Privacy Policy

How the Frame app and website handle the information you choose to share.

Frame App

When you enter a public wallet address in the app, Frame sends it to the Frame API to find public NFT information and artwork. The API obtains NFT data from OpenSea. The app saves your last wallet address and caches NFT and widget selections on your device so your gallery and widgets can display them.

Website Wallet Search

If you use the website's NFT collection search, Frame sends the public wallet address you enter to OpenSea to retrieve NFT information. We temporarily cache lookup results to make repeat searches faster. The website NFT endpoint also stores your IP address in a short-lived rate-limit counter, which expires after about two minutes.

Email Updates

If you sign up for updates on the website, Frame stores your email address to contact you about the app. We normalize email addresses to lowercase to prevent duplicate signups.

Hosting

The website runs on Cloudflare Pages. Cloudflare processes requests needed to serve the site and its signup and NFT lookup functions. The Frame API is reached through Cloudflare.

Storage

Frame's first-party API stores public wallet addresses, OpenSea NFT metadata, prepared artwork and image variants, and scan logs for repeat scans and widget images. After a successful full wallet scan, NFT records that OpenSea no longer returns or marks disabled are removed from the cache, and their prepared artwork is queued for deletion. Other wallet and NFT records, artwork, and scan logs have no fixed retention period and may remain indefinitely. The website keeps update emails in Cloudflare KV without an automatic expiration. The app also stores the last wallet address, NFT information, and widget selections on your device.

Questions and Data Requests

Email support@thrifa.io to ask about information Frame holds or request removal. Identify the subscribed email address for an update-email request or the relevant public wallet address for a wallet-cache request. A public wallet address by itself does not prove authority to delete a shared cache, so we may need to verify the request before manually modifying wallet data. There is no unauthenticated public wallet-cache deletion endpoint. Do not send a seed phrase or private key.