Tomi FrameTomi Frame
← Back to home

Privacy Policy

Last updated: 21 September 2026

This Privacy Policy explains how Tomi Frame (“we,” “us,” or “our”) collects, uses, and protects information about you when you use our mobile companion app, hardware device, and website at tomiframe.com. A Turkish version is also published.

Tomi Frame is not yet an incorporated company. Until it is, the data controller is İhsan Özlü acting as an individual, and “we” below refers to him. This notice will be updated when the company is formed.

1. Information We Collect

Waitlist

If you join the waitlist, we store your email address and the date you joined. That is the entire record — no name, no location, no tracking identifier. We use it for exactly one thing: to email you when pre-orders open. It is never used for marketing beyond that, never sold, and never shared. You can have your address removed at any time by emailing [email protected], and joining the waitlist does not create an account.

Retention periods, the legal basis, and the same information in Turkish are set out in the Waitlist Privacy Notice / KVKK Aydınlatma Metni.

Account Information

When you create an account, we collect your email address and a hashed password. If you sign in with Google, we receive your name, email address, and profile picture from Google.

Device Information

When you pair a Tomi Frame device, we store a unique device identifier, firmware version, and the time the device last contacted our servers. We do not collect your device's location.

Dashboard Configuration

We store the widgets, layout, and display preferences you configure in the companion app. This data is necessary to generate your dashboard image and sync settings to your device.

Third-Party Integrations

If you connect integrations (Google Calendar, Spotify, GitHub, Slack), we store OAuth access tokens encrypted with AES-256-GCM. We only request the minimum scopes needed to display information on your dashboard. We do not sell or share this data with any third party.

Usage and Technical Data

We collect standard server logs (IP address, request timestamps, HTTP status codes) for security and debugging. We do not use analytics SDKs or third-party tracking pixels.

2. How We Use Your Information

  • To operate, maintain, and improve the Tomi Frame service
  • To generate and deliver dashboard content to your device
  • To send account-related emails (password reset, security alerts)
  • To detect and prevent fraud or abuse

We do not use your data for advertising, and we do not sell your personal information to any third party.

3. Data Storage and Security

Your data is stored on servers hosted in the European Union and United States. OAuth tokens are encrypted at rest using AES-256-GCM. Passwords are hashed using bcrypt and never stored in plain text. All communications between your device, the app, and our servers use TLS encryption.

4. Data Retention

We retain your account data for as long as your account is active. You may delete your account at any time through the companion app (Settings → Delete Account), which permanently removes all associated data within 30 days.

5. Third-Party Services

We use the following third-party services to operate Tomi Frame:

  • Railway — cloud hosting for the backend API
  • Supabase — managed PostgreSQL database
  • OpenWeatherMap — weather data for the weather widget
  • CoinGecko — cryptocurrency price data (no account required)

Each of these services has its own privacy policy. We do not share personally identifiable information with them beyond what is technically required to operate the service.

6. Your Rights

Depending on your location, you may have the following rights:

  • Access to the personal data we hold about you
  • Correction of inaccurate data
  • Deletion of your data (“right to be forgotten”)
  • Portability of your data in a machine-readable format
  • Withdrawal of consent for optional processing

To exercise any of these rights, contact us at [email protected]. If you are in Turkey you may also complain to the Kişisel Verileri Koruma Kurumu; in the EU or UK, to your national data protection authority.

7. Children's Privacy

Tomi Frame is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice in the companion app. Your continued use of the service after changes constitutes acceptance of the revised policy.

9. Contact

If you have questions about this Privacy Policy, please contact us at:

Tomi Frame
[email protected]
tomiframe.com