Legal · Last updated 1 July 2026
Privacy Policy
BakeFrame (“we”, “our”, “us”) operates bakeframe.art and the BakeFrame application. This policy explains what data we collect, why we collect it, and how you control it.
Data Sovereignty by Design
BakeFrame is architected around the principle that your content is yours. Generated films, images, and audio stream directly to your own cloud storage (S3, R2, Azure, GCS) via BYOS — they are never stored on our servers. Your AI provider credentials are encrypted with AES-256-GCM and used only to proxy your requests to the providers you chose.
1. Who We Are
BakeFrame is a model-agnostic AI filmmaking platform built for creators, studios, and enterprises. For privacy inquiries, contact us at hello@bakeframe.art.
2. Data We Collect
Account data: Name, email address, and hashed password when you register.
API keys (BYOK): If you add AI provider credentials in Settings, they are encrypted at rest using AES-256-GCM with a server-side encryption key. Keys are decrypted only at request time to proxy calls to the provider you designate and are never logged or shared.
Project data: Scripts, character profiles, storyboard metadata, and project settings you create within the platform are stored in our database to provide the service.
Generated media: When BYOS is enabled (Bring Your Own Storage), all generated images, audio, and video are written directly to your storage bucket and are never stored on our servers. Without BYOS configured, temporary generated assets may be stored for up to 24 hours before deletion.
Demo and waitlist leads: If you submit the “Request a demo” form on the marketing site, we collect your name, email, company, and any message you provide. We also record the page URL and UTM attribution parameters present at the time of submission (e.g. utm_source, referrer) to understand how people discover BakeFrame. This data is used solely to respond to your inquiry and to measure marketing channel effectiveness. We will not add you to a mailing list without your consent.
Usage and analytics: We collect anonymized product usage events (page views, feature interactions) to understand how the platform is used and improve it. We do not sell this data.
Error tracking: We use Sentry to capture application errors. Error reports may include anonymized session context to help us diagnose issues.
Cookies: We use strictly necessary cookies for session authentication. We do not use third-party advertising cookies.
3. How We Use Your Data
We use collected data to:
- Provide, maintain, and improve the BakeFrame service
- Authenticate your account and keep it secure
- Route AI generation requests to your chosen providers using your encrypted API keys
- Send transactional emails (account confirmation, password reset)
- Respond to support requests
- Comply with legal obligations
We do not use your content to train AI models. We do not sell your data to third parties.
4. Data Sharing
We share data only in these circumstances:
- AI providers (your choice): When you configure BYOK, your prompts are forwarded to the provider(s) you selected (OpenAI, Anthropic, xAI, Gemini, Runway, etc.). Each provider's own privacy policy governs how they handle your requests.
- Cloud storage (your choice): Generated media is written to the storage provider you configure (AWS S3, Azure Blob, Cloudflare R2, GCS, Backblaze B2).
- Infrastructure providers: We use Vercel (hosting), MongoDB Atlas (database), and Sentry (error tracking). These providers process data under their own DPA agreements.
- Legal requirements: We may disclose data if required by law, court order, or to protect the safety of users or others.
5. Data Retention
Account data is retained for as long as your account is active. You may request deletion at any time — see Section 7. Encrypted API keys are deleted immediately upon removal from your Settings. Temporary generated assets (without BYOS) are automatically deleted within 24 hours.
6. Security
We protect your data with industry-standard safeguards: AES-256-GCM encryption for API keys, TLS in transit, bcrypt-hashed passwords, and role-based access controls. We conduct periodic security reviews and use automated error alerting to respond to incidents promptly.
No system is perfectly secure. If you discover a security vulnerability, please report it responsibly to hello@bakeframe.art.
7. Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you have the right to:
- Access a copy of your personal data
- Correct inaccurate data
- Delete your account and associated data
- Port your data in a machine-readable format
- Object to or restrict certain processing
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, email hello@bakeframe.art. We will respond within 30 days.
8. Children's Privacy
BakeFrame is not directed at children under 13 (or 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy as the service evolves. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect. The “Last updated” date at the top reflects the most recent revision.
10. Contact
For any privacy questions or requests, contact us at:
BakeFrame