Privacy policy

Last updated: 4 October 2026 (clarified retention of Reflect conversations and timer files; removed report links, as the feature no longer exists)

1. Controller

The controller within the meaning of the GDPR and the UK GDPR is:
Julian Koop (Anchor Yourself)
Friesenweg 2, 23558 Lübeck, Germany
Email: koop.anchor@outlook.com

2. What data we process

Anchor can be used in two ways. You can start the urge surf timer without any account — no data is sent to us when you do. If you save the session, it stays on your device and is only moved into your account if you sign up. Everything else — entries, insights, history — needs an email account. Nothing is created automatically in the background; an account only exists if you register. Anchor is intended for people aged 18 and over.

We store the following data:

  • User ID and email address – for signing in, managed by our authentication provider Supabase; passwords are stored only as a hash
  • Craving entries – time, intensity, physical hunger, time since your last meal, trigger, context, the situation you were in (where you were, what you were doing), emotion, outcome, notes, and the strength before, during and after a timer session (only if you choose to enter them). These are health data within the meaning of Art. 9 GDPR.
  • Morning check-ins – mood and sleep quality for the day (health data)
  • Journal and your own reminders (Premium) – your answers to journal questions and reminder texts you write, with their time
  • Files uploaded for “My timer” (Premium) – at most one music file, one voice message and one image, each up to 5 MB, in a storage area only you can access. If Premium ends, the files are deleted after at least 3 days; beforehand we send a notice if we have an email address for you.
  • Invitations – if you arrive through an invitation link, we store who invited whom in order to grant the invitation bonus.
  • Profile data – nickname (freely chosen, no real name needed), goal, preferred check-in time and the craving time you gave
  • Usage figures – experience points, your current and longest streak, the total number of active days, the streak shields you have left, the total time spent in the timer and in the practice, the number of finished timer sessions and the programme lessons you have completed, with their dates. They describe how often the app was used, not what you logged.
  • Feedback – message and optional rating you send through the feedback form
  • Usage events (linked to your account, only with separate consent) – which app features you use (e.g. craving logged, AI reflection started, urge surf timer used), linked to your account ID, without the content of your entries. They are used only to improve the product internally and are not passed on to third parties or used for advertising.
  • Reflection conversations (Premium only) – with active Premium, your messages in the Reflect chat and the replies are stored so the conversation can continue next time. At most the last 60 messages are kept. Messages older than 90 days are deleted the next time you use the chat with active Premium — deletion is tied to use, not to a fixed date. If the chat is no longer used, or Premium ends, the stored history stays until you have it deleted: through Settings → Delete account, or by email to koop.anchor@outlook.com. Without Premium no history is stored — the conversation exists only in your device’s memory and is gone when you close it.
  • Referral source – if you came to Anchor through an advertising or campaign link, we store that link’s label (e.g. “source: tiktok, campaign: evening”) and the name of the referring website. It is recorded once on your first visit, serves only to find out which channel works, and is analysed internally and in aggregate only. It contains no content and is not passed on to anyone.
  • Push notifications – if you turn notifications on, we store your browser’s push endpoint (a technical URL of your push service) to deliver them. You can delete this at any time in Settings.

We also count anonymously how often features are used per day (e.g. “timer started 37 times today”) — without a user ID, device identifier or cookie; these figures cannot be linked to any person. We do not collect location data or advertising IDs. Third-party tracking only happens if you expressly agree to it (see section 9) — without your consent, not a single advertising-network script is loaded. We also collect technical error reports and anonymous page views (see section 5, Sentry and Vercel Analytics) — without the content of your entries.

3. Purpose and legal basis

The data is used to provide the app’s features (craving tracking, insights, experiments) and for internal product analysis and improvement. In future this may include an aggregated analysis of entries across all users (e.g. “which coping strategies people use most”); this feature does not exist yet. Entries would then be evaluated only in aggregate, and results that could relate to a single person are neither published nor passed on. The legal basis for using the app is Art. 6(1)(b) GDPR (performance of a contract). We process health data (craving entries, check-ins, journal) on the basis of the explicit consent you give during onboarding under Art. 9(2)(a) GDPR. We record usage events only with your separate, optional consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), which the app asks for once you have used it for a while and which you can give or withdraw at any time under Settings → Usage statistics; the app works the same without it. Error reports and anonymous page views are based on our legitimate interest in an app that works (Art. 6(1)(f) GDPR). You can withdraw your consent at any time with effect for the future, by email to koop.anchor@outlook.com or by deleting your account (Settings → Delete account). Without this consent the app cannot store entries; the timer stays usable without an account.

4. How long we keep data

Your data is stored for as long as your account exists. You can delete your account and all stored data completely at any time: Settings → Delete account. You can also export your data: Settings → Export data.

Who sees individual entries: analyses the controller looks at to run the app are aggregated; automatic features such as the weekly summary and the reflection chat process your entries only for you. The controller only accesses individual entries when necessary — to fix a specific error, when you ask for help yourself, to handle an access, export or deletion request, or to meet legal obligations. Access to the database is protected by two-factor sign-in. Content is not used for advertising, quotes or training AI models.

5. Processors

We use the following service providers, with whom data processing agreements under Art. 28 GDPR have been concluded:

  • Supabase Inc. (USA) – database, sign-in and file storage. The data is held in a data centre in London (United Kingdom). An EU Commission adequacy decision applies to the United Kingdom; access by the US company is covered by EU Standard Contractual Clauses (SCCs).
  • Vercel Inc. (USA) – hosting of the app and anonymous page-view statistics (Vercel Analytics, without cookies). Transfer based on SCCs.
  • Functional Software Inc. (Sentry) (USA) – error reports when something goes wrong in the app. Technical details are sent (e.g. error message, device type, browser); the content of forms and entries is removed before sending, and no screen recording takes place. Transfer based on SCCs.
  • Anthropic PBC (USA) – AI features (personalised exercise texts, reflection chat). Sent are: in the reflection chat, your messages together with details from your current entry and check-in (e.g. emotion, trigger, intensity, hunger, outcome) and summarised details from your history such as your most frequent trigger and emotion, and for the monthly review also summarised monthly figures; for voice input when logging, the recognised text of your recording; for the personal timer texts (Premium), the emotion you tapped, the situation you chose, your most frequent emotion and whether intensity dropped in your recent timer sessions. Your nickname, email address and ID are never sent. Under Anthropic’s API terms this data is not used to train AI models. Transfer based on SCCs.
  • Resend Inc. (USA) – sending email: the weekly summary (if enabled, with summarised details from your entries), notices about stored timer files and feedback notifications. Transfer based on SCCs.
  • Cloudflare, Inc. (USA) – protecting the sign-in page against automated bulk sign-ups (Cloudflare Turnstile). When the sign-in page is opened, your IP address and technical details of your browser are sent to Cloudflare; the content of your entries is not. The legal basis is our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR). Transfer based on SCCs.

5a. Purchases through the Google Play Store

If you subscribe to Premium through the Google Play Store, Google is the seller and processes your payment data under its own responsibility — not as our processor. We receive no payment data: neither card number nor billing address. To check whether a subscription is valid we send the purchase identifier issued by Google to the Google Play Developer API; of that identifier we store only a hash, together with the product purchased and the date the entitlement runs until. Google notifies us automatically of changes to the subscription (e.g. cancellation or refund). Google’s own privacy policy applies in addition.

6. Your rights

Under the GDPR and the UK GDPR you have the following rights:

  • Access (Art. 15) – what data we hold about you
  • Rectification (Art. 16) – correcting wrong data (e.g. your nickname in Settings)
  • Erasure (Art. 17) – through “Delete account” in Settings or by email
  • Data portability (Art. 20) – export your data through “Export data” in Settings
  • Withdrawing consent (Art. 7(3)) – at any time, with effect for the future
  • Complaint – to a data protection authority. The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (Germany). You can also complain to the authority where you live, for example the Information Commissioner’s Office (ICO) in the United Kingdom or the Data Protection Commission in Ireland.

For requests, contact: koop.anchor@outlook.com

7. Cookies and local storage

The app uses localStorage for technically necessary purposes: session management (sign-in), theme setting, language choice, timer preferences, programme progress, timer sessions not yet uploaded, and the referral source described in section 2. Uploaded timer files are also cached in the browser so they start faster. When you sign out or switch accounts, account-related entries on the device are deleted. Tracking or advertising cookies are only set with your consent (section 9).

8. Voice input (optional)

The optional voice feature in the urge surf timer and when logging uses your browser’s speech recognition (Web Speech API). Depending on the browser (e.g. Chrome, Safari), audio may be sent to the browser maker (e.g. Google, Apple) for recognition — their privacy terms then apply. Anchor itself stores no audio recordings; only the recognised text is processed. In the timer (e.g. a number) this happens only locally on your device; when logging by voice, the recognised text is sent to Anthropic to map it to the fields of the entry (see section 5). You can turn voice input off at any time in the timer settings.

9. Ad measurement (only with consent)

When we run ads, we use pixels from Meta Platforms Ireland Ltd. (Facebook/Instagram) and TikTok Technology Ltd. They report back to the platform that a sign-up or a Premium subscription took place — without an amount and without naming the plan — so ads can be shown to more suitable people. The platform sets cookies and processes your IP address; a transfer to the USA is possible (basis: EU Standard Contractual Clauses or the EU-US Data Privacy Framework).

For TikTok the same sign-up is additionally reported from our server, because the report from the browser can be suppressed by ad blockers. What is sent is your IP address, your browser identification (user agent), the address you were on and — if you arrived through an ad — TikTok's click id. Both reports carry the same event id so they are counted as one event. This route is taken only after your consent as well: if you decline, it does not happen. Only the details listed here are sent — in particular no email address, no user ID and no content from your entries. The page address is stripped of all parameters before it leaves.

Only the event “sign-up completed” is sent. No content whatsoever is transferred — no craving entries, no emotions, no triggers, no email address and no user ID. “Advanced Matching” is deliberately switched off.

The legal basis is your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act), and for users in the United Kingdom the Privacy and Electronic Communications Regulations (PECR). No script from these providers is loaded before you agree. You can withdraw consent at any time with effect for the future: Settings → Ad measurement or by email to koop.anchor@outlook.com. Declining has no effect whatsoever on using the app.

If this English version and the German version differ, the German version at /datenschutz applies.