Contents
  1. Summary
  2. Data that stays on your device
  3. Data processed by our service providers
  4. What we do not do
  5. Disclosure to others
  6. Your rights
  7. Children
  8. Security
  9. International transfers
  10. Changes to this policy
  11. Contact

Privacy Policy

Effective 26 August 2026 Last updated 26 August 2026

Enframe is operated by Hibana, which is the data controller for the processing described below.

Contact for privacy matters: enframe.support@hibana.rs

1. Summary

Enframe is a photo-framing app for iOS and Android. It is built to work offline, on your device.

In plain terms:

  • Your photos never leave your device. We do not upload, store, or have any ability to see the images you import, edit, or export.
  • There are no accounts. We never ask for your name, email address, phone number, date of birth, or a password.
  • There are no ads, no advertising identifiers, and no tracking of you across other apps or websites.
  • We never sell or share your personal data, and we do not use it for profiling or automated decision-making.

We do process a small amount of pseudonymous technical data to keep the app working and to understand which features people use. That data is described in full in Section 3. It does not identify you by name, but under the GDPR a persistent device identifier still counts as personal data, so this policy treats it accordingly.

2. Data that stays on your device

The following never reaches us or any third party:

WhatWhere it lives
Photos you import Your device's app storage
Framed images you create, and their edit settings A local database inside the app's private storage
Albums and captions you create The same local database
App preferences (theme, onboarding state) Local device storage

Photo library access. The app asks for permission to read from your photo library so you can pick an image to frame, and to write to it so you can save the result. Access happens entirely on the device. We do not scan, index, or transmit your library.

Sharing. When you use the share button, your device's own share sheet hands the image to whichever app you choose. What that app does with it is governed by that app's privacy policy, not this one.

Deleting this data. Delete individual creations inside the app, or uninstall Enframe to remove all of it. Once removed from your device, it is gone — we hold no copy and cannot restore it.

3. Data processed by our service providers

Two third-party services process limited technical data on our behalf. Neither receives your photos.

3.1 Mixpanel — product analytics

We use Mixpanel to understand how the app is used in aggregate, so we can fix problems and decide what to build next.

What is processed:

  • A randomly generated identifier assigned to your app installation. It is not derived from your device's hardware identifiers and is not linked to any account, because there are no accounts.
  • Product events — for example that a screen was opened, that an export finished, that the subscription screen was shown, or that onboarding was completed.
  • Technical context automatically attached to those events: device model, operating system version, app version, and language setting.
  • Your IP address, used by Mixpanel to infer an approximate country. It is not stored by us and is not used to determine your precise location.

Where it is processed: Mixpanel's European Union data residency region (api-eu.mixpanel.com). Analytics data is not transferred outside the EEA.

Retention: Mixpanel retains this data for 12 months, after which it is deleted automatically.

Legal basis: Legitimate interests (GDPR Art. 6(1)(f)) — specifically our interest in maintaining, securing, and improving the app. We consider this proportionate because the data is pseudonymous, limited in scope, never used to target advertising, and never combined with data from other sources. You may object to this processing at any time; see Section 6.

3.2 RevenueCat — subscription management

We use RevenueCat to check whether a subscription is active and to restore purchases across devices.

What is processed:

  • An anonymous subscriber identifier generated by RevenueCat. We do not set it to any value of our own, so it is not linked to any identity we hold.
  • Purchase and entitlement records — which product was bought, when, whether it is active, renewal and expiry dates, and the store receipt issued by Apple or Google.
  • Your IP address and derived country, plus basic device and platform information.

Where it is processed: RevenueCat operates from the United States. This transfer is covered by the European Commission's Standard Contractual Clauses, supplemented by RevenueCat's technical and organisational safeguards.

Retention: For as long as the subscription record is needed to honour and restore your purchase, and to meet our record-keeping obligations.

Legal basis: Performance of a contract (GDPR Art. 6(1)(b)) — we cannot deliver or restore a subscription you paid for without it.

3.3 Payment processing

We never see or receive your payment details. All purchases are made through Apple's App Store or Google Play. Your card number, billing address, and identity remain with Apple or Google, who act as independent controllers under their own privacy policies:

We receive only the confirmation, via RevenueCat, that a purchase is valid.

3.4 Support correspondence

If you email enframe.support@hibana.rs, we receive your email address and whatever you write. We use it solely to answer you, and we keep the thread for up to 24 months so we have context if you write again.

Legal basis: Legitimate interests (GDPR Art. 6(1)(f)) in responding to enquiries about our product.

4. What we do not do

  • We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
  • We do not use advertising identifiers (IDFA / Android Advertising ID), and the app contains no advertising SDK.
  • We do not track you across other apps or websites.
  • We do not build profiles about you or subject you to automated decision-making that produces legal or similarly significant effects.
  • We do not collect precise location, contacts, calendars, microphone, or camera data.
  • We do not access, transmit, or analyse the content of your photos.

5. Disclosure to others

We disclose personal data only in these circumstances:

  • To the processors named in Section 3, acting on our documented instructions under data processing agreements.
  • Where legally required — to comply with a valid court order, subpoena, or other binding legal obligation. Note that our records contain no data capable of identifying an individual person, which materially limits what could be produced.
  • In a business transfer — if the app or our business is acquired, records may transfer to the acquirer, who would remain bound by this policy until you are given notice of any change.

6. Your rights

Under the GDPR and the Serbian Law on Personal Data Protection (ZZPL), you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing in certain circumstances
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interests, including our analytics (GDPR Art. 21)
  • Withdraw consent, where processing is based on consent
  • Lodge a complaint with a supervisory authority

How to exercise them: email enframe.support@hibana.rs. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.

A practical note on identification. Because Enframe has no accounts, we usually hold nothing that lets us connect a request to a specific record. If you ask us to delete your analytics data, we will need you to help us locate it, and in some cases we may be unable to — GDPR Art. 11(2) applies. We will always tell you plainly if that is the situation rather than leaving the request open.

Objecting to analytics. The current version of the app does not include an in-app analytics toggle. If you object to analytics processing, email us and we will suppress and delete the associated records using our provider's deletion tooling.

Supervisory authorities. In Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), https://www.poverenik.rs. In the EEA, your local data protection authority.

7. Children

Enframe is a general-audience app. It is not directed at children and we do not knowingly collect personal data from children under 13 (or under the applicable age of digital consent in your country, which may be up to 16 in the EEA).

If you believe a child has provided us with personal data, contact enframe.support@hibana.rs and we will delete it.

8. Security

Data on your device is held in the app's private storage, protected by your operating system's application sandbox and, where you have enabled it, by device-level encryption. All communication with our service providers uses TLS-encrypted connections.

No method of transmission or storage is completely secure. Because we hold no identifying data and no copies of your photos, the consequences of a compromise on our side are limited by design.

9. International transfers

Analytics data stays within the EEA (Mixpanel EU region). Subscription data is transferred to the United States (RevenueCat) under Standard Contractual Clauses. Payment data is handled by Apple and Google under their own transfer mechanisms.

10. Changes to this policy

We may update this policy as the app changes. When we do, we revise the "Last updated" date above. For material changes — for example, if we begin collecting a new category of data or introduce optional cloud sync — we will give notice in the app before the change takes effect.

This version reflects Enframe as it currently ships: a fully local app with no cloud storage and no user accounts.

11. Contact

Hibana
enframe.support@hibana.rs

Back to Enframe