1. Introduction
This Privacy Policy explains how Anchor handles information when you use the Anchor journaling and AI conversation service. “Anchor,” “we,” and “us” refer to the operator of the service.
The short version is that Anchor does not sell your personal information, does not use advertising trackers, and encrypts durable journal content before it is stored. Anchor is not end-to-end encrypted: its application servers must decrypt content when needed to show it to you, generate a Mira response, or create an export.
2. Information Anchor collects
Account and authentication information
Anchor uses Supabase Auth. We process your email address, authentication identifiers, session information, and information returned by an authentication provider you choose.
Password-recovery and other account messages are sent through Supabase Auth. Anchor does not currently operate a separate marketing-email system.
User Content
“User Content” means the material you provide or save in Anchor, including Conversation messages, Reflections, Core Memories, titles, previews, and recovery drafts. It also includes your choices about how that content is organized and whether Mira is invited into a Reflection.
Mira responses saved in Conversations are stored with the Conversation. A Reflection remains your writing; inviting Mira does not replace the saved Reflection with Mira’s response.
Preferences and feature settings
Anchor stores settings needed to provide the experience you choose, such as interface preferences.
Usage, security, and operational information
Anchor creates limited records needed to authenticate requests, enforce quotas, prevent duplicate writes, rate-limit abuse, diagnose failures, and operate Mira. These records can include account or record identifiers, timestamps, versions, request fingerprints, feature counts, model and token counts, latency, outcome codes, and subscription status. They do not contain the plaintext body of your journal entries or AI prompts.
For unauthenticated or security-sensitive requests, Anchor may process an IP address or normalized email address to enforce rate limits and temporary account lockouts. Content Security Policy reports are reduced to directive and numeric metadata before storage.
Billing information
Paid subscriptions use Stripe-hosted Checkout and Stripe’s Customer Portal. Anchor sends Stripe your account email, an internal account reference, and the plan you select. Anchor stores Stripe customer, subscription, status, and event metadata needed to provide paid access and reconcile billing.
Stripe, not Anchor, collects and processes full payment-card details in its hosted payment flow.
3. How Anchor uses information
- Authenticate you and maintain your session.
- Store, retrieve, edit, export, and delete the content you direct Anchor to manage.
- Provide Mira responses and user-approved Core Memory features.
- Enforce plan limits, maintain billing status, and prevent duplicate operations.
- Protect accounts and the service, investigate failures, and maintain reliability.
- Respond to support, privacy, or security requests.
4. Mira and AI processing
OpenAI is Anchor’s current AI service provider. When you ask Mira for a response, Anchor decrypts and sends OpenAI the plaintext needed for that request. Depending on what you do, this may include your current message, a bounded portion of Conversation history, up to three selected recent saved Core Memories, or the title and content of a Reflection you explicitly chose to discuss or invited Mira to consider.
Anchor asks OpenAI not to store the Chat Completions response for application features by sending the provider’s store setting as false. OpenAI states that API data is not used to train its models unless the customer opts in. Under OpenAI’s default API data controls, prompts and responses may still be retained in abuse-monitoring logs for up to 30 days, unless a longer period is required by law. Anchor does not claim that its production account has Zero Data Retention.
Anchor stores metadata about AI execution, such as model identifiers, token counts, and outcome. That execution ledger does not store prompt or response text. A Conversation response that you keep is separately saved as encrypted Conversation content.
Provider practices are controlled in part by OpenAI and may change. Anchor will update this policy when its provider or relevant configuration materially changes.
5. Core Memories and derived information
Core Memories are saved pieces of context that can help Mira respond more personally. You can create, edit, delete, clear, and export them. Anchor may select up to three recently updated saved memories for a Mira request.
A direct request to remember something can save it. Otherwise, a suggestion stays with its Conversation until you explicitly save it as a Core Memory. Anchor does not silently promote vague Conversation content into permanent memory.
Anchor keeps limited derived metadata needed to enforce uniqueness and quotas. For example, it stores a one-way equality fingerprint for saved Core Memories; the fingerprint is not the memory text and is not used to reconstruct it.
6. Encryption and security
Anchor encrypts durable User Content and saved preferences on its application servers before storing them in Supabase. Encryption keys are versioned and server-managed, and protected content is decrypted only through Anchor’s authenticated server paths. This protects content from being readable from a database-only copy that does not also have the required encryption authority.
Some metadata must remain readable to operate the service. This includes account and record identifiers, timestamps, relationships between records, versions, usage counters, billing status, and security records.
This design is not end-to-end or zero-knowledge encryption. Anchor’s servers need plaintext during authorized rendering, Mira processing, and export generation. A person with authorized access to the application runtime and its encryption authority, or an attacker who compromises both, could technically access plaintext. Encryption also does not protect a PDF or JSON file after you download it.
No online service can guarantee absolute security. Anchor uses access controls, encryption, fail-closed server boundaries, and minimized logs, but users should keep account credentials and downloaded files secure.
7. Service providers and data sharing
Anchor does not sell or rent personal information and does not publish your User Content. It shares information with service providers only as needed to operate the service, and may disclose limited information when required by law or reasonably necessary to protect users, rights, or service security.
Supabase
Authentication, PostgreSQL data storage, and account email delivery.
OpenAI
Mira response generation when you use an AI feature.
Stripe
Subscription checkout, payment processing, and billing management.
Vercel
Application hosting and request delivery.
9. Retention and deletion
Deleting individual content
Deleting a Conversation, Reflection, or Core Memory removes the saved content from Anchor’s active product tables. Conversation deletion leaves a content-free tombstone containing record metadata until account deletion so an older request cannot restore the deleted Conversation.
Deleting your account
Account deletion first attempts to cancel cancelable Stripe subscriptions and then deletes the Supabase Auth account. User-owned product, preference, usage, AI-execution, and Anchor billing rows are removed through database relationships. If an external cancellation succeeds but account deletion cannot finish, Anchor records a pending state so the operation can be retried safely.
Account deletion atomically removes retry identifiers from completed deletion bookkeeping and clears related orphan recovery payloads. Minimal deletion and resolved orphan evidence has a 30-day cleanup cutoff. Minimal processed Stripe event identity and provider-only deleted-customer markers have a 90-day cutoff to prevent duplicate processing and handle late deliveries; these do not contain copied Anchor account references. Minimized audit events exclude journal content and actor identity. Stripe may retain customer and transaction records under its own legal and operational requirements; deleting an Anchor account does not delete Stripe-held records.
Provider logs and backups
Deleting content from Anchor does not retroactively remove provider abuse-monitoring logs that may already exist under OpenAI’s retention controls. Deleted encrypted data may also remain temporarily in provider-managed backups. The repository does not establish a public maximum backup-retention period, so Anchor does not promise immediate removal from every backup copy.
Operational records
Anchor’s daily cleanup defines a 30-day cutoff for AI execution metadata and a 90-day cutoff for minimized security/account audit events. Cleanup also covers usage summaries, idempotency records, rate-limit counters, and expired authentication lockouts. The cutoff is applied when scheduled cleanup runs; it is not a promise of immediate deletion from provider logs or backups. Anchor expires stored checkout and portal URLs after 24 hours, removes completed billing request state at a 30-day cutoff, and removes processed webhook identity at a 90-day cutoff. Expired URLs are scrubbed on replay or scheduled cleanup, so stored residue may remain until cleanup runs. Active customer/subscription records, retryable webhook events, unresolved billing recovery records, and pending deletion attempts remain while needed for correctness. Host/provider retention has independent limits.
10. Your controls and privacy requests
Within Anchor you can edit or delete saved content, manage or clear Core Memories, change supported preferences, manage a paid subscription through Stripe’s portal, and delete your account. Enhanced and Complete plans can export individual Conversations and Reflections as PDFs and the current Core Memory bank as JSON. Free accounts cannot export. Anchor does not impose a product usage quota on exports.
You may contact Anchor to request access, correction, deletion, or another privacy right that applies where you live. Anchor may need to verify that the request belongs to the account holder. This policy does not claim a specific regional legal regime or right beyond what applicable law provides.
11. Changes to this policy
Anchor may revise this policy as the service, providers, or legal requirements change. The version and dates at the top of this page change only when the policy text changes. Material changes should be presented through the service or another available contact channel where appropriate.
12. Contact
For privacy questions, requests, or security concerns, contact Anchor at the address below.