Privacy Policy
Last updated: 2 September 2026
Frank connects to your email, reads it, drafts replies in your writing style, and — only where you explicitly allow it — sends some of them. That means we handle your mail. This policy explains exactly what we do with it, in plain language.
If you want the engineering detail instead, read our security page.
Who we are: Luke Brochu, sole proprietor, [BUSINESS POSTAL ADDRESS], United States.
Contact: lp.brochu03@gmail.com
1. What we collect
Your account information. Name, email address, and company name. Frank is not yet taking payment, so we currently hold no billing details at all. When paid plans launch, billing will be handled by a third-party payment processor named here, and we will never see your full card number.
Your email data. With your permission, through Google's Gmail API or Microsoft Graph:
- Message content, subject lines, senders, recipients, and timestamps of mail we process
- Your sent mail, read once when you connect a mailbox, to build your voice profile
- Labels, folders, and thread structure
Your usage of Frank. Which drafts you approved, rejected, or edited; settings you changed; when you signed in. We use the edits you make to drafts to measure how well Frank matches your voice.
Technical data. IP address, browser type, and error diagnostics. Message content is excluded from our error reporting.
2. How we use it
We use your email data for exactly one purpose: to run Frank for you. Specifically:
- To decide whether a message needs your attention, a draft, filing, or nothing
- To learn how you write, so drafts sound like you
- To generate draft replies
- To send replies, only in the specific situations you have switched on
- To keep a record of what Frank did, so you can audit it
We do not use your email data to advertise to you, and we do not sell it. Ever, to anyone, for any price.
3. AI and machine learning
This section matters more than the rest. Read it.
We do not retain or use user data obtained through Google Workspace APIs or Microsoft Graph APIs to develop, improve, or train non-personalized artificial intelligence or machine learning models.
What that means in practice:
- Your voice profile is yours. It is built from your sent mail, stored against your mailbox alone, never shared with another customer, and never pooled with anyone else's.
- We do not fine-tune models on customer mail. Not ours, not anyone's.
- We do not build a general product out of your writing. Your data improves your drafts. It does not improve anyone else's.
Third-party AI providers. To generate draft text we send message content to Anthropic (the Claude API). Before content leaves our systems it is redacted to remove personal details. Anthropic is contractually prohibited from retaining your content or using it to train their models.
Content we never send to a model at all. Frank screens every message first. Mail identified as involving legal matters, contracts, disputes, HR or employment, compensation, payments, invoices, banking, tax, insurance, health, credentials, security incidents, regulated advice, complaints, or child safety is routed to you without ever being transmitted to a model provider.
4. Google Workspace API disclosure
Frank's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We request the following Google OAuth scopes:
| Scope | Why we need it |
|---|---|
gmail.readonly | To read incoming mail so Frank can decide what it is and draft a reply, and to read your sent mail once to learn your writing style |
gmail.compose | To create draft replies in your mailbox for your review |
gmail.labels | To organize mail with labels |
gmail.send | Only requested if you enable automatic replies. To send the specific replies you have authorized |
If you never enable automatic replies, Frank never requests or holds send permission.
You can revoke Frank's access at any time from your Frank settings or directly at Google Account permissions.
5. Microsoft Graph disclosure
We request the following Microsoft Graph delegated permissions: Mail.ReadWrite, User.Read, offline_access, and — only when you enable automatic replies — Mail.Send.
Because of Microsoft's default consent policies, your organization's administrator must approve Frank before your mailbox can be connected. We access only the mailbox of the user who signed in. We do not use application-level permissions and cannot read other mailboxes in your organization.
6. How long we keep things
| What | How long |
|---|---|
| Message content | Only while a draft is awaiting review, plus the retention window you configure |
| Decision records | 12 months — the decision, rules applied, a content fingerprint, a redacted excerpt, recipients, and outcome. Not your message text. |
| Voice profile | Until you disconnect the mailbox |
| Sent mail read to build your profile | Not retained after the profile is built |
| OAuth tokens | Encrypted at rest; deleted immediately on disconnect |
| Account and billing records | 7 years, as required for tax and accounting |
When you disconnect a mailbox, we revoke access, delete the tokens immediately, stop all processing, and schedule your content for deletion within 30 days.
When you close your account, we delete your personal data within 30 days, except records we are legally required to keep.
7. Who we share with
Frank is not yet processing anyone's email, so at present we share no customer email data with anyone. This section describes what will happen when it does, and this list will be published in full — with each provider named — before a single real mailbox is connected.
The categories will be:
- Anthropic — generating draft text. Zero-retention, no-training terms. This one is decided.
- Application and database hosting — provider not yet selected. Will be named here before launch.
- Error tracking — diagnostics, with message content excluded. Provider not yet selected.
- Payment processing — not yet selected; Frank is not taking payment.
- Transactional email — our own notifications to you, never your mail. Not yet selected.
The public website you are reading is hosted by Netlify. It collects no email data of any kind.
A current list lives on our security page.
We also disclose data where legally compelled, and we will tell you unless we are prohibited from doing so.
We do not sell your data. We do not share it with advertisers, data brokers, or resellers.
8. Human access to your mail
Our staff may read your message content only when:
- You have specifically asked us to look at a specific message — for example, when reporting a problem with a draft; or
- It is necessary for security, or to comply with the law.
Every such access is logged and reviewed. We do not read customer mail for debugging, quality assurance, or product research. Our audit trail is deliberately built to tell us what happened without showing us what your mail said.
9. Security
Data is encrypted in transit and at rest. OAuth tokens are encrypted with AES-256-GCM. Access to production systems requires multi-factor authentication and is limited to the founder, and no one else. We run automated static analysis, dependency scanning, and dynamic security testing against every change we ship. Frank undergoes an independent CASA security assessment, recertified annually, as a condition of Google's restricted-scope access.
No system is perfectly secure. If we suffer a breach affecting your data, we will notify you within 72 hours with the specific messages affected, not a generic notice.
10. Your rights
Wherever you live, you can:
- See what we hold about you
- Correct it
- Delete it — disconnecting a mailbox does most of this immediately
- Export it in a portable format
- Object to processing, or ask us to restrict it
Email lp.brochu03@gmail.com. We respond within 30 days at no charge.
If you are in the EEA or UK: our legal basis is performance of our contract with you for core processing, and your consent for connecting your mailbox — which you may withdraw at any time by disconnecting. You may complain to your local supervisory authority. Data will be processed in the United States. Because Frank is not yet processing customer mail, no international transfers are taking place; the specific transfer mechanism will be published here before any EEA or UK mailbox is connected.
If you are in California: we do not sell or share personal information as those terms are defined by the CCPA. You may exercise your rights via the same address, and we will not discriminate against you for doing so.
11. A note about other people's email
Frank processes mail sent to you by other people, who have not agreed to this policy. We handle their data on your behalf and only to provide the service to you. We do not build profiles of your correspondents, do not use their data for any other customer, and do not sell or share it. If you are subject to GDPR, you are the data controller for that mail and we are your processor; we will sign a data processing agreement on request.
12. Children
Frank is for business use and is not directed at anyone under 16. We do not knowingly collect data from children.
13. Changes
We will post changes here and update the date at the top. For material changes affecting how we handle your email, we will email you at least 30 days before they take effect.
Questions
General and privacy questions: lp.brochu03@gmail.com
Security issues: lp.brochu03@gmail.com