Privacy Policy

This policy describes what personal data Ankaa processes, on what legal basis, with which service providers, and what rights you have as a data subject.

Version: 29 July 2026 · Provider: Maximilian Krewer, Hamburg

1Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Maximilian Krewer
Hamburg, Germany · full postal address see Imprint

Email: [email protected]
Data protection contact: [email protected]

A data protection officer has not been appointed and is, by current assessment, not legally required (no case under Art. 37 GDPR / § 38 BDSG).

2Overview of processing

Ankaa is a personal life system (app and wall display): routines, health and habit tracking, habit reduction, an AI coach, financial overview, calendar, and optional smart home control. To provide these functions we process the data described below. The app is designed so that each user account is technically isolated from other accounts, and hosting is targeted at the EU.

4Categories of data processed

  • Master data / account: email address, password (encrypted/hashed), account and subscription status.
  • Usage data: completed routines, daily goals, notes entered, app settings, device/sync status.
  • Health & habit data (sensitive): habit/reduction tracking, self-reported complaints (e.g. back pain), optionally recovery values (sleep, resting heart rate, HRV) from a connected smartwatch/health source.
  • Financial data (if used): budget/portfolio information you enter yourself. This is for your personal overview only and does not constitute investment advice.
  • Calendar & smart home data (optional): when actively connected: appointments and control commands/status of connected devices.
  • AI coach content: your chat/voice inputs to the coach and the relevant context. As long as the AI integration is not switched on, these inputs stay in your account and go to no AI service provider.
  • Error and crash data: time, error message, app version, device type and the technical path to the error. Free text, email addresses, identifiers and content from the health and finance areas are stripped before sending.
  • Product events (consent only): a pseudonymous user ID and a short, fixed list of events such as "app opened" or "routine completed". No content, no health or finance data. Switchable off in the app settings at any time.
  • Communication & waitlist data: email and information you provide when making enquiries or signing up to the waitlist.
  • Technical data: IP address, timestamps, technical logs (e.g. for attack prevention), shortened/aggregated where possible.
  • Payment data: collected by the payment service provider; we typically receive only transaction/subscription status, not full payment instrument details.

5Purposes of processing

  • Providing, personalising, and synchronising the app across your devices.
  • Operating the AI coach (generating responses, suggesting routines/appointments, executing actions with your confirmation).
  • Health, habit, and financial overview within the modules you have chosen.
  • Processing subscriptions/purchases and fulfilling legal obligations.
  • Security, stability, abuse prevention, and bug fixing.
  • Communication (support, service emails, optionally waitlist).
  • Where carried out at all: statistical analysis exclusively on an aggregated, anonymised basis - no sale of personal data.

6Services used & recipients (processors)

To provide Ankaa we use carefully selected service providers with whom data processing agreements under Art. 28 GDPR exist or are to be concluded. The Status column separates services that actually process data in the app today from services that are technically prepared but not yet active. A prepared service only receives data once the corresponding feature is switched on and this policy has been updated accordingly.

ServicePurposeData typesNote
Cloudflare (Workers, Pages, KV, Vectorize)
active
Hosting, delivery, edge storage, securityTechnical data, stored app dataEU/edge processing; data processing agreement in place
Supabase (Auth & database)
active
Accounts/login, isolated storage of user dataAccount, usage, and sensitive app dataSelect EU region; account isolation via Row-Level-Security
Sentry (error and crash reports)
active
Stability, debuggingCrash and diagnostic data, technical dataRuns only when an error occurs; email addresses, identifiers and content from the health and finance areas are stripped before sending; no advertising
PostHog (product analytics)
active, consent only
Understanding which features are usedPseudonymous user ID, a few product events (e.g. "routine started")Only after explicit consent in the app settings, switchable off there at any time; EU hosting (eu.i.posthog.com); no content, no health or finance data
Stripe (payment processing)
active once you start a purchase
Subscription/purchase handling, invoicingPayment/invoice data, subscription statusYou enter payment details directly with the provider; we receive transaction and subscription status. Paddle remains connected as a second route during the transition.
Email/delivery service
active (storage)
Service and waitlist emailsEmail addressCloudflare (stores the waitlist email); a separate delivery service is not yet finalised and will be added before the first mailing
AI provider (AI coach)
prepared, not yet active
Generating coach responsesYour coach inputs + relevant contextThe coach in the app currently passes no input to an AI provider. Before it is switched on we will name the providers actually used here, together with their processing location.
OpenAI (speech output)
prepared, not yet active
Reading texts aloud (text to speech)The text to be read aloudImplemented on the server, not reachable from the app yet; third country (see below)
Google (optional: calendar, speech-to-text)
prepared, not yet active
Calendar integration, optional dictation featureAppointments, voice/audio data from dictationOnly when actively connected/consented; may involve third-country transfer

Data is only disclosed to authorities where legally required. We do not sell personal data and do not share it with third parties for advertising purposes.

7Transfers to third countries

Where service providers process data outside the EU/EEA (e.g. in the United States), this only occurs on the basis of appropriate safeguards under Art. 44 et seq. GDPR - in particular EU Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework, plus supplementary protective measures. We aim to process data primarily within the EU and to minimise third-country transfers.

  • Processed in the EU: Supabase (EU region), PostHog (EU host eu.i.posthog.com).
  • Edge processing with an EU focus: Cloudflare (delivery and storage happen as close to your location as possible; configuration is aimed at the EU).
  • Third country possible, with safeguards: Sentry (crash reports) and Stripe (payments), based on the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
  • Not yet active: AI coach, speech output and the Google integrations. Before they are switched on we will add the provider, the processing location and the legal basis for the transfer here.

8Retention & deletion

  • App and usage data are retained for as long as your account exists and deleted within a reasonable period after account deletion (suggestion: no later than 30 days after a deletion request, minus data subject to statutory retention obligations).
  • Invoice/payment data is retained within the applicable statutory retention periods (commercial/tax law, generally up to 10 years).
  • Waitlist/newsletter data is processed until withdrawal or the purpose ceases to apply.
  • Technical logs are deleted or anonymised promptly.

9Security of processing

We implement technical and organisational measures in accordance with Art. 32 GDPR: encrypted transmission (HTTPS/TLS), account isolation at database level (Row-Level-Security), access controls, and regular review of the services used. Despite all due care, complete security cannot be guaranteed; please protect your login credentials.

10Your rights as a data subject

Under the GDPR you have, in particular, the following rights:

  • Access (Art. 15) to the data processed about you.
  • Rectification (Art. 16) of inaccurate data.
  • Erasure (Art. 17) - the "right to be forgotten".
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20) in a common, machine-readable format.
  • Objection (Art. 21) to processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3)) with effect for the future.

To exercise your rights, simply send a message to [email protected]. You can also initiate account deletion in the app settings; every step, and what exactly is removed, is described on the delete account and data page.

11Right to lodge a complaint with a supervisory authority

Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. In Germany, the competent authority is generally that of the federal state in which the controller is based: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (Hamburg Commissioner for Data Protection and Freedom of Information), Ludwig-Erhard-Str. 22, 20459 Hamburg.

12Changes to this policy

We update this privacy policy when the processing or the legal framework changes. The version published here at any given time applies. Version date: 29 July 2026.