Scope
This policy applies to the Frume app for iPhone and iPad and to these static support pages. Frume is a photo-puzzle app. You do not create a Frume account or provide a profile to play.
These support pages do not set cookies, run analytics, show ads, or load third-party scripts. If you follow an external link, the destination’s own privacy policy applies.
Data Frume handles
Your current puzzle and last result
Frume stores one current puzzle in local app storage so you can continue later. The save includes a photo reference and attribution, cut style, difficulty, piece positions, progress, moves, and elapsed play time. Frume also keeps one compact last-completion receipt with the photo reference, completion time, cut, difficulty, piece count, moves, and elapsed play time until you remove or replace it.
Curated Unsplash images are hotlinked from the provider and are not copied into Frume’s persistent storage, so they may need the network again after relaunch. A photograph you chose yourself is stored as a bounded local derivative. While replacing a puzzle, Frume may briefly keep old and candidate own-photo files so an interrupted save does not destroy existing progress; unused files are removed after ownership changes successfully.
Photographs you choose yourself
You can cut a photograph from your own library instead of a curated one. Frume never gains access to your photo library: the system picker shows it to you, and hands Frume only the single photograph you pick.
That photograph is copied into Frume’s private storage so a saved puzzle or last result still has its picture later. A valid large image is downsampled on device to a derivative of at most about 16 megapixels, and Frume marks its photo folders as excluded from iCloud Backup. The derivative is deleted when neither the current puzzle nor last result uses it, or when you delete the app. It is never uploaded: it is not sent to Frume’s photo service, to Unsplash, or anywhere else, and no photo-use receipt is created for it.
Curated photo information
When you choose a theme, Frume asks its photo service for a curated Unsplash photograph. The app receives limited public metadata: photo identifier and dimensions, image URL, description when available, photographer name and profile link, and Unsplash’s download-registration endpoint.
The service keeps a rotating pool of that public photo metadata. Frume does not send your puzzle moves or saved progress with a photo request.
Photo-use receipts
When you start a puzzle, Frume sends its service the Unsplash download-registration endpoint and a short-lived, opaque, single-use token. If the device is offline, the pending receipt remains in a bounded queue in local app storage and is retried when Frume launches or returns to the foreground.
Premium Cuts purchase access
Premium Cuts is an optional, one-time, non-consumable App Store purchase—not a subscription. RevenueCat processes an anonymous app-user identifier, product and offering information, store entitlement status, and purchase or transaction history received from Apple so Frume can unlock and restore access.
Apple handles payment. Frume does not receive your full card number or Apple Account password.
Messages you send to support
If you email support, the email address, message, and any attachments you choose to send are used to investigate and reply to your request. Do not send passwords or full payment details.
Redacted diagnostics on your device
Frume can keep up to ten recent JavaScript, rendering, or haptic error records locally. A record contains the time, broad error type, whether it was fatal, a safe error class, and up to eight component names. It does not contain photo content, photo or service URLs, file paths, exception messages, stack traces, tracking tokens, user names, or a device identifier.
Frume does not upload this log automatically. You may inspect and share the redacted report through About & Support, or clear it at any time. A report leaves the device only when you choose a destination in the system share sheet.
Anonymous usage counts
Unless you switch it off, Frume counts how the app is used so its design can be improved: the app being opened, which photo source you chose, a puzzle being started, completed, or left unfinished and how far it had got, the Premium Cuts screen being shown, and a purchase or restore succeeding. A count carries only the cut style, piece count, theme name, elapsed time, and product identifier involved.
Counts are labelled with a random identifier Frume creates on this device. It is not your Apple Account, not an advertising identifier, and not derived from your device, so it cannot be connected to you or to any other app. No profile is built from the counts and no location is derived from them. Nothing about your photographs is included: no image, filename, path, description, or photographer.
If the device is offline the counts wait in a bounded local queue and are sent when Frume next launches or changes foreground state.
You can turn measurement off in About & Support. Switching it off deletes that identifier, stops collection at once, and discards anything still queued, so turning it back on begins an unrelated identifier.
What “tracking receipt” means
Unsplash calls its required photo-use registration “download tracking.” In Frume, this is a technical receipt that tells Unsplash a selected photograph was used. It is not advertising tracking, and Frume does not use it to follow you across apps, websites, or companies.
Frume contains no advertising SDK. It does not request an advertising identifier, contact list, precise location, microphone, or camera access, and no access to your photo library — choosing your own photograph goes through the system picker, which hands over one file and nothing else.
The anonymous usage counts described above are also not advertising tracking. They are labelled with an identifier that exists only for this installation of Frume, are never sold or shared with advertisers or data brokers, and cannot follow you to another app or website.
Service providers
These providers handle only the parts of Frume needed to deliver photos, purchases, and network service. Network providers may process request information such as an IP address to deliver and secure their services under their own policies.
-
Unsplash Photographs, attribution, and required use registrationPrivacy policy
-
Cloudflare Hosting and protection for Frume’s photo servicePrivacy policy
-
RevenueCat Anonymous purchase-entitlement verification and restorePrivacy policy
-
PostHog Anonymous usage counts, while measurement is left onPrivacy policy
-
Apple App distribution, payment, and transaction recordsPrivacy policy
Retention and deletion
- Current puzzle: kept on your device until a confirmed replacement, app-data removal, or deletion of Frume.
- A photograph you chose yourself: kept in Frume’s private storage while the current puzzle or last result uses it, and removed after both release it or when you delete Frume. It is never uploaded or included in iCloud Backup.
- Last-completion receipt: kept locally until a later completion replaces it, you remove it from Home, clear app data, or delete Frume.
- Pending photo-use receipts: kept locally until they are delivered or rejected as invalid. Deleting Frume clears the local queue.
- Server photo-use grant: expires after 24 hours and is scheduled for removal about one hour after expiry. Public curated photo metadata remains in the rotating service pool until it is refreshed or removed for operational reasons.
- Purchase records: retained by Apple and RevenueCat according to their legal, fraud-prevention, and service requirements. They may remain available so a purchase can be restored after reinstalling Frume.
- Support email: kept only as long as reasonably needed to answer the request and meet applicable legal or operational obligations.
- Anonymous usage counts: held locally only until they are delivered, and discarded at once if you switch measurement off or delete Frume. Delivered counts are retained by PostHog under Frume's project configuration.
- Redacted diagnostics: limited to the ten most recent records and kept locally until you clear app data, delete Frume, or use the in-app clear action. Sharing creates a copy only at the destination you choose.
Your choices
You can switch anonymous usage counts off, remove the last result, and clear redacted diagnostics in the app, or remove all local Frume data by deleting the app. An own-photo puzzle remains available offline. A curated-photo puzzle may need to reload its hotlinked image, and an internet connection is required to load another curated photo and to purchase or restore Premium Cuts.
Privacy rights vary by location. You may contact Frume to ask about a support message or data connected to the service. Anonymous purchase records may require information that lets RevenueCat or Apple locate the relevant transaction, and some records may need to be retained by those providers.
Contact
For privacy questions or support, email:
targix8@gmail.comThis policy may change if Frume’s features or providers change. The effective date at the top will be updated when a revised policy is published.