Publication draft. The publisher must confirm remaining privacy details and review these terms before release.
Who is responsible
Chapterframe is published by StepSync Solutions LLC. Business mailing address: 21801 Gresham Street, West Hills, CA, United States. Contact support@chapterframe.ai about privacy questions, access requests, or deletion. This policy covers this website and the native Mac edition; the public web application is not yet available and will need disclosures for its hosted services before launch.
Your local creative library
The native Mac app stores chapter metadata, prompts, job records, and library settings in your local SQLite database. Audio, images, videos, and chapter files live in your selected media folder. Those files are used to organize, preview, edit, and produce your projects. A local library does not mean all generation happens locally.
When you use a generation provider
When you request a supported generation operation, the app sends the relevant prompts, reference images, audio, or other selected inputs to the provider or render server used for that operation. Which inputs are sent depends on the feature and workflow. Connections to hosted image services, Vast GPU management, and your render servers also transmit the credentials and request metadata needed to process the request.
The provider you select processes those requests under its own terms and privacy practices. Its retention, training, and deletion controls may differ from your local settings. Review them before submitting confidential or personal material. Removing a local file does not automatically delete a provider’s copy.
Credentials and connection data
The native app stores supported provider credentials in macOS Keychain. Connection settings, render identifiers, and status records let it connect to your chosen services and recover work. Vast management also keeps an SSH identity, known-host records, and rental/setup journals in its local application-support directory. Chapter transfer exports exclude provider keys.
Payments, subscriptions and refunds — Stripe
Stripe processes checkout, recurring payments, invoices, refunds and the customer billing portal. It receives the payment and billing information you enter, such as your name, email address, billing address and payment method, together with transaction and security information. We receive purchase, customer, invoice and subscription identifiers, payment amounts, currency and payment status to fulfill purchases, provide support and maintain records. We do not receive your full card number or card security code through our checkout. Stripe also processes information for its own payment, security and legal purposes. See Stripe’s privacy policy.
Licensing and device activation — Keygen
Keygen manages license issuance, activation limits, validation and updates coverage. Licensing records can include your purchase email, license key and identifiers, entitlement dates and activation history. The Mac app sends its license information, macOS platform, machine name and a device fingerprint derived from the Mac’s hardware identifier when activating or validating. Requests also expose network information such as an IP address to the service. These checks do not require sending your manuscript or media library. See Keygen’s privacy policy.
Purchase fulfillment and email automation — Zapier
We use Zapier to connect Stripe purchases and invoices with license creation or extension and transactional emails. Automation can process your name and email, Stripe invoice and subscription identifiers, amount and currency, license identifiers and keys, coverage dates, and workflow success or error information. Task history may retain these fields to diagnose failed fulfillment. These workflows do not need your manuscripts, prompts, recordings or rendered media. A license email is a service message, not consent to marketing. See Zapier’s privacy policy.
Optional Mac usage analytics — Google Analytics for Firebase
The Mac app integrates Google Analytics for Firebase to understand feature usage and improve the product. When collection is enabled, events describe screens and actions, built-in model or option choices, and counts such as selected takes. Firebase also processes an app-instance identifier and technical information such as app version, operating system and device information. We do not attach your name, email, license key, manuscript, prompts, recordings, images, typed text, project names, file paths, server addresses or provider credentials to these usage events. Advertising storage and personalization are disabled. See Firebase privacy information and Google’s privacy policy.
The consent-enabled Mac update keeps analytics off and does not initialize Firebase until you choose to share. It offers Share Usage Analytics and Don’t Share, including for users upgrading from an earlier version. You can refuse without losing app features and withdraw consent in Settings → Analytics. Turning sharing off stops future collection and resets local analytics data; it does not automatically erase events already received by Google. Earlier releases enabled analytics by default and did not show this prompt: users of those versions should turn sharing off in Settings → Analytics or install the consent-enabled update when available.
Why we process information
Where GDPR or similar rules apply, we rely on performance of our contract for purchase fulfillment, licensing and requested support; legal obligations for records we must keep; and legitimate interests for proportionate security, fraud prevention and service troubleshooting, subject to your rights. Optional product analytics and optional marketing use consent. You can withdraw consent without affecting processing lawfully carried out before withdrawal.
Service providers and international processing
Stripe, Keygen, Zapier, Google, our hosting and email providers, and the generation services you choose may process data outside your country, including in the United States. Roles and processing locations depend on the service. Where required by law, international transfers must use an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses. Contact us for information about the arrangements applicable to your data; this policy does not claim that all providers store data in your region.
This website
This site contains no advertising scripts, analytics SDKs, tracking pixels, or tracking cookies. Its cost calculator and workflow demonstration run in your browser. The support form prepares a local email draft; the website does not receive its contents.
Website hosting can process IP addresses, requested URLs, timestamps, and browser or device metadata for delivery and security. Hosting provider: Cloudflare. Hosting-log retention: Depends on the Cloudflare service and log settings. Contact support for the retention applicable to a specific request.. See Cloudflare’s privacy policy.
Support messages
If you email support, the publisher and its email service receive your address, message, and any attachments you send. These are used to respond to your request and investigate the issue. Do not include API keys, passwords, or unnecessary private source material. Support retention: 2 years after the support conversation closes, unless a legal obligation or unresolved dispute requires longer retention.
Retention and deletion
Your local library remains until you delete it or its contents. Generated versions, exports, backups, Keychain items, and remote provider data may exist separately and require separate removal. Uninstalling the app does not necessarily remove its data or stop remote rentals. Our data and choices page explains these separate locations and how to request help.
Business and provider retention
We retain purchase, license, subscription and refund records for as long as needed to administer your license, resolve disputes and meet applicable accounting or legal obligations. Support emails are retained for two years after the conversation closes, unless needed longer for legal obligations or an unresolved dispute. Google Analytics documents a default two-month retention period for detailed event data used in explorations; standard properties can instead be configured for 14 months. Standard aggregated reports are not subject to that same deletion period, and user-identifier retention can reset with new activity. See Google’s default retention guidance and retention controls. Zapier documents standard Zap content and history retention of 29–69 days, with shorter configurable periods on eligible plans; see Zapier’s retention policy. These are documented provider defaults and options, not verification of our account settings. Contact us for the settings applicable to your records and to request deletion. Deleting local app data does not delete provider records. Where retention is required by law, we retain only the information needed for that purpose.
Your choices and requests
You choose the source material, configured services, and generation actions. You can stop using a provider, remove its saved credentials, revoke its API keys through that provider, or remove local projects. Contact us to request access, correction, or deletion of information held by the publisher. Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy of your data, withdraw consent, and complain to your local data-protection authority. We may need to verify your request before acting. Request deletion of analytics or automation records through support; do not send passwords or full payment details.
Changes
We will update this page when the product or its data handling changes and identify the latest revision date. New hosted features require updated disclosures before they become available.