Just2Bucks

Legal

Privacy Policy

How JUST2BUCKS LLC handles your data.
The short version: we store your messages securely, we can read them only for safety and legal reasons, and we never sell your data. This page is the detail.

Last updated July 22, 2026.

What we collect

  • Account basics: an email address to sign in and reach you, and the invite relationship that let you join.
  • Age confirmation: your date of birth, collected once to confirm you are 18 or older. We never display it; other members see only your age, never your birthdate.
  • Profile: what you choose to put on your profile, including any photos you add.
  • Location: your device shares your position with us, and we store it to place your deliberately blurred dot on the map and sort what is near you. Other members only ever see the blurred point, including the dot for you; your exact location is never shown to anyone. One deliberate exception exists: when you drop a “Saw someone” pin, you are choosing to mark an exact public spot, and that exact point is shown on the map to other members until the pin expires or you take it down. The pin marks where the moment happened, not where you live or where you are.
  • Your Log: a private, dated record of things you did in the app (favorites, posts and pins, directions you sent or received, conversations that began, notes you write yourself). It is visible only to you, never to other members. You can delete any entry, clear all of it, or turn the Log off entirely in Settings, which stops anything new from being recorded.
  • Messages: the conversations and photos you send, stored on our servers (encrypted in transit and at rest) so they sync across your devices. We can access message content for safety and legal reasons (see below); we never sell it.
  • Basic operational data: the minimum needed to run and secure the service, such as authentication sessions and logs to prevent abuse.

We do not buy data about you from data brokers, and we do not run third-party ad networks or their trackers.

How your messages are stored

Your messages and photos are encrypted in transit (TLS) and stored encrypted at rest on our servers, so they sync across your devices and survive a lost or wiped phone. They are not end-to-end encrypted: we are able to read message content. We are upfront about that rather than implying otherwise. We never sell or share your messages, and we never use them to target advertising.

We access message content only for limited reasons: to keep people safe (see below), to operate and secure the service, and where the law genuinely compels us. We keep messages no longer than we need to for those purposes.

Moderation and safety

Because an adult platform attracts abuse, we moderate for safety. If you report a conversation, the messages in it are included with the report so our team can review what happened and act. Child sexual abuse material (CSAM) is absolutely prohibited: when we become aware of apparent CSAM we remove it, report it to the National Center for Missing & Exploited Children (NCMEC) as U.S. law requires, and preserve the related evidence for as long as the law requires, even after an account is closed.

Nonconsensual intimate imagery is also prohibited. If an intimate image of you is on the service without your consent, request its removal here: valid requests are actioned within 48 hours, including identical copies, and the removed image is blocked from being uploaded again.

How we handle your data

We do not sell, rent, or license your personal data to anyone, and we do not “share” it in the everyday sense either. Your data is stored and transmitted through the infrastructure services we use to run the app (even the map is drawn from our own tile store now), and those services process it only to keep the app running:

  • Vercel: application hosting; serves the app and passes your requests to our code, receiving your IP address and request data in the process.
  • Supabase: database, authentication, and encrypted media storage.
  • Resend: transactional email (login, invites, account notices).
  • Cloudflare: map tiles, served from our own tile store to your browser to draw the map; receives your IP address to deliver them and stores no member data for us.
  • komoot (Photon): place search when you set a travel destination; receives the place name you type and your IP address, and stores nothing for us.

We may disclose information, including message content, when the law genuinely compels us (such as a valid warrant or court order) or to address an imminent threat to someone’s safety. We push back on overbroad requests and disclose only what we are required to. There is more behind these promises, and the Charter has the full story.

Cookies & local storage

We set only the cookies the app needs to work. Supabase, our authentication provider, uses strictly-necessary cookies to keep you signed in and secure your session. Your browser also stores a few functional map preferences locally on your device, such as your distance unit (miles or kilometers), whether the zoom buttons show, and whether to hide people you have hidden. These stay in your browser and are not sent anywhere.

We do not use tracking cookies, advertising cookies, or third-party trackers of any kind. Because nothing we set is non-essential, there is no consent banner to click through.

Retention & your choices

We keep your data, including your messages, while your account is open and for as long as needed to run the service and meet legal obligations. You can delete a conversation, and you can close your account at any time, which removes your profile, messages, and data from the active service, subject to limited records we must keep (for example, safety reports and any evidence attached to them, payment records our processor holds for tax and anti-fraud rules, CSAM evidence we are legally required to preserve, and a small set of one-way hashed abuse-prevention signals described below). Deleting your account is self-serve in Settings; for questions about your data, email hello@just2bucks.app.

Keeping banned accounts out. To make a ban meaningful on an invite-only platform, we retain a small set of abuse-prevention signals even after an account is closed or removed, so that a banned person cannot simply sign up again. These are one-way hashed or coarsened values, never your underlying information: for example a hashed form of your email, the invite relationship that let you join, and coarse device and image signals. We use them only to enforce bans and detect duplicate or evading accounts, never to profile you, never for advertising, and never for sale, and they cannot be reversed back into your original details.

Children

Just2Bucks is strictly for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will remove it.

Changes & contact

If we change this policy we will update the “last updated” date above and, for material changes, make it noticeable. Privacy questions go to hello@just2bucks.app.