Anchor Privacy Policy
Your privacy matters to us — more than most apps, because of what Anchor is. Anchor is a recovery companion, and the data you put into it describes your recovery journey. We treat that as sensitive personal information, and this policy explains exactly what we collect, how we use it, who touches it, and the rights you have over it. Anchor is operated by ProgramU LLC. Questions: support@quitwithanchor.app.
Anchor is not a substitute for professional medical care, therapy, or treatment. If you are experiencing a medical emergency or severe withdrawal symptoms, contact a healthcare provider immediately.
Version 1 · Last Updated: July 19, 2026
1. Who This Policy Applies To
This Privacy Policy applies to all users of the Anchor mobile application, whether you are a paid subscriber, a free-tier user, or a trial user.
Anchor is currently available to residents of the United States only. We do not knowingly serve users outside the United States.
Anchor is intended for adults 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with their information, contact support@quitwithanchor.app and we will delete it promptly.
2. Information We Collect
Account Data:
- Your email address (from email sign-up, or from Apple/Google when you sign in with them)
- Your display name (the name you give us, or your first name if shared by Apple/Google sign-in)
We do not collect your date of birth. Age (18+) is confirmed by your attestation at consent.
Recovery Profile Data — this is sensitive data, and we treat it that way (see Section 4):
- The addiction or habits you choose to track (for example: alcohol, porn, drugs, nicotine, gambling, social media, caffeine, sugar, gaming, spending, or a custom entry you define)
- Your quit dates and streak history
- Daily check-ins: mood, craving level, and triggers you log
- Slips you record, and the notes you attach to them
- Wins and milestones you record
- Your daily pledge and whether you marked it held
- Craving-button events ("waves" you name) and how you marked they ended
- Your anchor text (the "why" you write), and any savings goals and weekly-spend figures you enter
- Journal notes and free-text reflections
- Transcripts of your companion AI conversations (voice and text — see Section 14 for exactly how these work)
- Weekly reflections our systems generate for you from your week's conversations
- Feedback you submit (thumbs ratings and optional notes)
Media in Your Anchor stays on your device. Photos and videos you add to Your Anchor — including messages you record to yourself — are stored ONLY on your phone. They are never uploaded to our servers or any third party. (This also means they are lost if you delete the app or lose the device; an optional cloud backup may be offered in the future and would be clearly labeled.) The written anchor text does sync to your account so your companion can hold it.
Usage Data:
- Feature activity that is itself your own stored record (check-in history, conversation history, craving-button events)
- In-app preferences and notification settings (stored on your device)
- Streak and pattern numbers computed by our servers from your own logged data
We do not run a third-party analytics SDK, and we do not collect behavioral analytics beyond the records described above.
Error Reports: If the app hits an error, a report may be sent to us containing the error message, a technical stack trace, your user ID, the app version, and platform — never your journal text, check-in content, media, or conversation content. These reports are stored in our database and emailed to our team so we can fix problems (see Resend in Section 3). Reports are limited to a few per day per device.
Home-Screen Widgets: If you add Anchor widgets, your pattern names and streak-start dates are copied into a private on-device container shared between the app and its widgets. This data never leaves your phone and is blanked when you sign out or delete your account.
Device Information: We collect app version and operating system platform at consent time for audit purposes. We do NOT collect: device model, IP-address-based location profiles, advertising identifiers, precise location, or device fingerprinting data.
Subscription and Payment Information: When paid features launch (live companion conversations are the paid part of Anchor), payment will be processed by Apple (iOS) or Google (Android). They handle your payment details per their own privacy policies; ProgramU LLC receives only your subscription/purchase status and a transaction identifier. If we adopt RevenueCat for subscription management, it will receive your user ID and subscription state — never your payment card details.
Crisis resources, tracking, breathwork, and the audio library are free and never gated behind a subscription — using them does not create any additional data collection.
3. Third-Party Services (Sub-Processors)
We use the following sub-processors to operate Anchor. Each processes only the data necessary for its function:
- Google Firebase: Authentication, Firestore database, and Cloud Functions. Stores your account data, recovery profile, check-ins, journal notes, and conversation transcripts. Data is encrypted at rest and in transit.
- Inworld AI: Powers all companion conversations — speech-to-text and text-to-speech for voice, and the language model (reached through Inworld's model router) that generates replies for both voice and text. Background jobs (conversation titles, weekly reflections, post-conversation safety review) use the same router. Your voice audio is processed in transit and is not stored by ProgramU LLC. See Section 14 for the full data flow.
- Cloudflare R2: Object storage for our shared, pregenerated audio library (the same tracks for every user). No personal data is stored there.
- Resend: Email delivery. Used to send error-report alerts to our own team, and for service email we may send you. Resend processes the email content it delivers.
- Expo (EAS Update): Delivers app updates. Your device requests updates with the app version and platform — no personal data.
- Sentry (when enabled): Crash reporting. If enabled, reports are PII-scrubbed before transmission — your journal text, check-in content, and conversation content are never included.
- RevenueCat (planned): Unified subscription management, if and when adopted. Would receive your user ID and subscription state only — never payment card details.
- Apple App Store / Google Play: In-app purchase processing for subscriptions. Each handles your payment details per their own privacy policies.
What we do NOT send to sub-processors: we do not send your email address to Inworld beyond what is described above (your first name and recovery context are included in conversation prompts so your companion knows you), and we do not use any advertising network, tracking pixel, or third-party analytics SDK that profiles you across other apps or websites.
4. Sensitive Data
The fact that you are on a recovery journey — and everything you log about it — is sensitive personal information. What you track in Anchor could affect how an employer, insurer, landlord, or family member sees you if it were disclosed. We designed Anchor with that risk in front of us, and we make these commitments plainly:
- We will never sell your data. Not to data brokers, not to advertisers, not to anyone.
- We will never show you ads or share your data with advertising networks.
- We will never share your data with employers or insurers. No exceptions, no "partner programs."
- We delete your data on request. See Section 8.
Your recovery data exists for one purpose: to support your own recovery journey inside the app. That is the only use we put it to.
5. How AI Data Processing Works
Anchor uses AI in two separate ways, and it matters which is which:
Live conversations (voice and text) run through Inworld's realtime agent API — Section 14 covers these in detail.
Background processing uses the same language-model router (Inworld). After a conversation ends, and on a weekly schedule, our servers send relevant slices of your data (a conversation transcript, or your week's conversations) to produce:
- Short titles and one-line descriptions for your conversation history
- A weekly reflection — a few warm sentences drawn from your week's conversations
- A post-conversation safety review (see Section 14)
Pattern statistics shown in the app (your hardest window, top triggers, craving trends) are computed directly by our own code from your logged data — no AI model involved.
These outputs are saved back to your account and are deleted with it.
Numbers are computed, not generated. Any streak count, day count, or pattern statistic your companion speaks or displays is computed by our servers from your own logged data. The AI model never invents these numbers.
No training on your data. Your conversations, journals, and recovery data are not used to train any AI model — ours or any third party's.
AI-generated content can contain errors. Your companion is a support tool, not an authority — use your own judgment, and lean on the humans in your corner: sponsor, therapist, meetings, and the people who know you.
6. How We Use Your Information
We use your information to:
- Provide the core Anchor service: your tracker, streaks, check-ins, audio library, and companion conversations
- Personalize your experience: your companion and generated audio reflect what you have shared about your own triggers and goals
- Compute your streaks, milestones, and pattern insights from your own data
- Process subscriptions (via Apple and Google)
- Send notifications you have opted into
- Catch and diagnose errors (via our error-report pipeline; PII-limited as described in Section 2)
- Comply with legal obligations and prevent fraud or abuse
We do NOT use your information to:
- Show you ads or sell ad space
- Train AI models
- Sell, rent, or trade your personal data
- Build advertising profiles of you
- Track you across other apps or websites
- Report on you to any employer, insurer, or third party
7. Data Security
Your data is stored in Google Firebase and Cloudflare R2, which employ industry-standard security practices:
- TLS encryption for all data in transit between your device and our servers
- Encryption at rest for stored data
- Firebase Security Rules restricting access to your authenticated account and authorized system processes
We minimize logging of personal content: your journal text, check-in content, and conversation content are never written to operational logs or crash reports.
No system is perfectly secure, and we cannot guarantee absolute security. But we apply modern best practices and continuously work to improve our safeguards — because of what this data is.
8. Your Rights
Access and Correction:
- Update your profile and recovery settings at any time within the app
- Request a copy of your personal data by emailing support@quitwithanchor.app
Deletion: You can permanently delete your account and all associated data at any time, in the app (Profile → Delete account) or by emailing support@quitwithanchor.app. Account deletion permanently wipes your recovery profile, check-in and slip history, journal notes, conversation transcripts, reflections, feedback, and authentication account. Media in Your Anchor lives only on your device — deleting the app removes it. Most deletions complete within 24 hours; in rare cases, full deletion may take up to 30 days.
Data Portability: The app includes a one-tap export (Profile → Export my data) that hands you your complete tracking record as a JSON file. You can also request a copy by email.
Right to Object: You may object to certain processing activities by contacting support@quitwithanchor.app.
9. Data Retention
Your data is retained for as long as your account remains active. We do not automatically delete inactive accounts — your history remains yours until you delete it.
Slips and lifetime history. Anchor is built so that your lifetime recovery history is preserved, never zeroed out — a slip resets a streak counter, not your record. That history exists for you: it powers your own pattern insights and your own sense of how far you have come. It is your data. You can delete individual entries on request, and all of it is deleted with your account.
What gets deleted when you delete your account:
- Firebase Auth account, your user document, and all subcollections (recovery profile, check-ins, slips, wins, pledges, waves, journals, conversation transcripts, reflections, feedback)
- On-device data (widget container, preferences) is blanked; Your Anchor media is removed when you delete the app
After deletion, data may persist briefly at sub-processors under their own retention policies (for example: Firestore automatic backups for up to ~35 days, Google Cloud operational logs ~30 days, Apple/Google transaction history at the account level, and AI-provider request data retained short-term for abuse detection per their terms). None of this retained data is used to contact you or re-identify you after deletion.
10. Children's Privacy
Anchor is intended for adults 18 years of age and older. Age is confirmed by your attestation during onboarding consent.
ProgramU LLC does not knowingly collect personal information from anyone under 18. If we become aware that we have, we will delete that information immediately. If you are a parent or guardian who believes we have collected data from a minor, contact support@quitwithanchor.app.
11. Geographic Availability
ProgramU LLC is organized in the State of Wyoming, United States. Anchor is currently available only to residents of the United States. Our servers and sub-processors are based in the United States, and our crisis resources — the 988 Suicide & Crisis Lifeline (call or text 988), the Crisis Text Line (text HOME to 741741), and the SAMHSA National Helpline (1-800-662-4357) — are U.S. services.
If you access Anchor from outside the United States, your access may be restricted, and we cannot guarantee compliance with the privacy laws of your country. When we expand to new regions, we will update this policy to address the privacy laws of those regions.
12. California and Other State Residents
Residents of certain U.S. states have additional rights under applicable privacy laws, including:
- The right to know what personal information we collect
- The right to delete personal information
- The right to correct inaccurate personal information
- The right to opt out of the sale or sharing of personal information (Anchor does not sell or share personal information)
- The right to limit the use of sensitive personal information
- The right to non-discrimination for exercising your privacy rights
To exercise any of these rights, email support@quitwithanchor.app. We will respond within the timeframe required by applicable law (typically 45 days).
ProgramU LLC does not sell or share personal information for cross-context behavioral advertising.
13. Changes to This Policy
We may revise this Privacy Policy from time to time. When we make material changes, we will:
1. Post the updated policy with a new "Last Updated" date 2. Notify you within the app 3. Require you to review and accept the updated policy before continuing to use Anchor
For minor changes (typo fixes, formatting), we may update the policy without requiring re-acceptance.
14. Companion AI Conversations (Voice and Text) — Data Flow
Your companion is an AI, available 24/7, built to be there when cravings hit. This section describes exactly how conversation data moves.
Live voice data flow. When you talk to your companion by voice, the conversation runs on Inworld's realtime agent API in three steps, in real time:
1. Your spoken audio is transmitted to Inworld and transcribed to text (speech-to-text) 2. The transcribed text, with your conversation context, goes to a fast language model reached through Inworld's model router, which generates the reply 3. The reply is synthesized back into speech (text-to-speech) and played to you
In text mode, only step 2 applies.
Your voice audio exists in transit only. It is processed to be transcribed and is not stored by ProgramU LLC. It is NOT used to create a voiceprint, and it is NOT used to train any model. Inworld processes conversation data under its own privacy policy.
Claude is never in the live loop. Anthropic's Claude handles background jobs only — summaries and pattern analysis after the fact (Section 5) — never your real-time conversation.
Computed numbers. Any streak or pattern figure your companion speaks is computed by our servers from your logged data, never generated by the model.
Transcript storage. After each conversation, a transcript (the text of what you and the companion said, with timestamps) is stored in your account (voice calls under companionCalls, text threads under companionChats), so you can revisit conversations in your history. Transcripts are your data: you can delete them, and they are wiped when you delete your account.
Safety review and crisis alerts. Conversations run through crisis detection on your device in real time, and a post-conversation safety review runs on our servers. If a conversation indicates a crisis, the app routes you to real help immediately — and a minimal internal alert (your user ID and a category only — never the content of what you said) may notify our team so we can review that our safety systems worked.
Feedback with crisis content. If a feedback note you write reads as a crisis, the app stops treating it as product feedback, shows you crisis resources, and flags it for priority review.
Consent flow. Anchor's onboarding consent covers the AI nature of conversations, data handling, safe listening, and the not-medical-care acknowledgment. Your acceptance (timestamp + version) is stored at users/{your-uid}/consent/v1. You will be asked to re-accept when these documents materially change.
Your companion works alongside your existing support — sponsor, therapist, meetings — it does not replace them. Anchor is not a substitute for professional medical care, therapy, or treatment. If you are experiencing a medical emergency or severe withdrawal symptoms, contact a healthcare provider immediately.
15. Contact Us
For privacy questions, data requests, or to exercise your rights:
- Privacy, data requests, and general support: support@quitwithanchor.app
ProgramU LLC · Wyoming, United States.
Thank you for trusting us with something this personal. We take that trust seriously. — The Anchor Team