Anchor Privacy Policy
Last updated: August 18, 2026
This Privacy Policy applies to Anchor, the status tracking app for iOS and Android published by Aruna Law Firm. It describes what Anchor stores, where it is held, who can read it, and what leaves our systems.
This policy covers the Anchor app only. This website and the Vigil compliance platform are covered by the Aruna Software Privacy Policy, and legal services by the Aruna Law Firm Privacy Policy. The terms on which Anchor may be used are in the Anchor Terms and Conditions.
1. Who we are
Anchor is provided by Aruna Law Firm. You can reach us at arunalawfirm@gmail.com.
Anchor is a status tracking tool, not legal advice. It reads dates off documents you give it and tells you when those dates are approaching. It does not interpret your immigration case.
2. What we collect
Everything below is either provided by you or derived from what you provide. Anchor carries no advertising, no analytics software, and no third party trackers.
Account
- Email address, to sign you in and identify your account.
- Password, for authentication. It is stored only as a hash by our authentication provider. Aruna Law Firm never sees it.
- Visa category (H-1B or F-1/OPT), which decides which rules, which document checklist, and which updates apply to you.
- Name, optional, shown back to you in the app.
Documents you upload
Immigration documents, for example an I-797 approval notice, an I-20, an EAD card, an I-94 record, a passport visa page, an LCA, an I-129, an I-983, or pay stubs. These commonly contain passport numbers, receipt numbers, SEVIS identifiers, employer names, and dates of status.
We store the file itself, and the fields read from it once you have confirmed them.
Derived from your documents
- Key dates, timeline entries, attention flags, and employment periods, all computed from the fields you confirmed.
Device and usage
- Your notification preferences.
- A push notification token, if you enable reminders and are running a build that supports push delivery.
- Nothing else. No location, no contacts, and no advertising identifiers.
3. What we do not collect
- No advertising identifiers, and no advertising.
- No analytics or behavioural tracking.
- No location data.
- No contacts, calendar, or microphone access.
- Camera and photo library access is used only to let you supply a document, and only at the moment you choose one.
4. Who your data is shared with
Document reading (Anthropic)
This is the one place the content of your documents leaves our infrastructure. When you upload a document, its contents are sent to Anthropic to be read, as images or as a PDF. The named fields for that document type are extracted and returned. It is used to read your document, never to interpret your case.
We use a paid application programming interface tier. Content submitted through it is not used to train models.
Hosting (Supabase)
Your account, your documents, and the data derived from them are stored in a Supabase project, using managed Postgres and object storage. Supabase is our hosting provider and processes this data on our behalf.
Push notifications (Expo)
If reminders are enabled, a push token is registered with Expo so a notification can reach your device. The notification text contains a date label and a day count.
Nobody else
We do not sell your data. We do not share it with advertisers, data brokers, or other users. Scoped sharing with a lawyer is not currently available in the app. If it is introduced, this policy will be updated before it ships.
5. Where your data lives
In our Supabase project, in the region configured for that project. Documents are held in a private storage bucket. Access is by short lived signed link only, generated when you open a document and expiring within minutes.
6. Who can see your data
- You. Row level security is enabled on every table and scoped to your own user identifier, enforced by the database rather than by application code.
- Aruna Law Firm, only where necessary to operate or support the service.
- Derived tables (dates, timeline, flags) are read only to the app and are written only by our own server side functions.
Anchor keeps a local cache on your device so it works offline. That cache holds only what a screen already displays: dates, labels, and document names. It never holds document contents or access links, and it is erased when you sign out. Beyond your device encryption and the operating system app sandbox, it is not separately encrypted.
7. How long we keep it
For as long as your account exists. If you delete your account, see the next section.
8. Deleting your account
You can delete your account in the app: You, then Delete account and documents.
Deletion is a request with a 30 day grace period. Nothing is removed immediately, and you can cancel at any point during those 30 days from the same screen. After 30 days your profile, uploaded documents, extracted fields, key dates, timeline, flags, employment history, preferences, and notification tokens are permanently deleted. We keep no copy and it cannot be recovered.
You can also request deletion without the app installed, and without signing in, at arunalaw.com/anchor/delete-account. The request must come from the email address on your account, which is how we know it is yours. We will confirm it, and the same 30 day grace period applies.
Two things are not removed with your account. Records of payments are retained by Stripe, our payment processor, which is required to keep them for tax and financial recordkeeping. And if you are also a client of Aruna Law Firm, your legal file is separate from your app account and is kept under the rules that apply to client records.
9. Getting a copy of your data
In the app, You, then Export everything, produces a single JSON file containing every record we hold that you can read: your profile, your documents and their fields, key dates, timeline, flags, employment, preferences, saved updates, and reminders sent.
Document files are not included in that export. They are listed with their storage paths, and each can be opened individually from the app.
10. Children
Anchor is not directed at children and is not intended for anyone under 18.
11. Changes
If this policy changes materially, we will update it here and change the date at the top.