1Who we are, and what this covers
Anchor AI (“Anchor”, “we”, “us”) provides an AI customer support agent that answers questions from content its users have approved, cites its sources, and hands conversations to human teammates when it should. This policy explains what personal information we collect, why we collect it, who we share it with, and what you can do about it.
It covers:
- our website and marketing pages;
- the Anchor dashboard, where customers configure and run their support agent; and
- the Anchor chat widget, wherever a customer has embedded it on their own site.
It does not cover the practices of our customers on their own sites, or any third-party site the widget or a cited source happens to link to. Those are governed by their own policies.
2The two roles we play
Which parts of this policy apply to you depends on how you meet Anchor. There are two distinct relationships, and the distinction matters for your rights.
When you are our customer
If you sign up for an Anchor account, we are the data controller for your account information: we decide why and how it is processed, and this policy governs it end to end.
When you chat with a customer’s widget
If you talk to an Anchor-powered chat widget on some other company’s website, that company is the data controller and Anchor is their data processor. We handle your messages on their instructions, under our contract with them. Their privacy policy governs why your data was collected in the first place, and requests to access or delete it are best directed to them. We will help them answer you, and you can always contact us directly at info@anchorai.chat if you cannot reach them.
3Information we collect
Account and workspace information
- Identity and contact details — name, email address, password (stored hashed, never in plain text), and the name and logo of your workspace.
- Team information — the teammates you invite, their email addresses, roles, and team membership.
- Billing information — your plan, credit balance, top-up history, and invoices. Card details go directly to our payment processor and are never stored on Anchor’s systems.
Content you give the agent
- Knowledge sources — the documents, articles, and files you upload or connect so the agent can answer from them. Whatever personal information you choose to put in those sources, we process on your behalf.
- Configuration — playbooks, tone and behaviour settings, widget branding, and the escalation rules that decide when a conversation goes to a human.
Conversation data
- Messages — what an end user writes to the widget, what the agent replies, the sources it cited, and any messages your team adds after a handoff.
- Contact records — the name, email address, or other details an end user provides during a conversation, or that a customer passes to the widget about a signed-in visitor.
- Tickets and their history — status, assignment, and internal notes.
Technical and usage information
- Device and connection data — IP address, browser and device type, operating system, and language. IP address is also used coarsely to infer country for security and abuse prevention.
- Product usage — pages visited in the dashboard, features used, credits consumed, resolution and handoff rates, and timestamps. We use this to run and improve the service and to bill accurately.
- Logs — diagnostic records of errors and requests, kept for security and debugging.
4How we use it
We use personal information to:
- Run the service — authenticate you, generate answers, retrieve and cite the right sources, route conversations to your team, and send the notifications you have turned on.
- Bill you — meter credit usage, process payments and top-ups, issue invoices, and chase failed payments.
- Support you — respond when you write to us, and investigate problems you report.
- Keep the service safe — detect and prevent abuse, spam, fraud, and unauthorised access, and enforce our Terms of Service.
- Improve the service — understand which features are used and where the product fails, in aggregate. See AI models and your content for the specific limits we hold ourselves to here.
- Communicate with you — service and security notices (which you cannot opt out of while you hold an account), and product updates (which you can).
- Meet legal obligations — accounting, tax, and lawful requests from authorities.
We do not sell personal information, and we do not share it with third parties for their own advertising.
5Our legal basis for processing
Under the Data Protection Act, 2012 (Act 843) and, where it applies, the GDPR, we process personal data on these bases:
- Performance of a contract — everything required to deliver the service you signed up for and to bill you for it.
- Legitimate interests — securing the service, preventing abuse, understanding usage in aggregate, and communicating about the product. We balance these against your interests and rights before relying on them.
- Consent — for optional cookies, marketing email, and browser push notifications. You can withdraw consent at any time, and withdrawing it does not affect processing already carried out.
- Legal obligation — where the law requires us to keep or produce records.
Where Anchor acts as a processor for a customer, that customer is responsible for establishing the legal basis for the data they route through us.
6AI models and your content
Anchor generates answers using large language models, some of which are operated by third parties. Because this is the question customers ask us most, here is the commitment plainly:
- Your content is not used to train shared models. Neither we nor our model providers train general-purpose or shared models on your knowledge sources or your conversations.
- Your content is not shared between workspaces. An agent can only retrieve from the sources belonging to its own workspace.
- The agent answers from your approved sources. Content is sent to a model to be read and summarised in the moment, and the reply cites the source it came from.
- We use model providers with zero-retention or short-retention terms under contracts that prohibit training on the data we send.
Automated answers are not decisions with legal or similarly significant effects. A human on your team can review, correct, or take over any conversation, and the escalation rules you configure decide when that happens automatically.
7Sharing and sub-processors
We share personal information only with service providers who help us run Anchor, each under a contract that limits them to our instructions:
| Provider | Purpose | Data involved |
|---|---|---|
| Cloud hosting and database providers | Running the application and storing data | All service data |
| Large language model providers | Generating answers and summaries | Message content and retrieved source excerpts |
| Paystack | Payments, subscriptions, and top-ups | Billing contact details and payment data |
| OneSignal | Browser and push notifications | Device push token and notification content |
| Email delivery provider | Transactional email — verification, invites, resets | Name and email address |
We may also disclose information:
- To your workspace administrators — if you join a workspace, its admins can see your account details, activity, and the conversations you handle.
- When the law requires it — in response to a valid legal request. Where we are permitted to tell you, we will.
- In a business transfer — if Anchor is involved in a merger, acquisition, or sale of assets, subject to this policy continuing to apply.
8International transfers
Anchor operates from Ghana and uses providers located in other countries, including in the United States and the European Union. Running the service therefore involves transferring personal data across borders.
Where we transfer personal data out of Ghana, we do so in line with the Data Protection Act, 2012 (Act 843). Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on Standard Contractual Clauses or another approved transfer mechanism, together with the contractual and security measures described in this policy.
9How long we keep it
We keep personal information only as long as we need it for the purpose we collected it for.
- Account data — for as long as your account is open.
- Knowledge sources and conversations — until you delete them, or until your account is closed.
- After you close your account — we delete or anonymise your workspace data within 90 days, except where we are required to keep records for longer.
- Billing records — retained for the period required by Ghanaian tax and accounting law.
- Backups — deleted data persists in encrypted backups for a limited period before those backups roll over.
You can ask us to purge your content from our systems at any time by writing to info@anchorai.chat.
10How we protect it
- Data is encrypted in transit (TLS) and at rest.
- Access is role-based: teammates see only what their role in the workspace allows, and workspaces are isolated from each other.
- Internal access to production data is limited to staff who need it, and is logged.
- Passwords are stored hashed. We never see or store them in plain text.
- Card details never touch our systems — they go directly to our payment processor.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the Data Protection Commission as the law requires. You can help by using a strong, unique password and keeping your account credentials to yourself.
11Your rights
Under Act 843 you have the right to:
- Access the personal data we hold about you and know how it is being processed;
- Correct data that is inaccurate, misleading, or out of date;
- Delete data we no longer have a lawful reason to keep;
- Object to processing based on our legitimate interests, and to opt out of direct marketing at any time;
- Withdraw consent where we relied on it; and
- Complain to the Data Protection Commission of Ghana if you believe we have handled your data unlawfully.
If you are in the European Economic Area or the United Kingdom, you additionally have the right to data portability, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority. If you are a California resident, you have the right to know what we collect, to request deletion, and not to be discriminated against for exercising those rights — and we confirm that we do not sell or share personal information as those terms are defined under the CCPA.
Much of this you can do yourself from your dashboard settings. For anything else, write to info@anchorai.chat. We will respond within 30 days, and we may need to verify your identity first. If your data was collected by a company using Anchor’s widget, please see The two roles we play.
12Cookies and similar technologies
We use a small number of browser storage technologies:
- Strictly necessary — to keep you signed in, remember your workspace, and secure the session. The service does not work without these.
- Preferences — to remember interface choices such as a collapsed sidebar.
- Widget storage — the chat widget stores a conversation identifier on the end user’s device so a conversation survives a page reload.
- Analytics — to understand aggregate product usage.
You can clear or block browser storage in your browser settings, but doing so will sign you out and may break parts of the service. We do not use advertising or cross-site tracking cookies.
13Children
Anchor is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, write to info@anchorai.chat and we will delete it.
14Changes to this policy
We update this policy when the product or the law changes. The date at the top of the page always reflects the current version. If a change materially affects your rights, we will tell you by email or in the dashboard before it takes effect — we will not quietly widen what we do with your data and hope you notice the date.
15Contact us
For any question about this policy, to exercise your rights, or to raise a concern about how we handle your data:
- Email: info@anchorai.chat
- Anchor AI, Ghana
If we cannot resolve your concern, you may lodge a complaint with the Data Protection Commission of Ghana.