Legal
How JUST2BUCKS LLC handles your data.
The short version: we store your messages securely, we can read them only for safety and legal reasons, and we never sell your data. This page is the detail.
Last updated July 22, 2026.
We do not buy data about you from data brokers, and no ad code runs in our pages; the one banner ad is sealed in its own frame (see “The one banner ad” below).
The app shows a single banner ad, served by an ad network (ExoClick). The ad renders inside its own sealed frame on the ad company’s web address: our pages run none of their code, and the frame cannot read anything in the app. When the banner loads, your device requests the ad from ExoClick; like any web request, that exposes your IP address to them, and because the frame is their origin, their own cookies can exist there, as on any site that serves their ads. We send them nothing about you: no profile, no location, no messages, no activity, and no identifiers, and we strip the referrer so the request does not reveal what you were doing in the app.
Your messages and photos are encrypted in transit (TLS) and stored encrypted at rest on our servers, so they sync across your devices and survive a lost or wiped phone. They are not end-to-end encrypted: we are able to read message content. We are upfront about that rather than implying otherwise. We never sell or share your messages, and we never use them to target advertising.
We access message content only for limited reasons: to keep people safe (see below), to operate and secure the service, and where the law genuinely compels us. We keep messages no longer than we need to for those purposes.
Because an adult platform attracts abuse, we moderate for safety. If you report a conversation, the messages in it are included with the report so our team can review what happened and act. Child sexual abuse material (CSAM) is absolutely prohibited: when we become aware of apparent CSAM we remove it, report it to the National Center for Missing & Exploited Children (NCMEC) as U.S. law requires, and preserve the related evidence for as long as the law requires, even after an account is closed.
Nonconsensual intimate imagery is also prohibited. If an intimate image of you is on the service without your consent, request its removal here: valid requests are actioned within 48 hours, including identical copies, and the removed image is blocked from being uploaded again.
We do not sell, rent, or license your personal data to anyone, and we do not “share” it in the everyday sense either. Your data is stored and transmitted through the infrastructure services we use to run the app (even the map is drawn from our own tile store now), and those services process it only to keep the app running:
The one other third party is the ad network that serves the single banner ad. It processes nothing for us and never receives your data; what its ad request exposes is covered in “The one banner ad” below.
We may disclose information, including message content, when the law genuinely compels us (such as a valid warrant or court order) or to address an imminent threat to someone’s safety. We push back on overbroad requests and disclose only what we are required to. There is more behind these promises, and the Charter has the full story.
We set only the cookies the app needs to work. Supabase, our authentication provider, uses strictly-necessary cookies to keep you signed in and secure your session. Your browser also stores a few functional map preferences locally on your device, such as your distance unit (miles or kilometers), whether the zoom buttons show, and whether to hide people you have hidden. These stay in your browser and are not sent anywhere.
We set no tracking or advertising cookies ourselves, and nothing runs in our pages to set them for anyone else. The one banner ad’s cookies belong to the ad company and live in its sealed frame on their web address, not ours (see “The one banner ad” above). Because nothing we set is non-essential, there is no consent banner to click through.
We keep your data, including your messages, while your account is open and for as long as needed to run the service and meet legal obligations. You can delete a conversation, and you can close your account at any time, which removes your profile, messages, and data from the active service, subject to limited records we must keep (for example, safety reports and any evidence attached to them, payment records our processor holds for tax and anti-fraud rules, CSAM evidence we are legally required to preserve, and a small set of one-way hashed abuse-prevention signals described below). Deleting your account is self-serve in Settings; for questions about your data, email hello@just2bucks.app.
Keeping banned accounts out. To make a ban meaningful on an invite-only platform, we retain a small set of abuse-prevention signals even after an account is closed or removed, so that a banned person cannot simply sign up again. These are one-way hashed or coarsened values, never your underlying information: for example a hashed form of your email, the invite relationship that let you join, and coarse device and image signals. We use them only to enforce bans and detect duplicate or evading accounts, never to profile you, never for advertising, and never for sale, and they cannot be reversed back into your original details.
Just2Bucks is strictly for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will remove it.
If we change this policy we will update the “last updated” date above and, for material changes, make it noticeable. Privacy questions go to hello@just2bucks.app.