The Premise Anchr Guide Inside Anchr Compare Pricing Download Anchr For Therapists

Anchr · Stop Drifting. Start Living.

1. Introduction

Anchr ("the App", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, how we use it, how we store and protect it, and your rights regarding that data.

Anchr is a mental health and wellness application that provides mood tracking, guided therapy modules, AI-assisted self-care, peer support, community discussion, and related features. Because of the sensitive nature of the data involved, we hold ourselves to the highest standards of privacy and transparency.

By creating an account and using Anchr, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the App.

2. Data Controller

The data controller responsible for your personal data is Anchr Health ("Anchr", "we"). For all privacy-related enquiries, data access requests, or complaints, you may contact us at:

If you are located in the European Economic Area (EEA) or the United Kingdom and wish to contact our designated privacy representative, please email privacy@anchr.health with the subject line "GDPR Request".

Anchr does not currently meet the legal threshold for being required to appoint a Data Protection Officer (DPO) under GDPR Article 37. Our privacy team acts as the single point of contact for data protection enquiries and is led by Anchr's management, who maintain direct oversight over data handling practices, sub-processor relationships, and breach response.

Where contact details for Anchr's legal entity or service of process are required by law, they can be obtained by emailing privacy@anchr.health with the subject line "Legal Notice".

3. Data We Collect

We collect only the data necessary to provide and personalise your self-care experience. Below is a comprehensive list of every category of data we collect:

3.1 Account Information

3.2 Mood & Wellness Data

3.3 Screening & Assessment Data

Screening scores are validated clinical instruments. They are used solely within the App to personalise your experience and are never shared with employers, insurers, or any third party.

3.4 Therapy & Self-Care Data

3.5 Living Compass Data

3.6 Vulnerability Vault Data

3.7 Community & Social Data

3.8 Peer Support Data (Anchr Someone)

3.9 Digital Sunset & Wellness Activity Data

3.10 Notification Data

3.11 Device & Technical Data

3.12 Audit & Compliance Data

3.13 Subscription & Billing Data

3.14 Authentication & Social Sign-In Data

We do NOT collect your precise location, contacts, browsing history, data from other apps on your device, or any biometric identifiers (e.g. fingerprints, face scans). We do not use device fingerprinting, advertising identifiers (IDFA/AAID), or cross-site tracking technologies.

4. Sensitive & Health-Related Data

Much of the data Anchr collects qualifies as sensitive personal data or special category data under privacy laws such as the GDPR, UK GDPR, and various US state privacy laws. This includes:

We process this sensitive data only with your explicit consent, which you provide when you create an account and accept these terms. You may withdraw consent at any time by deleting your account, which permanently erases all your data. See Section 10 (Your Rights) for details.

We apply heightened safeguards to all health-related data: it is encrypted in transit and at rest, isolated at the database level through row-level security, and access is logged in an immutable audit trail. Sensitive health data is never included in push notification content, community-visible profiles, or any data shared with third parties for their own purposes.

5. Legal Basis for Processing

We process your personal data on the following legal bases, depending on the type of data and the purpose of processing:

5.1 Performance of Contract (GDPR Art. 6(1)(b))

5.2 Explicit Consent (GDPR Art. 6(1)(a) & Art. 9(2)(a))

5.3 Legitimate Interest (GDPR Art. 6(1)(f))

5.4 Legal Obligation (GDPR Art. 6(1)(c))

6. How We Use Your Data

Your data is used exclusively to provide and improve your Anchr experience. Specifically, we use your data to:

7. Automated Decision-Making & Profiling

Anchr uses automated processing in the following areas. None of these produce legal effects or similarly significant effects on you, but we disclose them for full transparency:

7.1 AI Content Moderation

7.2 AI Therapy Recommendations

7.3 Wellness Scoring

7.4 Peer Support Matching

No automated decision made by Anchr restricts your access to the App, produces legal effects, or has similarly significant effects on you. All AI features are advisory tools to support your personal self-care journey. You have the right to request human review of any automated decision by contacting privacy@anchr.health.

8. What We Do NOT Do With Your Data

Your personal data will never be sold, rented, licensed, or shared with third parties for marketing, advertising, or any commercial purpose. Period.

9. Third-Party Services & Sub-Processors

We use a limited number of third-party services (sub-processors) to operate the App. Each sub-processor processes your data only as necessary to provide its specific function, under contractual obligations to protect your data. We do not permit any sub-processor to use your data for their own purposes.

9.1 Supabase (Database, Authentication & File Storage)

9.2 Anthropic (AI Language Model - Claude)

9.3 Expo (Push Notification Service)

9.4 RevenueCat (Subscription Management)

9.5 Apple & Google (App Distribution, Authentication & Device Services)

9.6 Sub-Processor Changes

We may engage new sub-processors from time to time to improve the App or replace an existing provider. We will update this list and, for material changes involving sensitive health data, provide notice in-app at least 14 days before the new sub-processor begins processing. If you object, you may withdraw consent by deleting your account before the change takes effect.

We maintain data processing agreements with all sub-processors. No sub-processor is permitted to use your data for their own marketing, analytics, advertising, or model training purposes. Where required by law (e.g. for transfers from the EEA, UK, or Switzerland), we rely on Standard Contractual Clauses or equivalent safeguards.

10. Your Rights

You have the following rights regarding your personal data, regardless of where you are located. Additional jurisdiction-specific rights are described in Section 14.

10.1 Right to Access

10.2 Right to Deletion

10.3 Right to Rectification

10.4 Right to Data Portability

10.5 Right to Withdraw Consent

10.6 Right to Restrict Processing

10.7 Right to Object

10.8 How to Exercise Your Rights

If you are located in the European Economic Area (EEA), United Kingdom, California, or other jurisdictions with specific privacy laws, you may have additional rights. See Section 14 for details.

11. Data Security

We take the security of your data seriously and implement multiple layers of protection:

11.1 Encryption

11.2 Access Controls

11.3 Monitoring & Auditing

11.4 Device Permissions

11.5 Photo Metadata & EXIF Handling

11.6 Security Incident Response

While we implement industry-standard security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents and notifying affected users in accordance with applicable law (see Section 16).

12. Data Retention

We retain your personal data only for as long as necessary to provide the App's services or as required by law. Below are our specific retention practices:

12.1 Active Account Data

12.2 Therapy Pathway Data

12.3 Temporary & Expiring Data

12.4 Audit & Compliance Logs

12.5 Account Deletion

13. Children's Privacy

Anchr is not intended for use by individuals under the age of 18 (or the age of majority in their jurisdiction). We do not knowingly collect personal data from children or minors.

If we become aware that we have inadvertently collected data from a person under the age of 18, we will take immediate steps to delete all associated data and terminate the account.

If you are a parent or guardian and believe your child has provided personal data to Anchr, please contact us immediately at privacy@anchr.health so we can take appropriate action.

We do not knowingly process data of children under 13 and therefore comply with the Children's Online Privacy Protection Act (COPPA). Under COPPA, we do not collect, use, or disclose personal information from children under 13.

14. Regional Privacy Rights

14.1 European Economic Area & United Kingdom (GDPR / UK GDPR)

If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation:

Our legal bases for processing are detailed in Section 5. For sensitive health data, our legal basis is your explicit consent (GDPR Article 9(2)(a)).

Where your data is transferred outside the EEA/UK (see Section 15), we rely on Standard Contractual Clauses approved by the European Commission and/or the UK's International Data Transfer Agreement.

To exercise any of these rights, email privacy@anchr.health with the subject line "GDPR Request". We will respond within 30 days.

14.2 California (CCPA / CPRA)

If you are a California resident:

In the preceding 12 months, we have not sold any personal information, nor do we intend to. We do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes other than providing the services you requested.

You may designate an authorised agent to submit a request on your behalf. The agent must provide proof of your authorisation, and we may still require you to verify your identity directly. To submit a request, email privacy@anchr.health with the subject line "CCPA Request". We will respond within 45 days (extendable by an additional 45 days with notice).

14.3 Virginia (VCDPA)

If you are a Virginia resident, the VCDPA provides you with rights to access, correct, delete, and obtain a portable copy of your personal data, as well as the right to opt out of targeted advertising, sale of personal data, and profiling. We do not engage in any of these. To exercise your rights, email privacy@anchr.health with the subject line "VCDPA Request".

14.4 Colorado (CPA)

If you are a Colorado resident, the Colorado Privacy Act provides similar rights. You may appeal a denied request by emailing privacy@anchr.health with the subject line "CPA Appeal". We will respond to appeals within 45 days.

14.5 Connecticut (CTDPA)

If you are a Connecticut resident, the CTDPA provides rights to access, correct, delete, and obtain a portable copy of your personal data. To exercise your rights, email privacy@anchr.health with the subject line "CTDPA Request".

14.6 Australia (Privacy Act 1988 & Australian Privacy Principles)

If you are located in Australia, Anchr handles your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). You have the right to request access to, and correction of, the personal information we hold about you, and to lodge a complaint about how we have handled your personal information. To exercise these rights or make a complaint, email privacy@anchr.health with the subject line "APP Request". If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

Sensitive health information is handled in accordance with APP 3.3 (collection only with consent) and APP 6 (use and disclosure restricted to the primary purpose of collection), with cross-border disclosures subject to APP 8 safeguards.

14.7 Canada (PIPEDA & Provincial Laws)

If you are located in Canada, your personal information is handled in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy laws (including Quebec's Law 25, British Columbia's PIPA, and Alberta's PIPA). You have the right to access, correct, and withdraw consent to the processing of your personal data, and to challenge our handling practices with the Office of the Privacy Commissioner of Canada (www.priv.gc.ca).

14.8 Other US States

If you reside in a US state that has enacted consumer privacy legislation (including but not limited to Utah, Texas, Oregon, Montana, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Minnesota, Maryland, and Kentucky), we honour the data access, deletion, correction, and portability rights provided by your state's law. We do not sell personal data, engage in targeted advertising, or use profiling that produces legal or similarly significant effects. To exercise your rights, email privacy@anchr.health with the subject line "Privacy Rights Request" and include your state of residence.

14.9 Right to Appeal

If we deny a privacy rights request, you have the right to appeal. Email privacy@anchr.health with the subject line "Privacy Appeal" within 60 days of receiving our denial. We will respond within 45 days. If your appeal is denied, we will provide you with information about how to contact your local data protection authority or attorney general's office.

15. International Data Transfers

Your data may be stored and processed on servers located in the United States, Australia, and other countries where our sub-processors operate. When your data is transferred outside your country of residence, we ensure appropriate safeguards:

You may request a copy of the relevant transfer safeguards by contacting privacy@anchr.health.

Please note that the United States may not provide the same level of legal protection for personal data as your country of residence. Surveillance laws in the U.S. may, in certain circumstances, permit government authorities to access data without notifying the affected individual. The safeguards listed above are designed to provide a level of protection essentially equivalent to that required by EU/UK law, but you should consider this carefully before consenting to the processing described in this Privacy Policy.

16. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

We maintain an internal breach response procedure including detection, investigation, containment, notification, and remediation. All breach-related records are retained for a minimum of 6 years.

17. Cookies & Tracking Technologies

Anchr is a native mobile application and does not use cookies. We do not use any analytics SDKs, tracking pixels, fingerprinting, or similar tracking technologies. Your activity within the App is not tracked or profiled for any purpose other than providing you with the App's core features.

Our landing website (anchr.app) is a static page that does not set cookies, use analytics tools, or track visitors.

We comply with Apple's App Tracking Transparency (ATT) framework. Anchr does not track users across other companies' apps or websites. We declare accurate privacy nutrition labels on the Apple App Store and Google Play Store Data Safety section.

17.1 Do Not Track & Global Privacy Control

Because Anchr does not track users across third-party sites or services and does not sell or share personal information, the App has nothing to honour or disable when it receives a "Do Not Track" browser signal or a Global Privacy Control (GPC) signal. Your privacy is protected by default, without the need to opt out.

17.2 Marketing Communications

We do not send marketing or promotional emails by default. If you opt in to marketing communications (for example, product newsletters or feature announcements), you can unsubscribe at any time by clicking the "unsubscribe" link in the email or by emailing privacy@anchr.health. Transactional communications (account verification, subscription receipts, security alerts, legal notices) are a necessary part of providing the service and cannot be opted out of while your account is active.

17.3 Aggregated & De-Identified Data

We may produce aggregated or de-identified statistics about App usage. Once data is aggregated or de-identified so it can no longer reasonably be linked to you, it is no longer considered personal data. We do not attempt to re-identify de-identified data, and we contractually prohibit our sub-processors from doing so.

17.4 Business Transfers

In the event of a merger, acquisition, corporate restructuring, financing, bankruptcy, or sale of some or all of Anchr's assets, your personal data may be transferred to the acquiring or successor entity. We will require the successor to honour the terms of this Privacy Policy, or we will notify you in-app and by email of any material change to privacy practices before your data becomes subject to a different privacy policy - giving you the opportunity to delete your account before the change takes effect.

17.5 Law Enforcement & Legal Process

We will disclose personal data to law enforcement, regulators, or other third parties only when compelled to do so by a valid legal process (subpoena, court order, warrant, or equivalent binding request) or when we believe in good faith that disclosure is necessary to comply with law, protect the rights, property, or safety of Anchr, users, or the public, or investigate fraud or violations of these Terms. Where permitted by law, we will attempt to notify affected users before making any such disclosure.

17.6 Anonymous Use & Identity

Community features operate under a display name and avatar that you control. You are not required to use your real name, and we encourage users to protect their privacy by choosing a display name that does not identify them. We do not verify display names, but we prohibit impersonation of other users, public figures, Anchr staff, or any healthcare professional.

18. Health Data Regulatory Compliance

Anchr is a consumer wellness application, not a covered entity or business associate under HIPAA. However, given the sensitive nature of the health data we handle, we voluntarily adopt practices aligned with HIPAA's Security Rule and Privacy Rule principles:

If your employer, health plan, or healthcare provider directs you to use Anchr and we enter into a Business Associate Agreement (BAA), the terms of that BAA will apply in addition to this Privacy Policy. Contact privacy@anchr.health for BAA enquiries.

19. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the App's features, or applicable laws.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data.

20. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

We will acknowledge receipt of your enquiry within 5 business days and provide a substantive response within 30 days, or within the shorter timeframe required by your jurisdiction's laws (e.g. 45 days for CCPA requests, 30 days for GDPR requests).

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. For EEA residents, a list of supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. For UK residents, you may contact the Information Commissioner's Office (ICO).