Privacy Center
Plain words about your data.
Pocket Anchor is a privacy-first platform. Here is exactly what that means today — no legal fog, no overclaiming.
What we store
Account basics (name, email, profile photo from Google), your sanctuary content (mood pulses, journal entries, Wall of Hope reasons), health information you choose to save (health card, medical vault, emergency card), safety content (evidence vault, safety plan, rebuilding plan), Déjà content (dreams, moments), and operational records (sessions, subscriptions, trusted contacts, guardians).
Why
Only to provide the features you use: keeping your sanctuary, matching dreams in Déjà, translating messages, emailing guardians you invite, and processing your subscription.
Who can access it
You. Supporters see only what you share through your Anchor Link. Guardians see only mood "weather" — never words. Our team does not read user content as a matter of policy and design.
What is optional
Everything beyond your account email. Every field in the Health Card, Emergency Card, Safety Plan, Trip Pack, and Déjà is optional.
What you control
Delete individual items (journal entries, dreams, evidence, vault items, contacts) at any time. Export your Déjà data as JSON. Delete all Déjà data in one step.
Third-party services
Stripe processes payments (we never see card numbers). Anthropic (Claude) processes AI requests — comfort chat, navigator, translation, and Déjà extraction; those requests include only the text you submit. OpenAI Whisper transcribes voice notes you record. Google verifies sign-in. Resend delivers guardian and contact emails. Google Analytics counts page visits (no health content).
Deletion
Deleting an item removes it from the active database immediately. Delete-all for Déjà wipes dreams and moments together. To delete your whole account, contact us and we remove everything.
What we do NOT claim
We do not claim zero-knowledge, end-to-end encryption, or HIPAA compliance today. Data is encrypted in transit (HTTPS) and at rest by our infrastructure. Client-side encryption — where not even we could read your records — is on our near-term roadmap, and this page will say so the day it ships.
Questions about your data? Email the team from the account address you signed up with.
