Privacy Policy
Last updated: 8 October 2026
This Privacy Policy explains how Tomi Frame (“we,” “us,” or “our”) collects, uses, and protects information about you when you use our mobile companion app, hardware device, and website at tomiframe.com. A Turkish version is also published.
The data controller is Tamara Midas Özlü, who runs Tomi Frame, and “we” below refers to her. Tomi Frame is her sole proprietorship (Gevher Nesibe tax office, Kayseri; in business since 6 October 2026). Address: Gevher Nesibe Mah. İstasyon Cad. A ve B Blok Sütsever Apt. No: 55 A İç Kapı No: 12, Kocasinan / Kayseri, Türkiye.
1. Information We Collect
Waitlist
If you join the waitlist, we store your email address and the date you joined. That is the entire record — no name, no location, no tracking identifier. We use it for exactly one thing: to email you when pre-orders open. It is never used for marketing beyond that, never sold, and never shared. You can have your address removed at any time by emailing hi@tomiframe.com, and joining the waitlist does not create an account.
Retention periods, the legal basis, and the same information in Turkish are set out in the Waitlist Privacy Notice / KVKK Aydınlatma Metni.
Account Information
When you create an account, we collect your email address and a hashed password. If you sign in with Google, we receive only your email address from Google. If you sign in with Apple, we receive the email address Apple shares (which may be Apple's private relay address) and an identifier Apple issues so we can recognise your account. We do not ask for your name or profile picture.
Device Information
When you pair a Tomi Frame device, we store a unique device identifier, firmware version, and the time the device last contacted our servers. We do not collect your device's location.
Dashboard Configuration
We store the widgets, layout, and display preferences you configure in the companion app. This data is necessary to generate your dashboard image and sync settings to your device.
Photos
If you use photo mode, only the photo you choose from your library or take in the app is uploaded to our server, converted into a black-and-white e-ink image for your frame, and stored in that form with your account. We do not access the rest of your photo library. The photo is deleted when you remove it in the app or delete your account.
Step Count (Apple Health / Health Connect)
If you add the step-count widget, the app reads, with your permission, only today's total step count from Apple Health or Android Health Connect on your phone and sends it to our server to show on your frame. No other health data is read, and nothing is written to health data. The step count is not stored in our database; it is held in temporary memory for at most 36 hours and then deleted automatically. Health data is never used for advertising, marketing or profiling and is never shared with third parties. Because the step count is health data, the app asks for your explicit consent before the phone's permission sheet; you can withdraw it at any time in the app under Settings → Step data, and the stored value is deleted at once. Details are in the App Privacy Notice.
Third-Party Integrations
If you connect integrations (Google Calendar, Spotify, GitHub, Slack), we store OAuth access tokens encrypted with AES-256-GCM. We only request the minimum scopes needed to display information on your dashboard. We do not sell or share this data with any third party.
Usage and Technical Data
We collect standard server logs (IP address, request timestamps, HTTP status codes) for security and debugging. We do not use analytics SDKs or third-party tracking pixels.
2. How We Use Your Information
- To operate, maintain, and improve the Tomi Frame service
- To generate and deliver dashboard content to your device
- To send account-related emails (password reset, security alerts)
- To detect and prevent fraud or abuse
We do not use your data for advertising, and we do not sell your personal information to any third party.
3. Data Storage and Security
Your data is stored with Amazon Web Services on servers in Türkiye (Istanbul). OAuth tokens are encrypted at rest using AES-256-GCM. Passwords are hashed using bcrypt and never stored in plain text. All communications between your device, the app, and our servers use TLS encryption.
4. Data Retention
We retain your account data for as long as your account is active. You may delete your account at any time through the companion app (Settings → Delete Account) — or, without the app, by request — which permanently removes all associated data within 7 days.
5. Third-Party Services
We use the following third-party services to operate Tomi Frame:
- Amazon Web Services — server and database (Türkiye, Istanbul)
- Resend — email delivery
- A licensed payment institution — card payments for orders in Türkiye (we never store card details)
- Paddle — reseller and Merchant of Record for BYOD licences sold outside Türkiye; it processes payment details itself
- OpenWeatherMap — weather data for the weather widget
- CoinGecko — cryptocurrency price data (no account required)
Each of these services has its own privacy policy. We do not share personally identifiable information with them beyond what is technically required to operate the service.
6. Your Rights
Depending on your location, you may have the following rights:
- Access to the personal data we hold about you
- Correction of inaccurate data
- Deletion of your data (“right to be forgotten”)
- Portability of your data in a machine-readable format
- Withdrawal of consent for optional processing
To exercise any of these rights, contact us at privacy@tomiframe.com. If you are in Turkey you may also complain to the Kişisel Verileri Koruma Kurumu; in the EU or UK, to your national data protection authority.
7. Children's Privacy
Tomi Frame is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice in the companion app. Your continued use of the service after changes constitutes acceptance of the revised policy.
9. Contact
If you have questions about this Privacy Policy, please contact us at:
Tomi Frame
privacy@tomiframe.com
tomiframe.com