Just Frank

Legal

Privacy Policy

Last updated: July 28, 2026 · Effective: July 25, 2026

Who we are

Just Frank is a community platform operated by JustFrank Holdings Inc., a Canadian corporation. Just Frank powers private communities, each led by a community owner (a “Host”). This policy covers both the Just Frank platform and the Just Frank mobile app.

Contact: hello@itsjustfrank.com

Mailing address: JustFrank Holdings Inc., 3707 West 7th Avenue, Unit 702, Vancouver, BC V6R 1W7, Canada.

Plain-language summary

  • You create a profile to use Just Frank. We store the data you give us.
  • Content you post (feed posts, comments, journal entries, dharma reviews, messages) is stored so the app can work. Who can see it depends on where you posted it.
  • We use AI (“Frank” and other community AIs) to help you. Your conversations with AI are processed by a third party (Anthropic) and stored so the AI has context.
  • We use analytics and session recordings to understand how the app is used, and they are linked to your account — not anonymous. Form inputs are always masked. We don’t sell your data.
  • You can request deletion of your account and data at any time.

1. Data we collect

Account data

Email address, name, profile photo, username, bio, and other profile fields you choose to fill in.

Content

Anything you post, write, send, or upload inside Just Frank: posts, comments, direct messages, reactions, journal entries, dharma reviews, loop entries, voice notes, photos, calendar events, scheduler bookings, and notes.

AI conversations

Your messages to Frank (or your community’s AI), the AI’s responses, and the context it uses to answer you (e.g. recent posts, classroom progress, journal entries — scope depends on the feature and your privacy settings). We retain conversation history so the AI has memory across sessions.

Community membership

Which communities you belong to, your role (member, admin, owner), when you joined, and your engagement level.

Device data

When you use the Just Frank mobile app (iOS or Android): your device type, OS version, app version, crash reports, and push notification tokens (if you enable push).

Usage data

Pages viewed, features used, session duration, and product analytics events (e.g. post_created, dharma_review_submitted). Used to improve the product. These events are linked to your account, including your email address and name — they are not anonymous.

Session recordings

We record how you interact with Just Frank — your clicks, navigation, and scrolling — so we can diagnose bugs and understand where people get stuck. These recordings are linked to your account.

What we never record: everything you type into a form is masked before it leaves your browser. That includes passwords, email fields, and any field we have marked sensitive. We do not capture the contents of your form inputs.

If your browser sends a Do Not Track signal, we do not record you at all.

Analytics provider

Analytics and session recordings are processed by PostHog, on servers in the United States. They process this data only on our behalf.

Cookies and local storage

Essential cookies keep you signed in and keep the app secure (your session, CSRF protection, two-factor, and your light/dark preference). These are required for Just Frank to work at all, so they are always on.

Everything else needs your consent. The first time you visit we ask, and nothing non-essential runs until you say yes:

  • Analytics and session recordings (PostHog) — a cookie and a stored identifier that let us see how the product is used and replay how you moved through it. These are linked to your account.
  • Marketing attribution — a first-party cookie, kept for 60 days, that records which link brought you to a community so the right person is credited if you join.

If you decline, none of them are set. We do not use advertising cookies, we run no advertising pixels, and we never sell your data.

Changing your mind: clearing your browser’s storage for this site resets your choice and we will ask again. If your browser sends a Global Privacy Control signal — or a Do Not Track signal — we treat that as a “no” and never ask.

Fonts and embedded videos are served in a way that does not contact third parties before you consent: we serve web fonts from our own servers, and YouTube embeds use YouTube’s privacy-enhanced mode, which sets no advertising cookies unless you press play.

Payment data

If your host charges for your community, payment is processed by Stripe. We receive only the minimum needed (subscription status, last-4 of card, country). We never see your full card number.

Connected services

If you connect Google Calendar (via the Just Frank Calendar feature), we receive calendar events you choose to sync, per the scope you grant. See §3b for our Google API Services Limited Use disclosure.

If a community admin connects a Facebook Page or Instagram Business account via the Just Frank → Meta integration, we receive the IDs and names of the Pages and Instagram Business accounts they grant access to, and the granted permission scopes. The access tokens themselves are held by our social publishing provider, Zernio — see §3a. We do not receive contact lists, friends lists, or any data outside the granted scopes.

What we do NOT collect

Precise location, contacts, health data, advertising identifiers, or biometric data. (Face ID / fingerprint unlock happens entirely on your device’s secure enclave; we never see the biometric template.)

2. How we use your data

  • Provide the Just Frank platform and app
  • Power AI assistance (Frank and community AIs) with your context
  • Send notifications you opted into (in-app, email, push)
  • Improve the product (analytics, feature usage)
  • Keep Just Frank secure (fraud detection, abuse prevention)
  • Comply with legal obligations

We do not sell your data. We do not use your content to train third-party AI models — our AI processor (Anthropic) is bound to process data only on our behalf and not train on it.

3. Who sees your data

Inside your community: hosts, moderators, and other members can see content based on where you post it. A post in the main feed is visible to all community members; a direct message is visible only to the recipient; your journal and dharma reviews are private to you (and optionally to your AI if you enable classroom context in your Frank settings).

Just Frank platform staff: access is limited and role-based, and is used only to operate, support, and secure the service — not to browse your content. Administrative actions taken through our admin tools are recorded in an audit log. A small number of engineers can also reach the production database directly for maintenance and incident response; that access is restricted to senior staff by credential.

Third-party processors. The services below process data on our behalf under their standard data processing terms. This list is complete as of the date at the top of this page.

ServicePurposeData shared
SupabaseDatabase, auth, file storageAll platform data (encrypted at rest)
VercelWeb + API hostingRequest logs, IP
AnthropicAI model inferenceAI conversation turns + context
StripePayment processing (if your host charges)Billing info
GoogleGoogle Calendar sync, Google Sign-In (optional)Calendar scope you grant, OAuth profile
Firebase Cloud MessagingAndroid push notificationsDevice token, notification payload
Apple Push Notification serviceiOS push notificationsDevice token, notification payload
Meta Platforms (Instagram)Publishing scheduled posts to a connected Instagram Business/Creator account, and sending and receiving that account’s direct messages, when a community admin connects it (see §3a)The Instagram account the admin grants, the post content + media the admin schedules, and the direct messages exchanged with that account
ZernioLegacy social publishing and inbox provider, used only for connections not made directly to Meta. For those, Zernio brokers the connection and holds the access tokens (see §3a)Connecting admin’s social identity and access tokens, plus the content an admin chooses to publish or the messages they manage
ResendEmail delivery (notifications, community email, broadcasts)Your email address and the contents of emails we send you
PostHogProduct analytics and session replay (see §1 — Session recordings)Your user ID, email, name, pages viewed, and interactions in the app
PlaidBank account connection, where a Host uses our accounting featuresBank account and transaction data for the account a Host chooses to connect. Members do not connect bank accounts
ZoomCommunity meetings and recordings, where a Host connects ZoomMeeting metadata, recordings, and transcripts for meetings run through the integration
CloudflareVideo hosting and media delivery (R2 storage, Stream)Videos, images, and files uploaded to communities
Bunny.netVideo hosting and delivery (migrating from Cloudflare Stream)Videos uploaded to communities
SentryError and crash reportingError reports, which may incidentally contain your user ID or request details

Law enforcement: we disclose data only when legally compelled by a valid order, subpoena, or warrant.

3a. Connecting an Instagram account (Meta)

A community admin can connect their own Instagram Business or Creator account to Just Frank so they can schedule and publish posts to it, and read and reply to the direct messages that account receives. The connection is per-community and admin-initiated, and it is made through Meta’s own login and consent screen. Members do not connect their personal Instagram accounts through Just Frank.

Permissions we request

  • instagram_business_basic — read the connected professional account’s ID, username and profile details, so we can show the admin which account is connected and attribute posts and conversations to it.
  • instagram_business_content_publish — publish photos, videos, Reels, Stories and carousels to the connected account at the time the admin scheduled them.
  • instagram_business_manage_messages — receive the direct messages sent to the connected account, display them to the admin in a unified inbox, send the admin’s replies, and run the automated replies the admin has configured.

We request only these permissions. We do not request access to advertising accounts, comments, insights, or any account the admin has not explicitly connected.

What we send to Meta

When an admin schedules a post, at the scheduled time Just Frank sends Meta the post text the admin authored, the images or videos they attached, and the access token for the connected account. When an admin or one of their automations replies to a direct message, we send Meta the reply text. Nothing is published or sent without the admin having composed and scheduled or configured it.

Just Frank does not transmit member identities, community posts, comments, reactions, AI conversations, journal entries, or email subscriber data to Meta.

What we receive from Meta, and how we use it

This is the data the messaging permission gives us. When someone sends a direct message to a connected Instagram account, Meta delivers that message to Just Frank by webhook and we store:

  • The sender’s Instagram-scoped user ID, username, display name and profile picture, as provided by Meta.
  • The text of the messages exchanged in that conversation, and the time each was sent.
  • Any answer the sender gives to a question an admin’s automation asked them, and any label (“tag”) the admin or their automation applies to that person.

We use this only to operate the inbox and automations for the admin whose account received the message: to show them the conversation, let them reply, and run the automated replies they configured. We do not use it to build advertising profiles, we do not sell it, we do not use it to train AI models, and we do not use it for any purpose unrelated to that admin’s own inbox. Where an admin has enabled Just Frank’s AI assistant to draft a reply, the conversation text is sent to our AI provider solely to produce that draft, which the admin must approve before it is sent.

An Instagram contact is kept separate from a community’s email subscribers. Messaging someone on Instagram does not add them to any email list.

Automated messages

Where an admin has set up an automated reply, the first automated message in a conversation is labelled as automated and tells the recipient they can reply STOP to opt out. That label is added by Just Frank when the message is sent and cannot be removed by the admin. A person who replies STOP (or UNSUBSCRIBE, CANCEL, QUIT, END, or OPT OUT) is removed from the automation immediately. If a human admin replies to a conversation themselves, the automation stands down and stops sending.

Who holds the connection, and how

For accounts connected directly to Meta, Just Frank holds the access token itself, encrypted at rest, and calls Meta’s Instagram API directly. Some older connections are instead brokered by Zernio, a third-party social publishing provider; for those, Zernio holds the token and processes the data on our instructions under its data processing terms. In both cases the token is scoped to the single account the admin connected.

Connections are scoped to the community that created them — one community’s connection cannot be used to publish or message on behalf of another.

How long we keep it

Direct message conversations are retained while the connection is active, so the admin has the history of their own inbox. When a connection is removed, or when we receive a deletion request or a deletion callback from Meta, the associated conversations, messages, contact records, automation enrolments and labels are deleted.

Disconnecting and data deletion

A community admin can disconnect Instagram at any time from the community’s admin settings. Anyone can also revoke Just Frank’s access from Instagram’s own settings → Apps and Websites, which revokes it at Meta directly.

Anyone who has messaged a connected Instagram account can request deletion of their data by submitting a request via itsjustfrank.com/legal/data-deletion, or by emailing us at the address in §11. Just Frank also honours Meta-initiated requests: Meta sends deletion callbacks to /api/public/meta/data-deletion-callback and app-removal callbacks to /api/public/meta/deauthorize-callback, and we delete that person’s messages, conversations, contact record, automation enrolments and labels on receipt.

3b. Google API Services — Limited Use

Just Frank’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Just Frank connects to Google Calendar only when you choose to link your Google account from the Just Frank Calendar feature. When you do, we request the following Google OAuth scopes:

  • https://www.googleapis.com/auth/calendar — to read your calendars and to create, update, and sync calendar events between Just Frank and Google Calendar.
  • https://www.googleapis.com/auth/userinfo.email and openid — to identify which Google account you connected.

Specifically, in relation to data obtained through these Google APIs, Just Frank:

  • uses Google user data only to provide and improve the user-facing calendar sync features you enable inside Just Frank;
  • does not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to users;
  • does not use Google user data for serving advertisements;
  • does not sell Google user data, and does not use it to train, develop, or improve generalized or non-personalized AI / machine-learning models;
  • does not allow humans to read Google user data unless we first obtain your affirmative agreement to view specific data, it is necessary for security purposes (such as investigating abuse), it is required to comply with applicable law, or the data has been aggregated and anonymized.

You can disconnect Google Calendar and revoke Just Frank’s access at any time from your Just Frank calendar settings, or from your Google Account → Security → Third-party access page. Disconnecting revokes the token at Google and deletes the stored access and refresh tokens from Just Frank.

4. AI and your data

Just Frank’s AI features (“Frank” and community-specific AIs) run on Anthropic Claude models. When you interact with AI:

  • Your current message plus relevant context (recent posts, profile, classroom progress, journal entries — scope depends on the feature and your Frank privacy toggle) is sent to Anthropic.
  • Anthropic processes the request and returns a response.
  • We retain your conversation history so the AI has memory across sessions.
  • Anthropic does not train on your data. It is processed under a commercial agreement that prohibits training use.

You can control AI context by adjusting privacy settings in Just Frank. Options include “full context,” “ask-only,” and “never use my classroom/journal data.”

5. Retention

  • Active account data: kept while your account is active.
  • After account deletion: most data is erased within 30 days; some data (audit logs, legal holds, anonymized analytics) may be retained longer where required by law.
  • AI conversations: retained alongside your profile; deleted when you delete your account or explicitly clear your AI history (where supported in your community’s configuration).
  • Backups: deleted data may persist in encrypted backups for up to 90 days before being purged.

6. Your rights

You can:

  • Access your data — export from your settings or by emailing us
  • Correct inaccurate data — edit in the app, or email us
  • Delete your account and data — Settings → Account → Delete Account, or email us
  • Port your data — export in machine-readable format (JSON or CSV)
  • Opt out of non-essential communications — Settings → Notifications
  • Withdraw consent to optional processing — revoke calendar sync, revoke AI context, etc.

EU / UK residents (GDPR): you also have the right to object to processing, restrict processing, and lodge a complaint with your local data protection authority.

California residents (CCPA / CPRA): you have the right to know, delete, correct, opt out of sale (we don’t sell), and non-discrimination. Email us to exercise these rights.

Data Controller: JustFrank Holdings Inc.

7. Security

We use industry-standard practices:

  • TLS 1.2+ for all data in transit
  • Encryption at rest (Supabase: AES-256)
  • Row-level security (RLS) on all database tables
  • Password, magic-link, or OAuth sign-in. Passwords are stored only as salted hashes — we never store or see your plaintext password
  • API keys and secrets stored as encrypted environment variables, never in our source code
  • Biometric unlock on mobile uses your device’s secure enclave — we never see the biometric template

No system is perfectly secure. In the event of a breach affecting your data, we will notify you within the timeframe required by applicable law (typically 72 hours under GDPR).

8. International transfers

Just Frank uses infrastructure providers (Supabase, Vercel, Anthropic, Google, Firebase) with data centers primarily in the United States and Europe. Transfers from the EU / UK are covered by Standard Contractual Clauses where required.

9. Children

Just Frank is not intended for users under 16 (or the minimum age required by your country’s law, whichever is higher). We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.

10. Changes to this policy

We will post the updated version at this URL with a new “Last updated” date. Material changes are announced in-app and by email at least 14 days before taking effect.

11. Contact

Privacy questions: hello@itsjustfrank.com

JustFrank Holdings Inc.
3707 West 7th Avenue, Unit 702
Vancouver, BC V6R 1W7
Canada
Canada

© 2026 JustFrank Holdings Inc.PrivacyTermsSupport