NanaFrame Privacy Policy
Effective: July 11, 2026 · Last updated: July 15, 2026 (anonymous usage analytics section added).
What we collect
- A Google or Apple account subject identifier for parent account authentication.
- Family group names, invitation status, and display names needed to deliver the private family service.
- Photos and optional captions uploaded by parents. Photos are re-encoded as JPEG on your device before upload, so EXIF metadata (including GPS location) is removed from both the original and the thumbnail.
- Device binding hashes, delivery receipts, hearts, push tokens, and the device language (used to send notifications in your language) needed for secure receiver access and notifications.
Who can see family photos
Only active members of the invited family group. NanaFrame has no public feed, discovery, public profiles, or public photo links. Photo objects are private and are retrieved only through short-lived signed URLs.
Retention and deletion
A parent can delete a photo or account in the app. Photo deletion removes the original and thumbnails and invalidates receiver deliveries and widget caches. Account deletion removes the parent's uploads and membership; groups with no remaining parent are removed. A parent may remove a receiver at any time, immediately ending access.
Anonymous usage analytics
To improve the product we collect a minimal set of anonymous usage statistics.
- What we collect: a small number of in-app action events (for example: onboarding completed, photo sent, first photo delivered to a grandparent's home screen, review prompt shown).
- What we do not collect: your account identity, your photos or captions, your location, IP-based location, or advertising identifiers. Analytics events are not linked to your account — we do not create user profiles for analytics.
- Processor: PostHog, Inc. (data stored on servers in the United States).
- These statistics are never used for tracking across apps or websites, and never for advertising.
- Grandparents (receivers): the analytics events above are sent from the parent side of the app only.
Third parties
We do not sell personal data. Beyond the analytics processor named above, we share data only with the infrastructure providers required to run the service (cloud hosting and push notification delivery by Apple and Google).
Contact
kkhdevs@gmail.com