Tomi FrameGet the App
← Back to home

Privacy Policy

Last updated: January 1, 2025

This Privacy Policy explains how Tomi Frame (“we,” “us,” or “our”) collects, uses, and protects information about you when you use our mobile companion app, hardware device, and website at tomiframe.com.

1. Information We Collect

Account Information

When you create an account, we collect your email address and a hashed password. If you sign in with Google, we receive your name, email address, and profile picture from Google.

Device Information

When you pair a Tomi Frame device, we store a unique device identifier, firmware version, and the time the device last contacted our servers. We do not collect your device's location.

Dashboard Configuration

We store the widgets, layout, and display preferences you configure in the companion app. This data is necessary to generate your dashboard image and sync settings to your device.

Third-Party Integrations

If you connect integrations (Google Calendar, Spotify, GitHub, Slack), we store OAuth access tokens encrypted with AES-256-GCM. We only request the minimum scopes needed to display information on your dashboard. We do not sell or share this data with any third party.

Usage and Technical Data

We collect standard server logs (IP address, request timestamps, HTTP status codes) for security and debugging. We do not use analytics SDKs or third-party tracking pixels.

2. How We Use Your Information

  • To operate, maintain, and improve the Tomi Frame service
  • To generate and deliver dashboard content to your device
  • To send account-related emails (password reset, security alerts)
  • To detect and prevent fraud or abuse

We do not use your data for advertising, and we do not sell your personal information to any third party.

3. Data Storage and Security

Your data is stored on servers hosted in the European Union and United States. OAuth tokens are encrypted at rest using AES-256-GCM. Passwords are hashed using bcrypt and never stored in plain text. All communications between your device, the app, and our servers use TLS encryption.

4. Data Retention

We retain your account data for as long as your account is active. You may delete your account at any time through the companion app (Settings → Delete Account), which permanently removes all associated data within 30 days.

5. Third-Party Services

We use the following third-party services to operate Tomi Frame:

  • Railway — cloud hosting for the backend API
  • Supabase — managed PostgreSQL database
  • OpenWeatherMap — weather data for the weather widget
  • CoinGecko — cryptocurrency price data (no account required)

Each of these services has its own privacy policy. We do not share personally identifiable information with them beyond what is technically required to operate the service.

6. Your Rights

Depending on your location, you may have the following rights:

  • Access to the personal data we hold about you
  • Correction of inaccurate data
  • Deletion of your data (“right to be forgotten”)
  • Portability of your data in a machine-readable format
  • Withdrawal of consent for optional processing

To exercise any of these rights, contact us at privacy@tomiframe.com.

7. Children's Privacy

Tomi Frame is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice in the companion app. Your continued use of the service after changes constitutes acceptance of the revised policy.

9. Contact

If you have questions about this Privacy Policy, please contact us at:

Tomi Frame
privacy@tomiframe.com
tomiframe.com