Security
Security and your data.
You put your tasks, your money and your health into Framezone. That's a lot of trust, so here is exactly how I handle it, in plain words.
I build and run Framezone alone. This page lists what is in place today and, just as clearly, what isn't yet.
- Hosted in Europe
- HTTPS everywhere
- Export or delete anytime
The path your data takes
Your browser
https://framezone.app
Cloudflare
Filters abuse before it reaches the server
App and database
DigitalOcean, Germany
Secrets encrypted at rest
Bank, Google and AI keys
01 · Hosting
Where your data lives
Everything sits on one server in the EU. Nothing is spread across services you haven't heard of.
Hosted in Europe
The app and its database run on a DigitalOcean server in Germany, inside the EU.
Cloudflare in front
Traffic passes through Cloudflare, which filters abuse before it reaches the server.
HTTPS with HSTS
Every page is served over HTTPS, and browsers are told never to fall back to plain HTTP.
02 · Protection
How it's protected
Secrets encrypted at rest
Bank tokens, Google tokens and AI keys are encrypted in the database with the app's key. A copy of the database alone doesn't reveal them.
Passwords hashed
Passwords are stored as one-way hashes. I can't see yours, and nobody else can either.
Admin area locked down
The admin area is restricted to me, and I'm the only person with access to the server.
Rate limits
Sign-up and login are rate limited, which slows down anyone trying to guess passwords.
Throwaway emails blocked
Temporary email addresses are refused at sign-up, which keeps out most automated accounts.
03 · Backups
Nightly backups, kept two weeks
24h
Backup cycle
14
Days kept
The database is backed up every night, and each backup is kept for 14 days. If something goes wrong, I can restore from any of the last two weeks.
To be honest about it, those backups currently live with the same hosting provider. An off-site copy somewhere else is coming.
04 · Not yet
What isn't done yet
You should know the gaps before you decide what to put in. These are the two that matter most.
-
No end-to-end encryption
Apart from the tokens and keys above, your data is not end-to-end encrypted. It's protected by the server and HTTPS, and I could technically read it. End-to-end encryption is planned.
-
No audit or certification
Framezone hasn't had a third-party security audit and holds no certification such as SOC 2 or ISO 27001. I won't claim otherwise.
05 · Your controls
Your controls
It's your data. You can take it, delete it, or limit what gets collected, without asking me.
Export everything
Download all your data from settings, any time.
Delete your account
Deleting your account removes all your data, files and connected tokens.
One-click unsubscribe
Every email has a link that switches it off in one click.
Cookie settings
Change your cookie choice any time from the footer.
Analytics by consent
Google Analytics only runs if you accept cookies. It sees page visits, never your data.
A basic visit log
Framezone keeps its own simple log of pages and referrers for 12 months.
The details are in the privacy policy and the cookie policy.
06 · Connections
Connecting your AI and your bank
- Connects through OAuth, so your AI assistant never sees your password
- You choose read, write and delete access when you connect
- Disconnect it any time in Settings, Connections
- Disconnect it whenever you like
- Read-only access to balances and transactions
- It can never move money or make payments
- The access token is encrypted at rest
07 · Disclosure
Report a security issue
Found something that looks wrong? Tell me through the contact page and pick "Bug report". I read every message myself and usually reply within a day or two.
Your life in one place, handled with care.
Start with one area. It takes about a minute.
Free during early access. No card needed.