Legal

Privacy policy

What Framulus does with personal data, described from what the software actually does rather than from what a product of this kind usually does.

LAST UPDATED 7 September 2026

01Who is responsible

The controller for the processing described here, within the meaning of Art. 4 No. 7 of the General Data Protection Regulation (GDPR), is:

Responsible for this website
To be providedthe full name the business is operated under (for a Kleingewerbe, the owner's first and last name)
Address
To be provideda summonable postal address: street and number, postal code, city, country
Contact for data protection
To be providedan address for data protection requests

No data protection officer has been appointed. The thresholds in Art. 37 GDPR and § 38 BDSG are not met by an operation of this size, and the contact above reaches the controller directly.

02Visiting the website

Framulus is hosted by To be providedthe company that hosts this deployment, with the country its servers are in. When you open a page, your browser sends the information any web request carries: your IP address, the address of the page requested, the time of the request, the referring page where your browser sends one, and your browser and operating system identifiers. This is processed by the hosting provider to deliver the page and to keep the service running and secure.

The legal basis is Art. 6 (1) (f) GDPR. The legitimate interest is operating a website that can be delivered at all and can be defended against attack. Framulus does not combine this information with your account, does not use it to build a profile, and does not analyse it for any purpose beyond operating the service.

Fonts are served from this website. Framulus downloads Instrument Sans, Instrument Serif and Geist Mono when it is built and delivers them from its own servers, so your browser makes no request to Google Fonts or to any other font host when a page is rendered.

03Your account

You need an account to use the editor. Creating one processes the following:

  • The email address and password you enter. The password is never stored: only a bcrypt hash of it is kept, and the original cannot be recovered from that hash.
  • A name and a profile image, where you provide them.
  • A verification code sent to your address, which is deleted as soon as it is used and expires after 15 minutes in any case. An account whose address has not been confirmed cannot sign in.
  • The number of failed sign-in attempts and the time of the last one, so an account can be locked temporarily after repeated failures.
  • If you switch on two-factor authentication, the shared secret your authenticator app is set up with, and a record confirming a successful second factor for the sign-in in progress.
  • The time from which previously issued sessions are refused, so that changing your password can end sessions on other devices.

The legal basis is Art. 6 (1) (b) GDPR: this processing is what providing you with an account consists of. The security measures within it, the lockout counters and the session cutoff, additionally rest on Art. 6 (1) (f) GDPR, the interest in accounts that cannot be taken over by guessing at passwords.

Signing in with Google

Framulus supports signing in with a Google account. If you use it, Google tells us the identifier of your Google account, your email address and your name, and we store the tokens that keep that link working. Where your account has a profile image, that image is loaded from Google’s servers when it is shown, so your browser contacts Google at that moment. Sign-in with Google happens only if you choose it; the legal basis is Art. 6 (1) (b) GDPR.

04The documents you make

Framulus stores the documents you create: their slides, the elements repeated across them, the design tokens they are written against, the templates you save, and the titles and timestamps that let them be listed. Anything you type into a document is stored as part of it, including personal data if you put personal data on a slide.

The legal basis is Art. 6 (1) (b) GDPR. Storing your documents is the service. They are not read for any other purpose, are not used to train anything, and are not published: a document is reachable by its owner, by anyone it has been shared with, and by members of the workspace it belongs to, and by nobody else. There is no public link that makes a document readable without an account.

Images and other assets you reference

A document can reference an image by its address rather than by uploading a file, and Framulus has no file upload at all. When a document that references a remote image is displayed or exported, the browser doing the displaying requests that image directly from whichever server you named. That request carries the IP address of whoever is viewing the document to that server, which is outside our control and follows from the address you chose.

Sharing and workspaces

You can give another Framulus user access to a project, and you can group projects into a workspace with members. Doing so looks the person up by the email address you enter and records that they hold access at a given level. If you share a project, the people you share it with can see its contents and the name of its owner. The legal basis is Art. 6 (1) (b) GDPR.

05Email we send you

Framulus sends two kinds of message and no others: the code that confirms your email address, and the link that resets your password. A reset link expires after one hour and is deleted the moment it is used. There is no newsletter, no product mail and no marketing list, so there is nothing to unsubscribe from.

The legal basis is Art. 6 (1) (b) GDPR for messages that are part of providing the account, and Art. 6 (1) (f) GDPR for the password reset, in the interest of letting you recover access to your own account.

06Abuse prevention

Sign-in, registration and password reset are rate limited. This counts requests against your IP address for the length of a 15 minute window and refuses further attempts once a threshold is passed. The counter holds your IP address and a number, expires by itself when the window ends, and is not linked to your account or used for anything else.

The legal basis is Art. 6 (1) (f) GDPR: the interest in a sign-in form that cannot be used to guess at other people’s passwords.

reCAPTCHA

The registration, sign-in and password reset forms are protected by Google reCAPTCHA v3, which distinguishes people from automated scripts. When you submit one of those forms, Google’s script collects your IP address together with browser and device information and how you interacted with the page, and returns a score. Framulus uses that score for exactly one thing: deciding whether to accept the submission. It is not stored, not attached to your account and not used for anything else.

reCAPTCHA is loaded only on those screens. It is not on the marketing site and not in the editor, so it observes nothing while you are working. There is no puzzle to solve and nothing is shown to you. The legal basis is Art. 6 (1) (f) GDPR: the interest in a registration form that cannot be driven by a script and a password reset that cannot be used to send mail to strangers. Google’s own privacy policy governs what they do with what they collect.

07Paying for a subscription

Framulus offers a paid Studio subscription. Payments are processed by Stripe, and how that works is worth stating precisely, because the most sensitive data involved never reaches us.

When you enter payment details, you are typing into a form served by Stripe and displayed inside the page. The card number, expiry and security code go directly from your browser to Stripe. Framulus never sees, receives or stores your card details. What we hold is an identifier for your Stripe customer record, an identifier for your subscription, which plan it is for, its status, when the current period ends, and whether it is set to cancel. For display we ask Stripe for the brand, the last four digits and the expiry month of the card on file.

Stripe receives your name and email address so it can create a customer record and issue invoices, the payment details you enter, and the location and tax details it needs to charge the correct amount. Stripe is a payment service provider in its own right and processes some of this to meet its own legal obligations, including anti-money-laundering and fraud prevention rules.

The legal basis is Art. 6 (1) (b) GDPR for everything necessary to provide the subscription you asked for, and Art. 6 (1) (c) GDPR for the records German commercial and tax law requires us to keep of a sale. If you never subscribe, none of this applies to you and no Stripe customer record is created for your account.

08Cookies and browser storage

Framulus sets no advertising cookies, no analytics cookies and no third-party cookies. Everything it stores on your device is listed here in full.

cookie
authjs.session-token (__Secure- prefixed over HTTPS)Keeps you signed in. It holds a signed token identifying your session and nothing else.30 days, or until you sign out
cookie
authjs.csrf-tokenProtects the sign-in and sign-out forms against cross-site request forgery.For the browser session
cookie
authjs.callback-urlRemembers the page you were trying to reach, so signing in returns you to it.For the browser session
cookie
__stripe_mid, __stripe_sidSet by Stripe to detect fraudulent payments and to keep a payment session together. Framulus cannot read them.__stripe_mid one year, __stripe_sid 30 minutes
cookie
_GRECAPTCHASet by Google's reCAPTCHA to tell people from automated scripts when one of those forms is submitted.Six months
localStorage
framulus:layout:v1Remembers how you arranged the editor's panels, so the workspace opens the way you left it.Until you clear your browser storage. This one stays in your browser and is never sent to us.
localStorage
framulus:guides:<project id>Remembers the layout guides you configured for one project: column count, gutter and margins.Until you clear your browser storage. This one stays in your browser and is never sent to us.

Every one of these is strictly necessary to provide the service you asked for, so § 25 (2) No. 2 TDDDG applies and no consent is required for any of them. That is why Framulus shows you no cookie banner: there is nothing here you could decline and still sign in, and a dialog asking permission for a session cookie would be asking a question with only one answer.

The two editor entries are settings you made yourself, in a tool you opened deliberately. They stay in your browser, are never transmitted, and you can remove them at any time by clearing site data for this website.

09Connecting a coding agent

Framulus can let a coding agent running on your own machine, such as Claude Code, edit an open document through the Model Context Protocol. This is worth describing precisely, because it is the part of the product that sounds as though it sends your work to an AI company.

It does not. Framulus holds no AI provider account, no model API key and no vendor SDK, and it sends nothing to any AI service. When you pair an agent, you start a session in your open editor tab and receive a pairing token. Your agent, running where you run it, uses that token to call the tools this application publishes, and the document is read and written on our servers in response to those calls. Whatever your agent then does with what it read is governed by the agent and by whichever provider you configured it with, and is a relationship between you and them that Framulus is not part of.

The pairing token authenticates one agent to one editor session. It is held in server memory only, is never written to a database, a document or a log, expires two hours after it was issued, and is not an API key for any model. A session ends when you close it or when the tab goes away. The legal basis is Art. 6 (1) (b) GDPR, as part of providing the editor.

10Who receives data

The following service providers process personal data on our behalf, as processors under Art. 28 GDPR. Each one is listed with what it actually receives.

Neon

Managed PostgreSQL database, where every account and every document is stored. Processing region: Europe (Frankfurt, eu-central-1).

  • account data (name, email address, password hash, profile image URL)
  • two-factor settings and secret, where two-factor authentication is switched on
  • sign-in attempt counters and lockout timestamps
  • the documents you create, their slides, master elements and design tokens
  • sharing and workspace membership records

Resend

Transactional email delivery.

  • your email address
  • the verification code or password reset link being sent to it

Upstash

Rate limiting, to stop repeated sign-in and registration attempts.

  • a counter keyed to your IP address, held for the length of the rate limit window

Google reCAPTCHA

Telling people from automated scripts on the registration, sign-in and password reset forms.

  • your IP address, taken by Google's own script when one of those forms is submitted
  • browser and device information, and interaction signals from the form page, which Google uses to produce a score

Google

Optional sign-in with a Google account.

  • the sign-in request itself, if you choose to authenticate with Google
  • a request for your profile image, if your account has one, because the image is loaded from Google's servers when it is displayed

Beyond these, personal data is disclosed only where we are legally required to disclose it. There is no other transfer, no sale, and no sharing with advertisers, data brokers or analytics companies.

Transfers outside the EU

Some of the providers above are established outside the European Economic Area or belong to groups that are. Where a transfer to a third country takes place, it requires a basis under Chapter V GDPR, which in practice means an adequacy decision or the European Commission’s standard contractual clauses in the data processing agreement with that provider. The specific basis in force for each provider depends on the contract concluded with them and must be stated here by the operator once confirmed.

11How long data is kept

Where the software itself sets a period, it is stated here exactly. Where it does not, the rule is the one Art. 5 (1) (e) GDPR requires: data is kept for as long as the purpose it was collected for lasts.

  • Account data and documents: for as long as your account exists. They are deleted when the account is.
  • Email verification codes: 15 minutes, or until used, whichever comes first.
  • Password reset links: one hour, or until used.
  • Rate limit counters: 15 minutes from the request that created them.
  • Agent pairing sessions: two hours, in memory only, and gone when the process restarts.
  • Sign-in session cookie: 30 days, or until you sign out.
  • Server logs: for the period the hosting provider retains them. This is set by that provider and not by Framulus.

Deletion is carried out on request, and it removes the account together with everything that references it in one operation: your projects and their slides, your templates, the record of any workspace membership, the access anyone held to your projects, your linked sign-in providers and any outstanding verification or reset codes. There is no soft delete and no recovery period, so the deletion is final.

12Your rights

Under the GDPR you have the following rights in respect of your personal data. Writing to the contact in section 01 is enough to exercise any of them, and no particular form is required.

  • Access (Art. 15): confirmation of whether we process data about you, and a copy of it.
  • Rectification (Art. 16): correction of anything inaccurate.
  • Erasure (Art. 17): deletion of your account and everything belonging to it. Write to the address above and it will be carried out.
  • Restriction (Art. 18) and data portability (Art. 20).
  • Objection (Art. 21): you may object at any time to processing based on Art. 6 (1) (f), which here means the security and abuse prevention measures described in sections 02 and 06.

You also have the right to complain to a supervisory authority (Art. 77 GDPR). In Germany you may address the authority of the federal state in which you live or work, or the one responsible for the controller.

13Changes to this policy

This policy describes Framulus as it is built today. It will be updated when the software changes what it does with data, and the date at the top of this page states when the wording last changed.

Who operates the service and how to reach them is set out in the Impressum.