Last updated: 7 August 2026
Anthora is operated by Clexa GmbH (“Clexa”, “we”, “us”, “our”), Germany. We run the website theanthora.com and the Anthora mobile application for iOS and Android (together, “the Service”). Clexa GmbH is the data controller within the meaning of Art. 4(7) GDPR.
For any question about this policy, your data, or to exercise your rights, contact us at privacy@anthora.co.
Email address, username, and hashed password (bcrypt — we never see your actual password). If you sign in with Google we receive your Google account ID and email. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
Display name, bio, profile photo, personal link, and phone number. You control everything here and can remove it from Settings at any time.
Lists, items, comments, likes, saves, predictions, and notes you create are stored to operate and display the Service. Legal basis: performance of a contract.
Which lists you view, save, like, or interact with — used to personalise your feed and recommendations. Retained until you delete your account. Legal basis: legitimate interest, Art. 6(1)(f) GDPR.
Web: browser type, OS, approximate location from IP (country/city only), referring URL. Mobile: device model, OS version, app version, language, time zone, crash data. IP addresses are truncated after use.
We do not collect IDFA or AAID. We do not use cross-app or cross-site tracking.
Stored for up to 90 days, not linked to your account, used to improve search quality. Legal basis: legitimate interest.
Login attempts, failures, and lockouts (with masked email addresses). Retained 90 days. Legal basis: legitimate interest in protecting accounts.
If you accept the analytics category in the cookie banner, we use Vercel Analytics — privacy-first, no cookies, no cross-site tracking, no persistent identifiers. Legal basis: consent, Art. 6(1)(a) GDPR.
If you start a paid membership on the web, Stripe processes your name, email, billing address, payment method, tax information, and transaction details. Anthora stores only the Stripe customer and subscription references needed to recognise your membership, along with its plan, status, billing interval, and renewal date. We never receive or store your full card number. Legal basis: performance of a contract and compliance with tax and accounting obligations, Art. 6(1)(b) and (c) GDPR.
The app requests only what a feature needs: photos library (list uploads), camera (in-app capture), location (trip/travel maps), push notifications (activity alerts). You can revoke any permission in system settings; the rest of the app continues to work.
When someone follows a book, place, ticket, product, or other action link, Anthora stores the recommendation, item number, destination, partner, creator, and time of the action. We do not use an advertising identifier or record the visitor's identity in this attribution record. If a partner later reports an eligible transaction, we store its partner reference, amount, currency, status, and creator share. Legal basis: performance of the creator earnings agreement and our legitimate interest in accurate attribution and fraud prevention, Art. 6(1)(b) and (f) GDPR.
| Purpose | Legal basis |
|---|---|
| Account & content | Contract — Art. 6(1)(b) |
| Personalised feed & recommendations | Legitimate interest — Art. 6(1)(f) |
| Search query logging | Legitimate interest — Art. 6(1)(f) |
| Security logs & fraud prevention | Legitimate interest — Art. 6(1)(f) |
| Analytics (Vercel) | Consent — Art. 6(1)(a) |
| Membership billing | Contract and legal obligation — Art. 6(1)(b), (c) |
| Recommendation attribution and creator earnings | Contract and legitimate interest — Art. 6(1)(b), (f) |
| Push notifications | Consent — Art. 6(1)(a) |
| Crash & error reporting (Sentry) | Legitimate interest — Art. 6(1)(f) |
| Legal requests | Legal obligation — Art. 6(1)(c) |
Anthora uses Anthropic's Claude API to help you generate list drafts from a text prompt. When you use this feature, the prompt you type is sent to Anthropic. Anthropic does not use prompts submitted through our API integration to train its models. AI-generated suggestions are a starting point — nothing is published until you save it.
Anthora may work with Amazon Associates and other book, travel, ticket, restaurant, grocery, and retail partners. Before redirecting you, Anthora records the recommendation action described in section 2.11. The destination partner may then set cookies or use similar technology under its own privacy policy. We do not set an affiliate tracking cookie on theanthora.com. Partners provide transaction and commission reports but should not provide us with your name or payment details. See Amazon's Privacy Notice for details.
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Web hosting and analytics | USA (SCCs) |
| Railway Corp. | Backend server and database hosting | USA (SCCs) |
| Anthropic PBC | AI list generation | USA (SCCs) |
| Stripe Payments Europe, Limited | Web membership checkout, invoicing, tax, billing management, and future creator payouts | Ireland / USA (SCCs or DPF) |
| Affiliate, booking, ticketing, and retail partners | Recommendation actions, transaction attribution, and commission reporting | Varies by the partner shown before leaving Anthora |
| Pexels GmbH | Image search for list items | Germany / USA |
| Google Maps Platform | Geocoding and map tiles for trip lists | USA (SCCs) |
| Functional Software Inc. (Sentry) | Error and crash monitoring | USA (SCCs) |
| Apple Inc. | iOS app distribution and push notifications | USA (SCCs) |
| Google LLC | Android app distribution and push notifications | USA (SCCs) |
| Strato AG | Email hosting for @anthora.co | Germany |
We do not sell personal data. We do not share data with advertisers. We do not use Meta Pixel, TikTok Pixel, Google Analytics, Firebase Analytics, Mixpanel, or any similar tracking platforms.
Transfers to processors outside the EEA are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, combined with supplementary technical and organisational measures. For providers certified under the EU–US Data Privacy Framework, the Framework's adequacy decision also applies. To request copies of applicable SCCs, email privacy@anthora.co.
If you are in the EEA, UK, or Switzerland, you have the right to:
Email privacy@anthora.co. We respond within 30 days.
We do not use automated decision-making that produces legal or similarly significant effects under Art. 22 GDPR. Our recommendation engine personalises which lists you see but does not restrict access, set prices, or make consequential decisions about you.
| Data type | Retention |
|---|---|
| Account and profile data | Until you delete your account |
| Content (lists, comments, predictions) | Until you or we delete it, or account deletion |
| Usage data | Until you delete your account |
| Search queries | 90 days (not linked to account) |
| Security and audit logs | Up to 90 days; current infrastructure logs expire sooner |
| Crash reports | 90 days |
| Analytics data (Vercel) | One-month reporting window on our current plan; provider-side storage may be longer |
| Membership state in Anthora | Until account deletion; an active membership is cancelled first |
| Recommendation action attribution | Until account deletion or 24 months after the action, whichever comes first |
| Creator commission records | For the statutory tax, accounting, and dispute period, generally up to 10 years; account identifiers are removed after account deletion where legally possible |
| Invoices and legally required payment records | For the statutory tax and accounting retention period, generally up to 10 years |
| Email correspondence with privacy@ | 3 years (German limitation period) |
When account deletion succeeds, any active web membership is cancelled first, then account data and user-linked content are removed from live systems immediately. Stripe and Clexa GmbH may retain invoices and transaction records where tax, accounting, fraud-prevention, or other law requires it. Copies of other account data may remain in access-restricted disaster-recovery backups until the applicable backup expires, for no longer than 90 days. Backups are not used for ordinary product processing.
Passwords stored as bcrypt hashes. All traffic over HTTPS (TLS 1.2+). Authentication tokens are short-lived (15 minutes) with rotating refresh tokens. Rate limiting and account lockout against brute-force attacks. Access to production systems restricted to authorised personnel. In the event of a breach affecting your rights, we will notify you and the supervisory authority within 72 hours as required by Art. 33–34 GDPR.
The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@anthora.co and we will delete it promptly.
Detailed information is in our Cookie Policy. The banner you see on first visit lets you accept all, reject all, or customise by category. You can change your choice at any time using the button below.
We may update this policy when we add features, change processors, or adapt to legal requirements. We will post the updated policy here with a new “Last updated” date. For significant changes we will notify you by email or in-app message at least 14 days before the change takes effect.
Email privacy@anthora.co. We aim to respond to every query within 5 working days and resolve every formal request within 30 days. If you are not satisfied, you have the right to complain to your local supervisory authority (see section 8).