Privacy Policy
Last updated: August 31, 2026
CloudFrame TV (“the app”) is a Roku application, operated by Francis Axis LLC (“Francis Axis,” “we,” “us”), that puts photos on your TV. This policy explains what data the app accesses, what we store, and how we protect it. We aim to access as little as possible and to keep your account credentials off your TV entirely.
There are two ways to use the app, and they handle your photos very differently. This policy covers them separately:
- Connecting a cloud account (Microsoft OneDrive). Your photos stay in your account; we store details about them, never the images. Covered in the sections immediately below.
- Casting from your phone. No account and no sign-in. You send photos to the TV through our infrastructure. This is the one feature where we do hold your actual photos: briefly, encrypted, and then deleted. See Casting from your phone.
What you can connect
To show your photos, CloudFrame TV asks you to connect a cloud storage account. We support Microsoft OneDrive (personal). You authorize the connection through Microsoft’s own sign-in page. You never enter your Microsoft password into our Roku app or our website.
What we access
-
Read-only access to your files. To connect to your OneDrive account,
we request the minimum permissions needed to list folders and read images:
Files.Read(read-only file access), plusoffline_access(so the connection can stay active without asking you to sign in repeatedly). The app cannot create, modify, or delete anything in your OneDrive account. - Our sign-in flow through Microsoft requests your account identifier and email address, so we can link your Microsoft login to the CloudFrame account.
- Basic OneDrive storage information needed to locate and display your photos.
What we store
- A connection token. When you authorize the app, Microsoft issues a refresh token that lets the app stay connected. We store this token on our secure backend (hosted on Cloudflare), so the app can fetch photos without asking you to sign in repeatedly. This token is never sent to your Roku device.
- A session token on your Roku. Your TV holds only a session identifier issued by us. It grants access to your photos through our backend and contains no Microsoft credentials. Your Roku also stores any configuration that has been modified in the app.
- A private catalog of your photo details. To make browsing fast and to power features like folder and album navigation and “On This Day,” we keep a catalog of information about your photos. We do not store your OneDrive photos themselves. This catalog stores file and folder names, your folder structure, item identifiers, image dimensions, the “date taken” and “date modified” timestamps, file types, and which albums a photo belongs to. It is stored on our Cloudflare backend, isolated per account and keyed by a one-way hash of your account identifier (we never store your raw account identifier as a lookup key).
We do not copy, archive, or store the photos in your connected cloud account. Image files are streamed from your cloud account to your TV as you view them — either redirected straight from Microsoft’s servers or resized on the fly by our backend and only briefly cached at the network edge. Only the catalog described above (details about your photos, not the images) is stored.
This applies to the photos you connect. Casting works differently — when you send photos from your phone, we do hold those images for a short time in order to show them on the TV. That is described next.
Casting from your phone
Casting lets anyone put photos on the TV from a phone browser, with no account and no sign-in. The TV shows a QR code and a short pairing code; opening it on a phone gives you a page to pick photos, which are then sent to the TV. It is deliberately temporary: the photos exist only for that session and are then deleted.
What we receive
- The photos you choose to send. This is the one place we hold your actual images rather than details about them.
- A resized copy is sent to us instead of your original file. Your phone resizes each photo (to about 1920 pixels on its longest side) and re-encodes it before it leaves the browser. We never receive your original full-resolution file, and because the copy is rebuilt from the image’s pixels, it carries no EXIF metadata. This means no GPS location, no camera or device details, no original timestamps are sent to us. We also do not receive the file’s name.
- Minimal technical details needed to display each photo: its width and height, its file type, its size in bytes, and the time it arrived.
-
A random session code (for example
K4XN-79FP) that identifies the TV’s casting session. It is generated at random, is not derived from you or your device, and stops working when the session ends.
Casting asks for no identifying information whatsoever: no account, no sign-in, no name or email, and no device identifier. A cast is not linked to any other CloudFrame session, including one signed in on the same TV. We cannot tell who sent a photo, and we cannot connect one cast to another.
How they’re stored
While a cast photo is on our backend it is encrypted at rest. Every photo is encrypted separately, with its own randomly generated key, before it is written to storage. That key is never kept with the image. It lives only in the temporary record for that casting session. The stored file on its own is therefore unreadable: not a photo anyone can open, just meaningless data with nothing on it to say what it ever was.
This is also what makes deleting a cast photo final. The session record holds the only copy of each encryption key, so ending a session destroys the keys with it, and the photo becomes permanently unreadable the moment that happens, before the file itself is even swept away. Deletion isn’t something we schedule and hope completes.
To be straight about what this does and doesn’t mean: your photos travel over an encrypted (HTTPS) connection, and our backend does handle each image itself, because it has to in order to receive it from your phone and send it to your TV. Encryption at rest means the copy we hold in between cannot be read out of storage — including casually by us, such as while investigating a technical problem. It is not end-to-end encryption, and we don’t claim it is.
The storage those photos briefly pass through is located in North America.
How long we keep it
Cast photos are deleted automatically. Whichever of these comes first:
- When you leave the Cast screen (press Back). The session and its photos are deleted immediately.
- About a minute after the TV stops responding. If the TV is switched off, returns to the Roku home screen, loses power, or drops off the network, we notice it has gone quiet and delete the session and its photos.
- One hour after the session started, in any case.
- A storage rule sweeps up anything the steps above somehow missed, within a day. Anything still waiting for that sweep is already unreadable since its key was destroyed when the session ended (see How they’re stored).
Cast photos are never archived, backed up, or added to any catalog, and they are not available anywhere except that TV session. Once deleted they are gone. We cannot recover them for you, so please don’t use casting as a way to store anything.
Who can see cast photos
Anyone who can see the TV, of course. Beyond that: while the Cast screen is open, anyone who has the pairing code or can scan the QR code can send photos to that TV. That is what lets a guest cast without an account. Treat the code like a door key: only share it with people you want putting photos on your screen, and press Back to end the session when you’re done. The code stops working the moment the session ends, and codes are randomly generated from a large enough space that they cannot realistically be guessed.
The code is a key for sending only. It does not let anyone see what has already been sent: fetching a session’s photos needs a second, separate credential that is issued once, to the TV that started the cast, and never shown on screen or given to a phone. So someone holding the code can put a picture on your TV, but cannot pull back the pictures already on it.
On our side, the photos are encrypted while we hold them and are never published anywhere: the only way to see one is through that TV’s live session. See How they’re stored.
Diagnostics
To keep the service working we keep short-lived technical logs recording that a session was created, joined, or deleted, and how many photos it held. These record the random session code and counts only — never your images — and are discarded after about a week. IP addresses are used momentarily to limit abuse of the casting endpoints; we do not store one alongside your photos.
We also count requests to keep an eye on errors and speed. Those counts are kept for about three months and are deliberately blunt: which kind of request it was (the casting session code is stripped out before anything is written), whether it succeeded, and how long it took. No images, no session codes, no IP address, and nothing that could pick out a person or a cast.
This website
Everything above is about the app. This website itself (cloudframe.tv) counts page views, so we can tell whether anyone is finding it. The counting happens on our server as the page is sent to you. There is no analytics script and no tracking pixel on any page here. Nothing is stored on your device, and there is nothing for a tracker blocker to block.
The sign-in and account pages run a small amount of our own JavaScript, and signing in uses cookies. One keeps you signed in: it holds a random identifier, no personal detail, and it is never read by any other website. It lasts thirty days, or until you sign out. The sign-in and OneDrive-linking steps each set a second, short-lived cookie that exists only for the few seconds of that step and is deleted the moment it finishes. All of them are ours alone and do nothing but make signing in work. That is a login, not tracking: no page of this site can follow you anywhere else, and the pages above still count a view exactly as anonymously as any other, with nothing recorded that could tie a view to your account.
More broadly, viewing a page here contacts nobody but us. Everything a page loads, including its styling, its images, even its typeface, comes from our own domain. Fonts are a common exception on other sites, because the usual way to use a web font quietly hands the font’s host the address of everyone who reads the page; ours are served by us instead. Links that lead off this site are of course still links — they take you to someone else’s site only when you choose to follow one.
For each page view, the entire record is:
- which page of this site it was;
- the country it came from — the country alone, never your IP address;
-
the site that linked you here, if any — just its name (for example
example.com), never the full address of the page you came from; - whether the visit looked like an automated crawler rather than a person;
- the time it happened.
That is all of it. We do not record your IP address, your browser or device details, or an identifier of any kind — so these entries are anonymous in the ordinary sense of the word, not merely stripped of names. Nothing in a record points to a person, and nothing links one record to another: we cannot tell that two page views came from the same visitor, follow anyone from one page to the next, or recognize you if you come back. They are counts, not visits by people we could name.
To be straight about one detail: Cloudflare, which delivers this site, necessarily sees your IP address in order to route the request to you, and the country above is worked out from it at that moment. We never receive or keep the address itself — only the two-letter country survives into anything we store.
We use this to answer questions like “did anyone read the privacy page?” It is not used for advertising, is never sold or shared, and cannot be combined with anything else to identify you, because there is nothing in it to combine.
Your CloudFrame account
You only need an account for the optional OneDrive photo library. Casting from your phone needs none, and never will.
An account holds exactly this:
- Your email address, from the Microsoft account you signed in with. We use it to recognize you when you come back, and to reach you if something about your library needs your attention. We do not add you to a mailing list.
- A link to your OneDrive, if you connect one. This connection is held as a token that lets our server read your photos. It stays on our server; it is never sent to your Roku, and your Roku never contacts Microsoft at all. You can disconnect it here at any time, which also deletes the catalog described below.
- Which Rokus you are signed in on, so you can see and remove them. We store the model name your Roku reports (for example “Roku Ultra”) so you can tell one from another. We do not store serial numbers or anything that identifies the device to anyone else.
- Your subscription status, if you subscribe to the OneDrive library: whether it is trialing, active, or ended, and when the current period ends. We use it only to know whether to unlock your library. The payment itself is handled by our merchant of record (see Billing and payments).
If you connect OneDrive we build a catalog of it. This contains file names, folders, dates and sizes. We do this so the Roku can browse your library without waiting. It is a list of what exists, not copies of your photos. The pictures themselves stay in OneDrive and are fetched only as they are shown. Disconnecting OneDrive deletes it. If you do not regularly use the Roku app, we’ll purge the catalog after 90 days of inactivity.
We never write to your OneDrive. Our access is read-only, so nothing there can be changed, moved, or deleted by us — including by mistake.
Billing and payments
The OneDrive photo library is a paid subscription. When you subscribe, payment is handled by our merchant of record, Polar (Polar Software, Inc.), not by us. You enter your card and billing details on Polar’s own secure checkout, and we never see or store your full card number.
From Polar we receive only what we need in order to know whether your library is unlocked:
- the status of your subscription (for example trialing, active, or cancelled) and when the current period ends;
- an identifier for your subscription, so we can match it to your account;
- the billing email you used, which is normally the email already on your account.
Polar collects and holds your payment and billing information (such as your card details, name, and the billing address or country needed to work out tax) as the seller of record. Its handling of that information is governed by Polar’s own privacy policy. On our side we store only the subscription status and identifiers listed above, alongside the rest of your account.
Checkout, and the billing portal where you update your card, view invoices, or cancel, are hosted by Polar. This website sets no payment cookies of its own.
What we don’t do
- We do not sell your personal data. We share it only with the service providers needed to run CloudFrame (see Third-party services and Billing and payments), and never for their own advertising.
- We do not show advertising.
- We do not track you across websites. This is true both in the app and on this site. The cookies we set exist only to sign you in and keep you signed in — never to track you. See the This website section.
- We do not use your photos, connected from OneDrive or cast, for analytics, profiling, or model training. We do not look at, scan, or index the content of cast photos.
- We do not keep cast photos after the session ends, and we do not back them up. Once a session ends we could not read those photos even if we wanted to. The keys are destroyed with it.
Third-party services
CloudFrame TV relies on Microsoft (for your OneDrive account and sign-in), Cloudflare (which hosts our backend), and Polar (our merchant of record for paid subscriptions, which processes payments and handles billing). Your use of those services is also governed by their respective privacy policies.
Disconnecting and deleting your data
Cast photos need no action from you. They are deleted automatically, and pressing Back on the Cast screen deletes them immediately. See Casting from your phone for the full schedule. Because casting is anonymous, there is no cast account to delete and nothing of yours left behind afterwards.
Your OneDrive connection belongs to your CloudFrame account, not to any one Roku, so you remove it from your account page on this site rather than from the app. Choosing Disconnect OneDrive deletes both the stored connection token and the entire photo-details catalog built from it, straight away.
Signing a Roku out is a different thing, and deliberately so. It revokes that TV’s access immediately, and it is the right button when you sell a set/device or lend one to a guest. It leaves your library connected for your browser and for any other Roku you are signed in on, so it does not delete the catalog. You can sign in on several Rokus with one account; they share a single catalog.
If your subscription ends (you cancel, or a payment ultimately fails), your signed-in TVs stop showing the OneDrive library. We keep the photo-details catalog for a short grace period (about 30 days) so that resubscribing restores your library without rebuilding it from scratch, and then delete the catalog. Your OneDrive connection and your account remain until you disconnect or delete them, or until the 90-day inactivity rule above takes effect.
Deleting your account removes all of it. The Delete your account button on your account page removes the account itself, the email address on it, your OneDrive connection, the photo-details catalog, and every Roku signed in to it immediately. Signing in again afterwards starts a new, empty account rather than restoring the old one. Your photos in OneDrive are not touched.
A few things outlive that deletion. Operational records, such as error logs and counters we keep to see whether the service is working, can mention a scrambled, one-way identifier for a library. This never contains your email address or your photos. They are not searchable back to you and they are discarded on their own schedule, within about three months. Photo files we have recently resized for a TV may also sit in a temporary cache for a matter of hours.
We also keep short-lived, encrypted backups of account data, so we can restore the service after a failure or a mistake. A backup can include your account details: your email address, your OneDrive connection, the list of Rokus you use, and your subscription status. It never includes your photos, your photo-details catalog, or your cast images. Backups are held on our Cloudflare backend and roll over on a cycle of about two weeks, so a copy of your data can survive in a backup for a short time after you disconnect OneDrive or delete your account, and then ages out on its own. We use backups only to bring the service back, never to restore an account you asked us to delete.
If you simply stop using CloudFrame TV, after 90 days with no Roku and no access to your library, we delete your account, your OneDrive connection and your catalog.
You can also revoke CloudFrame TV’s access from your Microsoft account’s app permissions page. That stops us reading your OneDrive from that moment on. However, it cannot reach into our storage and remove our copy of the (invalid) connection token. That copy is deleted when you press Disconnect or delete your account, and otherwise after 90 days of inactivity.
Children’s privacy
CloudFrame TV is not directed to children under 13 and does not knowingly collect personal information from them.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected by the “Last updated” date above.
Contact
CloudFrame TV is operated by Francis Axis LLC, a limited liability company based in the State of Maine, USA, which is responsible for the data described in this policy. Questions about this policy or your data? Email hello@cloudframe.tv.