FrameYield
DashboardJoin beta
Back to FrameYieldPRIVACY & DATA

Measure attention. Not people.

FrameYield is designed around aggregate campaign delivery, limited account data and clear retention states.

Beta draft 2026-08-06Counsel review required before public launchLast updated 6 August 2026
Plain-language operating policy

FinalFlow · CVR 46076842, Tulipanhaven 142, 1. 3, 8200 Aarhus N, Denmark, is the data controller for the FrameYield private beta. Privacy requests may be sent to privacy@frameyield.com. Processor roles, hosting regions and transfer safeguards still require final review before public launch.

01

Data we collect

We collect the information needed to run accounts, review eligibility, match campaigns, report delivery and settle funds.

  • Account: name, email, role, country, currency and versioned acceptance records.
  • Creator: channel URL, category, aggregate analytics, connection state, disclosure attestations and payout state.
  • Payout: Stripe account/transfer/payout ids, KYC readiness, human-readable due requirements, destination type/label/last four digits, currency, arrival estimate, failure/hold state and receipts.
  • Brand: company, website, industry, budget range, regions and billing state.
  • Campaign: briefs, creative versions, approvals, aggregate delivery, exclusions, disputes and ledger events.
02

Read-only platform connections

A production analytics connection should request the narrowest read-only scopes available. FrameYield does not need permission to publish, delete videos, read private messages or take over a social account.

  • The billable private-beta scope is accepted YouTube long-form video ids; Shorts, Reels and TikTok covers are excluded.
  • Access tokens are encrypted and separated from ordinary profile data.
  • Connected analytics are used for eligibility, measurement, fraud review and reporting.
  • Revoking a connection stops new collection; prior campaign records may remain where required for settlement or disputes.
03

Why we use data

Data is used to perform accepted campaign services, secure the marketplace, comply with law and improve aggregate product performance.

  • We do not sell personal data or private-message data.
  • We do not bill brands from private chat exposure or external link-preview guesses.
  • Automated signals may flag unusual delivery, but a person reviews material holds or account actions.
  • Product analytics should be aggregated or minimised wherever individual identity is unnecessary.
04

Who receives data

Participants receive only what is necessary for the campaign. Brands see approved creator identity and aggregate delivery, not private channel credentials. Creators see the relevant brand, brief, rate and settlement record.

  • Vetted hosting, identity, analytics, fraud, support and payment providers may process limited data under contract.
  • Authorities receive data only where legally required.
  • Cross-border transfers use the safeguards required for the launch market.
05

Retention

The proposed beta schedule is shown for transparency but remains subject to legal review: incomplete local drafts stay on the device; rejected or abandoned applications are deleted or anonymised after 180 days; OAuth credentials are erased on disconnect; operational backups expire within 30 days; campaign, tax, payout, fraud and dispute records are retained for the legally required accounting/reporting period, proposed as five years after the relevant financial year.

  • A shorter period applies where the purpose ends and no legal duty remains.
  • Deletion requests remove data that is no longer required for an active account, security evidence or legal record.
  • Frame PNGs and hashes follow the associated campaign/dispute retention state.
  • The final production schedule and legal basis will be published before public onboarding.
06

Choices and rights

Depending on location, participants may request access, correction, deletion, restriction, portability or objection, and may complain to a data protection authority.

  • Requests may be sent to privacy@frameyield.com; identity may be checked before account data is disclosed or changed.
  • You can disconnect a social account without deleting the FrameYield account.
  • Marketing communication is optional and separate from operational campaign notices.
  • Identity verification data is handled by the configured provider under the disclosures shown at collection.
07

Security

FrameYield uses least-privilege access, encrypted transport, protected secrets, audit trails and role-based controls. No service can promise absolute security, so incident response and notification procedures are part of production readiness.

  • Password handling is delegated to the platform authentication layer rather than a custom password database.
  • Sensitive payment details stay with the configured payment provider where possible.
  • Participants should report suspected account access through the authenticated support channel shown in the dashboard.
08

Processors and transfers

The intended production stack includes Cloudflare for application/database/object hosting, OpenAI’s hosting identity layer, Google for YouTube OAuth/reporting and Stripe for payment, KYC and payout services. Their final roles, legal entities, regions, subprocessors and transfer safeguards must be recorded before public launch.

  • Stripe collects raw bank-account, identity-document and sensitive KYC fields on its hosted flow; FrameYield is designed to retain only the status, requirement names, destination label/last four digits and provider receipts needed to operate and audit payout.
  • Additional tax/DAC7 seller data is not assumed to be covered by Stripe KYC and receives its own collection notice where legally required.
  • Google tokens are encrypted with a separate application key and removed on disconnect.
  • Monitoring and support providers may be added only after contract and privacy review.
09

Cookies and device storage

The product uses essential session mechanisms supplied by the hosting identity layer and browser storage for an unfinished local onboarding draft. Non-essential analytics or advertising cookies require a separate inventory and consent decision before activation.

  • Local drafts are not submitted until the user chooses to send them.
  • No third-party advertising pixel is part of the private beta build.
  • A production cookie table will list name, provider, purpose and lifetime.
10

Controller and production notice

FrameYield is a product operated by FinalFlow, a Danish sole proprietorship owned by Thomas Tobias Hansen, CVR 46076842, at Tulipanhaven 142, 1. 3, 8200 Aarhus N, Denmark. Privacy contact: privacy@frameyield.com.

  • Before public onboarding, this notice must also include the final processor inventory, hosting regions, cookie choices, lawful bases and jurisdiction-specific supplements.
  • Real OAuth and test-mode payments may be used only in the controlled private pilot after configuration review.
  • Any material change receives a new effective date.
  • Campaign-specific processing terms may supplement this notice for business customers.
END OF POLICY

Clear before live.

Every participant sees the applicable rate, frame, dates, disclosure wording and measurement method before approving a placement.

Join as creator Join as brand