Skip to main content

Privacy

Legal

Privacy

The privacy policy you agree to by using Stateframe apps and services.

Last updated 4 August 2026

Summary

We prioritise your privacy by giving you full control over your data. Here's how we handle your privacy based on how you interact with Stateframe.

Stateframe app for desktop

  • All data is saved locally on your device and is never sent to our servers.
  • We do not collect any personal data.
  • We do not collect any telemetry data.
  • We do not connect to the internet to check for updates.
  • If you share a workspace with a colleague, it travels directly between your machines over your own network. It never passes through us.

Stateframe license purchases

  • To purchase a Stateframe license, you need to provide an email address.
  • We store that address with your order, so we can send your key, resend it if it goes astray, and answer questions about the purchase.
  • We share it with our payment processor to take the payment. We never see or store your card details.
  • We email you about your purchase and your support requests, and nothing else. There is no mailing list.

This website

  • We measure how the website is used, so we can tell which pages and referrers lead people to try Stateframe.
  • We set a cookie that recognises a returning visit only if you accept the banner.
  • If you decline, we still count the visit, but using a code that is regenerated daily and store nothing on your device.
  • We work out an approximate country from your IP address, using a database held on our own server. The address itself is not stored with the visit.
  • No third-party analytics or visitor-identification service runs on this website, and we show no advertising.

Privacy Policy

Last updated 4 August 2026

Stateframe Policy on Privacy of Customer Personal Information

MappingAI is committed to protecting the privacy and security of your personal information obtained by reason of your use of STATEFRAME. This policy explains the types of customer personal information we collect, how it is used, and the steps we take to ensure your personal information is handled appropriately.

Who is MappingAI?

For purposes of this Privacy Policy, “MappingAI” means MappingAI (PTY) Ltd., the company developing and providing STATEFRAME and related websites and services.

What is personal information?

Personal information is information relating to an identifiable, living natural person, and where applicable an identifiable, existing juristic person, as defined in the Protection of Personal Information Act, 2013 (POPIA). It includes such things as your name, email address, contact details, and information about your activities that can be linked back to you. If you are in the European Economic Area or the United Kingdom, “personal data” under the GDPR means the same thing for the purposes of this policy.

Information that cannot be linked back to an identifiable person is not personal information, and we use it freely to understand how the website is used. Most of our website measurement is of that kind by design: it is keyed to a code derived fresh each day, described under “Cookies and website analytics” below.

We are accountable to you

MappingAI is responsible for all personal information under its control. We are the responsible party under POPIA and, where the GDPR applies, the data controller. Our Information Officer can be reached at support@stateframe.app.

MappingAI identifies the purpose for which your personal information is collected and will be used or disclosed. If that purpose is not listed below we will do this before or at the time the information is actually being collected. You will be deemed to consent to our use of your personal information for the purpose of:

  • Providing the products and services you ask for, including issuing and delivering your license key
  • Processing your purchase and keeping a record of it for tax and accounting purposes
  • Answering your questions, support requests and feedback
  • Protecting against fraud, abuse and error
  • Measuring how this website is used, so we can see which pages and referrers lead people to try Stateframe
  • Complying with legal and regulatory obligations

Where the GDPR applies, we rely on the following lawful bases: performance of a contract for purchases, key delivery and support; legal obligation for the tax and accounting records we must keep; consent for the persistent visitor cookie, which is set only if you accept the banner; and legitimate interests for measuring website use in pseudonymous form, and for protecting the site against abuse. Where we rely on legitimate interests, you may object — see “Your rights over your personal information” below.

Otherwise, MappingAI will obtain your express consent (by verbal, written or electronic agreement) to collect, use or disclose your personal information. You can change your consent preferences at any time by contacting MappingAI (please refer to the “How to contact us” section below).

We limit collection of your personal information

MappingAI collects only the information required to provide products and services to you. MappingAI will collect personal information only by clear, fair and lawful means.

We receive and store any information you enter on our website or give us in any other way. You can choose not to provide certain information, but then you might not be able to take advantage of many of our features.

MappingAI does not receive or store personal content saved to your local device while using Stateframe.

Examples of the information we collect and analyse include the e-mail address you give us at checkout; connection information such as browser type and version, operating system, device type, window size and the approximate country your connection comes from; the pages you visit on this website, including date, time and the site that referred you; and anything you choose to write in the feedback form. During some visits we use JavaScript to measure session information such as how long a page held your attention, how far you scrolled, and interactions such as clicks and video plays. Exactly what is measured, and what you can decline, is set out under “Cookies and website analytics” below.

We limit disclosure and retention of your personal information

We do not sell, rent or trade your personal information. We disclose it only in the following circumstances.

Service providers who process it on our behalf. Running a website and delivering a purchase takes a small number of providers, each with access only to what its function requires:

Provider What it does for us What it sees
Fly.io Hosts this website and its database Website traffic, including the IP address a request arrives from
Tigris Stores our database backups, and serves the application files you download Backup contents; the IP address of a download request
PayFast Takes payment at checkout Your email address and your payment details
Fastmail Sends our outbound email Your email address and the contents of the message

These providers act on our instructions and may not use the information for their own purposes. Some are located outside South Africa, so your personal information may be processed in other countries. Where the GDPR or POPIA requires it, such transfers are made under the safeguards those laws provide, including standard contractual clauses and, in POPIA's terms, laws or agreements affording comparable protection.

Where the law requires it. We disclose personal information where we are obliged to by law or a court order, or where it is necessary to establish, exercise or defend a legal claim.

A change of ownership. If MappingAI or substantially all of its assets were acquired, customer information would be one of the transferred assets, and would remain subject to the promises made in this policy unless you agree otherwise.

Retention is set out under “How long we keep it” in the next section.

We keep your personal information up to date and accurate

MappingAI keeps your personal information up to date, accurate and relevant for its intended use.

You may request access to the personal information we have on record in order to review and amend it. To do so, refer to the “How to contact us” section below.

The security of your personal information is a priority for MappingAI

We take steps to safeguard your personal information, including:

  • Encryption in transit. Every connection to this website, and between us and the providers listed above, uses Transport Layer Security (TLS).
  • Encryption at rest. Our database and its backups are held on provider infrastructure that encrypts stored data.
  • Collecting less in the first place. Identifiers are derived rather than stored raw wherever the raw value is not needed — see “Your IP address” below.
  • Access control. The operator console is password-protected and unlisted, and access to the database is limited to the people who run the service.
  • Contractual obligations on the providers who process personal information for us, requiring them to protect and secure it.

Your license key is the only credential Stateframe uses, and there is no account or password to protect. Treat the key as confidential: anyone who has it can apply it.

Cookies and website analytics

We do not run advertising on this website, and we do not sell or rent your personal information to anyone.

Cookies we set. The website uses two cookies, and only two:

Cookie What it is for Set when
sf_consent Records your answer to the privacy banner, so that a decline is honoured instead of being asked again on every visit. Whenever you answer the banner, whichever way you answer.
sf_vid A random identifier that lets us recognise a returning visit. It contains no personal information, is not readable by scripts, and is not shared with anyone. Only if you accept.

There is also a sf_admin cookie, but it exists only for the site operator's own login and is never set for visitors.

Measurement without cookies. If you decline, we still count the visit, but nothing is stored on your device and we will not recognise you on a return visit. We derive a temporary code from your IP address and browser, which is regenerated every day, so our own records cannot follow you from one day to the next.

What we measure. Pages viewed, the site or campaign that referred you, approximate country (see below), browser, operating system, device type, the size of your browser window, how long a page held your attention, how far down a page you scrolled, and interactions such as clicking a download or outbound link, playing a video, or opening a question. We also record which visit each download came from, so we can tell which pages and referrers actually lead people to try Stateframe.

Your IP address. Your IP address reaches our server because that is how the web works. What happens to it next depends on what you are doing:

  • Measuring a visit. It is combined with your browser's user-agent string and a secret key to produce a code that changes every day. That code is stored; the address is not.
  • Working out a country. It is looked up against a database held on our own server, and only the resulting two-letter country code is stored. No third party is contacted to do this, and the result reflects where your connection reaches the internet, which is not always where you are.
  • Downloading the app. A one-way keyed hash of it is stored, so that repeat downloads can be told apart without keeping the address.
  • Sending feedback. The address is stored alongside your message, so we can investigate abuse of the form. Ask us and we will remove it.

The feedback form. If you send us feedback, we store what you wrote, which kind of feedback it is, the app version and email address if you chose to give them, your IP address and your browser's user-agent string. The submission is also emailed to us. We use it to fix what you reported and to reply if you asked for a reply, and for nothing else.

Distinguishing automated traffic. We score each visit on how likely it is to be an automated crawler rather than a person, and record the reasons for that assessment, so that our own traffic figures are not inflated by bots.

Third-party services on this website. No analytics, advertising or visitor-identification service runs on this website, and no page loads a script from another company. All measurement described here is our own, carried out on our own server. We previously used an external analytics provider and a business-identification service; both have been removed. The providers listed under “We limit disclosure and retention of your personal information” host the site and deliver purchases, but receive no measurement data about your visit.

How long we keep it.

What How long
Website measurement records Indefinitely, so long-term trends remain available. They are pseudonymous and are not linked to your name or email address.
The daily code that groups a visit together Regenerated every day; once the day turns, the previous day's cannot be reconstructed.
Order records, including the email address given at checkout, and issued license keys For as long as we sell and support licenses, and in any event for the period South African tax law requires us to keep the accounting record — five years from the end of the relevant tax year.
Feedback submissions Until the issue raised is resolved and no longer useful as history. The IP address and email address on a submission are removed on request.

Changing your mind. Clearing your browser cookies for this site removes both cookies and returns you to the unanswered state, and you will be asked again on your next visit. Declining, or clearing the cookies, withdraws your consent for the persistent visitor cookie. To object to any other processing described here, contact us using the details below.

This website links to other websites, including our payment processor and our social profiles. Those sites have their own privacy practices, which this policy does not cover. Please read theirs before providing them with personal information.

We are open about our privacy and security policy

We are committed to providing you with understandable and easily available information about our policy and practices related to management of your personal information. This policy and any related information is available at all times on our website, stateframe.app, under Privacy or on request. To contact us, refer to the “How to contact us” section below.

Your rights over your personal information

Under POPIA, and under the GDPR if you are in the European Economic Area or the United Kingdom, you have the right to:

  • Ask what we hold about you, how it is used and to whom it has been disclosed, and to receive a copy of it
  • Correct or complete anything inaccurate, misleading or out of date
  • Ask us to delete information we no longer have a lawful reason to keep
  • Object to processing we carry out in our legitimate interests, including website measurement
  • Withdraw consent you have given, at any time, without affecting what was lawful before you withdrew it — declining the banner, or clearing this site's cookies, does exactly that for the visitor cookie
  • Receive your information in a portable form, where the GDPR gives you that right
  • Complain to a regulator if you believe we have got this wrong

To exercise any of these, email support@stateframe.app. We will respond within 30 days. We may ask you to confirm the email address used at checkout, so that we do not hand someone else's information to the wrong person.

One honest limitation: most of our website measurement is pseudonymous by design. Unless you accepted the banner and still hold the cookie, we have no way to pick out the records belonging to a particular person, and we will tell you so rather than guess.

Complaints. In South Africa, you may complain to the Information Regulator, whose current contact details are published at inforegulator.org.za. In the European Economic Area or the United Kingdom, you may complain to your local supervisory authority. We would rather hear from you first, and will try to put it right.

We respond to your questions, concerns and complaints about privacy

MappingAI responds in a timely manner to your questions, concerns and complaints about the privacy of your personal information and our privacy policies and procedures.

How to contact us

Our business changes, and this privacy notice will change with it. Changes are posted on this page with a new date at the top, and the version history below records what changed. If a change materially affects people who have bought a license, we will email the address on the order. We will never materially change our policies and practices to make them less protective of information already collected without the consent of the people affected.

Version history

4 August 2026: Removed the third-party analytics and visitor-identification services. Documented the feedback form, how your IP address is handled, the providers who process data for us, how long each kind of record is kept, and your rights under POPIA and the GDPR.

29 April 2026: Clarification update.

12 March 2026: First version.