Privacy Policy
Effective date: set when you publish (draft)
Last updated: April 4, 2026
This policy describes how Frannie (“Frannie,” “we,” “us,” “our”) collects, uses, stores, and shares information when you use our mobile applications, websites, and related services (together, the “Services”).
Legal review: This is a draft. Have qualified counsel review before you rely on it. Fill in your legal entity name and address where noted.
1. Who we are
Data controller: [Insert legal entity name], [registered address]
Contact (general): support@frannie.app
Privacy inquiries: privacy@frannie.app
2. Scope
This policy applies to caregivers, care recipients, and others who use the Services. If you use Frannie on behalf of someone else (for example, as a caregiver), you should share this policy with them where appropriate.
3. Information we collect
3.1 Account and profile information
- Name, email address, and credentials you provide when you register or sign in
- Role (for example, care recipient or caregiver) and relationships you set up in the app
- Care recipient profile information you or your caregiver enters (for example, name, timezone, optional contact details, notes relevant to care)
- Language preferences and similar settings
3.2 Check-ins, conversations, voice, and audio
- Text, answers, and other content you submit during check-ins or in-app conversations
Microphone (Android / iOS)
Frannie uses the microphone only when you use voice check-ins or talk features. We request microphone permission through the operating system for that purpose.
What we do with audio
When you speak, audio is sent to our servers. We use service providers—including OpenAI (and similar vendors where we use them)—to:
- Transcribe speech to text (for example, using speech-to-text / Whisper-style models)
- Generate conversational responses and support check-in flows
We do not use your voice or audio for advertising.
What we store
We may store text transcripts and references to audio files (for example, URLs to audio you uploaded) with your check-in history in our systems, so we can run the product, show history to you and authorized caregivers, and improve safety and quality. Technical implementation ties this data to check-in response records in our database.
3.3 Health and activity-related data
When you connect Health Connect (Android), Apple Health (where supported), Fitbit, or other integrations we offer:
- We may access categories of data you authorize (for example, steps, distance, active energy, heart rate, sleep, resting heart rate—only as enabled in the product and as you permit)
- We use this information to personalize check-ins, show trends or insights, and support care coordination with caregivers you designate
We do not sell your health information for marketing. Additional health data disclosures may be published separately.
3.4 Wearable and third-party connections
- When you connect Fitbit or similar services, we receive tokens and profile or device identifiers as needed to sync data you authorize
- That data is subject to this policy and, where relevant, the third party’s policies (for example, Fitbit / Google)
3.5 Location
Whether we collect it
If you turn on location for a care recipient in the app (Settings / location tracking preference), or use features that request location (for example, Talk with location enabled), we collect device location.
What we collect
We collect latitude and longitude, optional accuracy, and, if the app provides it, a human-readable address or place description.
How it is used
We store and use this information to support safety and care context and to allow authorized caregivers to see current location information as designed in the product.
Updates
Location may be sent to our servers when the app detects updates. Our API applies rate limiting so updates are not sent excessively; the app may also throttle how often it sends location.
Android
Location access may be declared via our dependencies (for example expo-location) in addition to permissions listed in app configuration. Disclose location in store listings (for example Google Play Data safety) when the build includes location capability.
Your control
You can turn off location tracking in app settings where the product provides that control, and revoke location permission in device system settings.
3.6 Device, log, and technical data
- Device type, operating system, app version, push notification tokens
- IP address, timestamps, and diagnostic logs to secure the Services, fix bugs, and measure reliability
- Cookies and similar technologies on websites (where applicable)
3.7 Communications
- Emails or messages you send us (support, feedback)
- Records we need to provide support and comply with law
4. How we use information
We use the information above to:
- Provide, operate, and improve the Services
- Authenticate users and protect accounts
- Run check-ins, voice features, reminders, and notifications you expect
- Show insights, history, and summaries to you and authorized caregivers
- Connect and sync permitted health or wearable data
- Comply with law, enforce our terms, and protect rights and safety
Legal bases (EEA/UK users, if applicable): contract, legitimate interests (security, improvement, support), consent where required (for example, sensitive health or microphone use where consent is the appropriate basis), legal obligation.
5. How we share information
We may share information with:
- Caregivers and care recipients you link in the app, as the product is designed to allow
- Service providers who help us host, store, analyze, or operate the Services—including cloud hosting, databases, email, analytics, and AI / speech providers (e.g. OpenAI)—under arrangements that require appropriate protection
- Professional advisers (lawyers, auditors) when needed
- Authorities if required by law or to protect safety
We do not sell your personal information for money. We do not share personal information for cross-context behavioral advertising as described in some U.S. state laws.
6. Retention
- We keep information while your account is active and as needed to provide the Services.
- Transcripts and audio references are kept with check-in and response records for as long as those records exist in our systems, unless we delete them as part of account closure, your request, or a data lifecycle program you operate.
- After account closure or deletion request, we delete or anonymize personal information within a reasonable period, subject to backup cycles and legal retention needs. If you commit to a specific backup window (for example 90 days after deletion), state the exact period in your published policy only if it matches operations.
- Policy claims should match actual database, backup, and deletion practices. There is no automatic time-based deletion of voice-related fields in the application code paths we reviewed.
7. Security
We use administrative, technical, and organizational measures designed to protect personal information (including encryption in transit such as HTTPS/TLS, access controls, and secure hosting). No method of transmission or storage is 100% secure.
8. Your rights and choices
Depending on where you live, you may have the right to:
- Access, correct, or delete your personal information
- Export certain data in a portable format
- Withdraw consent where processing is consent-based (for example, disconnect Health Connect or Fitbit, turn off location in app settings, or revoke microphone or location permission in device settings)
- Object or restrict certain processing
- Lodge a complaint with a supervisory authority (EEA/UK)
To exercise these rights, contact privacy@frannie.app. We may verify your request as permitted by law.
California residents: You may have additional rights under the CCPA/CPRA (for example, to know, delete, or correct personal information, and to opt out of sale or certain sharing). We do not sell personal information. We do not share personal information for cross-context behavioral advertising as defined under California law.
9. Children
The Services are not directed at children under 13, and we do not knowingly collect personal information from children under 13 without appropriate parental consent. If you believe we have collected information from a child under 13 in violation of this policy, contact us at privacy@frannie.app and we will take appropriate steps.
10. International transfers
If we process data in countries outside your own (for example, the United States or the EEA), we use appropriate safeguards such as standard contractual clauses or other mechanisms required by applicable law when transferring personal data from the EEA, UK, or Switzerland.
11. Third-party services
The Services may link to or integrate with third parties (Fitbit, Google, Apple, OpenAI, etc.). Their collection and use of information is governed by their policies. We encourage you to read them.
12. Changes to this policy
We will post updates here and update the “Last updated” date. For material changes, we may provide additional notice (for example, in-app or email) where required.
13. Contact
Privacy: privacy@frannie.app
Support: support@frannie.app
Postal: [Insert legal entity mailing address if required in your jurisdiction]