Privacy policy
Last updated: August 2026
What we collect
- Account info: name, email, password (hashed at rest), state of residence.
- Family data: student names, birth dates, school year configuration, activity logs you create.
- Uploaded files: photos and PDFs you attach to records.
- Usage telemetry: anonymous error reports; no third-party advertising trackers.
Where it lives
Encrypted at rest in a managed PostgreSQL database in the United States. Photos and PDFs live in encrypted object storage in the same region. Authentication, payments, email delivery, and AI processing are handled by reputable U.S. sub-processors who do not use your data for their own training or marketing. The current sub-processor list is available on request via the contact page.
AI processing
When you use Anchor's AI features (photo description, weekly summaries, compliance Q&A), the relevant data — a photo, activity text, or state rules block — is sent to our AI sub-processor for processing and the result returned to you. We do not train any AI model on your data, and our sub-processor does not train on data passed through their API.
What we don't do
- We don't sell your data.
- We don't share student records with third parties (other than the processors above required to run the app).
- We don't run ad networks or behavioral tracking.
Emergency & safety information
When you enroll a student in a microschool through Anchor, you may provide emergency contact details, allergy/medical notes, pickup authorization, and a photo-release choice. This information is visible only to you and to microschools your student is actively enrolled with (including their printed rosters), and is never used for any other purpose. It is deleted with your account.
Product analytics
We record basic usage events (for example, "signed up" or "logged an activity") tied to a random browser identifier, to understand which parts of Anchor work well. Analytics are processed by PostHog (U.S.), including limited session recordings in which all typed input is masked. These events and recordings never include your notes, photos, student records, or email contents, and we don't use third-party ad trackers.
Testimonials
If you check "You may quote this publicly" when sending feedback, we may share that feedback in our marketing, attributed by first name, last initial, and state only. We never quote feedback without that explicit consent, and you can withdraw it anytime via the contact page.
Your data, your control
Use the contact page to request a full export of your data or to delete your account. Both happen within 7 days.
How long we keep it
While your account is in use, we keep your records so they're there when you need them. We don't keep them forever for accounts that aren't in use: if an account is not on a paid plan and goes unused for 120 days, we may deactivate it, and we may permanently delete it and its records at any time after that. Signing in resets the clock, and accounts with an active paid subscription aren't subject to it. The terms of service covers this too.
We aren't required to notify you before deactivating or deleting an account. If your account has been deactivated and you'd like it back, contact us; if the data hasn't been purged yet, we may be able to restore it.
Because of that, please keep your own copies of anything you may need later — many states require families to retain homeschool records for years, and Anchor shouldn't be your only copy. Export any time while your account is active.
Backups are kept for a short period after deletion as part of normal database operation, and then age out.
Children and student logins
Anchor is built for parents and microschool operators. Children don't sign themselves up, and we don't market to them, show them ads, or use their information for anything beyond running the app.
A parent may choose to give their student a login. To do that, the parent provides the student's email address and name, and in doing so consents on that child's behalf — we collect nothing directly from a child without the parent setting it up first. A student with a login can only ever see their own records, never a sibling's, and what they're allowed to do is controlled by per-student permissions the parent sets. Parents can revoke a student's access, or delete the login entirely, at any time from the Students page. Parents remain the account owners and are responsible for the records they create.
Changes
We'll email all active users at least 30 days before any material change to this policy.