Privacy policy
Last updated: August 17, 2026
Anchor is built so that it does not need to know anything about you. There are no accounts and no analytics, and your browsing never leaves your device. This page explains exactly what the extension stores and where.
What Anchor does not do
- It does not collect, transmit, or sell any personal data.
- It does not track the pages you visit or your search history.
- It does not send images anywhere. The AI image filter is a local model that runs entirely on your device.
- It does not use analytics, telemetry, or advertising identifiers of any kind.
What stays on your device
The extension stores its working data in your browser's local extension storage: your settings, your commitment lock (period and state), your custom block and trust lists, the personal note you write to yourself, and anonymous local counters used for your own stats (such as blocked-page counts and streaks). Temporary image-check results are kept in session storage and discarded when the browser closes. All of this stays on your computer, and removing the extension deletes it.
One exception, if you also use the Windows app. The app keeps
its own record of your commitment — the end date and nothing about your
browsing — outside the browser, so that removing the extension or clearing
your browser data cannot end a commitment early. That record lives in
C:\ProgramData\Anchor and is removed when you uninstall the app,
which you can only do once the commitment has finished. See
“The Windows app” below.
Network requests the extension makes
- Filtering: blocking rules, safe-search enforcement, and image checks run locally. Checking an image means your browser loads that image — the same request the page itself makes; nothing is sent to us.
- Payments (optional Pro upgrade): if you choose to upgrade, checkout is handled by Stripe on stripe.com — payment details go to Stripe, never to Anchor. After payment, our activation service issues you a random license key; we store that key, the Stripe payment reference needed to validate it, and a masked version of the billing email — for example
l••••••@gmail.com— so the extension can remind you which address opens the Stripe billing portal when you want to cancel. The full address is never stored on our side; only the masked form is. We store no names. The extension contacts our server only to check that a key you enter is genuine. - Unlock-code delivery (optional): when you start a commitment and choose email delivery of the one-time unlock code, the email address you enter and the code are sent to our server, which passes them to our email provider (Resend) solely to deliver that one message. We do not store the address or the code on our server, and they are never used for anything else. If you'd rather share nothing at all, choose the memorable-sentence option, the manual draft, or hard mode — a sentence you make up is hashed and kept on your own device, and never reaches us in any form.
Permissions, plainly
Anchor asks for broad site access because its job is to filter every page: it needs to block adult sites, enforce safe search, and blur explicit images wherever they appear. That access is used for filtering only — never for collecting or transmitting your browsing.
The Windows app
Everything above describes the browser extension. Anchor for Windows is a separate, optional download, and it does more to your computer than an extension can — so it is described separately here. Installing it shows you a licence agreement covering all of this before anything is changed.
- It changes this computer's DNS settings so name lookups pass through a filter running locally on your own machine. That filter is checked against a list of about 25,000 domains held on your computer. It counts how many lookups it refused; it does not record which sites those were, and no lookup is ever sent to us.
- It runs a background service as the Windows SYSTEM account, started by a scheduled task, plus a second task that checks once a minute whether the filter is alive and restores your normal DNS settings if it is not — so a crash cannot leave you without internet.
- It writes Windows enterprise policy to install the Anchor extension into Chrome, Edge, Brave, Vivaldi and Chromium and hold it there, and to switch off DNS-over-HTTPS, which would otherwise bypass the filter.
- It reads the Anchor extension's own saved data from your browser profiles. This is how the app knows you have started a commitment. It opens only the folder holding Anchor's extension data — never your history, bookmarks, saved passwords, cookies, or any other extension — and takes only four numbers from it: when a commitment ends, when it began, the date of your first commitment, and the total time you have spent under finished commitments. To find those numbers it loads that storage file into memory and searches it; anything else in the file is discarded unread. None of it is written down or sent anywhere. This read is local, and happens roughly every ten seconds while the computer is on.
- Your commitment is held by the app independently. Once the app has seen a commitment it keeps its own copy of the end date, so removing the extension, clearing your browser data, switching profiles or uninstalling the browser does not end it. This is the point of a commitment, and the licence agreement says so before you install.
- It sends us nothing about your browsing. The app contacts our server only to check a Pro licence key, exactly as the extension does. It has no analytics and no telemetry.
Uninstalling the app reverses the changes above: your DNS settings are returned
to what they were and only the registry values Anchor wrote are removed. Its own
data folder, which holds your settings and commitment record, is on your computer
at C:\ProgramData\Anchor.
Who controls this data, and your rights
Anchor is operated by Levi Scheiner, a sole trader based in London, United Kingdom, trading as Anchor — the data controller for the small amount of data described above, under UK and EU data protection law.
- What is held, and why: a licence key, the Stripe payment reference needed to validate it, and a masked billing email. The lawful basis is performance of a contract — without these we cannot verify a purchase or tell you which address opens the billing portal.
- How long, precisely:
- Licence records — while the licence is valid, then deleted within 30 days of it lapsing or of you asking.
- Payment records (the Stripe reference and masked email) — six years from the end of the relevant tax year, because UK tax law requires us to keep them. We cannot delete these earlier, even on request; this is the "legal obligation" exception to erasure.
- Support emails — 12 months, then deleted.
- Error reports — 30 days, then deleted automatically.
- Rate-limiting records (an IP address, to stop abuse of the email endpoints) — one hour, then they expire on their own.
- Your rights: you may ask for a copy of what is held about you, or ask for it to be corrected, deleted, restricted, or provided in a portable form, and you may object to how it is used. We action deletion requests within 30 days, except for the payment records above, which we are legally required to keep. Email [email protected] and we will respond within one month. Deleting a licence record ends Pro access on that key.
- Who processes it: Stripe (payments), Resend (the single unlock-code email) and Cloudflare (hosting), each acting on our instructions only.
- Complaints: in the UK, the Information Commissioner's Office at ico.org.uk; in the EU, your national supervisory authority.
Children
Anchor is a self-control tool intended for adults. You must be 18 or over to buy Anchor Pro. Anchor does not knowingly collect information from anyone, including children, and holds no accounts or profiles of any kind.
Changes
If this policy changes, the new version will be posted at this address with an updated date above.
Contact
Questions about privacy: [email protected]