Privacy & Security
Privacy & Security at Pocket Anchor
Privacy is not an add-on at Pocket Anchor. We design sensitive health, safety and support experiences to minimize unnecessary data collection, authentication and exposure.
Pocket Anchor is an AI-native health, safety and privacy platform designed around low-barrier access to sensitive support and safety resources. This page is a technically honest disclosure — written for privacy researchers, survivors, health professionals and independent reviewers, not as marketing. Where a detail is not yet verified or documented, we say so plainly.
- StatusPublicly launched
- ArchitecturePrivacy-first, data-minimizing
- No-account accessSelected crisis & safety resources
- EncryptionHTTPS/TLS in transit; at rest by infrastructure
- End-to-end encryptionNot claimed today
- Open-source statusClosed-source
- Independent auditNot yet audited
- JurisdictionCanada
Quick answers
Direct answers to the questions reviewers and users ask most. Details follow below.
Is Pocket Anchor end-to-end encrypted?
No. Pocket Anchor does not currently claim end-to-end or client-side (zero-knowledge) encryption. Data is encrypted in transit (HTTPS/TLS) and at rest by the underlying infrastructure. Client-side encryption is on the roadmap and this page will say so the day it ships.
Are crisis conversations processed locally or sent to a server?
AI-assisted conversations (comfort chat, the resource navigator, translation) are processed on our servers and sent to an AI provider (Anthropic Claude) to generate a response. They are not processed only on your device. Static crisis and safety resources (hotline lists, the Survivor Navigator directory) load without any account and without AI processing.
Is identifiable information attached to crisis events?
No-account crisis and safety resources do not require or attach your identity. Messages left on an Anchor Link are stored with a hashed, non-reversible sender fingerprint used only for blocking and rate-limiting — not your name. Account-based features are tied to your account so you can return to your own content.
Does Pocket Anchor collect or share your location?
Pocket Anchor does not access your device GPS and does not track your location. Location appears only where you manually type a city/country (for example, an optional photo context tag). We do not read GPS/EXIF metadata from your photos.
Can Pocket Anchor automatically contact another person or emergency services?
No. Pocket Anchor does not automatically alert emergency services or third parties on your behalf. It surfaces resources and numbers for you to contact yourself. Any guardian or trusted-contact notifications are set up and initiated by you.
How long is crisis-related data retained?
No-account resources create no personal record to retain. For account-based content you control (messages, journal, vault items, Déjà), items remain until you delete them; deletion removes them from the active database immediately. Formal per-category retention windows are still being documented.
Has an independent security audit been performed?
No. Pocket Anchor has not yet completed an independent third-party security or privacy audit. Our statements are based on the current implementation, not on external certification.
Our privacy principles
- Data minimization. We only collect information needed for the feature you are using.
- No unnecessary authentication. Selected crisis and safety resources stay accessible without registration, because an account is not needed to read them.
- Privacy by context. Health, crisis, safety and survivor-oriented features get stronger privacy handling than ordinary consumer features.
- Transparency. We explain what is collected, why, who processes it where applicable, and how long it is kept.
- Security by design. We protect sensitive information with the controls actually implemented today — described plainly on this page.
- Honest limitations. We never describe Pocket Anchor as anonymous, untraceable, or risk-free, because those claims cannot be guaranteed.
What data we collect
We collect only what a feature needs. This table maps each category to its purpose, whether an account is required, and your controls.
| Data category | Examples | Why | Account required? | Stored? | Retention | Third-party processing | Your control |
|---|---|---|---|---|---|---|---|
| Account information | Name, email, profile photo (from Google sign-in) | Create and secure your account | Yes | Yes | Until account deletion | Google (sign-in) | Edit profile; delete via contact |
| Health information | Health card, Medical Vault records, allergies, medications, emergency card | Provide the features you choose to use | Yes | Yes (only what you enter) | Until you delete it | Not sent to AI for storage | Delete any item anytime |
| Safety information | Guardians, trusted contacts, safety plan, check-ins, evidence vault | Operate safety features you set up | Yes | Yes | Until you delete it | Resend (guardian invite emails only) | Delete items; remove guardians |
| Personal content | Journal entries, memories, Déjà dreams, photos, Anchor Link messages | Store and display your own content | Mostly yes (Anchor messages can be left without an account) | Yes | Until you delete it | Anthropic/OpenAI for moderation & features (see AI) | Delete items; export Déjà; delete-all Déjà |
| Location information | Manually typed city/country tags only | Add context to a memory | No (optional) | Only if you type it | With the item | None | Leave blank; we never read GPS/EXIF |
| Technical information | IP address, browser/device info, server logs, timestamps, session records | Deliver the site, keep sessions, basic security | No (for site access) | Session records yes; request logs per infrastructure | Being documented | Hosting/CDN infrastructure | Sign out to end a session |
| Analytics | Page-visit measurement (Google Analytics 4, PostHog) | Understand aggregate usage | No | By the analytics provider | Per provider | Google, PostHog | Browser/extension controls |
What we do not collect
- • We do not access your device GPS or track your location.
- • We do not read GPS/EXIF metadata from photos you upload; only city/country you type is used.
- • We do not sell your data, and we do not use your health information for advertising.
- • We do not require an account to read selected crisis and safety resources.
For anything not listed here, we do not currently make a blanket public claim that the information is never processed — we would rather be accurate than overclaim.
Free. No account. No trace.
Selected crisis and safety resources — for example hotline directories and the Survivor Navigator — are intentionally accessible without creating an account. For those static resources, no account is required, no account content is created, and no AI processing runs to display them.
Analytics (Google Analytics 4 and PostHog) and standard web/server technical processing (including IP addresses handled by hosting/CDN) still apply to ordinary page loads, as with most websites. “No trace” refers to Pocket Anchor not requiring an identity or creating an account record for these resources — it does not mean the internet cannot record that you visited.
Important: Pocket Anchor cannot control records created by your browser, device, network provider, employer, school, managed device, or other third parties.
Account-based features
Some features necessarily require an account so your content is saved to you and protected from others. These include the Medical Vault, Journal, Guardians, Memory Vault, Déjà, and private Anchor messaging controls. For each, only the information you enter is processed and stored, access is limited to you (and only what you explicitly share), and you can delete items at any time.
Health information & Medical Vault
You can store health-card details, medications, allergies, emergency information and medical documents in the Medical Vault. This exists only to give you your information when you need it. Everything is optional.
Health data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure. It is visible to you; supporters and guardians never see it. It is not used for advertising, and storing a record does not send it to AI providers. Only if you actively use an AI feature (such as translation) is the text you submit sent for processing. You can delete any item at any time.
Pocket Anchor is designed with privacy and sensitive-data protection in mind. Applicable legal obligations depend on your location, the service provided, the data involved, and Pocket Anchor’s actual processing activities. We do not claim HIPAA, GDPR or PIPEDA compliance on this page.
Encryption & security controls
- In transit: HTTPS/TLS across the site and API.
- At rest: provided by the underlying managed database and storage infrastructure. This has not been independently verified or certified.
- Application-level / end-to-end: Pocket Anchor does not currently claim end-to-end or client-side (zero-knowledge) encryption. This is on the roadmap and this page will be updated the day it ships.
- Authentication: sign-in is handled through Google OAuth; Pocket Anchor does not store passwords. Sessions use a server-side session record and an
HttpOnly,Securecookie that expires after 7 days. - File storage: uploaded documents and photos are stored via managed object storage and served over HTTPS.
AI & privacy
Pocket Anchor is AI-native. AI is used for message moderation, comfort chat and the resource navigator, translation, voice-note transcription, and Déjà matching. AI requests run on our servers and are sent to the providers below via a managed proxy — they are not processed only on your device.
| AI feature | Provider / model | Data sent | Stored by provider? | Used for training? | User control |
|---|---|---|---|---|---|
| Message moderation (text, image, voice) | Anthropic Claude (claude-sonnet-4-6) via Emergent proxy | The message text, image, or voice transcript you submit | Not currently documented | Not currently documented | Do not submit; message without a photo/voice |
| Comfort chat & resource navigator | Anthropic Claude via Emergent proxy | The text you type in the conversation | Not currently documented | Not currently documented | Optional feature; avoid sharing sensitive details |
| Translation | Anthropic Claude via Emergent proxy | Only the text you ask to translate | Not currently documented | Not currently documented | Optional feature |
| Voice-note transcription | OpenAI Whisper (speech-to-text) via Emergent proxy | The audio you record | Not currently documented | Not currently documented | Type instead of recording |
| Déjà (dream/moment matching) | Anthropic Claude via Emergent proxy | The dream/moment text you submit | Not currently documented | Not currently documented | Delete individual or all Déjà data |
Please do not submit highly sensitive information to an AI feature unless Pocket Anchor explicitly states the feature is designed to process it.
Third-party services
These are the meaningful external services Pocket Anchor actually depends on.
| Provider | Purpose | Information potentially shared | Privacy policy |
|---|---|---|---|
| Emergent (hosting, CDN, integration proxy, object storage) | Runs the app, serves assets, routes AI requests, stores uploaded files | Requests, uploaded files, technical data | https://emergent.sh |
| MongoDB | Primary database | Your stored account and content data | https://www.mongodb.com/legal/privacy-policy |
| Sign-in (OAuth) and Google Analytics 4 | Name, email, profile photo; aggregate analytics | https://policies.google.com/privacy | |
| Anthropic (Claude) | AI moderation, comfort chat, navigator, translation, Déjà | The text/image/transcript you submit to those features | https://www.anthropic.com/legal/privacy |
| OpenAI | Whisper voice-note transcription | Audio you record | https://openai.com/policies/privacy-policy |
| Stripe | Payments for Nomad Pass / Enterprise | Billing details (we never see card numbers) | https://stripe.com/privacy |
| Resend | Delivers guardian and contact emails you initiate | Recipient email + message you send | https://resend.com/legal/privacy-policy |
| PostHog | Product analytics | Aggregate usage/events | https://posthog.com/privacy |
Links open each provider’s own privacy policy.
Location & safety data
Pocket Anchor does not access device location, does not track you, and does not continuously monitor location. Location appears only where you manually type a city/country. Manually entered location is stored with the item you attach it to and is shown only to people allowed to see that item. It is not sent to third parties.
Data retention
| Data | Retention | Reason |
|---|---|---|
| Account data | Until account deletion | Service operation |
| Health data | User-controlled; until you delete it | You own the storage |
| Journal / memories / Déjà | User-controlled; until you delete it | User-controlled features |
| Safety data (guardians, evidence, plans) | User-controlled; until you delete it | Feature operation |
| Session records | Session cookie expires after 7 days | Keep you signed in |
| Server / request logs | Being documented | Security & operations |
| Analytics | Per provider policy | Aggregate measurement |
| Deleted data | Removed from active database immediately; backup propagation being documented | Deletion processing |
Where a formal window is not yet defined, we say “being documented” rather than invent a number.
Your data & deletion
You can delete individual items — journal entries, memories, Déjà dreams, evidence, vault items, guardians, trusted contacts and Anchor messages — at any time from your dashboard. Déjà data can be exported as JSON and deleted all at once. Deleting an item removes it from the active database immediately.
Full-account self-service deletion is not yet a one-click feature: to delete your whole account, contact the team from your account email and we remove everything. Backup propagation timing is still being documented. Some records may be retained where required for security or legal reasons.
Who can access your data?
You can access your data. Supporters see only what you share through your Anchor Link. Guardians see only your mood “weather” — never your words. As a matter of policy and design, the Pocket Anchor team does not read user content. However, because data is not end-to-end encrypted, infrastructure administrators technically could access stored data to operate and maintain the service. We are transparent about this rather than claiming administrators cannot access data.
Legal requests & jurisdiction
Pocket Anchor operates from Canada. Data is stored with managed cloud infrastructure and may be processed across borders by the third parties listed above. We evaluate legal requests according to applicable law; we do not promise to refuse all lawful requests. Minimizing what we retain limits what could ever be disclosed. The specific hosting region is not currently publicly disclosed.
Security incidents
We monitor the service and respond to issues as they arise. Where a security incident legally requires user or regulator notification, we will follow applicable law. A formal, published incident-response process is currently being developed; we do not claim certifications or processes that do not yet exist.
Independent security audit
Pocket Anchor has not yet completed an independent third-party security audit. This means no independent audit claim is being made, and the statements on this page are based on the current implementation and documentation rather than external certification.
Open-source status
Pocket Anchor is currently closed-source. PrivacyTools.io generally prefers open-source software and services; we are being transparent about our current source-availability status and do not represent Pocket Anchor as open-source.
Who is Pocket Anchor designed to protect?
- Everyday privacy: reducing unnecessary tracking, profiling and data collection.
- Sensitive situations: protecting people seeking health, crisis and safety resources.
- Targeted personal threats: acknowledging users may face abusers, stalkers, controlling partners, hostile employers or unsafe family situations.
Pocket Anchor should not be treated as a guarantee against a determined adversary who has access to your device, browser, network, accounts or physical environment.
Safety limitations for people in dangerous situations
Quick Exit can reduce visible exposure inside the app, but it cannot erase your browser history, cannot erase network or ISP logs, cannot control screenshots, and cannot stop someone with access to your device from inspecting it. It cannot guarantee anonymity, and it cannot guarantee that another person will not discover that you used the service.
If you are in immediate danger, contact your local emergency services. Consider using a private browsing window or a device only you can access, and review our guidance on documenting safely.
Report a security issue
If you believe you have found a security or privacy vulnerability, please report it privately to security@pocketanchor.tech (a dedicated security mailbox is being set up; until then this reaches the team).
- • Include: what you found, where, and clear steps to reproduce.
- • Please practise responsible disclosure and give us reasonable time to fix the issue before publishing.
- • Do not send real medical records, other people’s data, or sensitive personal information as part of a report.
- • This channel is not for emergencies — if you are in crisis, use our safety resources or local emergency services.
Privacy status summary
| Area | Current status |
|---|---|
| Publicly available | Yes — publicly launched |
| Active development | Yes |
| No-account resources | Yes — selected crisis & safety resources |
| Data minimization | Core product principle |
| Encryption in transit | Yes — HTTPS/TLS |
| Encryption at rest | Yes — by infrastructure (not independently verified) |
| End-to-end encryption | No — not claimed today |
| AI data processing documented | Yes — see AI & Privacy |
| Third-party services documented | Yes — see Third-Party Services |
| Data retention documented | Partial — some windows still being documented |
| Data deletion | Per-item self-service; full-account deletion via contact |
| Independent security audit | Not yet audited |
| Open source | Closed-source |
| Company jurisdiction | Canada |
| Business model | Paid Nomad Pass / Enterprise; crisis & safety tools free |
Related: Privacy Policy (plain-words privacy notice) · Safety resources · Resource hub
Important privacy limitations
- Pocket Anchor is not currently open-source.
- No independent third-party security or privacy audit has been completed.
- Some features (Medical Vault, Journal, Guardians, Memory Vault, private Anchor messaging) require an account.
- Certain third-party services (hosting, database, AI, analytics, payments, email) necessarily process some data.
- AI features involve external processing by Anthropic and OpenAI via a proxy; provider retention/training behaviour is not currently documented here.
- End-to-end / client-side encryption is not yet implemented.
- Records created by your browser, device, network provider, employer, school, managed device, or other parties are outside Pocket Anchor’s control.
PrivacyTools.io review summary
This page is designed to make the relevant evidence transparent for independent review. It does not claim endorsement or that Pocket Anchor “meets” any external criteria.
Privacy & Security page last reviewed: June 2026. This page is updated as the implementation changes.
