Privacy & processing.
Local file checks happen in your browser. They do not automatically send your photos to our servers.
What is sent, and when
If you choose to upload, we receive your selected photo, optional SKU, filename, image role and account identifier. We use them to check, process and deliver that batch. Firebase provides Google and email authentication when connected. Payment is handled by the configured hosted payment provider; SkuFrame does not receive your full card number.
Processing permission
You must own or have permission to process the photographs. Your processing consent is for the selected service, not marketing, public examples or training. No customer photo is displayed as a public example without separate permission. Each uploaded photo records the processing notice version, account owner and consent time. You must confirm the upload permission in the workspace before files are sent.
External services
When AI processing is enabled, product images are sent to the approved background-segmentation provider. Storage, account authentication, payment and segmentation are separate services. Their settings, retention and data locations must be verified before live processing. We do not claim data stays in a particular country or that every provider excludes training merely because our application does.
Connections that are not configured are unavailable. You can see the public connection status. Runtime checks still apply to each request.
Retention
| Data | Retention design |
|---|---|
| Local file checks | Not uploaded or stored on our server. |
| Free sample originals and previews | 24 hours after upload. A payment can unlock eligible downloads; it does not extend a free file’s lifetime. |
| Paid task originals, masks, results and ZIP files | 7 days after terminal task state. Download your files promptly. |
| Task reports and ordinary technical metadata | Kept for service delivery, recovery and security until the configured cleanup runs. Minimum references needed for financial records are kept separately; this initial notice does not claim a fixed metadata deletion deadline. |
| Financial records | Kept separately where required for accounting, payment disputes and unused credit obligations. |
Deletion and security
Deleting a batch stops new access and cancels eligible pending work. Primary storage cleanup is targeted within 24 hours. Previously issued short-lived links and external processors may have their own deletion windows. Financial records and necessary security records may be retained. Unused credits are not deleted simply because your photos are deleted.
Photo storage is private. Authenticated requests check ownership. Do not upload identity documents, bank cards, medical records or sensitive personal material: this first release is for product photographs.
Questions about your data
Use the support page for the available account and order actions. Before a live service accepts uploads, its operator and approved processing-service details must be made available. This initial release notice does not substitute for those disclosures.