Expected mid-August 2026For iPhoneNo subscription

Privacy policy

Collect less. Explain the rest.

Core use of Anchor does not require an Anchor account. Most app data stays on your device; this policy explains the limited situations in which information leaves it.

Effective August 11, 2026 · Applies worldwide to the Anchor iOS and Android apps, website, orders, and support

Core app use

No Anchor account

Pairing, modes, selected apps and websites, schedules, and focus history are designed to remain on your device except for the limited iCloud backup described below.

Our commitments

No ads or data sales

We do not sell personal information, run targeted advertising, or use your app selections, DNS requests, or focus history to build an advertising profile.

1. Scope and who is responsible

BNS Development Inc. (“BNS,” “Anchor,” “we,” “us,” or “our”) is an Alberta corporation and is responsible for personal information under our control. This policy applies when you use an Anchor mobile app or our website, buy or receive an Anchor, communicate with us, or make a privacy request.

The app may be downloaded worldwide. The online store is not currently accepting orders. App-store operators, operating-system providers, communications providers, and other services may also process information for their own purposes under their own privacy notices when you use them.

This policy does not create an Anchor user account and a website purchase is not automatically linked to use of the mobile app. A purchaser may be buying a gift or a multi-pack for other people.

2. Information you provide to us

  • Launch notifications: your email address, subscription status, consent record, and related delivery information when you ask to hear when Anchor becomes available.
  • Orders and delivery: your name, email address, telephone number when provided, billing and delivery addresses, purchased items, order value, discounts, taxes, delivery details, and order, return, or warranty status.
  • Payments: Shopify and its payment providers collect and process payment credentials. We receive the transaction details and payment status needed to administer the order, but not your complete payment-card number.
  • Support and claims: your contact details, order or receipt information, device and operating-system details, messages, photographs, videos, diagnostic details, and anything else you choose to send.
  • Privacy requests: your request, contact information, our correspondence, and information reasonably needed to verify identity and respond.

We use a launch-notification address only for the Anchor availability and launch emails described beside the signup form. Buying or downloading Anchor does not, by itself, subscribe you to general marketing. Optional marketing requires separate consent where required, and every marketing email includes a way to unsubscribe.

3. Information used by the mobile apps

Anchor generates or accesses information needed to pair the physical Anchor, configure restrictions, run focus and Feet First sessions, display statistics, recover from interruptions, and honour your settings. Depending on the platform and the features you use, this may include a random local installation identifier, paired-tag identifier and verification information, mode names and settings, selected apps or app categories, selected website domains, active-session state, completed focus history and statistics, alarm schedules, chosen or imported sounds, appearance settings, and permission status.

Except for the iCloud backup and limited analytics described in this policy, this operational app information is designed to be stored and processed on your device. We do not operate a server that receives your paired-tag identifier, local installation identifier, selected apps or domains, custom mode names, active restrictions, imported sounds, or focus history.

iPhone

Anchor uses Apple's Family Controls and Screen Time frameworks to let you choose and shield apps, categories, and websites. The app and its Screen Time extensions store Apple-provided opaque selection tokens in Anchor's private app-group storage. BNS does not receive the content of your messages, browsing content, photos, contacts, or the contents of shielded apps. Apple controls permission for Family Controls, NFC, Notifications, and Alarm features.

Private iCloud backup on Apple devices

When the iCloud backup feature is available in the version you use and you are signed into iCloud, Anchor stores a backup in a private CloudKit database associated with your Apple account. The backup may contain inactive mode names and settings, completed focus sessions, Feet First schedule and completion information, onboarding status, appearance and strict-mode preferences, analytics preference, and remaining emergency-access count. It excludes the paired Anchor identifier, active sessions, selected apps, app categories, website domains and their opaque Screen Time tokens, and imported custom sounds. BNS does not receive your Apple ID or iCloud email address. Apple processes this backup as the iCloud provider.

Android

  • Installed-app access: Anchor reads the package names and labels of launchable apps so you can choose which apps to block. Your selections remain on the device.
  • Accessibility:if you enable Anchor's Accessibility service, it reads the package name of the app currently in the foreground so it can enforce the block you configured. It does not read screen text or content, capture screenshots, record taps or keystrokes, or perform actions on your behalf.
  • Usage Access: if enabled, Anchor reads on-device app-usage events and times to support enforcement fallback, permission status, and aggregate usage insights. It processes and stores those results locally.
  • Local VPN and DNS filtering: during a focus session that includes website restrictions, Anchor creates an on-device VPN interface to inspect requested domain names, compare them with your local block list, and block matches. Unblocked DNS requests are forwarded to the DNS resolver configured by your device or current network. Anchor does not send DNS requests to a BNS server, route general internet traffic through a BNS remote VPN, inspect page content, or retain a browsing history.
  • Device operation: Anchor may use NFC, notifications, exact alarms, full-screen alarm notices, foreground services, boot and time-change events, vibration, wake lock, network status, and battery-optimization status to provide pairing, restriction, recovery, and Feet First features.

Android operating-system cloud backup is disabled for the Anchor app. Android device manufacturers and Google may still process app installation, permissions, and store activity under their own policies.

4. Privacy-friendly analytics

When Aptabase is configured in the distributed app or website, we use it to understand broad product use and improve Anchor. App events are limited to app opening, setup completion, an Anchor being activated or seen during a day, and the start or end of a focus or Feet First session, with restricted trigger or completion-reason labels. Website events may include viewing or choosing a package, opening an FAQ, checking product availability, beginning checkout, or submitting the launch notification form. The email address entered in that form is not sent to Aptabase.

Aptabase events include an event time, a temporary session identifier, event name and permitted event properties, locale, operating system and version, app version and build, SDK version, debug status, and, on supported SDKs, device model. Like any internet service, Aptabase receives the source IP address and request information. Aptabase states that it creates a per-app daily identifier by hashing the IP address and user agent with an app-specific salt that is discarded every 24 hours. This is designed to prevent identification or correlation across days and apps, but applicable law may still treat some of this technical information as personal information.

Our event schemas do not intentionally send names, email addresses, account identifiers, the local installation or paired-tag identifier, advertising identifiers, selected app or domain lists, custom mode names, imported sounds, message or app content, payment information, or precise location. We do not use Aptabase for advertising or cross-app tracking.

Analytics is enabled by default in the mobile apps and can be disabled at any time under Settings → Anonymous Analytics. Disabling it prevents future Anchor analytics events from being sent from that app installation. Aptabase processes Anchor analytics in Virginia, United States, and states that it retains app analytics for up to five years. Because the events are not tied to an Anchor account and the daily identifier rotates, BNS and Aptabase generally cannot identify and isolate a particular person's historical events for access or deletion.

Read the Aptabase privacy policy .

5. Website, notifications, checkout, and support information

Our website is hosted and delivered using Vercel. The host and security services may process standard request and security information such as IP address, browser and device type, requested URL, referring page when supplied, timestamps, network and error data, and signals used to prevent abuse and keep the website available.

Launch-notification signup is provided by Buttondown. When you submit the form, Buttondown processes your email address, subscription and consent status, message-delivery activity, and standard request information needed to provide and secure the service. Buttondown provides confirmation and unsubscribe controls under its own privacy notice .

Email providers and communications services process the information needed to deliver launch, support, order, return, warranty, and privacy-request messages. When orders are open, delivery carriers receive the contact, address, shipment, and customs information needed to deliver and administer an order.

The Anchor website does not currently use advertising pixels, cross-site behavioural advertising, session-replay tools, or a separate crash-reporting service.

6. Why we use information

  • Provide, maintain, secure, restore, and troubleshoot the app, website, and features you request.
  • Confirm availability, process and deliver orders, send transactional communications, and administer returns, refunds, support, and warranty claims.
  • Record your consent and send the Anchor availability and launch emails you requested, until you unsubscribe.
  • Prevent fraud, misuse, security incidents, and violations of our terms; protect users, BNS, and others.
  • Understand aggregate feature and purchase-path performance through privacy-minimized analytics.
  • Keep required business, tax, accounting, and legal records; establish, exercise, or defend legal claims; and comply with lawful requests and applicable law.

Depending on the law and context, we rely on performing a contract or taking requested pre-contract steps, your consent, compliance with legal obligations, and our legitimate interests in operating, securing, improving, and protecting Anchor. Where we rely on legitimate interests, we consider the information's sensitivity, our limited use, and the available controls. You may withdraw consent or object where applicable, but this does not affect processing already lawfully completed.

7. When information is disclosed

We disclose information only as reasonably necessary for the purposes above, including to:

  • Apple: app distribution, operating-system permissions and services, and private CloudKit backup on supported Apple devices.
  • Google and Android device providers: app distribution, operating-system permissions, and device services.
  • Aptabase / Technov Solutions SRL: limited product analytics processed in Virginia, United States.
  • Buttondown: launch-notification signup, consent records, email delivery, and unsubscribe controls.
  • Vercel, email providers, and, when orders are open, delivery carriers: website delivery and security, communications, and fulfilment.
  • Professional advisers and authorities: when reasonably necessary for accounting, insurance, legal advice, compliance, a lawful request, or protection of rights, safety, and security.

We may transfer information in connection with a proposed or completed financing, merger, reorganization, sale, or transfer of all or part of the business, subject to appropriate confidentiality and use restrictions and applicable law.

8. International processing

BNS is based in Alberta, Canada. Aptabase analytics is processed in the United States. Apple, Google, Buttondown, Shopify, Shopify Payments, Vercel, communications providers, and their subprocessors may process information in Canada, the United States, and other countries where they operate. Those countries may have privacy laws that differ from the laws where you live, and information there may be accessible to courts, law enforcement, or regulators under local law.

Where required, we use contractual terms and other recognized safeguards for international transfers. You may contact our privacy lead for more information about providers, countries, or applicable safeguards.

9. Retention

  • Local app data: remains on the device until you change or reset it, uninstall the app, or the operating system removes it, subject to operating-system backup, Keychain, and device behaviour.
  • Private iCloud backup:remains until it is replaced or deleted through Anchor's reset process or your Apple/iCloud controls, subject to Apple's systems and backup practices.
  • Aptabase analytics: Aptabase states that it retains app analytics for up to five years.
  • Launch notifications: Buttondown retains your email address and subscription record while you are subscribed and as otherwise needed for suppression, consent, security, legal, and service records after you unsubscribe.
  • Orders, payments, support, and legal records: are kept for as long as reasonably needed for fulfilment, customer service, warranty, fraud prevention, tax, accounting, legal, chargeback, and dispute purposes. The period varies by record and legal requirement.

When information is no longer required, we delete, anonymize, or securely dispose of it as appropriate. Limited copies may remain temporarily in protected backups or logs until they rotate, or longer when retention is required by law or needed for legal claims.

10. Your choices and privacy rights

You can review or revoke system permissions in iOS or Android settings. A related Anchor feature may stop working if its permission is unavailable. You can disable mobile-app analytics in Anchor settings. The app's Reset All Data control removes the app data identified in its confirmation and requests deletion of the private iCloud backup where enabled. You may also uninstall the app and use Apple, Google, Buttondown, Shopify, and payment-provider controls for information those services hold. Every launch email includes a Buttondown unsubscribe control, and you may also ask us to withdraw your marketing consent.

Depending on where you live, you may have rights to know whether we process personal information about you; request access, correction, deletion, or portability; withdraw consent; object to or restrict certain processing; and appeal or complain to a regulator. You will not be discriminated against for exercising an applicable privacy right. We may need to verify identity, clarify the request, charge a legally permitted fee, or retain information where law permits or requires it.

Much of Anchor's app data stays only on your device and is not available to BNS. Aptabase events are not connected to an Anchor account and generally cannot be isolated by person. We will explain these limitations if they affect a request.

We do not sell or rent personal information. We do not share personal information for cross-context behavioural advertising or use it for targeted advertising. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Shopify or payment providers may independently use automated tools for fraud and payment decisions under their notices.

11. Children and teens

Anchor is intended for people aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. A parent or legal guardian may configure Anchor on a child's device and should manage the device permissions and settings. Purchases must be made by an adult or with the involvement of a parent or legal guardian where required.

If you believe a child under 13 has sent personal information to BNS, contact our privacy lead so we can review and delete it where appropriate. We will obtain parental authorization or apply additional protections if a law requires them for a particular user or use.

12. Safeguards and incidents

We use administrative, technical, contractual, and physical safeguards appropriate to the sensitivity and amount of information, including access limitation, secure platform storage, encryption provided by the operating system and service providers, and data minimization. No transmission or storage system is completely secure. If a breach occurs, we will assess it and notify affected people and regulators when required by applicable law.

13. Changes to this policy

We may update this policy when our products, providers, practices, or legal obligations change. The revised version will be posted here with a new effective date. If a change is material, we will provide additional notice or request consent where required. The policy in effect when we collected information continues to govern that processing unless law permits or you agree to a change.

14. Contact the privacy lead

Send privacy questions, rights requests, or complaints to the person accountable for privacy at BNS Development Inc.. Please write “Privacy Request” in the subject line. We will respond within the time required by applicable law.

Email info@bnsdevelopments.com
35 Woodstock Road SW, Calgary, Alberta T2W 5V8, Canada