FrameSave saves video frames that you explicitly request. The Chrome extension requires the FrameSave macOS app and communicates with it through Chrome's native messaging interface and a local bridge. No FrameSave server receives captures.
Information used
When you request a capture, FrameSave inspects the active tab of your connected Chrome profile, including embedded video players. It reads video pixels, dimensions, playback position, and available page title, URL and favicon URL. It temporarily examines video visibility to select the player. It does not scan inactive tabs.
The extension stores a random local profile identifier and the profile label you choose. This identifies the Chrome profile to your Mac app. It is not an account identifier and is not sent to a FrameSave server.
The extension requests website access to support videos hosted on other domains inside a page. It does not query cookies, password stores, form submissions, Chrome’s browsing-history database, or personal account details. Source URLs and titles are read from the page you choose to capture. It performs no background video capture, screen recording, analytics, advertising, or sale of user data.
Optional screenshot fallback
Screenshot fallback is offered only after a direct pixel-access failure. The default is Ask each time; Settings also offers Automatic and Never. Enabling this feature requires an optional Chrome permission for <all_urls> so it can work from the Mac button and shortcut. Capture remains restricted to normal HTTP/HTTPS tabs in your selected profile. You can revoke that permission in Chrome.
For a requested fallback, Chrome temporarily provides an image of the visible tab, which may include visible text and form fields elsewhere on that page. The extension crops it to the selected video's displayed bounds locally. Only the crop is sent to the Mac app and saved. The full-tab image is not saved or uploaded and is discarded after processing. Player controls, letterboxing, and overlays within the crop may appear in the saved image. No screen recording or OS screen-recording permission is used. Protected playback may prevent screenshot capture as well.
The extension can retain a reference to the selected video and its page identifiers for up to 60 seconds while a screenshot offer is pending. A new capture or disconnect invalidates the offer. It does not retain screenshot pixels during that waiting period.
Storage and network requests
PNG images and enabled source metadata are saved in the destination selected in FrameSave. Turn source title, source URL, or timecode storage off in the app's Capture settings. Capture data passes locally through the native helper and is discarded from extension memory after the request; the extension does not retain an image library.
Capture provenance is embedded in standard XMP metadata and travels with an image when you share it. Favorites, file-occurrence mappings and synchronization state are stored separately in a private local database. Images contain no favorite rating, account identifier, local path or embedded favicon from FrameSave.
Optional “Sync favorites with iCloud” is off by default. When enabled in a provisioned build, FrameSave sends full capture IDs, favorite values and necessary logical synchronization versions to your private CloudKit database. It does not upload images, titles, source URLs, filenames, paths or folder permissions through this feature. Turning sync off retains local state and pending changes. Different iCloud accounts have separate private favorite state. Ordinary imports without FrameSave capture provenance keep local-only favorites.
Private-state exports contain personal library/account data and are separate from image sharing. Migration backups preserve the original files, including their old embedded favorites, and must be kept private. Removing a connected folder or clearing disposable caches does not erase your private favorite database.
The Mac app may request a source website's favicon, using its existing cache first. Those requests disclose the favicon URL and ordinary network information, such as your IP address, to that website. FrameSave sends no cookies, credentials or page referrer with these favicon requests.
When updates are configured, the Updates page requests release information from FrameSave's download hosting provider, Cloudflare R2. Manual checks and approved automatic checks also request the update feed; choosing Install downloads the app update. These requests expose ordinary network information, including your IP address and the app's user agent, to the hosting provider. Captured images, source URLs, filenames and library contents are not sent with update requests. Sparkle system-profile submission is disabled. Automatic checks require your permission, and installation requires a user action. Verified release notes are cached locally for offline viewing.
If you save into Dropbox, iCloud, or another synchronized folder, your chosen provider may synchronize those files under its own privacy policy. Chrome Web Store and operating-system update/install services are governed by their providers.
Control and retention
You can restrict site access or remove the extension in Chrome. FrameSave retains saved PNGs until you delete them. Removing the extension or helper does not delete your images. The Mac app includes controls to remove connected folders and clear disposable caches. Deleting an image through FrameSave uses macOS Trash.
This website
This privacy-policy website is hosted by Cloudflare. Cloudflare processes ordinary connection information, such as IP addresses and request details, to deliver and protect the website. We do not add advertising, analytics scripts, or tracking cookies to this page.
Contact
For privacy questions and support, contact framesave@tienvi.co.
FrameSave is published by Tien Vi.
FrameSave's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements where applicable.