Legal

Anby App Privacy Policy

Last updated: August 27, 2026

This policy covers the Anby app — the daily work check-in companion at app.anby.ai and the Anby apps for iOS and Android. Anby is built around one rule: your data is yours. You score your own days, you compare only with yourself, and nobody else — not a manager, not your organization — gets a view of it. This page lists exactly what we collect and why, in plain language.

1. What we collect

  • Account information— your name and email address, received when you sign in with Apple or Google. You don't create a password with us: authentication is handled by Apple or Google. The one exception is a small number of accounts we issue by hand (an app store review account, for instance), which sign in with an email and a password we set; for those we store a salted scrypt hash, never the password itself. If your Google account has a profile photo, we store its URL to show your avatar.
  • Content you create — your personal performance picture (the things you chose to measure), daily check-in scores and notes, journal entries, your answers in the onboarding story, messages you write in the coaching chat, and feedback you send us.
  • Sources you connect — each one optional, read-only, and connected only when you explicitly choose to. See the next section.
  • Usage analytics — interaction events (which screen was opened, which button was tapped) with counts and flags only. Analytics events never contain your scores, your notes, or any content you wrote.

2. Google Calendar — the one source you can connect, optional and read-only

Anby can assemble your day from your calendar, so checking in takes a moment instead of a form. This is the only external source the app reads, it is off until you choose to connect it when signing in, and it is read-only:

  • Google Calendar (scope calendar.readonly) — we read your day's events (titles, times, attendees' presence) to build your daily context. We never create, edit, or delete events, and we never read calendars you didn't grant.

The OAuth refresh token is stored encrypted (AES-256-GCM). You can revoke Anby's access at any time from your Google Account permissions, which cuts the connection immediately.

Limited Use. Anby's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not let humans read it (except with your explicit consent, for security, or where required by law), and do not use it to train AI models.

3. AI features

Exactly two features send content to a large language model (currently OpenAI), and both run only when you tap them:

  • The day summary— one sentence summarizing your day's context, generated when you ask for it.
  • The coaching chat— a reflective conversation that uses what you've told it in that conversation.

Content sent for these features is used solely to generate your response. Our AI provider is contractually barred from using it to train its models. Opening the app, checking in, and viewing your trends involve no AI processing at all.

4. What we never do

  • No manager or organization dashboards — only you can see your scores, notes, and journal.
  • No comparing you with other people, in the product or in any report.
  • No advertising, no tracking across other apps or websites, no selling or sharing data with data brokers.
  • No training AI models on your content.
  • No reading more than we asked for — every connected source is read-only.

5. Retention and deletion

  • Start over in-app— the "start over" action inside Anby permanently deletes your performance picture, every day's scores and notes, your story answers, and your coaching conversations. Your account and calendar connection remain.
  • Disconnect your calendar — revoke Anby from your Google Account permissions (or ask us at privacy@anby.ai) and the stored token stops working immediately; we delete it on request.
  • Delete your account — email privacy@anby.aiand we'll permanently delete your account and all associated data within 30 days.

6. Security

  • All data in transit is encrypted via TLS.
  • Data is stored in managed, encrypted-at-rest infrastructure (Vercel, Neon Postgres).
  • Source tokens are additionally encrypted at the application layer (AES-256-GCM).
  • Security reports: security@anby.ai.

7. Your rights

Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of your personal data. Write to privacy@anby.aiand we'll respond within 30 days.

8. Children's privacy

Anby is not directed to children under 16 and we do not knowingly collect personal data from children. If you believe we have, contact us and we'll delete it.

9. Changes to this policy

If we add a new category of data or a new sub-processor, we'll update this page and announce material changes in the app before they take effect. The "Last updated" date above reflects the most recent revision.

Questions?

Write to privacy@anby.ai. This policy covers the Anby check-in app; the platform-wide policy (including Anby Meeting) lives at anby.ai/privacy.