Privacy Policy.
Last updated: June 1, 2026
Anthracite is built around one principle: your data is yours, it lives on your device by default, and nothing leaves without your consent. This policy explains exactly what that means across every service we use.
What we collect on this website
When you sign up at anthracite.live/waitlist, we collect your email address, name, and preferred platform (iOS or Android). This data is stored in a Supabase PostgreSQL database. We use it to email you when the app is available on your platform and for occasional product updates. We do not share this list.
The website itself does not run analytics, behavioral tracking, fingerprinting, advertising pixels, or third-party scripts that observe your visit. Fonts are self-hosted. There are no tracking cookies.
What the Anthracite mobile app collects
Local data (stays on your device)
Anthracite stores your logged data in an encrypted SQLite database on your iPhone or Android device. This includes: habits definitions and completion logs, nutrition entries and nutrient breakdowns, financial transactions, workout records, water intake, meal plans, custom foods, day ratings, personal goals, and AI chat history. None of this local data is accessible to us unless you enable cloud sync.
Apple HealthKit
With your explicit permission, Anthracite reads Apple HealthKit data (sleep, workouts, heart rate, HRV, nutrition, steps, body metrics, and more). This data is used solely for on-device correlation computation. HealthKit data is never sent to our servers, never used for advertising or marketing, and never sold to third parties. You can revoke access anytime in iOS Settings.
Cloud sync (opt-in)
If you sign in and enable cloud sync, your data syncs to your private storage in Supabase. Data is encrypted in transit (TLS) and at rest. The following tables are synced: app_preferences, board_finance_categories, personalized_plans, my_foods, finance_table, activity_table, habits_rules, habits_logs, water_entries, nutrition_table, nutrition_entry_nutrients, meal_plan_entries, and meal_plan_entry_nutrients. Each contains the data you have logged in those categories. HealthKit data and local-only tables (day ratings, goals, assistant threads, correlation cache) are never synced to the cloud.
Cloud sync exists to let you restore data across devices and to keep your data safe if you lose your phone. You can disable it at any time in Settings, which stops new data from syncing but does not retroactively delete already-synced data. To delete synced data, delete your account (Settings, Account, Delete account).
Account authentication
You can use Anthracite without an account. If you choose to create one (for cloud sync), we support Sign in with Apple, Sign in with Google, and email/password authentication via Supabase Auth. We receive a unique user ID and, optionally, the name associated with your account. We use this only for authentication and subscription state. We do not use it for marketing.
Even without an account, Anthracite creates an anonymous Supabase session to enable basic functionality. This session contains no personal information.
Subscription state
Subscriptions are handled by Apple's App Store and managed by RevenueCat. We see whether you have an active subscription and when it expires. We do not see your payment method, billing address, or App Store purchase history.
External services (subprocessors)
| Service | Purpose | Data Received |
|---|---|---|
| Supabase | Database hosting, authentication, realtime sync | All synced tables, auth tokens, user IDs |
| Sentry (sentry.io) | Crash and error reporting | Stack traces, device model, OS version, app version, device UUID, IP-derived country |
| PostHog | Product analytics (currently dormant, no events ingested) | SDK configured but not receiving data |
| Cloudflare Workers | Food and exercise database API proxy | Search queries for foods and exercises |
| Cloudflare R2 | Exercise image hosting | Image requests (public bucket) |
| AI model provider | AI chat (Ludwik) via Supabase Edge Function | Chat prompts you send, per-category consent governs access to your logged data |
| RevenueCat | Subscription management | Subscription status, expiration date |
| Apple | In-app purchases and HealthKit | Subscription receipts, HealthKit permissions you grant |
Crash reporting
Anthracite uses Sentry (sentry_flutter SDK) for crash and error reporting. When a crash occurs, Sentry automatically captures: the error type and full stack trace, your device model and manufacturer, OS version, app version and build number, a unique device installation identifier, and IP-derived approximate location (country/city). We have configured Sentry to not collect personally identifiable information: sendDefaultPii is set to false, screenshots and view hierarchies are disabled, and a PII redaction pipeline strips emails, tokens, IP addresses, and phone numbers from all event data before transmission.
Crash reporting is enabled by default but can be disabled at any time in Settings. Additionally, crash reports are dual-written to our Supabase database for reliability. You can see the raw count of logged crashes on our landing page.
Analytics
PostHog is configured in the app for product analytics but is currently dormant: no analytics events have been ingested. The SDK is set to only create identified profiles (not anonymous), and session recordings are disabled. If we activate analytics in the future, we will update this policy before doing so and provide an opt-out toggle in Settings.
The website (anthracite.live) has no analytics, tracking, or third-party scripts of any kind.
AI Chat (Ludwik)
Anthracite includes an AI assistant called Ludwik. When you send a message, your prompt is sent to a Supabase Edge Function which forwards it to an AI model. Chat messages are stored in Supabase (chat_conversations, chat_messages, chat_token_usage tables) so you can review your conversation history.
Before Ludwik can access any of your logged data (nutrition, activity, habits, finance, health metrics), you must grant explicit, per-category consent via a consent dialog. You can manage these permissions at any time in Settings. The AI provider receives only the prompt you type and any data categories you have consented to share. Your data is never used to train the AI provider's models.
Data retention
- Waitlist signups: Stored until you unsubscribe or request deletion.
- Cloud-synced data: Stored for the life of your account. Deleted within 30 days of account deletion.
- Crash reports: Retained indefinitely for debugging. Aggregated and anonymized after 12 months.
- Chat history: Stored for the life of your account. Deleted on account deletion.
- Sentry events: Governed by Sentry's retention policy (90 days by default).
- Cloudflare logs: Workers logs are retained per Cloudflare's standard retention (typically 7 days).
What we never do
- We do not sell your data. There is no data-broker arrangement, no advertising network, no marketing list.
- We do not train machine-learning models on your data, ours or anyone else's. The correlation engine ships fixed.
- We do not use AI to coach you or decide what is good for you. AI assists at the edges (parsing, summarizing), never as an authority.
- We do not track you across other apps or websites (App Tracking Transparency: declined).
- We do not embed third-party SDKs that read your usage beyond what is disclosed above.
- Your HealthKit data never leaves your device. It is not synced to the cloud, not shared with AI providers, and not accessible to us.
Your rights
Access, correction, and deletion (GDPR, CCPA)
Because most data stays on your device, you already have direct access to it. You can export your data as JSON, CSV, Markdown, HTML, or Apple Health format from the app's Settings at any time. Deleting the app deletes all local data.
If you have an account, you can delete it from within the app (Settings, Account, Delete account). This removes all cloud-synced data and your authentication record. Chat history is deleted alongside your account.
EU and UK residents have the right to access, rectify, erase, restrict, and port their personal data under the GDPR. California residents have analogous rights under the CCPA. To exercise these rights for data stored on our servers, email privacy@anthracite.live. We respond within 30 days.
Do Not Sell or Share (CCPA)
We do not sell or share your personal information for cross-context behavioral advertising. There is nothing to opt out of.
Children's privacy
Anthracite is not directed at users under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, email privacy@anthracite.live and we will delete it.
International data transfers
Anthracite is based in the Dominican Republic. Cloud-synced data is stored in Supabase's servers (US region). Crash reports go to Sentry's US servers. Cloudflare Workers run on Cloudflare's global edge network. By using the cloud sync feature, you consent to your data being processed in these jurisdictions. We rely on standard contractual clauses and service provider agreements to protect your data.
Changes to this policy
If we make material changes, we will update the date above and, if you have an account, notify you in-app at least 30 days before the change takes effect.
Contact
Questions go to privacy@anthracite.live. We respond within 5 business days.