1. Introduction
Anchr ("the App", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, how we use it, how we store and protect it, and your rights regarding that data.
Anchr is a mental health and wellness application that provides mood tracking, guided therapy modules, AI-assisted self-care, peer support, community discussion, and related features. Because of the sensitive nature of the data involved, we hold ourselves to the highest standards of privacy and transparency.
By creating an account and using Anchr, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the App.
2. Data Controller
The data controller responsible for your personal data is Anchr Health ("Anchr", "we"). For all privacy-related enquiries, data access requests, or complaints, you may contact us at:
- Email: privacy@anchr.health
- General support: privacy@anchr.health
If you are located in the European Economic Area (EEA) or the United Kingdom and wish to contact our designated privacy representative, please email privacy@anchr.health with the subject line "GDPR Request".
Anchr does not currently meet the legal threshold for being required to appoint a Data Protection Officer (DPO) under GDPR Article 37. Our privacy team acts as the single point of contact for data protection enquiries and is led by Anchr's management, who maintain direct oversight over data handling practices, sub-processor relationships, and breach response.
Where contact details for Anchr's legal entity or service of process are required by law, they can be obtained by emailing privacy@anchr.health with the subject line "Legal Notice".
3. Data We Collect
We collect only the data necessary to provide and personalise your self-care experience. Below is a comprehensive list of every category of data we collect:
3.1 Account Information
- Email address (used for authentication and account recovery)
- Display name and avatar image (chosen by you for community features)
- Terms & Conditions and Privacy Policy acceptance timestamps
- Onboarding completion status and date
- App preferences: theme (light/dark/system), haptic feedback, grounding reminders, screen time goal, preferred therapy modalities
3.2 Mood & Wellness Data
- Daily mood ratings (1-5 scale) and the time period of each entry (e.g. morning, afternoon, evening)
- Emotional state selections from a predefined list (e.g. happy, anxious, grateful, lonely) and any custom emotion labels you create
- Sleep data: hours slept, sleep quality rating (1-5), sleep disruptions (e.g. racing thoughts, nightmares, pain), and estimated time to fall asleep
- Energy levels and stress levels (1-5 scale each)
- Physical symptoms you report (e.g. headache, muscle tension, fatigue) and any custom symptoms you enter
- Daily activities and avoided activities, including custom entries you add
- Context tags you attach to mood entries
- Journal entries and gratitude entries (free-text)
- Thought snapshots: a brief situation description, an automatic thought, and emotion intensity rating (1-10)
- Computed wellness scores and Anchr Score
- Streak data (consecutive daily check-ins)
3.3 Screening & Assessment Data
- PHQ-9 depression screening scores (9 item-level scores covering mood, sleep, energy, appetite, self-worth, concentration, psychomotor changes and self-harm thoughts, plus total score)
- GAD-7 anxiety screening scores (7 item-level scores covering nervousness, worry, restlessness, irritability and fearful anticipation, plus total score)
- Assessment trigger context (e.g. pathway start, pathway completion, reassessment)
- AI-extracted screening indicators from therapy conversations
3.4 Therapy & Self-Care Data
- AI conversation history with the Anchr Guide (intake and therapeutic sessions), including all messages you send and responses generated
- AI-generated clinical summaries, identified themes, and recommended therapy modules
- Contextual memories used to personalise your AI experience: semantic embeddings (numerical vector representations) of your insights, concerns, progress, and coping strategies
- Therapy module progress, lesson completion records, and notes you take during lessons
- Module feedback: ratings and comments you provide after completing a module
- Pathway data: your active therapy pathway, recommended modules, completed modules, and pathway transition history
- Thought Defusion Journal entries: original thought, reframed thought, defusion technique used, values alignment, intensity ratings before and after, and thought theme
- AI Relationship Balance assessment scores, category breakdowns, and AI-generated recommendations
3.5 Living Compass Data
- Selected life domains and personal values you define
- Bull's-eye alignment ratings for each value (1-10)
- Intentions (value-aligned action plans): description, planned date and time, size, completion status, and repeat pattern
- Intention reflections: engagement quality (1-5), mood shift (better, same, worse), written reflection, and whether you found the activity worth doing
- Compass score and intention streaks
3.6 Vulnerability Vault Data
- Written letters, text entries, voice memos, and photos you upload to your personal Vault
- Voice memo duration and revisit history
- These files are stored securely and are accessible only to you
3.7 Community & Social Data
- Discussion thread posts and replies you author (title, content, tags)
- Support reactions (hearts) you give or receive on threads and replies
- Community support group memberships
- User block and report actions (including reason and description)
- Automated moderation verdicts on messages and posts (safe, unsafe, crisis, pending) generated by our AI moderation system
3.8 Peer Support Data (Anchr Someone)
- Supportive messages you write for others (4-280 characters)
- Requests to receive peer support
- Anonymous match records and replies
- Reports you file about inappropriate peer support messages
3.9 Digital Sunset & Wellness Activity Data
- Digital Sunset sessions: your day reflection, suggested wind-down activity, and breathing exercise completion
- Challenge completions: which challenges you completed, your reflection, and whether you shared to the community feed
- Grounding moment (Anchr Moments) completion records
- In-app screen time session data: activity type, duration, and timestamps
3.10 Notification Data
- Device push notification tokens (used solely to deliver notifications you have opted into)
- Device platform type (iOS or Android)
- Your notification preferences for each notification category (e.g. daily check-in reminders, community replies, and peer support messages)
3.11 Device & Technical Data
- Device platform (iOS or Android) for notification routing
- Device locale for localisation purposes
- Authentication tokens stored securely on your device
3.12 Audit & Compliance Data
- Access logs recording when protected health information is read, created, updated, deleted, or exported - including the resource type, a timestamp, your IP address, and your device's user agent string
- These logs are append-only and cannot be modified or deleted. They are maintained for compliance and security purposes.
3.13 Subscription & Billing Data
- Subscription status, plan type, renewal date, trial status, and entitlement flags that unlock Premium features within the App
- Platform-issued purchase identifiers (Apple App Store transaction IDs, Google Play order IDs) used to link your account to your subscription
- Anonymised subscriber IDs generated by RevenueCat to synchronise subscription state across your devices
- Anchr does NOT receive, store, or process your payment card number, CVC, bank account number, or billing address. These are handled exclusively by Apple and Google.
3.14 Authentication & Social Sign-In Data
- When you sign in with Apple or Google, we receive a unique user identifier, your verified email address (or a relay email if you choose to hide it), and your name (if you share it)
- We do not receive your password, social-platform friends list, posts, or any data beyond the basic authentication payload
- If you use Sign in with Apple's "Hide my email" option, we honour the private relay address and will never attempt to de-anonymise it
4. Sensitive & Health-Related Data
Much of the data Anchr collects qualifies as sensitive personal data or special category data under privacy laws such as the GDPR, UK GDPR, and various US state privacy laws. This includes:
- Mental health data: mood ratings, depression and anxiety screening scores (PHQ-9, GAD-7), emotional states, stress levels, and AI-identified psychological themes
- Physical health data: sleep patterns, energy levels, physical symptoms
- Therapeutic data: AI conversation history about mental health concerns, clinical summaries, therapy module progress, thought records
- Self-reported behavioural data: avoided activities, substance-related sleep disruptions, daily activity patterns
We apply heightened safeguards to all health-related data: it is encrypted in transit and at rest, isolated at the database level through row-level security, and access is logged in an immutable audit trail. Sensitive health data is never included in push notification content, community-visible profiles, or any data shared with third parties for their own purposes.
5. Legal Basis for Processing
We process your personal data on the following legal bases, depending on the type of data and the purpose of processing:
5.1 Performance of Contract (GDPR Art. 6(1)(b))
- Providing the core App features you signed up for: mood tracking, therapy modules, AI Guide conversations, community features, peer support, and related services
- Managing your account: authentication, profile storage, preference management
- Delivering push notifications you have opted into
5.2 Explicit Consent (GDPR Art. 6(1)(a) & Art. 9(2)(a))
- Processing sensitive health data (mood, screening scores, therapy sessions, physical symptoms) - your explicit consent is provided when you create an account and can be withdrawn at any time
- Generating and storing semantic embeddings of your therapeutic insights for AI personalisation
- Sending your conversation data to Anthropic for AI response generation, content moderation, and embedding creation
5.3 Legitimate Interest (GDPR Art. 6(1)(f))
- Maintaining the security of the App and preventing abuse (e.g. content moderation, fraud detection, rate limiting)
- Generating aggregated, anonymised insights to improve App quality (no individual data is shared or identifiable)
- Maintaining audit logs for compliance and security purposes
5.4 Legal Obligation (GDPR Art. 6(1)(c))
- Maintaining compliance records including data access audit logs, breach records, and consent records as required by applicable privacy and health data laws
- Responding to lawful data access requests from regulatory authorities
6. How We Use Your Data
Your data is used exclusively to provide and improve your Anchr experience. Specifically, we use your data to:
- Personalise your self-care journey, including mood trends, wellness insights, sleep analysis, and the Anchr Score
- Provide contextual, personalised AI support through the Anchr Guide using your conversation history and semantic memories
- Administer validated screening instruments (PHQ-9, GAD-7) and track changes over time to help you monitor your wellbeing
- Track your therapy module progress, pathway completions, and surface relevant content and recommendations
- Power your Living Compass: tracking values, intentions, and alignment to support behavioural activation
- Enable community features such as discussion forums and support groups
- Facilitate anonymous peer support matching through the Anchr Someone feature
- Moderate user-generated content for safety: all community posts, replies, and peer support messages are screened by our automated AI moderation system to detect harmful, abusive, or crisis-indicating content
- Detect crisis language and surface emergency resources when potentially concerning language is identified in your entries or conversations
- Deliver push notifications you have opted into (check-in reminders, community replies, and peer support messages)
- Generate aggregated, anonymised insights to improve the App (no individual data is ever shared or identifiable)
- Maintain security and compliance through audit logging, rate limiting, and abuse prevention
7. Automated Decision-Making & Profiling
Anchr uses automated processing in the following areas. None of these produce legal effects or similarly significant effects on you, but we disclose them for full transparency:
7.1 AI Content Moderation
- Community posts, replies, and peer support messages are automatically screened by our AI system and classified as safe, unsafe, or crisis-indicating
- Messages flagged as unsafe may be hidden from other users. Messages flagged as crisis-indicating trigger the display of emergency resources
- You may report a moderation decision you believe is incorrect through the in-app reporting feature
7.2 AI Therapy Recommendations
- The Anchr Guide uses your conversation history, identified themes, and semantic embeddings to recommend therapy modules and pathways
- Screening scores (PHQ-9, GAD-7) may be extracted from your AI conversations to inform personalisation. You are never diagnosed; these are self-monitoring tools.
- AI-generated clinical summaries are created to provide continuity across sessions. These are not professional clinical assessments.
7.3 Wellness Scoring
- The Anchr Score and wellness scores are computed automatically from your mood, sleep, energy, stress, engagement, and activity data
- These scores are for your personal insight only and have no impact on your access to features or services
7.4 Peer Support Matching
- The Anchr Someone feature uses automated matching to connect users offering support with those requesting it. Matching is random and anonymous; no profiling is used to select matches.
8. What We Do NOT Do With Your Data
- We do NOT sell your data to anyone, under any circumstances, and have not done so in the preceding 12 months
- We do NOT "share" your data for cross-context behavioural advertising as defined under CCPA/CPRA and analogous state privacy laws
- We do NOT use third-party analytics or tracking tools (no Google Analytics, Firebase Analytics, Segment, Amplitude, Mixpanel, or similar services)
- We do NOT serve advertisements, use your data to build advertising profiles, or participate in any ad network
- We do NOT track your behaviour across other apps or websites, and do not set or read the IDFA/AAID advertising identifier
- We do NOT share your data with data brokers or aggregators
- We do NOT use your personal data to train general-purpose AI models - your conversations and health data are never used as training data by us or by our sub-processors
- We do NOT create shadow profiles or collect data about non-users
- We do NOT share your health data with employers, insurers, or any commercial entity
- We do NOT use device fingerprinting, canvas fingerprinting, browser fingerprinting, or any similar identification technique
- We do NOT disclose your data to government agencies except where legally required by valid subpoena, court order, or equivalent binding legal process - and we will, where lawful and practical, notify you before doing so
- We do NOT merge, link, or aggregate your Anchr data with data from other sources that might identify you without your explicit consent
9. Third-Party Services & Sub-Processors
We use a limited number of third-party services (sub-processors) to operate the App. Each sub-processor processes your data only as necessary to provide its specific function, under contractual obligations to protect your data. We do not permit any sub-processor to use your data for their own purposes.
9.1 Supabase (Database, Authentication & File Storage)
- Provider: Supabase Inc.
- Purpose: Hosting our database, handling authentication, and storing your uploaded files (vault media, avatar images)
- Data processed: All account, health, therapy, community, and media data described in Section 3
- Infrastructure: Cloud servers hosted by Amazon Web Services (AWS)
- Safeguards: Row-level security (RLS) policies ensure only you can access your own data. All data is encrypted at rest and in transit. Private storage buckets prevent unauthorised file access.
- Privacy policy: https://supabase.com/privacy
9.2 Anthropic (AI Language Model - Claude)
- Provider: Anthropic PBC
- Purpose: Powering the Anchr Guide AI conversations (intake sessions, therapeutic sessions), generating clinical summaries, content moderation, crisis detection, and generating semantic embeddings for personalisation
- Data processed: Your AI conversation messages, session context (the active pathway and brief recent check-in summaries), moderation requests, and text snippets from therapy sessions for embedding generation
- Data NOT sent to Anthropic: Your real name, email address, date of birth, payment details, IP address, device identifiers, screening scores (PHQ-9, GAD-7, AUDIT-C, PC-PTSD-5, K6, ISI), Vulnerability Vault entries (photos, audio, written entries), Defusion journal entries, Living Compass entries, mood-tracking history, and any other private records held in your account. Conversation context sent to Anthropic is stripped of identifiers before transmission.
- Semantic embeddings: Numerical vector representations of your therapeutic insights, concerns, and progress are generated by Anthropic's services. These are not human-readable text. They are stored in our database to enable semantic similarity matching for personalisation.
- Retention: Conversation data sent to Anthropic's API is processed in real-time to generate responses. Under our commercial API agreement, Anthropic does not use your inputs or outputs to train or improve their models, and inputs/outputs are subject to Anthropic's published API data retention schedule.
- Consent: Before any data is sent to Anthropic for the first time, you are shown an in-app disclosure that names Anthropic, lists what is and is not transmitted, and requires you to tap "I Agree & Continue" to opt in. You can withdraw by ceasing to use the AI features or by deleting your account from Settings.
- Privacy policy: https://www.anthropic.com/legal/privacy
9.3 Expo (Push Notification Service)
- Provider: Expo (650 Industries Inc.)
- Purpose: Delivering push notifications to your device
- Data processed: Your device push token and notification content (titles, message text). No personal health data is included in notification payloads.
- Privacy policy: https://expo.dev/privacy
9.4 RevenueCat (Subscription Management)
- Provider: RevenueCat, Inc.
- Purpose: Synchronising subscription entitlements across your devices, verifying receipts with Apple and Google, and managing subscription lifecycle events (purchase, renewal, cancellation, refund)
- Data processed: Your Anchr user ID, platform transaction receipts, subscription state, device platform, and country/region derived from your App Store or Google Play account
- RevenueCat never receives payment card details. Payment is handled exclusively by Apple or Google.
- Privacy policy: https://www.revenuecat.com/privacy
9.5 Apple & Google (App Distribution, Authentication & Device Services)
- Apple (App Store) and Google (Google Play) distribute the App and process your app download and in-app purchase transactions. Their respective privacy policies apply to those interactions.
- Sign in with Apple and Google Sign-In provide optional social authentication. The data we receive is limited to the basic identity payload (unique ID, verified email, optional name).
- Apple Push Notification Service (APNs) and Google Firebase Cloud Messaging (FCM) act as intermediary delivery services for push notifications. Expo sends notifications through these platform services.
9.6 Sub-Processor Changes
We may engage new sub-processors from time to time to improve the App or replace an existing provider. We will update this list and, for material changes involving sensitive health data, provide notice in-app at least 14 days before the new sub-processor begins processing. If you object, you may withdraw consent by deleting your account before the change takes effect.
10. Your Rights
You have the following rights regarding your personal data, regardless of where you are located. Additional jurisdiction-specific rights are described in Section 14.
10.1 Right to Access
- You can view all of your data within the App at any time (mood history, journal entries, session records, vault contents, community posts, therapy progress)
- You may request and download a full export of all your personal data in machine-readable JSON format through Settings (Data Export)
- Your data export includes all tables and records associated with your account
10.2 Right to Deletion
- You may delete individual entries (mood logs, journal entries, vault items, community posts, defusion records, compass data) at any time
- You may delete your entire account and all associated data through Settings. This triggers a cascading permanent deletion across all data tables, storage buckets, and audit records associated with your account.
- Deletion is permanent and cannot be reversed
- We honour deletion requests within 30 days, or sooner where required by law
10.3 Right to Rectification
- You can edit your profile information (display name, avatar) at any time
- You can update your preferences, notification settings, and therapy modality preferences at any time
- If you believe any data we hold about you is inaccurate, contact privacy@anchr.health
10.4 Right to Data Portability
- You may export your data in a structured, commonly used, machine-readable JSON format
- The export includes all personal data categories described in Section 3
10.5 Right to Withdraw Consent
- You may withdraw consent for push notifications at any time through your device settings or the App's notification preferences
- You may withdraw consent for the processing of your health data by deleting your account
- Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal
10.6 Right to Restrict Processing
- You may request that we restrict the processing of your data in certain circumstances
- Contact privacy@anchr.health to make a restriction request
10.7 Right to Object
- You may object to processing based on legitimate interest at any time by contacting privacy@anchr.health
- We will cease processing unless we demonstrate compelling legitimate grounds that override your interests
10.8 How to Exercise Your Rights
- Most rights can be exercised directly in the App: data access, data export, individual entry deletion, account deletion, and preference changes are all available in Settings
- For rights that require contacting us, email privacy@anchr.health
- We will verify your identity before processing any request
- We will respond within 30 days, or within the shorter timeframe required by your jurisdiction's laws
- We will never charge a fee for exercising your rights under normal circumstances
11. Data Security
We take the security of your data seriously and implement multiple layers of protection:
11.1 Encryption
- All data in transit is encrypted using TLS 1.2 or higher
- All data at rest is encrypted using AES-256 encryption
- Authentication tokens are stored using the platform's secure storage (iOS Keychain / Android Keystore)
11.2 Access Controls
- Row-level security (RLS) policies enforce database-level isolation
- Media files are stored in private, authenticated storage buckets accessible only by the owning user
- Server-side edge functions use service-role credentials scoped to the minimum necessary permissions
- API endpoints enforce authentication and authorisation checks before processing any request
11.3 Monitoring & Auditing
- All access to protected health information is logged in an immutable, append-only audit trail
- Community content moderation includes automated AI screening
- Rate limiting and abuse prevention mechanisms protect against automated attacks
11.4 Device Permissions
- Camera access: requested only to take photos for your Vault entries and profile picture
- Photo library access: requested only to select existing photos
- Microphone access: requested only when you choose to record a voice memo in the Vault
- Notification permission: requested so we can send reminders and alerts you opt into
- You may revoke any permission at any time through your device's Settings. Revoking a permission may disable the associated feature but will not affect the rest of the App.
11.5 Photo Metadata & EXIF Handling
- When you upload a photo to the Vault or use it as an avatar, the image file may include embedded metadata (EXIF data) such as camera model, timestamp, and, where available on your device, GPS coordinates.
- We do not use or display this metadata within the App. However, because we upload the original file to secure storage, metadata may be retained inside the file until you delete it. If you wish to strip metadata before uploading, your device's Photos app typically offers a "remove location" or similar option when sharing.
11.6 Security Incident Response
- We maintain an internal security incident response procedure including monitoring, triage, escalation, containment, user notification, and post-incident review
- We conduct periodic access reviews and enforce principle-of-least-privilege for all internal systems
- Credentials for third-party services are stored in a secret-management system, rotated on personnel changes, and never committed to source control
- Security researchers are welcome to report suspected vulnerabilities in good faith to privacy@anchr.health with the subject line "Security Report". We do not take legal action against good-faith researchers who follow responsible disclosure practices.
While we implement industry-standard security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents and notifying affected users in accordance with applicable law (see Section 16).
12. Data Retention
We retain your personal data only for as long as necessary to provide the App's services or as required by law. Below are our specific retention practices:
12.1 Active Account Data
- All personal data (mood entries, therapy sessions, vault items, community posts, compass data, etc.) is retained for as long as your account exists and is active
- You may delete individual entries at any time, and they will be permanently removed
12.2 Therapy Pathway Data
- Completed therapy modules and lesson progress are preserved as part of your historical record
- Abandoned therapy pathways follow a structured cleanup: completed modules are preserved, in-progress modules enter a cooling-off period, and never-started modules are removed
12.3 Temporary & Expiring Data
- Peer support pool entries (Anchr Someone) expire automatically after 24 hours if not matched
- Unpaired peer support messages held for matching are purged on the same 24-hour expiry schedule
12.4 Audit & Compliance Logs
- PHI audit logs are retained for a minimum of 6 years
- These logs are append-only and cannot be modified or selectively deleted
12.5 Account Deletion
- When you delete your account, all associated personal data is permanently and irreversibly deleted from our primary database and storage systems
- Standard encrypted database backups may retain deleted data for up to 30 days, after which it is permanently purged
- Data previously sent to Anthropic for AI processing cannot be recalled, but under our API terms it is not retained for training and is subject to Anthropic's published data retention schedule
13. Children's Privacy
Anchr is not intended for use by individuals under the age of 18 (or the age of majority in their jurisdiction). We do not knowingly collect personal data from children or minors.
If we become aware that we have inadvertently collected data from a person under the age of 18, we will take immediate steps to delete all associated data and terminate the account.
If you are a parent or guardian and believe your child has provided personal data to Anchr, please contact us immediately at privacy@anchr.health so we can take appropriate action.
We do not knowingly process data of children under 13 and therefore comply with the Children's Online Privacy Protection Act (COPPA). Under COPPA, we do not collect, use, or disclose personal information from children under 13.
14. Regional Privacy Rights
14.1 European Economic Area & United Kingdom (GDPR / UK GDPR)
If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation:
- Right to access, correct, or delete your personal data (Articles 15-17)
- Right to restrict processing (Article 18)
- Right to object to processing based on legitimate interest (Article 21)
- Right to receive your personal data in a portable format (Article 20)
- Right not to be subject to decisions based solely on automated processing (Article 22) - see Section 7
- Right to lodge a complaint with your local supervisory authority
Our legal bases for processing are detailed in Section 5. For sensitive health data, our legal basis is your explicit consent (GDPR Article 9(2)(a)).
Where your data is transferred outside the EEA/UK (see Section 15), we rely on Standard Contractual Clauses approved by the European Commission and/or the UK's International Data Transfer Agreement.
To exercise any of these rights, email privacy@anchr.health with the subject line "GDPR Request". We will respond within 30 days.
14.2 California (CCPA / CPRA)
If you are a California resident:
- Right to know: What personal information we collect, the sources, the business purposes, and the categories of third parties with whom we share it
- Right to delete: Request deletion of your personal information
- Right to correct: Request correction of inaccurate personal information
- Right to opt out of the sale or sharing of personal information - we never sell or share your data
- Right to limit use of sensitive personal information - we use it only for core services
- Right to non-discrimination for exercising your privacy rights
In the preceding 12 months, we have not sold any personal information, nor do we intend to. We do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes other than providing the services you requested.
You may designate an authorised agent to submit a request on your behalf. The agent must provide proof of your authorisation, and we may still require you to verify your identity directly. To submit a request, email privacy@anchr.health with the subject line "CCPA Request". We will respond within 45 days (extendable by an additional 45 days with notice).
14.3 Virginia (VCDPA)
If you are a Virginia resident, the VCDPA provides you with rights to access, correct, delete, and obtain a portable copy of your personal data, as well as the right to opt out of targeted advertising, sale of personal data, and profiling. We do not engage in any of these. To exercise your rights, email privacy@anchr.health with the subject line "VCDPA Request".
14.4 Colorado (CPA)
If you are a Colorado resident, the Colorado Privacy Act provides similar rights. You may appeal a denied request by emailing privacy@anchr.health with the subject line "CPA Appeal". We will respond to appeals within 45 days.
14.5 Connecticut (CTDPA)
If you are a Connecticut resident, the CTDPA provides rights to access, correct, delete, and obtain a portable copy of your personal data. To exercise your rights, email privacy@anchr.health with the subject line "CTDPA Request".
14.6 Australia (Privacy Act 1988 & Australian Privacy Principles)
If you are located in Australia, Anchr handles your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). You have the right to request access to, and correction of, the personal information we hold about you, and to lodge a complaint about how we have handled your personal information. To exercise these rights or make a complaint, email privacy@anchr.health with the subject line "APP Request". If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
Sensitive health information is handled in accordance with APP 3.3 (collection only with consent) and APP 6 (use and disclosure restricted to the primary purpose of collection), with cross-border disclosures subject to APP 8 safeguards.
14.7 Canada (PIPEDA & Provincial Laws)
If you are located in Canada, your personal information is handled in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy laws (including Quebec's Law 25, British Columbia's PIPA, and Alberta's PIPA). You have the right to access, correct, and withdraw consent to the processing of your personal data, and to challenge our handling practices with the Office of the Privacy Commissioner of Canada (www.priv.gc.ca).
14.8 Other US States
If you reside in a US state that has enacted consumer privacy legislation (including but not limited to Utah, Texas, Oregon, Montana, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Minnesota, Maryland, and Kentucky), we honour the data access, deletion, correction, and portability rights provided by your state's law. We do not sell personal data, engage in targeted advertising, or use profiling that produces legal or similarly significant effects. To exercise your rights, email privacy@anchr.health with the subject line "Privacy Rights Request" and include your state of residence.
14.9 Right to Appeal
If we deny a privacy rights request, you have the right to appeal. Email privacy@anchr.health with the subject line "Privacy Appeal" within 60 days of receiving our denial. We will respond within 45 days. If your appeal is denied, we will provide you with information about how to contact your local data protection authority or attorney general's office.
15. International Data Transfers
Your data may be stored and processed on servers located in the United States, Australia, and other countries where our sub-processors operate. When your data is transferred outside your country of residence, we ensure appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA
- The UK's International Data Transfer Agreement (IDTA) or UK Addendum to SCCs for transfers from the United Kingdom
- Swiss Federal Act on Data Protection (FADP) transfer mechanisms for transfers from Switzerland
- Australian Privacy Principle 8 cross-border disclosure safeguards for transfers of Australian-collected personal information
- Encryption of all data in transit (TLS 1.2+) and at rest (AES-256)
- Contractual obligations with all sub-processors to maintain security standards consistent with this policy
- Row-level security ensuring data isolation regardless of server location
You may request a copy of the relevant transfer safeguards by contacting privacy@anchr.health.
Please note that the United States may not provide the same level of legal protection for personal data as your country of residence. Surveillance laws in the U.S. may, in certain circumstances, permit government authorities to access data without notifying the affected individual. The safeguards listed above are designed to provide a level of protection essentially equivalent to that required by EU/UK law, but you should consider this carefully before consenting to the processing described in this Privacy Policy.
16. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33)
- Notify affected users without undue delay when the breach is likely to result in a high risk (GDPR Article 34)
- Comply with applicable US state breach notification laws (generally 30-60 days)
- Describe: the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken to address the breach
- Deliver notifications through the App and/or via your registered email address
We maintain an internal breach response procedure including detection, investigation, containment, notification, and remediation. All breach-related records are retained for a minimum of 6 years.
17. Cookies & Tracking Technologies
Anchr is a native mobile application and does not use cookies. We do not use any analytics SDKs, tracking pixels, fingerprinting, or similar tracking technologies. Your activity within the App is not tracked or profiled for any purpose other than providing you with the App's core features.
Our landing website (anchr.app) is a static page that does not set cookies, use analytics tools, or track visitors.
We comply with Apple's App Tracking Transparency (ATT) framework. Anchr does not track users across other companies' apps or websites. We declare accurate privacy nutrition labels on the Apple App Store and Google Play Store Data Safety section.
17.1 Do Not Track & Global Privacy Control
Because Anchr does not track users across third-party sites or services and does not sell or share personal information, the App has nothing to honour or disable when it receives a "Do Not Track" browser signal or a Global Privacy Control (GPC) signal. Your privacy is protected by default, without the need to opt out.
17.2 Marketing Communications
We do not send marketing or promotional emails by default. If you opt in to marketing communications (for example, product newsletters or feature announcements), you can unsubscribe at any time by clicking the "unsubscribe" link in the email or by emailing privacy@anchr.health. Transactional communications (account verification, subscription receipts, security alerts, legal notices) are a necessary part of providing the service and cannot be opted out of while your account is active.
17.3 Aggregated & De-Identified Data
We may produce aggregated or de-identified statistics about App usage. Once data is aggregated or de-identified so it can no longer reasonably be linked to you, it is no longer considered personal data. We do not attempt to re-identify de-identified data, and we contractually prohibit our sub-processors from doing so.
17.4 Business Transfers
In the event of a merger, acquisition, corporate restructuring, financing, bankruptcy, or sale of some or all of Anchr's assets, your personal data may be transferred to the acquiring or successor entity. We will require the successor to honour the terms of this Privacy Policy, or we will notify you in-app and by email of any material change to privacy practices before your data becomes subject to a different privacy policy - giving you the opportunity to delete your account before the change takes effect.
17.5 Law Enforcement & Legal Process
We will disclose personal data to law enforcement, regulators, or other third parties only when compelled to do so by a valid legal process (subpoena, court order, warrant, or equivalent binding request) or when we believe in good faith that disclosure is necessary to comply with law, protect the rights, property, or safety of Anchr, users, or the public, or investigate fraud or violations of these Terms. Where permitted by law, we will attempt to notify affected users before making any such disclosure.
17.6 Anonymous Use & Identity
Community features operate under a display name and avatar that you control. You are not required to use your real name, and we encourage users to protect their privacy by choosing a display name that does not identify them. We do not verify display names, but we prohibit impersonation of other users, public figures, Anchr staff, or any healthcare professional.
18. Health Data Regulatory Compliance
Anchr is a consumer wellness application, not a covered entity or business associate under HIPAA. However, given the sensitive nature of the health data we handle, we voluntarily adopt practices aligned with HIPAA's Security Rule and Privacy Rule principles:
- We maintain an immutable audit log recording all access to protected health information
- We have established a documented breach notification procedure consistent with HIPAA's Breach Notification Rule
- We implement administrative, physical, and technical safeguards for health data
- We retain compliance and audit records for a minimum of 6 years
If your employer, health plan, or healthcare provider directs you to use Anchr and we enter into a Business Associate Agreement (BAA), the terms of that BAA will apply in addition to this Privacy Policy. Contact privacy@anchr.health for BAA enquiries.
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the App's features, or applicable laws.
- Material changes (e.g. new data categories, new sub-processors, changes to your rights) will be communicated through an in-app notification banner before the changes take effect
- For material changes, we will provide at least 14 days' notice before the updated policy takes effect
- Non-material changes (e.g. formatting, clarifications that do not alter the substance) may be made without prior notice
- The "Effective Date" at the top of this policy indicates when it was last materially updated
- Your continued use of the App after a material change constitutes your acceptance of the updated policy. If you do not agree with the changes, you should stop using the App and delete your account.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data.
20. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Privacy enquiries and data rights requests: privacy@anchr.health
- General support: privacy@anchr.health
- GDPR-specific requests: privacy@anchr.health (subject line: "GDPR Request")
- CCPA/state law requests: privacy@anchr.health (subject line: "CCPA Request" or "Privacy Rights Request")
We will acknowledge receipt of your enquiry within 5 business days and provide a substantive response within 30 days, or within the shorter timeframe required by your jurisdiction's laws (e.g. 45 days for CCPA requests, 30 days for GDPR requests).
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. For EEA residents, a list of supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. For UK residents, you may contact the Information Commissioner's Office (ICO).