Frank.

Privacy Policy

Last updated: 2 September 2026

Frank connects to your email, reads it, drafts replies in your writing style, and — only where you explicitly allow it — sends some of them. That means we handle your mail. This policy explains exactly what we do with it, in plain language.

If you want the engineering detail instead, read our security page.

Who we are: Luke Brochu, sole proprietor, [BUSINESS POSTAL ADDRESS], United States.
Contact: lp.brochu03@gmail.com

1. What we collect

Your account information. Name, email address, and company name. Frank is not yet taking payment, so we currently hold no billing details at all. When paid plans launch, billing will be handled by a third-party payment processor named here, and we will never see your full card number.

Your email data. With your permission, through Google's Gmail API or Microsoft Graph:

Your usage of Frank. Which drafts you approved, rejected, or edited; settings you changed; when you signed in. We use the edits you make to drafts to measure how well Frank matches your voice.

Technical data. IP address, browser type, and error diagnostics. Message content is excluded from our error reporting.

2. How we use it

We use your email data for exactly one purpose: to run Frank for you. Specifically:

We do not use your email data to advertise to you, and we do not sell it. Ever, to anyone, for any price.

3. AI and machine learning

This section matters more than the rest. Read it.

Our commitment

We do not retain or use user data obtained through Google Workspace APIs or Microsoft Graph APIs to develop, improve, or train non-personalized artificial intelligence or machine learning models.

What that means in practice:

Third-party AI providers. To generate draft text we send message content to Anthropic (the Claude API). Before content leaves our systems it is redacted to remove personal details. Anthropic is contractually prohibited from retaining your content or using it to train their models.

Content we never send to a model at all. Frank screens every message first. Mail identified as involving legal matters, contracts, disputes, HR or employment, compensation, payments, invoices, banking, tax, insurance, health, credentials, security incidents, regulated advice, complaints, or child safety is routed to you without ever being transmitted to a model provider.

4. Google Workspace API disclosure

Limited Use

Frank's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We request the following Google OAuth scopes:

ScopeWhy we need it
gmail.readonlyTo read incoming mail so Frank can decide what it is and draft a reply, and to read your sent mail once to learn your writing style
gmail.composeTo create draft replies in your mailbox for your review
gmail.labelsTo organize mail with labels
gmail.sendOnly requested if you enable automatic replies. To send the specific replies you have authorized

If you never enable automatic replies, Frank never requests or holds send permission.

You can revoke Frank's access at any time from your Frank settings or directly at Google Account permissions.

5. Microsoft Graph disclosure

We request the following Microsoft Graph delegated permissions: Mail.ReadWrite, User.Read, offline_access, and — only when you enable automatic replies — Mail.Send.

Because of Microsoft's default consent policies, your organization's administrator must approve Frank before your mailbox can be connected. We access only the mailbox of the user who signed in. We do not use application-level permissions and cannot read other mailboxes in your organization.

6. How long we keep things

WhatHow long
Message contentOnly while a draft is awaiting review, plus the retention window you configure
Decision records12 months — the decision, rules applied, a content fingerprint, a redacted excerpt, recipients, and outcome. Not your message text.
Voice profileUntil you disconnect the mailbox
Sent mail read to build your profileNot retained after the profile is built
OAuth tokensEncrypted at rest; deleted immediately on disconnect
Account and billing records7 years, as required for tax and accounting

When you disconnect a mailbox, we revoke access, delete the tokens immediately, stop all processing, and schedule your content for deletion within 30 days.

When you close your account, we delete your personal data within 30 days, except records we are legally required to keep.

7. Who we share with

Frank is not yet processing anyone's email, so at present we share no customer email data with anyone. This section describes what will happen when it does, and this list will be published in full — with each provider named — before a single real mailbox is connected.

The categories will be:

The public website you are reading is hosted by Netlify. It collects no email data of any kind.

A current list lives on our security page.

We also disclose data where legally compelled, and we will tell you unless we are prohibited from doing so.

We do not sell your data. We do not share it with advertisers, data brokers, or resellers.

8. Human access to your mail

Our staff may read your message content only when:

Every such access is logged and reviewed. We do not read customer mail for debugging, quality assurance, or product research. Our audit trail is deliberately built to tell us what happened without showing us what your mail said.

9. Security

Data is encrypted in transit and at rest. OAuth tokens are encrypted with AES-256-GCM. Access to production systems requires multi-factor authentication and is limited to the founder, and no one else. We run automated static analysis, dependency scanning, and dynamic security testing against every change we ship. Frank undergoes an independent CASA security assessment, recertified annually, as a condition of Google's restricted-scope access.

No system is perfectly secure. If we suffer a breach affecting your data, we will notify you within 72 hours with the specific messages affected, not a generic notice.

10. Your rights

Wherever you live, you can:

Email lp.brochu03@gmail.com. We respond within 30 days at no charge.

If you are in the EEA or UK: our legal basis is performance of our contract with you for core processing, and your consent for connecting your mailbox — which you may withdraw at any time by disconnecting. You may complain to your local supervisory authority. Data will be processed in the United States. Because Frank is not yet processing customer mail, no international transfers are taking place; the specific transfer mechanism will be published here before any EEA or UK mailbox is connected.

If you are in California: we do not sell or share personal information as those terms are defined by the CCPA. You may exercise your rights via the same address, and we will not discriminate against you for doing so.

11. A note about other people's email

Frank processes mail sent to you by other people, who have not agreed to this policy. We handle their data on your behalf and only to provide the service to you. We do not build profiles of your correspondents, do not use their data for any other customer, and do not sell or share it. If you are subject to GDPR, you are the data controller for that mail and we are your processor; we will sign a data processing agreement on request.

12. Children

Frank is for business use and is not directed at anyone under 16. We do not knowingly collect data from children.

13. Changes

We will post changes here and update the date at the top. For material changes affecting how we handle your email, we will email you at least 30 days before they take effect.

Questions

General and privacy questions: lp.brochu03@gmail.com
Security issues: lp.brochu03@gmail.com