← Anthora

Privacy Policy

Last updated: 17 August 2026

1. Who we are (Controller)

Anthora is operated by Clexa GmbH (“Clexa”, “we”, “us”, “our”), Germany. We run the website anthora.co and the Anthora mobile application for iOS (together, “the Service”). Clexa GmbH is the data controller within the meaning of Art. 4(7) GDPR.

For any question about this policy, your data, or to exercise your rights, contact us at privacy@anthora.co.

2. Data we collect

2.1 Account data

Email address, username, and hashed password (bcrypt — we never see your actual password). If you sign in with Google we receive your Google account ID and email. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.

2.2 Profile data (optional)

Display name, bio, profile photo, personal link, and phone number. You control everything here and can remove it from Settings at any time.

2.3 Content you create

Lists, items, comments, likes, saves, predictions, and notes you create are stored to operate and display the Service. Legal basis: performance of a contract.

2.4 Usage data

Which lists you view, save, like, or interact with — used to personalise your feed and recommendations. Retained until you delete your account. Legal basis: legitimate interest, Art. 6(1)(f) GDPR.

2.5 Device and technical data

Web: browser type, OS, approximate location from IP (country/city only), referring URL. Mobile: device model, OS version, app version, language, time zone, crash data. IP addresses are truncated after use.

We do not collect IDFA or AAID. We do not use cross-app or cross-site tracking.

2.6 Search queries

Stored for up to 90 days, not linked to your account, used to improve search quality. Legal basis: legitimate interest.

2.7 Security and audit logs

Login attempts, failures, and lockouts (with masked email addresses). Retained 90 days. Legal basis: legitimate interest in protecting accounts.

2.8 Error and performance monitoring

We use Sentry to identify crashes, failed requests, and performance problems. Error events may contain a timestamp, app and operating-system version, the affected endpoint, a stack trace, and limited technical request metadata. Default personal-information collection is disabled. We do not intentionally send passwords, authentication tokens, or the contents of your Anthora recommendations to Sentry. Legal basis: our legitimate interest in keeping the Service secure and reliable, Art. 6(1)(f) GDPR.

2.9 Analytics (with consent)

If you accept the analytics category in the cookie banner, we use Vercel Analytics — privacy-first, no cookies, no cross-site tracking, no persistent identifiers. Legal basis: consent, Art. 6(1)(a) GDPR.

2.10 Membership and billing data

If you start a paid membership on the web, Stripe processes your name, email, billing address, payment method, tax information, and transaction details. Anthora stores only the Stripe customer and subscription references needed to recognise your membership, along with its plan, status, billing interval, and renewal date. We never receive or store your full card number. Legal basis: performance of a contract and compliance with tax and accounting obligations, Art. 6(1)(b) and (c) GDPR.

2.11 Mobile app permissions

The app requests only what a feature needs: photo-library access for images you choose to add and camera access when you choose in-app capture. You can revoke either permission in system settings; the rest of the app continues to work.

2.12 Recommendation actions

When someone follows a book, place, ticket, product, or other action link, Anthora stores the recommendation, item number, destination, partner, creator, and time of the action. We do not use an advertising identifier or record the visitor's identity in this attribution record. If a partner later reports an eligible transaction, we store its partner reference, amount, currency, and status for attribution and fraud prevention. Creator revenue sharing is disabled at launch. Legal basis: our legitimate interest in accurate attribution and operating the Service, Art. 6(1)(f) GDPR.

2.13 Reports, blocks, and community safety

When you report content, Anthora stores your account, the reported content or profile, the reason, optional details, review status, and moderation notes. Reports are visible only to authorised moderators. Your blocked-person list is stored to hide each person's profiles, public content, comments, and interactions from the other. Legal basis: our legitimate interest in community safety and enforcing these Terms, Art. 6(1)(f) GDPR, and compliance with legal obligations where applicable.

3. Legal basis summary

PurposeLegal basis
Account & contentContract — Art. 6(1)(b)
Personalised feed & recommendationsLegitimate interest — Art. 6(1)(f)
Search query loggingLegitimate interest — Art. 6(1)(f)
Security logs & fraud preventionLegitimate interest — Art. 6(1)(f)
Error and performance monitoringLegitimate interest — Art. 6(1)(f)
Community reports and blockingLegitimate interest — Art. 6(1)(f)
Analytics (Vercel)Consent — Art. 6(1)(a)
Membership billingContract and legal obligation — Art. 6(1)(b), (c)
Recommendation attributionLegitimate interest — Art. 6(1)(f)
Push notificationsConsent — Art. 6(1)(a)
Legal requestsLegal obligation — Art. 6(1)(c)

4. AI features

Anthora uses Anthropic's Claude API to help you make list drafts and translate an entry when you ask to read it in another language. The prompt or entry text needed for that feature is sent to Anthropic. Anthropic does not use prompts submitted through our API integration to train its models. Suggestions are never published until you save them. A translation never replaces your original entry.

5. Affiliate and booking links

Anthora may work with Amazon Associates and other book, travel, ticket, restaurant, grocery, and retail partners. Before redirecting you, Anthora records the recommendation action described in section 2.12. The destination partner may then set cookies or use similar technology under its own privacy policy. We do not set an affiliate tracking cookie on anthora.co. Partners provide transaction and commission reports but should not provide us with your name or payment details. See Amazon's Privacy Notice for details.

6. Who we share data with

ProviderPurposeLocation
Vercel Inc.Web hosting and analyticsUSA (SCCs)
Railway Corp.Backend server and database hostingUSA (SCCs)
Functional Software, Inc. (Sentry)Error and performance monitoringEU / USA (DPF and SCCs as applicable)
Anthropic PBCAI list generation and on-demand translationUSA (SCCs)
Stripe Payments Europe, LimitedWeb membership checkout, invoicing, tax, and billing managementIreland / USA (SCCs or DPF)
Affiliate, booking, ticketing, and retail partnersRecommendation actions, transaction attribution, and commission reportingVaries by the partner shown before leaving Anthora
Pexels GmbHImage search for list itemsGermany / USA
Google Maps PlatformGeocoding and map tiles for trip listsUSA (SCCs)
Apple Inc.iOS app distribution and push notificationsUSA (SCCs)
Strato AGEmail hosting for @anthora.coGermany

We do not sell personal data. We do not share data with advertisers. We do not use Meta Pixel, TikTok Pixel, Google Analytics, Firebase Analytics, Mixpanel, or any similar tracking platforms.

7. International data transfers

Transfers to processors outside the EEA are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, combined with supplementary technical and organisational measures. For providers certified under the EU–US Data Privacy Framework, the Framework's adequacy decision also applies. To request copies of applicable SCCs, email privacy@anthora.co.

8. Your rights under GDPR

If you are in the EEA, UK, or Switzerland, you have the right to:

  • Access the data we hold about you (Art. 15)
  • Rectify inaccurate or incomplete data (Art. 16)
  • Erase your data — you can also self-delete your account in Settings (Art. 17)
  • Restrict processing in certain circumstances (Art. 18)
  • Data portability — download your JSON account export from Settings (Art. 20)
  • Object to processing based on legitimate interest, including personalised recommendations (Art. 21)
  • Withdraw consent at any time via the cookie banner, app notification settings, or email
  • Lodge a complaint with your local supervisory authority

Email privacy@anthora.co. We respond within 30 days.

9. Automated decision-making

We do not use automated decision-making that produces legal or similarly significant effects under Art. 22 GDPR. Our recommendation engine personalises which lists you see but does not restrict access, set prices, or make consequential decisions about you.

10. Data retention

Data typeRetention
Account and profile dataUntil you delete your account
Content (lists, comments, predictions)Until you or we delete it, or account deletion
Usage dataUntil you delete your account
Search queries90 days (not linked to account)
Security and audit logsUp to 90 days; current infrastructure logs expire sooner
Error and performance events (Sentry)Configured provider retention; no longer than 90 days
Analytics data (Vercel)One-month reporting window on our current plan; provider-side storage may be longer
Membership state in AnthoraUntil account deletion; an active membership is cancelled first
Recommendation action attributionUntil account deletion or 24 months after the action, whichever comes first
Blocks and reports you submitUntil account deletion; resolved moderation records may be retained for up to 3 years where needed to prevent repeated abuse or defend legal claims
Invoices and legally required payment recordsFor the statutory tax and accounting retention period, generally up to 10 years
Email correspondence with privacy@3 years (German limitation period)

When account deletion succeeds, any active web membership is cancelled first, then account data and user-linked content are removed from live systems immediately. Stripe and Clexa GmbH may retain invoices and transaction records where tax, accounting, fraud-prevention, or other law requires it. Copies of other account data may remain in access-restricted disaster-recovery backups until the applicable backup expires, for no longer than 90 days. Backups are not used for ordinary product processing.

11. Data security

Passwords stored as bcrypt hashes. All traffic over HTTPS (TLS 1.2+). Authentication tokens are short-lived (15 minutes) with rotating refresh tokens. Rate limiting and account lockout against brute-force attacks. Access to production systems restricted to authorised personnel. Where required, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours under Art. 33 GDPR. We notify affected people without undue delay when Art. 34 GDPR requires it.

12. Children

The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@anthora.co and we will delete it promptly.

13. Cookies and similar technologies

Detailed information is in our Cookie Policy. The banner you see on first visit lets you accept all, reject all, or customise by category. You can change your choice at any time using the button below.

14. Changes to this policy

We may update this policy when we add features, change processors, or adapt to legal requirements. We will post the updated policy here with a new “Last updated” date. For significant changes we will notify you by email or in-app message at least 14 days before the change takes effect.

15. Questions and complaints

Email privacy@anthora.co. We aim to respond to every query within 5 working days and resolve every formal request within 30 days. If you are not satisfied, you have the right to complain to your local supervisory authority (see section 8).

Terms of ServiceCookie PolicyImpressum