Legal
Privacy Policy
Last updated: July 13, 2026 · Effective: July 13, 2026
Who we are
Just Frank is a community platform operated by QX Holdings Inc., a Canadian corporation. Just Frank powers private communities, each led by a community owner (a “Host”). This policy covers both the Just Frank platform and the Just Frank mobile app.
Contact: hello@itsjustfrank.com
Mailing address: QX Holdings Inc., 4705 Mann Road, Box 302, Rossland, BC V0G 1Y0, Canada.
Plain-language summary
- You create a profile to use Just Frank. We store the data you give us.
- Content you post (feed posts, comments, journal entries, dharma reviews, messages) is stored so the app can work. Who can see it depends on where you posted it.
- We use AI (“Frank” and other community AIs) to help you. Your conversations with AI are processed by third parties (Anthropic via our AI partner Anima) and stored so the AI has context.
- We use analytics and session recordingsto understand how the app is used, and they are linked to your account — not anonymous. Form inputs are always masked. We don’t sell your data.
- You can request deletion of your account and data at any time.
1. Data we collect
Account data
Email address, name, profile photo, username, bio, and other profile fields you choose to fill in.
Content
Anything you post, write, send, or upload inside Just Frank: posts, comments, direct messages, reactions, journal entries, dharma reviews, loop entries, voice notes, photos, calendar events, scheduler bookings, and notes.
AI conversations
Your messages to Frank (or your community’s AI), the AI’s responses, and the context it uses to answer you (e.g. recent posts, classroom progress, journal entries — scope depends on the feature and your privacy settings). We retain conversation history so the AI has memory across sessions.
Community membership
Which communities you belong to, your role (member, admin, owner), when you joined, and your engagement level.
Device data
When you use the Just Frank mobile app (iOS or Android): your device type, OS version, app version, crash reports, and push notification tokens (if you enable push).
Usage data
Pages viewed, features used, session duration, and product analytics events (e.g. post_created, dharma_review_submitted). Used to improve the product. These events are linked to your account, including your email address and name— they are not anonymous.
Session recordings
We record how you interact with Just Frank— your clicks, navigation, and scrolling — so we can diagnose bugs and understand where people get stuck. These recordings are linked to your account.
What we never record: everything you type into a form is masked before it leaves your browser. That includes passwords, email fields, and any field we have marked sensitive. We do not capture the contents of your form inputs.
If your browser sends a Do Not Track signal, we do not record you at all.
Analytics provider
Analytics and session recordings are processed by PostHog, on servers in the United States. They process this data only on our behalf.
Cookies and local storage
Essential cookies keep you signed in and keep the app secure (your session, CSRF protection, two-factor, and your light/dark preference). These are required for Just Frank to work at all, so they are always on.
Everything else needs your consent. The first time you visit we ask, and nothing non-essential runs until you say yes:
- Analytics and session recordings (PostHog) — a cookie and a stored identifier that let us see how the product is used and replay how you moved through it. These are linked to your account.
- Marketing attribution — a first-party cookie, kept for 60 days, that records which link brought you to a community so the right person is credited if you join.
If you decline, none of them are set. We do not use advertising cookies, we run no advertising pixels, and we never sell your data.
Changing your mind:clearing your browser’s storage for this site resets your choice and we will ask again. If your browser sends a Global Privacy Controlsignal — or a Do Not Track signal — we treat that as a “no” and never ask.
Fonts and embedded videos are served in a way that does not contact third parties before you consent: we serve web fonts from our own servers, and YouTube embeds use YouTube’s privacy-enhanced mode, which sets no advertising cookies unless you press play.
Payment data
If your host charges for your community, payment is processed by Stripe. We receive only the minimum needed (subscription status, last-4 of card, country). We never see your full card number.
Connected services
If you connect Google Calendar (via the Just Frank Calendar feature), we receive calendar events you choose to sync, per the scope you grant. See §3b for our Google API Services Limited Use disclosure.
If a community admin connects a Facebook Page or Instagram Business account via the Just Frank → Meta integration, we receive the IDs and names of the Pages and Instagram Business accounts they grant access to, and the granted permission scopes. The access tokens themselves are held by our social publishing provider, Zernio— see §3a. We do not receive contact lists, friends lists, or any data outside the granted scopes.
What we do NOT collect
Precise location, contacts, health data, advertising identifiers, or biometric data. (Face ID / fingerprint unlock happens entirely on your device’s secure enclave; we never see the biometric template.)
2. How we use your data
- Provide the Just Frank platform and app
- Power AI assistance (Frank and community AIs) with your context
- Send notifications you opted into (in-app, email, push)
- Improve the product (analytics, feature usage)
- Keep Just Frank secure (fraud detection, abuse prevention)
- Comply with legal obligations
We do not sell your data. We do not use your content to train third-party AI models — AI processors (Anthropic via Anima) are bound to process data only on our behalf and not train on it.
3. Who sees your data
Inside your community: hosts, moderators, and other members can see content based on where you post it. A post in the main feed is visible to all community members; a direct message is visible only to the recipient; your journal and dharma reviews are private to you (and optionally to your AI if you enable classroom context in your Frank settings).
Just Frank platform staff: access is limited and role-based, and is used only to operate, support, and secure the service — not to browse your content. Administrative actions taken through our admin tools are recorded in an audit log. A small number of engineers can also reach the production database directly for maintenance and incident response; that access is restricted to senior staff by credential.
Third-party processors. The services below process data on our behalf under their standard data processing terms. This list is complete as of the date at the top of this page.
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database, auth, file storage | All platform data (encrypted at rest) |
| Vercel | Web + API hosting | Request logs, IP |
| Anthropic (via Anima) | AI model inference | AI conversation turns + context |
| Anima | AI orchestration layer | Same as Anthropic (Anima is the API gateway) |
| Stripe | Payment processing (if your host charges) | Billing info |
| Google Calendar sync, Google Sign-In (optional) | Calendar scope you grant, OAuth profile | |
| Firebase Cloud Messaging | Android push notifications | Device token, notification payload |
| Apple Push Notification service | iOS push notifications | Device token, notification payload |
| Meta Platforms (Facebook / Instagram) | Cross-posting community content to connected Facebook Pages and Instagram Business accounts when a community admin enables it | Pages / Instagram accounts the admin grants, and the post content + media the admin chooses to cross-post |
| Zernio | Social publishing and inbox provider. Zernio brokers the connection to Meta on our behalf and holds the Meta access tokens (see §3a) | Connecting admin’s social identity and access tokens, plus the content an admin chooses to publish or the messages they manage |
| Resend | Email delivery (notifications, community email, broadcasts) | Your email address and the contents of emails we send you |
| PostHog | Product analytics and session replay (see §1 — Session recordings) | Your user ID, email, name, pages viewed, and interactions in the app |
| Plaid | Bank account connection, where a Host uses our accounting features | Bank account and transaction data for the account a Host chooses to connect. Members do not connect bank accounts |
| Zoom | Community meetings and recordings, where a Host connects Zoom | Meeting metadata, recordings, and transcripts for meetings run through the integration |
| Cloudflare | Video hosting and media delivery (R2 storage, Stream) | Videos, images, and files uploaded to communities |
| Bunny.net | Video hosting and delivery (migrating from Cloudflare Stream) | Videos uploaded to communities |
| Sentry | Error and crash reporting | Error reports, which may incidentally contain your user ID or request details |
Law enforcement: we disclose data only when legally compelled by a valid order, subpoena, or warrant.
3a. Connecting third-party social accounts (Meta)
Community admins can connect a Facebook Page or Instagram Business account so they can cross-post community content from Just Frank to those surfaces. The connection is per-community and admin-initiated. Members do not connect their personal Facebook or Instagram accounts through Just Frank.
Permissions we request
- pages_show_list — list the Facebook Pages the admin manages so they can pick which one to connect.
- pages_manage_posts — publish posts to the connected Facebook Page on the admin’s behalf.
- pages_read_engagement — read post identifiers returned by Meta after a successful publish (used for the Just Frank audit log).
- instagram_basic — fetch the Instagram Business account ID and handle linked to the connected Facebook Page.
- instagram_content_publish — publish posts to the linked Instagram Business account when an admin enables Instagram cross-posting.
What flows from Just Frank to Meta
Only when a community admin explicitly toggles “Cross-post to Facebook” (or Instagram) on an individual post, Just Frank sends to Meta:
- The post text body the admin authored.
- Image and video URLs the admin attached, if any (Instagram requires media).
- The Page or Instagram Business account access token (used to authenticate the publish request).
Just Frank does not transmit member identities, comments, reactions, AI conversations, journals, direct messages, or any other community data to Meta. We do not use Meta-granted tokens to read content from connected Pages or Instagram accounts beyond confirming a successful publish.
Who holds the connection, and how
The Meta connection is brokered by Zernio, a third-party social publishing provider we use. When an admin connects a Facebook Page or Instagram Business account, the resulting access tokens are held by Zernio, not by Just Frank. Just Frank stores only a reference to the connected profile, and calls Zernio’s API to publish on the admin’s behalf. Zernio processes this data on our instructions under its data processing terms.
Connections are scoped to the community that created them — one community’s connection cannot be used to publish on behalf of another.
Disconnecting and data deletion
A community admin can disconnect Meta at any time from the community’s admin settings; this revokes the connection at the provider. The admin can also revoke access from Facebook’s own settings → Business Integrations panel, which revokes it at Meta directly.
Members of the community whose posts were cross-posted to Meta can request deletion of the Meta-side post by contacting the community admin (who controls the connected Page) or by submitting a deletion request via itsjustfrank.com/legal/data-deletion. Just Frank forwards Meta-initiated data deletion callbacks to /api/public/meta/data-deletion-callbackper Meta’s requirements.
3b. Google API Services — Limited Use
Just Frank’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Just Frank connects to Google Calendar only when you choose to link your Google account from the Just Frank Calendar feature. When you do, we request the following Google OAuth scopes:
https://www.googleapis.com/auth/calendar— to read your calendars and to create, update, and sync calendar events between Just Frank and Google Calendar.https://www.googleapis.com/auth/userinfo.emailandopenid— to identify which Google account you connected.
Specifically, in relation to data obtained through these Google APIs, Just Frank:
- uses Google user data only to provide and improve the user-facing calendar sync features you enable inside Just Frank;
- does not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to users;
- does not use Google user data for serving advertisements;
- does not sell Google user data, and does not use it to train, develop, or improve generalized or non-personalized AI / machine-learning models;
- does not allow humans to read Google user data unless we first obtain your affirmative agreement to view specific data, it is necessary for security purposes (such as investigating abuse), it is required to comply with applicable law, or the data has been aggregated and anonymized.
You can disconnect Google Calendar and revoke Just Frank’s access at any time from your Just Frank calendar settings, or from your Google Account → Security → Third-party access page. Disconnecting revokes the token at Google and deletes the stored access and refresh tokens from Just Frank.
4. AI and your data
Just Frank’s AI features (“Frank” and community-specific AIs) run on Anthropic Claude models via our AI partner Anima (also operated by QX Holdings Inc.). When you interact with AI:
- Your current message plus relevant context (recent posts, profile, classroom progress, journal entries — scope depends on the feature and your Frank privacy toggle) is sent to Anthropic.
- Anthropic processes the request and returns a response.
- We retain your conversation history so the AI has memory across sessions.
- Anthropic does not train on your data. It is processed under a commercial agreement that prohibits training use.
You can control AI context by adjusting privacy settings in Just Frank. Options include “full context,” “ask-only,” and “never use my classroom/journal data.”
5. Retention
- Active account data: kept while your account is active.
- After account deletion: most data is erased within 30 days; some data (audit logs, legal holds, anonymized analytics) may be retained longer where required by law.
- AI conversations:retained alongside your profile; deleted when you delete your account or explicitly clear your AI history (where supported in your community’s configuration).
- Backups: deleted data may persist in encrypted backups for up to 90 days before being purged.
6. Your rights
You can:
- Access your data — export from your settings or by emailing us
- Correct inaccurate data — edit in the app, or email us
- Delete your account and data — Settings → Account → Delete Account, or email us
- Port your data — export in machine-readable format (JSON or CSV)
- Opt out of non-essential communications — Settings → Notifications
- Withdraw consent to optional processing — revoke calendar sync, revoke AI context, etc.
EU / UK residents (GDPR): you also have the right to object to processing, restrict processing, and lodge a complaint with your local data protection authority.
California residents (CCPA / CPRA):you have the right to know, delete, correct, opt out of sale (we don’t sell), and non-discrimination. Email us to exercise these rights.
Data Controller: QX Holdings Inc.
7. Security
We use industry-standard practices:
- TLS 1.2+ for all data in transit
- Encryption at rest (Supabase: AES-256)
- Row-level security (RLS) on all database tables
- Password, magic-link, or OAuth sign-in. Passwords are stored only as salted hashes — we never store or see your plaintext password
- API keys and secrets stored as encrypted environment variables, never in our source code
- Biometric unlock on mobile uses your device’s secure enclave — we never see the biometric template
No system is perfectly secure. In the event of a breach affecting your data, we will notify you within the timeframe required by applicable law (typically 72 hours under GDPR).
8. International transfers
Just Frank uses infrastructure providers (Supabase, Vercel, Anthropic, Google, Firebase) with data centers primarily in the United States and Europe. Transfers from the EU / UK are covered by Standard Contractual Clauses where required.
9. Children
Just Frank is not intended for users under 16 (or the minimum age required by your country’s law, whichever is higher). We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.
10. Changes to this policy
We will post the updated version at this URL with a new “Last updated” date. Material changes are announced in-app and by email at least 14 days before taking effect.
11. Contact
Privacy questions: hello@itsjustfrank.com
QX Holdings Inc.
4705 Mann Road, Box 302
Rossland, BC V0G 1Y0
Canada
Canada