Controller Identity & Contact

The data controller for all personal data processed through the Anchor Loop mobile application and associated services is:

Gavril Buda, trading as Anchor Loop
Privacy contact: privacy@anchor-loop.app

A Data Protection Officer (DPO) has not been appointed. Appointment is not required under Article 37 GDPR because: (a) Anchor Loop is not a public authority; (b) habit tracking is user-initiated self-monitoring and does not constitute regular and systematic monitoring of data subjects on a large scale; and (c) no special-category data under Article 9 is processed as a core activity. You may direct privacy enquiries to the contact address above.

Data We Collect

We collect only what is necessary to provide and improve the service. Below is a full inventory organized by category.

Account Data

Collected when you create an account and maintained for the lifetime of your account:

  • Email address — used for authentication and, if you opt in, service communications
  • Display name — shown in the app and shared with other members of accountability pods you join
  • Profile picture (avatar URL) — optional; displayed on your profile
  • Timezone and language — used to schedule notifications at appropriate local times and to localize the interface
  • Terms and privacy acceptance timestamps — records confirming you acknowledged these legal documents before creating your account
  • Review-prompt and share-hint state — timestamps and a prompt count used to limit how often the app may request a store review and to avoid repeating an optional sharing hint

Behavioral Data

Created by your interactions with the app's core features:

  • Habits — names, descriptions, anchor behaviors, tiny and full versions, celebrations, if-then triggers and locations, temptation bundles, schedules, streaks, difficulty settings
  • Check-ins — completion status, mood at check-in, energy level, location context (if provided), skip reasons and notes, notification engagement data (whether prompted, time to action)
  • Goals — goal definitions, progress, outcomes
  • Weekly reviews — wins, reflections, diagnosis notes, commitment statements, adjustments
  • Identity statements — the identity labels you define (e.g., "I am a runner"), descriptions, and associated icons
  • COM-B profile — your primary barrier (Capability / Opportunity / Motivation) and motivation profile assessed during onboarding, used to personalize recommendations
Mood and energy ratings are behavioral self-reports, not clinical health data. They are not processed to infer any medical condition. We treat them with the same care as health-adjacent data: encrypted in transit, fully user-controlled, and completely deletable.

Technical Data

  • Push notification token — device-specific token used to deliver habit reminders; automatically cleared on sign-out or invalidation
  • Platform — iOS or Android, for notification routing
  • App version and device OS — used in crash reports (only if analytics consent is given)

Analytics Data (consent-based only)

Collected only if you grant consent in Preferences. You may withdraw consent at any time with no impact on the service.

  • Usage events — in-app interactions (screens visited, features used) sent to Firebase Analytics
  • Crash reports — stack traces and device context sent to Firebase Crashlytics when the app crashes

Social Data (user-initiated)

Only created if you voluntarily join accountability pods or create pacts with other users:

  • Pod membership — pod name, your role, join date
  • Shared habit progress — habit names and streaks shared with pod members
  • Encouragements — messages sent between pod members
  • Pacts — accountability agreements between users

Payment Data

If you subscribe to a premium plan:

  • Subscription status, product ID, expiry date, and purchase token — received from Google Play or Apple App Store to verify your subscription. We do not process payment card data; all billing is handled by the app stores directly.

Feedback

  • Messages submitted via in-app feedback — your name and email at time of submission, plus your message text

Why We Collect It (Lawful Basis)

Data Category Purpose Lawful Basis (Art. 6 GDPR)
Account data (email, display name, avatar, timezone, language) Create and maintain your account; deliver the service Art. 6(1)(b) — Contract
Behavioral data (habits, check-ins, goals, reviews, identities, COM-B profile) Core app functionality — tracking, personalization, progress Art. 6(1)(b) — Contract
Technical data (push token, platform) Deliver contextual habit reminders Art. 6(1)(b) — Contract
Review-prompt and share-hint state Prevent repetitive store-review requests and remember whether a passive sharing hint was shown Art. 6(1)(f) — Legitimate interests (respectful product experience)
Firebase Analytics and Crashlytics events Product improvement, crash diagnosis Art. 6(1)(a) — Consent
Social data (pods, pacts, encouragements) Accountability features you opt into Art. 6(1)(b) — Contract
Subscription records Verify premium access; dispute resolution Art. 6(1)(b) — Contract
Feedback submissions Product improvement Art. 6(1)(b) — Contract
Server and security logs Security, fraud prevention, operational integrity Art. 6(1)(f) — Legitimate Interest
Privacy acceptance timestamp Accountability record — demonstrating Art. 5(2) compliance Art. 6(1)(f) — Legitimate Interest

Consequences of Not Providing Data

Required data

Email address is required to create an account. Without it, you cannot use the service. This is necessary to authenticate your identity and prevent duplicate accounts.

Optional data

  • Mood, energy, and location at check-in — the app functions fully without these. Providing them allows better personalization of prompt timing and difficulty recommendations.
  • Avatar, display name — display name defaults to your email prefix if not set. Avatar is never required.
  • Social features — pods and pacts are entirely opt-in. You can use all core habit-tracking features without joining any pod.

Analytics consent

Declining or withdrawing analytics consent has no impact on the service. All features work identically whether or not analytics is enabled.

How Long We Keep It

Data Retention Period
Account and behavioral data (habits, check-ins, goals, reviews, identities) Retained while your account is active
Review-prompt and share-hint state Retained while your account is active; permanently removed with the account
Deleted account — soft-delete grace period 30 days after you request deletion (allows recovery if you change your mind)
Deleted account — permanent removal All personal data purged after the 30-day grace period ends
Firebase Analytics events Retained while consent is active; cleared when your account is hard-deleted
Feedback messages Your name and email are removed at soft-delete; the anonymized message is retained for product improvement
Subscription records Deleted when account is permanently removed (after 30-day grace period)
Server and application logs (Azure Application Insights) 30 days
Audit logs (planned, Phase 3+) 3 years; user_id anonymized on account deletion, action record retained for compliance

Who We Share Data With

We do not sell, rent, or trade your personal data. We share data only with the service providers necessary to operate Anchor Loop, under legally adequate data processing agreements.

Processors (Art. 28 GDPR) — act on our instructions

Provider Service Data Shared
Google (Firebase Auth) Authentication Email, UID, auth tokens
Google (Firebase Analytics) Usage analytics Usage events (consent-based only)
Google (Firebase Crashlytics) Crash reporting Stack traces, device info (consent-based only)
Google (Firebase Cloud Messaging) Push notifications (Android) Push token, notification payload
Apple (APNs) Push notifications (iOS) Push token, notification payload
Microsoft (Azure) Database, hosting, monitoring All backend data (stored encrypted in EU)

Independent controllers — process data under their own terms

Google Play Store and Apple App Store process subscription and payment data as independent data controllers. Their processing is governed by their own privacy policies. We receive only a purchase token to verify your subscription status.

No data brokering. We do not share, sell, or license your personal data to advertising networks, data brokers, or any third party for commercial purposes.

International Transfers

Some of our service providers are based outside the EU/EEA. We ensure all transfers are protected by one of the following safeguards under Chapter V GDPR:

Destination Provider Safeguard
EU (France / francecentral) Microsoft Azure — database, hosting, monitoring Data remains in EU — no transfer
United States Google (Firebase Auth, Analytics, Crashlytics, FCM) Standard Contractual Clauses (SCCs)
United States / Ireland Apple App Store, APNs Standard Contractual Clauses (SCCs)
United States / Ireland Google Play Store Independent controller (own SCCs)

Your Rights

Under the GDPR (Articles 15–22), you have the following rights. Most can be exercised directly within the app.

📄 Right of Access (Art. 15)

Request a copy of all personal data we hold about you. In-app: Profile → Export My Data (JSON download).

Right to Rectification (Art. 16)

Correct inaccurate data. In-app: edit your profile, habits, or goals at any time.

🗑 Right to Erasure (Art. 17)

Request deletion of your account and all associated data. In-app: Profile → Delete Account. A 30-day grace period applies, after which data is permanently deleted.

📤 Right to Portability (Art. 20)

Receive your data in a machine-readable format. In-app: Profile → Export My Data (JSON).

🚫 Right to Object (Art. 21)

Object to analytics tracking. In-app: Preferences → Analytics toggle. Objecting has no impact on service availability.

Right to Withdraw Consent (Art. 7)

Withdraw analytics consent at any time. In-app: Preferences → Analytics. Withdrawal does not affect lawfulness of prior processing.

Right to Restriction (Art. 18)

Request restriction of processing in specific circumstances. Contact privacy@anchor-loop.app.

👪 Right to Lodge a Complaint

You have the right to lodge a complaint with your national data protection supervisory authority. In Romania: ANSPDCP (dataprotection.ro).

To exercise rights not available in-app, contact us at privacy@anchor-loop.app. We will respond within 30 days as required by Art. 12 GDPR.

Automated Decision-Making (Art. 22)

Anchor Loop uses your habit data to adapt notification scheduling — for example, adjusting prompt times based on when you typically complete habits, and scaling difficulty based on your recent performance.

This adaptation is a core feature of the service and is not automated decision-making that produces legal effects or similarly significant effects within the meaning of Article 22 GDPR. It only affects when you receive a notification and what difficulty level is suggested — it does not determine eligibility for services, creditworthiness, or any outcome with legal or comparable significance.

No decisions with legal or similarly significant effects are made solely by automated means.

Source of Data (Art. 14)

All personal data we process is provided directly by you — when you create an account, enter habits, complete check-ins, write reviews, or use social features. We do not obtain your personal data from third parties or public sources, except for the purchase token received from Google Play or Apple App Store to verify your subscription.

Children

Anchor Loop is not directed at children and is not available to users under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently received data from a child under 16, please contact us at privacy@anchor-loop.app and we will delete it promptly.

Changes to This Policy

We may update this privacy policy from time to time. For material changes — changes that meaningfully affect your rights or the ways we process your data — we will notify you via an in-app announcement before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.

Continued use of Anchor Loop after a material change takes effect constitutes acceptance of the updated policy. If you do not agree, you may delete your account before the change becomes effective.

Contact

For any privacy-related questions, requests to exercise your rights, or complaints, contact:

Anchor Loop — Privacy
privacy@anchor-loop.app

We aim to respond to all privacy requests within 30 days (Art. 12 GDPR).