Privacy Policy
Last updated: March 20, 2026
HouseholdAnchor is a calm, private planning companion for your household. We built it with privacy as a foundation, not an afterthought. This policy explains — in plain language — what data we collect, how we protect it, and what we never do.
The short version:
Your documents and personal content are encrypted on your device before they ever leave it. We cannot read your data. We do not sell your data. We do not track your behavior.
What We Collect
Account information: Your email address and optional display name, used for authentication and to identify your account.
Planning data: Documents, family contacts, household roles, rhythms, legacy letters, and reflections that you create in the app. All content is encrypted with AES-256-GCM on your device before being synced to our servers.
Usage metadata: We store when you last synced and basic account status (subscription tier, onboarding completion). We do not track which screens you visit, how long you use the app, or what you tap on.
How We Protect Your Data
- Encryption: All sensitive content is encrypted with AES-256-GCM using a key derived from your password (PBKDF2 with 600,000 iterations). The encryption key is stored in your device's hardware-backed secure storage (iOS Keychain / Android Keystore).
- Zero-knowledge sync: When your data syncs to our cloud servers (hosted by Supabase), it arrives already encrypted. Our servers store encrypted blobs — we cannot read your documents, contacts, or personal content.
- No analytics: We do not use Google Analytics, Mixpanel, Amplitude, or any behavioral tracking tool. There are no tracking pixels, no ad SDKs, and no third-party analytics scripts in the app.
Third-Party Services
We use a small number of services to operate HouseholdAnchor:
- Supabase — Database and authentication. Stores encrypted data and manages your account. Supabase Privacy Policy
- Sentry — Error tracking. When the app encounters a technical issue, Sentry receives a crash report with your user ID hashed (SHA-256) and no personal content. Sentry Privacy Policy
- Resend — Transactional email only (welcome messages, invitation emails). We never send marketing emails. Resend Privacy Policy
- Stripe — Payment processing for paid subscriptions. We never see or store your credit card number. Stripe Privacy Policy
What We Never Do
- We never sell, rent, or share your data with advertisers
- We never read your encrypted documents or personal content
- We never track your location (Quiet Coordination uses one-time, opt-in check-ins only)
- We never send push notifications or marketing emails
- We never use your data to train AI models
Children's Data
HouseholdAnchor is designed for adults managing household planning. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Data Sharing
You control who sees your planning information:
- Private by default: All content is private to your account unless you explicitly choose to share it.
- Family sharing: You can invite household members with "Co-Anchor" (full access) or "Viewer" (summary only) permissions. You can revoke access at any time.
- Continuity Handoff: You can configure trusted contacts who may request access under conditions you define, with a waiting period you set. This is not a legal instrument — it is a planning consideration.
Data Deletion
You can delete your account and all associated data at any time from Settings → Account → Delete Account. This permanently removes your encrypted data from our servers. Local data on your device is also cleared.
Changes to This Policy
If we make changes to this policy, we will update the date at the top and notify you in the app. We will never reduce your privacy protections without your explicit consent.
Contact
Questions about your privacy? Reach us at privacy@householdanchor.com