CloudFrame TV
← Back to home

Privacy Policy

Last updated: August 31, 2026

CloudFrame TV (“the app”) is a Roku application, operated by Francis Axis LLC (“Francis Axis,” “we,” “us”), that puts photos on your TV. This policy explains what data the app accesses, what we store, and how we protect it. We aim to access as little as possible and to keep your account credentials off your TV entirely.

There are two ways to use the app, and they handle your photos very differently. This policy covers them separately:

What you can connect

To show your photos, CloudFrame TV asks you to connect a cloud storage account. We support Microsoft OneDrive (personal). You authorize the connection through Microsoft’s own sign-in page. You never enter your Microsoft password into our Roku app or our website.

What we access

What we store

We do not copy, archive, or store the photos in your connected cloud account. Image files are streamed from your cloud account to your TV as you view them — either redirected straight from Microsoft’s servers or resized on the fly by our backend and only briefly cached at the network edge. Only the catalog described above (details about your photos, not the images) is stored.

This applies to the photos you connect. Casting works differently — when you send photos from your phone, we do hold those images for a short time in order to show them on the TV. That is described next.

Casting from your phone

Casting lets anyone put photos on the TV from a phone browser, with no account and no sign-in. The TV shows a QR code and a short pairing code; opening it on a phone gives you a page to pick photos, which are then sent to the TV. It is deliberately temporary: the photos exist only for that session and are then deleted.

What we receive

Casting asks for no identifying information whatsoever: no account, no sign-in, no name or email, and no device identifier. A cast is not linked to any other CloudFrame session, including one signed in on the same TV. We cannot tell who sent a photo, and we cannot connect one cast to another.

How they’re stored

While a cast photo is on our backend it is encrypted at rest. Every photo is encrypted separately, with its own randomly generated key, before it is written to storage. That key is never kept with the image. It lives only in the temporary record for that casting session. The stored file on its own is therefore unreadable: not a photo anyone can open, just meaningless data with nothing on it to say what it ever was.

This is also what makes deleting a cast photo final. The session record holds the only copy of each encryption key, so ending a session destroys the keys with it, and the photo becomes permanently unreadable the moment that happens, before the file itself is even swept away. Deletion isn’t something we schedule and hope completes.

To be straight about what this does and doesn’t mean: your photos travel over an encrypted (HTTPS) connection, and our backend does handle each image itself, because it has to in order to receive it from your phone and send it to your TV. Encryption at rest means the copy we hold in between cannot be read out of storage — including casually by us, such as while investigating a technical problem. It is not end-to-end encryption, and we don’t claim it is.

The storage those photos briefly pass through is located in North America.

How long we keep it

Cast photos are deleted automatically. Whichever of these comes first:

Cast photos are never archived, backed up, or added to any catalog, and they are not available anywhere except that TV session. Once deleted they are gone. We cannot recover them for you, so please don’t use casting as a way to store anything.

Who can see cast photos

Anyone who can see the TV, of course. Beyond that: while the Cast screen is open, anyone who has the pairing code or can scan the QR code can send photos to that TV. That is what lets a guest cast without an account. Treat the code like a door key: only share it with people you want putting photos on your screen, and press Back to end the session when you’re done. The code stops working the moment the session ends, and codes are randomly generated from a large enough space that they cannot realistically be guessed.

The code is a key for sending only. It does not let anyone see what has already been sent: fetching a session’s photos needs a second, separate credential that is issued once, to the TV that started the cast, and never shown on screen or given to a phone. So someone holding the code can put a picture on your TV, but cannot pull back the pictures already on it.

On our side, the photos are encrypted while we hold them and are never published anywhere: the only way to see one is through that TV’s live session. See How they’re stored.

Diagnostics

To keep the service working we keep short-lived technical logs recording that a session was created, joined, or deleted, and how many photos it held. These record the random session code and counts only — never your images — and are discarded after about a week. IP addresses are used momentarily to limit abuse of the casting endpoints; we do not store one alongside your photos.

We also count requests to keep an eye on errors and speed. Those counts are kept for about three months and are deliberately blunt: which kind of request it was (the casting session code is stripped out before anything is written), whether it succeeded, and how long it took. No images, no session codes, no IP address, and nothing that could pick out a person or a cast.

This website

Everything above is about the app. This website itself (cloudframe.tv) counts page views, so we can tell whether anyone is finding it. The counting happens on our server as the page is sent to you. There is no analytics script and no tracking pixel on any page here. Nothing is stored on your device, and there is nothing for a tracker blocker to block.

The sign-in and account pages run a small amount of our own JavaScript, and signing in uses cookies. One keeps you signed in: it holds a random identifier, no personal detail, and it is never read by any other website. It lasts thirty days, or until you sign out. The sign-in and OneDrive-linking steps each set a second, short-lived cookie that exists only for the few seconds of that step and is deleted the moment it finishes. All of them are ours alone and do nothing but make signing in work. That is a login, not tracking: no page of this site can follow you anywhere else, and the pages above still count a view exactly as anonymously as any other, with nothing recorded that could tie a view to your account.

More broadly, viewing a page here contacts nobody but us. Everything a page loads, including its styling, its images, even its typeface, comes from our own domain. Fonts are a common exception on other sites, because the usual way to use a web font quietly hands the font’s host the address of everyone who reads the page; ours are served by us instead. Links that lead off this site are of course still links — they take you to someone else’s site only when you choose to follow one.

For each page view, the entire record is:

That is all of it. We do not record your IP address, your browser or device details, or an identifier of any kind — so these entries are anonymous in the ordinary sense of the word, not merely stripped of names. Nothing in a record points to a person, and nothing links one record to another: we cannot tell that two page views came from the same visitor, follow anyone from one page to the next, or recognize you if you come back. They are counts, not visits by people we could name.

To be straight about one detail: Cloudflare, which delivers this site, necessarily sees your IP address in order to route the request to you, and the country above is worked out from it at that moment. We never receive or keep the address itself — only the two-letter country survives into anything we store.

We use this to answer questions like “did anyone read the privacy page?” It is not used for advertising, is never sold or shared, and cannot be combined with anything else to identify you, because there is nothing in it to combine.

Your CloudFrame account

You only need an account for the optional OneDrive photo library. Casting from your phone needs none, and never will.

An account holds exactly this:

If you connect OneDrive we build a catalog of it. This contains file names, folders, dates and sizes. We do this so the Roku can browse your library without waiting. It is a list of what exists, not copies of your photos. The pictures themselves stay in OneDrive and are fetched only as they are shown. Disconnecting OneDrive deletes it. If you do not regularly use the Roku app, we’ll purge the catalog after 90 days of inactivity.

We never write to your OneDrive. Our access is read-only, so nothing there can be changed, moved, or deleted by us — including by mistake.

Billing and payments

The OneDrive photo library is a paid subscription. When you subscribe, payment is handled by our merchant of record, Polar (Polar Software, Inc.), not by us. You enter your card and billing details on Polar’s own secure checkout, and we never see or store your full card number.

From Polar we receive only what we need in order to know whether your library is unlocked:

Polar collects and holds your payment and billing information (such as your card details, name, and the billing address or country needed to work out tax) as the seller of record. Its handling of that information is governed by Polar’s own privacy policy. On our side we store only the subscription status and identifiers listed above, alongside the rest of your account.

Checkout, and the billing portal where you update your card, view invoices, or cancel, are hosted by Polar. This website sets no payment cookies of its own.

What we don’t do

Third-party services

CloudFrame TV relies on Microsoft (for your OneDrive account and sign-in), Cloudflare (which hosts our backend), and Polar (our merchant of record for paid subscriptions, which processes payments and handles billing). Your use of those services is also governed by their respective privacy policies.

Disconnecting and deleting your data

Cast photos need no action from you. They are deleted automatically, and pressing Back on the Cast screen deletes them immediately. See Casting from your phone for the full schedule. Because casting is anonymous, there is no cast account to delete and nothing of yours left behind afterwards.

Your OneDrive connection belongs to your CloudFrame account, not to any one Roku, so you remove it from your account page on this site rather than from the app. Choosing Disconnect OneDrive deletes both the stored connection token and the entire photo-details catalog built from it, straight away.

Signing a Roku out is a different thing, and deliberately so. It revokes that TV’s access immediately, and it is the right button when you sell a set/device or lend one to a guest. It leaves your library connected for your browser and for any other Roku you are signed in on, so it does not delete the catalog. You can sign in on several Rokus with one account; they share a single catalog.

If your subscription ends (you cancel, or a payment ultimately fails), your signed-in TVs stop showing the OneDrive library. We keep the photo-details catalog for a short grace period (about 30 days) so that resubscribing restores your library without rebuilding it from scratch, and then delete the catalog. Your OneDrive connection and your account remain until you disconnect or delete them, or until the 90-day inactivity rule above takes effect.

Deleting your account removes all of it. The Delete your account button on your account page removes the account itself, the email address on it, your OneDrive connection, the photo-details catalog, and every Roku signed in to it immediately. Signing in again afterwards starts a new, empty account rather than restoring the old one. Your photos in OneDrive are not touched.

A few things outlive that deletion. Operational records, such as error logs and counters we keep to see whether the service is working, can mention a scrambled, one-way identifier for a library. This never contains your email address or your photos. They are not searchable back to you and they are discarded on their own schedule, within about three months. Photo files we have recently resized for a TV may also sit in a temporary cache for a matter of hours.

We also keep short-lived, encrypted backups of account data, so we can restore the service after a failure or a mistake. A backup can include your account details: your email address, your OneDrive connection, the list of Rokus you use, and your subscription status. It never includes your photos, your photo-details catalog, or your cast images. Backups are held on our Cloudflare backend and roll over on a cycle of about two weeks, so a copy of your data can survive in a backup for a short time after you disconnect OneDrive or delete your account, and then ages out on its own. We use backups only to bring the service back, never to restore an account you asked us to delete.

If you simply stop using CloudFrame TV, after 90 days with no Roku and no access to your library, we delete your account, your OneDrive connection and your catalog.

You can also revoke CloudFrame TV’s access from your Microsoft account’s app permissions page. That stops us reading your OneDrive from that moment on. However, it cannot reach into our storage and remove our copy of the (invalid) connection token. That copy is deleted when you press Disconnect or delete your account, and otherwise after 90 days of inactivity.

Children’s privacy

CloudFrame TV is not directed to children under 13 and does not knowingly collect personal information from them.

Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected by the “Last updated” date above.

Contact

CloudFrame TV is operated by Francis Axis LLC, a limited liability company based in the State of Maine, USA, which is responsible for the data described in this policy. Questions about this policy or your data? Email hello@cloudframe.tv.