Privacy Policy
Last updated: January 1, 2025
This Privacy Policy explains how Tomi Frame (“we,” “us,” or “our”) collects, uses, and protects information about you when you use our mobile companion app, hardware device, and website at tomiframe.com.
1. Information We Collect
Account Information
When you create an account, we collect your email address and a hashed password. If you sign in with Google, we receive your name, email address, and profile picture from Google.
Device Information
When you pair a Tomi Frame device, we store a unique device identifier, firmware version, and the time the device last contacted our servers. We do not collect your device's location.
Dashboard Configuration
We store the widgets, layout, and display preferences you configure in the companion app. This data is necessary to generate your dashboard image and sync settings to your device.
Third-Party Integrations
If you connect integrations (Google Calendar, Spotify, GitHub, Slack), we store OAuth access tokens encrypted with AES-256-GCM. We only request the minimum scopes needed to display information on your dashboard. We do not sell or share this data with any third party.
Usage and Technical Data
We collect standard server logs (IP address, request timestamps, HTTP status codes) for security and debugging. We do not use analytics SDKs or third-party tracking pixels.
2. How We Use Your Information
- To operate, maintain, and improve the Tomi Frame service
- To generate and deliver dashboard content to your device
- To send account-related emails (password reset, security alerts)
- To detect and prevent fraud or abuse
We do not use your data for advertising, and we do not sell your personal information to any third party.
3. Data Storage and Security
Your data is stored on servers hosted in the European Union and United States. OAuth tokens are encrypted at rest using AES-256-GCM. Passwords are hashed using bcrypt and never stored in plain text. All communications between your device, the app, and our servers use TLS encryption.
4. Data Retention
We retain your account data for as long as your account is active. You may delete your account at any time through the companion app (Settings → Delete Account), which permanently removes all associated data within 30 days.
5. Third-Party Services
We use the following third-party services to operate Tomi Frame:
- Railway — cloud hosting for the backend API
- Supabase — managed PostgreSQL database
- OpenWeatherMap — weather data for the weather widget
- CoinGecko — cryptocurrency price data (no account required)
Each of these services has its own privacy policy. We do not share personally identifiable information with them beyond what is technically required to operate the service.
6. Your Rights
Depending on your location, you may have the following rights:
- Access to the personal data we hold about you
- Correction of inaccurate data
- Deletion of your data (“right to be forgotten”)
- Portability of your data in a machine-readable format
- Withdrawal of consent for optional processing
To exercise any of these rights, contact us at privacy@tomiframe.com.
7. Children's Privacy
Tomi Frame is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice in the companion app. Your continued use of the service after changes constitutes acceptance of the revised policy.
9. Contact
If you have questions about this Privacy Policy, please contact us at:
Tomi Frame
privacy@tomiframe.com
tomiframe.com