analytics scripts or tracking cookies. Hosting still processes request information such as your IP address and requested URL to deliver content, maintain security and measure service usage. Google states that Firebase Hosting retains IP data for a few months.

When you open an online scene, its host receives normal internet-request information, including your IP address and requested file. The app’s online demo references include storage.googleapis.com and sparkjs.dev. Requests depend on the scene you open. Visiting scene credits or other external links also contacts the linked service, whose privacy practices apply.

Support links open your email application. Messages sent to our support address are processed through Google’s Gmail service. We receive your email address, message and any attachments, and use them to respond, investigate problems and handle privacy requests. Include only relevant information; do not send passwords, authentication tokens, payment-card details or private scene files.

The app does not include an advertising feature or a separate app-authored analytics or crash-report upload pipeline. Purchase, hosting and other service providers can still process technical and operational data. See Firebase’s privacy information and Google’s privacy policy.

Beta signup

When you submit the beta signup form, we collect your email address, optional name, optional intended use and Other answer, signup time and contact consent. Submissions are processed by Google Apps Script and stored in a private Google Sheet. Google also processes technical request information under its own privacy practices.

We use this list to provide beta access, request testing feedback and deliver launch rewards. We manually record invitation, participation and reward status. This signup does not subscribe you to a general marketing newsletter, create an app account or collect your Apple Account credentials. Joining via a public TestFlight link does not automatically match your TestFlight identity to this list.

We keep signup and participation records while running the beta and fulfilling rewards, then review and delete data no longer needed for those purposes. Email thingsmadebymako@gmail.com to leave the list, correct your details or request deletion. Access is limited to the team members administering the beta.

Why information is used and who receives it

Information is used to provide local creative tools, manage purchases, respond to support and privacy requests, prevent abuse, diagnose service failures and meet applicable legal obligations. Service providers receive the information needed for these functions. Apple and Google also process information under their own policies when you use their store or email services.

We do not sell personal information or share it for cross-context behavioral advertising. Information may also be disclosed when necessary to comply with a valid legal requirement or protect users, the service or legal rights. Material you choose to share is delivered to your selected recipient.

Where data-protection law requires a legal basis, we rely on performance of the service you request for purchase functions; legitimate interests in service security, troubleshooting and responding to correspondence; consent where required for optional processing; and legal obligations where they apply. You can withdraw consent for processing based on consent without affecting earlier lawful processing. Device permissions can be changed in iOS Settings.

Deletion and privacy requests

Delete local projects and pending imports through the app. V1 has no FrameRoam account screen or cloud backup to restore deleted work. Device backups and exported copies are controlled separately.

For purchase-profile privacy requests or records from earlier account-enabled test builds, email thingsmadebymako@gmail.com. We may ask for limited transaction or account information to locate the record and verify your authority. Do not send passwords, authentication tokens or full payment-card details.

Deleting records does not refund purchases or erase records independently controlled by Apple. Provider transaction and legal retention requirements may apply. We respond within applicable legal periods and explain limitations or additional information needed.

How long information is kept

  • Local projects and imported files: remain until removed through the app or applicable device-storage controls. Shared copies and device backups are managed separately.
  • Earlier test accounts and cloud records: disabling accounts in V1 does not delete these records; contact us to request deletion. The production Firestore database has no scheduled backups or point-in-time recovery enabled. Provider recovery and deletion processes can still retain data temporarily.
  • Earlier test authentication: Google states that Firebase Authentication retains logged IP addresses for a few weeks and removes other authentication information from live and backup systems within 180 days after user deletion is initiated.
  • Purchase profiles: used to maintain and restore purchase access until deletion is requested and processed, subject to provider transaction, security and applicable record-retention requirements. Privacy requests are described above; provider-held transaction records are not a promise of immediate erasure.
  • Support and privacy correspondence: retained for as long as needed to resolve and follow up on the request, document its handling, address a dispute or meet an applicable legal requirement. We assess continued need based on those purposes and remove information when it is no longer needed.
  • Operational logs: the production project’s standard operational log bucket is configured for 30 days and its required audit log bucket for 400 days. Those periods are separate from providers’ own security and Hosting logs. Account deletion does not immediately erase all operational or audit records.

Your choices and rights

Depending on where you live and the applicable law, you may have rights to access, correct, delete or obtain a portable copy of personal information, restrict or object to processing, and withdraw consent. You may also raise a complaint with your local data-protection authority, including the UK Information Commissioner where applicable. You may contact us to exercise a right, ask about a decision or request review of our response. Applicable exceptions and identity verification may apply.

V1 stores creative work locally. You can decline camera permission and avoid online scenes or external sharing. We do not use personal information to make solely automated decisions producing legal or similarly significant effects.

International processing and security

Services are available to users in different countries. Our providers’ infrastructure and earlier test-account database may process information outside your country, including in the United States. Local privacy laws may differ. Where required, transfers are subject to applicable safeguards, including the contractual safeguards provided under our service providers’ data-processing terms. Contact us for information about the safeguards applicable to your data.

We use encrypted network connections and access controls for online services. No storage or transmission method is completely secure. Protect your device and avoid putting unnecessary sensitive information in project names, notes or support messages.

Children

FrameRoam is a spatial camera and creative planning tool and is not directed at children. If you believe a child has supplied personal information that should not have been collected under applicable law, contact us so we can investigate and take appropriate action, including deletion where required.

Changes to this policy

We will update this page and its effective date when our information practices change. Where required, we will provide additional notice of material changes or request consent. For questions about this policy, contact thingsmadebymako@gmail.com.