Controller Identity & Contact
The data controller for all personal data processed through the Anchor Loop mobile application and associated services is:
Privacy contact: privacy@anchor-loop.app
A Data Protection Officer (DPO) has not been appointed. Appointment is not required under Article 37 GDPR because: (a) Anchor Loop is not a public authority; (b) habit tracking is user-initiated self-monitoring and does not constitute regular and systematic monitoring of data subjects on a large scale; and (c) no special-category data under Article 9 is processed as a core activity. You may direct privacy enquiries to the contact address above.
Data We Collect
We collect only what is necessary to provide and improve the service. Below is a full inventory organized by category.
Account Data
Collected when you create an account and maintained for the lifetime of your account:
- Email address — used for authentication and, if you opt in, service communications
- Display name — shown in the app and shared with other members of accountability pods you join
- Profile picture (avatar URL) — optional; displayed on your profile
- Timezone and language — used to schedule notifications at appropriate local times and to localize the interface
- Terms and privacy acceptance timestamps — records confirming you acknowledged these legal documents before creating your account
- Review-prompt and share-hint state — timestamps and a prompt count used to limit how often the app may request a store review and to avoid repeating an optional sharing hint
Behavioral Data
Created by your interactions with the app's core features:
- Habits — names, descriptions, anchor behaviors, tiny and full versions, celebrations, if-then triggers and locations, temptation bundles, schedules, streaks, difficulty settings
- Check-ins — completion status, mood at check-in, energy level, location context (if provided), skip reasons and notes, notification engagement data (whether prompted, time to action)
- Goals — goal definitions, progress, outcomes
- Weekly reviews — wins, reflections, diagnosis notes, commitment statements, adjustments
- Identity statements — the identity labels you define (e.g., "I am a runner"), descriptions, and associated icons
- COM-B profile — your primary barrier (Capability / Opportunity / Motivation) and motivation profile assessed during onboarding, used to personalize recommendations
Technical Data
- Push notification token — device-specific token used to deliver habit reminders; automatically cleared on sign-out or invalidation
- Platform — iOS or Android, for notification routing
- App version and device OS — used in crash reports (only if analytics consent is given)
Analytics Data (consent-based only)
Collected only if you grant consent in Preferences. You may withdraw consent at any time with no impact on the service.
- Usage events — in-app interactions (screens visited, features used) sent to Firebase Analytics
- Crash reports — stack traces and device context sent to Firebase Crashlytics when the app crashes
Social Data (user-initiated)
Only created if you voluntarily join accountability pods or create pacts with other users:
- Pod membership — pod name, your role, join date
- Shared habit progress — habit names and streaks shared with pod members
- Encouragements — messages sent between pod members
- Pacts — accountability agreements between users
Payment Data
If you subscribe to a premium plan:
- Subscription status, product ID, expiry date, and purchase token — received from Google Play or Apple App Store to verify your subscription. We do not process payment card data; all billing is handled by the app stores directly.
Feedback
- Messages submitted via in-app feedback — your name and email at time of submission, plus your message text
Why We Collect It (Lawful Basis)
| Data Category | Purpose | Lawful Basis (Art. 6 GDPR) |
|---|---|---|
| Account data (email, display name, avatar, timezone, language) | Create and maintain your account; deliver the service | Art. 6(1)(b) — Contract |
| Behavioral data (habits, check-ins, goals, reviews, identities, COM-B profile) | Core app functionality — tracking, personalization, progress | Art. 6(1)(b) — Contract |
| Technical data (push token, platform) | Deliver contextual habit reminders | Art. 6(1)(b) — Contract |
| Review-prompt and share-hint state | Prevent repetitive store-review requests and remember whether a passive sharing hint was shown | Art. 6(1)(f) — Legitimate interests (respectful product experience) |
| Firebase Analytics and Crashlytics events | Product improvement, crash diagnosis | |
| Social data (pods, pacts, encouragements) | Accountability features you opt into | Art. 6(1)(b) — Contract |
| Subscription records | Verify premium access; dispute resolution | Art. 6(1)(b) — Contract |
| Feedback submissions | Product improvement | Art. 6(1)(b) — Contract |
| Server and security logs | Security, fraud prevention, operational integrity | Art. 6(1)(f) — Legitimate Interest |
| Privacy acceptance timestamp | Accountability record — demonstrating Art. 5(2) compliance | Art. 6(1)(f) — Legitimate Interest |
Consequences of Not Providing Data
Required data
Email address is required to create an account. Without it, you cannot use the service. This is necessary to authenticate your identity and prevent duplicate accounts.
Optional data
- Mood, energy, and location at check-in — the app functions fully without these. Providing them allows better personalization of prompt timing and difficulty recommendations.
- Avatar, display name — display name defaults to your email prefix if not set. Avatar is never required.
- Social features — pods and pacts are entirely opt-in. You can use all core habit-tracking features without joining any pod.
Analytics consent
Declining or withdrawing analytics consent has no impact on the service. All features work identically whether or not analytics is enabled.
How Long We Keep It
| Data | Retention Period |
|---|---|
| Account and behavioral data (habits, check-ins, goals, reviews, identities) | Retained while your account is active |
| Review-prompt and share-hint state | Retained while your account is active; permanently removed with the account |
| Deleted account — soft-delete grace period | 30 days after you request deletion (allows recovery if you change your mind) |
| Deleted account — permanent removal | All personal data purged after the 30-day grace period ends |
| Firebase Analytics events | Retained while consent is active; cleared when your account is hard-deleted |
| Feedback messages | Your name and email are removed at soft-delete; the anonymized message is retained for product improvement |
| Subscription records | Deleted when account is permanently removed (after 30-day grace period) |
| Server and application logs (Azure Application Insights) | 30 days |
| Audit logs (planned, Phase 3+) | 3 years; user_id anonymized on account deletion, action record retained for compliance |
Who We Share Data With
We do not sell, rent, or trade your personal data. We share data only with the service providers necessary to operate Anchor Loop, under legally adequate data processing agreements.
Processors (Art. 28 GDPR) — act on our instructions
| Provider | Service | Data Shared |
|---|---|---|
| Google (Firebase Auth) | Authentication | Email, UID, auth tokens |
| Google (Firebase Analytics) | Usage analytics | Usage events (consent-based only) |
| Google (Firebase Crashlytics) | Crash reporting | Stack traces, device info (consent-based only) |
| Google (Firebase Cloud Messaging) | Push notifications (Android) | Push token, notification payload |
| Apple (APNs) | Push notifications (iOS) | Push token, notification payload |
| Microsoft (Azure) | Database, hosting, monitoring | All backend data (stored encrypted in EU) |
Independent controllers — process data under their own terms
Google Play Store and Apple App Store process subscription and payment data as independent data controllers. Their processing is governed by their own privacy policies. We receive only a purchase token to verify your subscription status.
International Transfers
Some of our service providers are based outside the EU/EEA. We ensure all transfers are protected by one of the following safeguards under Chapter V GDPR:
| Destination | Provider | Safeguard |
|---|---|---|
| EU (France / francecentral) | Microsoft Azure — database, hosting, monitoring | Data remains in EU — no transfer |
| United States | Google (Firebase Auth, Analytics, Crashlytics, FCM) | Standard Contractual Clauses (SCCs) |
| United States / Ireland | Apple App Store, APNs | Standard Contractual Clauses (SCCs) |
| United States / Ireland | Google Play Store | Independent controller (own SCCs) |
Your Rights
Under the GDPR (Articles 15–22), you have the following rights. Most can be exercised directly within the app.
Request a copy of all personal data we hold about you. In-app: Profile → Export My Data (JSON download).
Correct inaccurate data. In-app: edit your profile, habits, or goals at any time.
Request deletion of your account and all associated data. In-app: Profile → Delete Account. A 30-day grace period applies, after which data is permanently deleted.
Receive your data in a machine-readable format. In-app: Profile → Export My Data (JSON).
Object to analytics tracking. In-app: Preferences → Analytics toggle. Objecting has no impact on service availability.
Withdraw analytics consent at any time. In-app: Preferences → Analytics. Withdrawal does not affect lawfulness of prior processing.
Request restriction of processing in specific circumstances. Contact privacy@anchor-loop.app.
You have the right to lodge a complaint with your national data protection supervisory authority. In Romania: ANSPDCP (dataprotection.ro).
To exercise rights not available in-app, contact us at privacy@anchor-loop.app. We will respond within 30 days as required by Art. 12 GDPR.
Automated Decision-Making (Art. 22)
Anchor Loop uses your habit data to adapt notification scheduling — for example, adjusting prompt times based on when you typically complete habits, and scaling difficulty based on your recent performance.
This adaptation is a core feature of the service and is not automated decision-making that produces legal effects or similarly significant effects within the meaning of Article 22 GDPR. It only affects when you receive a notification and what difficulty level is suggested — it does not determine eligibility for services, creditworthiness, or any outcome with legal or comparable significance.
No decisions with legal or similarly significant effects are made solely by automated means.
Source of Data (Art. 14)
All personal data we process is provided directly by you — when you create an account, enter habits, complete check-ins, write reviews, or use social features. We do not obtain your personal data from third parties or public sources, except for the purchase token received from Google Play or Apple App Store to verify your subscription.
Children
Anchor Loop is not directed at children and is not available to users under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently received data from a child under 16, please contact us at privacy@anchor-loop.app and we will delete it promptly.
Changes to This Policy
We may update this privacy policy from time to time. For material changes — changes that meaningfully affect your rights or the ways we process your data — we will notify you via an in-app announcement before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.
Continued use of Anchor Loop after a material change takes effect constitutes acceptance of the updated policy. If you do not agree, you may delete your account before the change becomes effective.
Contact
For any privacy-related questions, requests to exercise your rights, or complaints, contact:
privacy@anchor-loop.app
We aim to respond to all privacy requests within 30 days (Art. 12 GDPR).