Back to the fun

Privacy Policy

This policy explains how First in Frame processes personal data in the app, private hunts, support and public website.

1. Dates

Effective date: 7 October 2026. Last updated: 7 October 2026.

2. Information and purposes

We process your chosen name, bundled avatar, preferences, guest/session ID, rooms, photos, votes, scores, reports, purchase records and technical information to provide and protect the game. We do not require an email login, legal name or birth date. Support email includes what you send. Where applicable, necessary service processing relies on the contract; optional analytics on consent; proportionate security on legitimate interests where permitted; and mandatory records on legal obligations. Our email provider processes support email.

3. Camera and sharing

Submissions are fresh camera photos, resized and re-encoded without original metadata. Camera and export permissions are requested when needed. We do not request precise location, contacts or microphone access for gameplay. Participants see your name, avatar, results and eligible photos. Only your own eligible photos can be exported; scoreboards include players’ names and scores. Screenshots and copies shared outside the service cannot be recalled by deletion. Avoid photographing people without permission, private documents or sensitive screens.

4. AI and service providers

Our hosting provider hosts the backend and private media. Our AI processing provider checks submitted photos for safety and object matches. We request no stored response and do not opt in to training or data sharing. We do not use face recognition. AI can make mistakes; eligible matching disputes use room voting. Our AI processing provider may retain abuse-monitoring data normally up to 30 days, with safety-review or legal exceptions for flagged images. Providers may process data abroad, including in the United States. You can email us for the names of the providers that receive your data and information about processing countries, retention and applicable international-transfer safeguards.

5. Purchases

The app store handles payment; we do not receive full card details. Our purchase-validation provider and our backend use guest IDs and transaction/access records to deliver and restore purchases. Store history can remain after deletion.

6. Optional usage sharing

Usage sharing starts off. If you enable it, our optional analytics provider receives a separate random installation ID and limited usage events; our optional error-reporting provider receives scrubbed JavaScript error reports. These optional streams exclude photos, player names, room codes and report details. Automatic capture, session replay and advertising tracking are disabled. You can turn sharing off in Settings; this stops future collection, not previously sent data. Essential security processing continues. We do not sell personal data or use it for targeted advertising.

7. How long data stays

Ordinary room photos expire one hour after a match. Temporary device photos are cleared on normal exit, or within 24 hours after interrupted flows. Reported photo evidence stays at most 30 days. Compact match records generally stay 30 days; non-photo reports and access audits up to 365 days. Detailed application logs use seven days and operating counters 30 days. Eligible inactive guests are removed after 365 days, except purchase or unresolved enforcement records. Analysis by our optional analytics provider defaults to 12 months, but the current plan can keep events queryable for seven years; our optional error-reporting provider uses 30 days. Limited legal, purchase, backup, support and deletion records may remain. Some hashed erasure markers have no automatic expiry.

8. Your rights and deletion

Email [email protected] for access, correction, deletion, portability, objection, restriction, consent withdrawal or review of automated decisions, where your law provides these rights. Include your saved Support ID if available; never send credentials or sensitive photos. We may verify only what is necessary to locate and protect your data. You can also use Settings → Delete My Data after leaving a room. Local cache clearing is different from server deletion. Provider erasure may finish asynchronously; lawful retained records and other people’s exports can remain. You may complain to ANPD or your local privacy authority.

9. Underage users

First in Frame is intended for people aged 18 or older. Continuing confirms that age; the app does not verify it or collect a birth date. If someone under 18 uses the app, or a child’s personal information is submitted, email [email protected]. We will investigate, restrict access and remove data as required by law.

10. Security and changes

We use encrypted transport, restricted media access and limited report-review access, but cannot guarantee absolute security. The website uses language preferences without analytics scripts or language cookies; hosting processes network metadata. We update the effective date and last-updated date on every change and give legally required notice or seek renewed consent for material changes. The app and website show the same policy.

11. Contact

Vitor Quadros
[email protected]