Privacy Policy.

Anthracite is built around one principle: your data is yours, it lives on your device by default, and nothing leaves without your consent. This policy explains exactly what that means across every service we use.

What we collect on this website

When you sign up at anthracite.live/waitlist, we collect your email address, name, and preferred platform (iOS or Android). This data is stored in a Supabase PostgreSQL database. We use it to email you when the app is available on your platform and for occasional product updates. We do not share this list.

The website itself does not run analytics, behavioral tracking, fingerprinting, advertising pixels, or third-party scripts that observe your visit. Fonts are self-hosted. There are no tracking cookies.

What the Anthracite mobile app collects

Local data (stays on your device)

Anthracite stores your logged data in an encrypted SQLite database on your iPhone or Android device. This includes: habits definitions and completion logs, nutrition entries and nutrient breakdowns, financial transactions, workout records, water intake, meal plans, custom foods, day ratings, personal goals, and AI chat history. None of this local data is accessible to us unless you enable cloud sync.

Apple HealthKit

With your explicit permission, Anthracite reads Apple HealthKit data (sleep, workouts, heart rate, HRV, nutrition, steps, body metrics, and more). This data is used solely for on-device correlation computation. HealthKit data is never sent to our servers, never used for advertising or marketing, and never sold to third parties. You can revoke access anytime in iOS Settings.

Cloud sync (opt-in)

If you sign in and enable cloud sync, your data syncs to your private storage in Supabase. Data is encrypted in transit (TLS) and at rest. The following tables are synced: app_preferences, board_finance_categories, personalized_plans, my_foods, finance_table, activity_table, habits_rules, habits_logs, water_entries, nutrition_table, nutrition_entry_nutrients, meal_plan_entries, and meal_plan_entry_nutrients. Each contains the data you have logged in those categories. HealthKit data and local-only tables (day ratings, goals, assistant threads, correlation cache) are never synced to the cloud.

Cloud sync exists to let you restore data across devices and to keep your data safe if you lose your phone. You can disable it at any time in Settings, which stops new data from syncing but does not retroactively delete already-synced data. To delete synced data, delete your account (Settings, Account, Delete account).

Account authentication

You can use Anthracite without an account. If you choose to create one (for cloud sync), we support Sign in with Apple, Sign in with Google, and email/password authentication via Supabase Auth. We receive a unique user ID and, optionally, the name associated with your account. We use this only for authentication and subscription state. We do not use it for marketing.

Even without an account, Anthracite creates an anonymous Supabase session to enable basic functionality. This session contains no personal information.

Subscription state

Subscriptions are handled by Apple's App Store and managed by RevenueCat. We see whether you have an active subscription and when it expires. We do not see your payment method, billing address, or App Store purchase history.

External services (subprocessors)

ServicePurposeData Received
SupabaseDatabase hosting, authentication, realtime syncAll synced tables, auth tokens, user IDs
Sentry (sentry.io)Crash and error reportingStack traces, device model, OS version, app version, device UUID, IP-derived country
PostHogProduct analytics (currently dormant, no events ingested)SDK configured but not receiving data
Cloudflare WorkersFood and exercise database API proxySearch queries for foods and exercises
Cloudflare R2Exercise image hostingImage requests (public bucket)
AI model providerAI chat (Ludwik) via Supabase Edge FunctionChat prompts you send, per-category consent governs access to your logged data
RevenueCatSubscription managementSubscription status, expiration date
AppleIn-app purchases and HealthKitSubscription receipts, HealthKit permissions you grant

Crash reporting

Anthracite uses Sentry (sentry_flutter SDK) for crash and error reporting. When a crash occurs, Sentry automatically captures: the error type and full stack trace, your device model and manufacturer, OS version, app version and build number, a unique device installation identifier, and IP-derived approximate location (country/city). We have configured Sentry to not collect personally identifiable information: sendDefaultPii is set to false, screenshots and view hierarchies are disabled, and a PII redaction pipeline strips emails, tokens, IP addresses, and phone numbers from all event data before transmission.

Crash reporting is enabled by default but can be disabled at any time in Settings. Additionally, crash reports are dual-written to our Supabase database for reliability. You can see the raw count of logged crashes on our landing page.

Analytics

PostHog is configured in the app for product analytics but is currently dormant: no analytics events have been ingested. The SDK is set to only create identified profiles (not anonymous), and session recordings are disabled. If we activate analytics in the future, we will update this policy before doing so and provide an opt-out toggle in Settings.

The website (anthracite.live) has no analytics, tracking, or third-party scripts of any kind.

AI Chat (Ludwik)

Anthracite includes an AI assistant called Ludwik. When you send a message, your prompt is sent to a Supabase Edge Function which forwards it to an AI model. Chat messages are stored in Supabase (chat_conversations, chat_messages, chat_token_usage tables) so you can review your conversation history.

Before Ludwik can access any of your logged data (nutrition, activity, habits, finance, health metrics), you must grant explicit, per-category consent via a consent dialog. You can manage these permissions at any time in Settings. The AI provider receives only the prompt you type and any data categories you have consented to share. Your data is never used to train the AI provider's models.

Data retention

  • Waitlist signups: Stored until you unsubscribe or request deletion.
  • Cloud-synced data: Stored for the life of your account. Deleted within 30 days of account deletion.
  • Crash reports: Retained indefinitely for debugging. Aggregated and anonymized after 12 months.
  • Chat history: Stored for the life of your account. Deleted on account deletion.
  • Sentry events: Governed by Sentry's retention policy (90 days by default).
  • Cloudflare logs: Workers logs are retained per Cloudflare's standard retention (typically 7 days).

What we never do

  • We do not sell your data. There is no data-broker arrangement, no advertising network, no marketing list.
  • We do not train machine-learning models on your data, ours or anyone else's. The correlation engine ships fixed.
  • We do not use AI to coach you or decide what is good for you. AI assists at the edges (parsing, summarizing), never as an authority.
  • We do not track you across other apps or websites (App Tracking Transparency: declined).
  • We do not embed third-party SDKs that read your usage beyond what is disclosed above.
  • Your HealthKit data never leaves your device. It is not synced to the cloud, not shared with AI providers, and not accessible to us.

Your rights

Access, correction, and deletion (GDPR, CCPA)

Because most data stays on your device, you already have direct access to it. You can export your data as JSON, CSV, Markdown, HTML, or Apple Health format from the app's Settings at any time. Deleting the app deletes all local data.

If you have an account, you can delete it from within the app (Settings, Account, Delete account). This removes all cloud-synced data and your authentication record. Chat history is deleted alongside your account.

EU and UK residents have the right to access, rectify, erase, restrict, and port their personal data under the GDPR. California residents have analogous rights under the CCPA. To exercise these rights for data stored on our servers, email privacy@anthracite.live. We respond within 30 days.

Do Not Sell or Share (CCPA)

We do not sell or share your personal information for cross-context behavioral advertising. There is nothing to opt out of.

Children's privacy

Anthracite is not directed at users under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, email privacy@anthracite.live and we will delete it.

International data transfers

Anthracite is based in the Dominican Republic. Cloud-synced data is stored in Supabase's servers (US region). Crash reports go to Sentry's US servers. Cloudflare Workers run on Cloudflare's global edge network. By using the cloud sync feature, you consent to your data being processed in these jurisdictions. We rely on standard contractual clauses and service provider agreements to protect your data.

Changes to this policy

If we make material changes, we will update the date above and, if you have an account, notify you in-app at least 30 days before the change takes effect.

Contact

Questions go to privacy@anthracite.live. We respond within 5 business days.