Nothing leaves
your Mac.
AnyFrame is designed with privacy as a product pillar. Screen content is processed entirely on‑device. No personal data is collected, transmitted, or shared with anyone — including us.
Last updated · April 30, 2026Data Controller
19 Finger GmbH
Mozartstr. 41
22083 Hamburg
Germany
E‑mail:
Overview
AnyFrame processes screen content entirely on your device. No personal data is collected, transmitted, or shared with anyone — including us.
Data collected when you visit this website
This website is hosted by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). When you visit anyframe.app, Cloudflare processes your IP address and standard HTTP request data (browser type, referring page, date/time) as part of delivering the website and protecting against abuse.
This processing is based on our legitimate interest in operating a secure and functional website (Art. 6 para. 1 lit. f GDPR). Cloudflare acts as a data processor under a Data Processing Agreement with us. For details on how Cloudflare processes personal data, see Cloudflare's Privacy Policy.
Transfer to the United States
Cloudflare is a company based in the United States. Delivering this website therefore involves a transfer of personal data (your IP address and request metadata) to the U.S. Cloudflare is certified under the EU‑U.S. Data Privacy Framework, which the European Commission has recognized as providing an adequate level of data protection (Adequacy Decision of 10 July 2023). The transfer is therefore lawful under Art. 45 GDPR. Where applicable, Cloudflare additionally relies on Standard Contractual Clauses pursuant to Art. 46 GDPR.
Log retention
Cloudflare retains access logs (raw HTTP request records) for up to seven days for abuse prevention and performance monitoring, after which they are aggregated and anonymized. We do not have access to these raw logs and do not store any additional log data on our own infrastructure.
We do not use cookies, analytics, tracking pixels, or any other tracking technology on this website. Cloudflare may set strictly necessary technical cookies (e.g., __cf_bm) for bot mitigation; these contain no personal identifiers and are exempt from consent under § 25 para. 2 no. 2 TTDSG.
Contacting us by e‑mail
If you reach out to us by e‑mail — for example via the "Email us" or any mailto: link on this site — we receive the data you voluntarily provide (typically your e‑mail address, name if included, and the content of your message). We use this data solely to answer your request (Art. 6 para. 1 lit. b GDPR for pre‑contractual / contractual enquiries, Art. 6 para. 1 lit. f GDPR for all other general enquiries on the basis of our legitimate interest in responding).
We store your message in our mailbox for as long as necessary to handle your request and to meet statutory retention obligations (typically up to six years under German tax / commercial law for business‑relevant correspondence), then delete it. Nothing is added to a mailing list unless you explicitly subscribe via a dedicated opt‑in.
E‑mail subscription for product updates (Brevo)
The landing page offers a "Stay in the loop" signup form so you can receive occasional e‑mails from us about new AnyFrame features, version updates, and any limited‑time offers. Submitting the form posts your e‑mail address, the locale identifier en, and your explicit opt‑in confirmation directly to our email service provider, Brevo (Sendinblue S.A.S., 106 boulevard Haussmann, 75008 Paris, France). No third‑party script, stylesheet, or cookie is loaded by this page to power the form; the form itself is plain HTML hosted on anyframe.app, and the submission is a single POST request to sibforms.com that runs only when you click "Subscribe".
Data processed: the e‑mail address you enter, the consent flag indicating you ticked the opt‑in box, and a timestamp recorded server-side by Brevo. We do not collect or transmit your name, IP address (beyond what Brevo automatically receives as part of any HTTPS request), or any other identifier.
Lawful basis: Art. 6 para. 1 lit. a GDPR — your explicit, freely given, revocable consent, captured via the ticked checkbox next to the e‑mail field. The checkbox is unchecked by default; you must actively tick it for the form to be submitted, and consent is not bundled with any other action on this site.
Double opt‑in: after you submit the form, Brevo sends a confirmation e‑mail to the address you entered. You are added to the mailing list only after you click the confirmation link in that e‑mail. If you do not confirm, your address is discarded by Brevo and never used to send anything further.
Purpose: to send you occasional product e‑mails about AnyFrame — typically a few per year covering new features, version updates, and limited‑time offers. We will not sell, rent, or share the list, and we will not use it for unrelated marketing.
Retention: we keep your e‑mail address on the subscriber list until you unsubscribe or request deletion. After unsubscription Brevo retains a hashed record of the address solely to honour the suppression list (so we don't accidentally re‑add you), which is itself a GDPR-required safeguard.
Recipient / processor: Sendinblue S.A.S. (operating under the Brevo brand) acts as our data processor under a Data Processing Agreement pursuant to Art. 28 GDPR. Brevo is headquartered in France and stores European customer data in the EU (primary data centres in France and Germany); no transfer of your personal data to a third country outside the EU/EEA takes place in connection with this form.
Right to withdraw: you may withdraw your consent at any time with effect for the future. Every e‑mail we send through Brevo includes a one-click unsubscribe link; you can also request deletion by writing to us at . Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
No profiling, no tracking: we do not track link clicks, opens, or any behavioural signal within these e‑mails. The list is used solely for the product communications described above.
Screen Recording permission (app)
AnyFrame requires macOS Screen Recording permission to function. This permission is used solely to capture and display a portion of your screen within the app's viewport window. Specifically:
- Screen content is rendered in real‑time within the viewport and is never recorded to disk.
- Screen content is never transmitted over any network.
- Screen content is never stored, cached, or logged.
- No screenshots or video files are created by the app.
Data collected by the app
AnyFrame collects no data whatsoever. This includes:
- No personal information
- No usage analytics or telemetry
- No crash reports (unless you opt in via macOS system preferences)
- No advertising identifiers
- No cookies or tracking of any kind
Local storage (app)
AnyFrame stores the following data locally on your Mac using macOS UserDefaults:
- Window position and size (so the viewport restores where you left it)
- Your saved presets (name, position, size)
- App preferences (click‑through mode, control bar visibility, etc.)
This data never leaves your device and is not accessible to us or any third party.
In‑app purchases
If you upgrade to AnyFrame Pro, the transaction is processed entirely by Apple through the App Store. We never receive your payment details — no credit card number, no billing address, no payment identifier. Apple provides the app with a signed entitlement token (via StoreKit 2's JWS‑verified transaction records) that only indicates whether you hold a valid Pro license. This token stays on your Mac; nothing is stored on our servers. See Apple's Privacy Policy for how Apple handles purchase data.
Third‑party services
AnyFrame uses no third‑party SDKs, analytics services, ad networks, or cloud services. The app operates entirely offline after installation, except for Apple's App Store framework, which handles in‑app purchases as described above.
Your rights under GDPR
Under the General Data Protection Regulation (GDPR), you have the following rights regarding personal data we process:
- Right of access (Art. 15 GDPR) — you may request information about whether and which personal data we process.
- Right to rectification (Art. 16 GDPR) — you may request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR) — you may request deletion of your data.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR).
- Right to object (Art. 21 GDPR) — you may object to processing based on legitimate interest.
Since AnyFrame collects no personal data, there is in practice nothing to access, correct, or delete. To exercise any of these rights or for questions about this policy, contact us at .
You also have the right to lodge a complaint with a supervisory authority. The competent authority for 19 Finger GmbH is the Hamburg Commissioner for Data Protection and Freedom of Information (datenschutz.hamburg.de).
Children's privacy
AnyFrame does not collect any data from anyone, including children under 13.
Changes to this policy
If we change this privacy policy, we will update this page with the new date. Given that AnyFrame collects no personal data, significant changes are unlikely.
Questions about privacy?
Reach a human in Hamburg — we answer every email.