PRIVACY POLICY · LAST UPDATED JULY 27, 2026

Visual context is your choice.

This policy explains how Framnova handles webpage captures, optional page context, consent-based website analytics, billing, and Direct MCP sync.

Important: screenshots and page context can contain personal or confidential information. Capture and share only material you are authorized to handle, and review every selected set before external delivery or hosted sync.

01

Scope

This policy applies to the Framnova Chrome extension, website, billing activation pages, and Direct MCP services. Third-party AI websites, AI clients, Chrome, and payment providers apply their own privacy terms to the parts of the workflow they control.

02

Data Framnova may handle

For a capture workflow, Framnova may handle content you explicitly select: screenshot images, a sanitized page title and origin, selected-element structure and styles, design tokens, asset references, capture notes, and queue metadata. The extension also stores preferences, consent state, and—if configured—the Direct MCP endpoint and Token.

For Pro billing, Framnova may receive checkout, customer, subscription, plan, status, and provider identifiers. Full payment-card details remain with the hosted payment provider.

03

Default local storage

Original captures and their queue are stored in the Chrome profile by default. After website access is granted, Framnova’s lightweight content script can load on regular pages to check whether the optional quick dock is enabled and to receive explicit capture actions. It does not continuously scan page content or collect browsing history for behavioral advertising. You can disable the dock, remove captures, clear the queue, remove an MCP connection, or revoke website access in Chrome.

04

When selected content leaves the browser

Framnova transfers selected content only to provide a user-facing delivery feature you invoke or separately enable.

1

Web AI attachment

The selected originals are prepared for the supported AI website you choose. That provider then handles the content under its own policy.

2

Local MCP export

The selected set is written to the workspace folder you choose on your device.

3

Direct MCP sync

The selected set and approved context are sent to the Token-scoped hosted endpoint after manual sync or intentionally enabled automatic sync.

05

Direct MCP service

Direct MCP uses HTTPS and the Pro Token configured by the user. Hosted Framnova infrastructure processes and stores synced capture sets in a Token-scoped workspace so an authenticated compatible MCP client can retrieve them. Automatic sync is off by default and can be disabled in extension settings.

Do not enable hosted sync for content you do not want stored remotely. You can delete one hosted set at a time from the self-service deletion page using its capture-set ID and the owning Pro Token. The page does not store the Token.

06

How data is used and shared

Framnova uses this data to provide and secure capture, visual-context, attachment, export, billing, and MCP features. Selected webpage content is not sold or used for behavioral advertising.

Data is shared only with services needed for the user-selected action, such as the AI destination, configured MCP route, payment provider, and infrastructure providers hosting Framnova. Framnova does not grant people routine access to capture content.

07

Consent-based website analytics

Google Analytics 4 is off by default on the Framnova website. It loads only after you choose “Allow analytics,” and your choice is stored locally in this browser. If enabled, it helps Framnova understand public-page visits and engagement using a page path without query parameters or fragments, the referring site’s origin, page title, browser and device information, approximate region, and interaction measurements supported by Google Analytics. Google Analytics may set _ga and _ga_* browser identifiers for up to 90 days from consent; Framnova configures those cookies not to renew on each page load.

Framnova does not configure analytics events to send screenshots, page DOM or CSS context, Pro Tokens, recovery keys, checkout identifiers, capture-set identifiers, URL queries, or form values. The analytics tag is not included on billing success, billing management, Token recovery, hosted-set deletion, or unknown 404 routes. Google receives network information such as the IP address needed to deliver and secure its analytics service, may process analytics data in countries where Google operates, and handles it under the Google Privacy Policy. User-level event retention follows the GA4 property setting; aggregated reports may remain available for longer.

You can withdraw or change your choice at any time. Turning analytics off prevents the tag from loading on the next page load and removes Framnova’s Google Analytics cookies where the browser permits. Withdrawal stops future collection but does not retroactively remove events already processed in aggregate reports.

08

Security and retention

Local captures remain in the Chrome profile or workspace until removed by the user. Hosted capture sets remain in the Direct MCP storage needed to provide retrieval. A precise default hosted-retention schedule has not yet been published, so users should not sync material requiring a specific retention guarantee. See the Security page for current controls and limitations.

09

Your choices and requests

You can decline website access, avoid external AI delivery or hosted sync, keep automatic sync off, clear local captures, revoke Chrome access, remove stored MCP configuration, and delete a hosted capture set. For requests not covered by self-service controls, follow the support instructions or contact the privacy mailbox below.

support@framnova.com Monitored privacy contact · identify the relevant checkout or capture-set without sending a Token
10

Changes to this policy

This policy may be updated when functionality, providers, retention, or data practices change. The last-updated date at the top identifies the current published version. Material changes should be disclosed where required by law.