AnorPrivacy
Anor — Personal Alignment Engine

Privacy policy

How Anor handles your information. Effective 26 July 2026 — this policy governs Anor's private beta; we will post any material change here and, where it matters, tell you directly.

The short version

Your material sits in two places, and it matters which is which. The law you make — every version of your Law and of the law of each Domain, and the record of how they changed — is stored in Anor's database, walled off from every other account. The bodies of what you author and gather — your Sources, your ceremony material, your Journal entries, and the search index built from them — live encrypted in your own cloud storage. We do not sell your data, run advertising, build advertising profiles, or train models on your private content. You can ask us to delete your account at any time.

What we collect

Account: your email address, used to sign in and to reach you about the service. Governance state: the law you author in the product — versions of your Law, Domains, ceremonies, commitments the check held, suspensions, and the pointers that locate your content. Storage authorization: if you connect Google Drive, an encrypted token that lets Anor read and write only its own app folder (the drive.appdata scope — Anor cannot see the rest of your Drive). Operational logs: ordinary server logs needed to run and secure the service. We do not collect anything you did not volunteer to the product, and there are no third-party advertising or analytics trackers.

Where your content lives

In Anor's database: the full text of every version of your Law and of the law of each Domain, together with the record around them — Domains, ceremonies, commitments the check held, suspensions — and the pointers that locate the rest. We say this plainly because the law you write is the heart of the product and it does rest on our servers, under the account walls described below.

In your own cloud storage:the bodies of your governed content — your Sources and what you write about them, your ceremony material, your Journal entries, and the search index derived from them — stored in a Google Drive app folder and encrypted with a per-user key before they are written, so that even if the files were surfaced they would not be coherently readable, only deletable. The one exception is the raw media of a perceptual Source (an image, audio, or video): because it uploads straight from your device to your own cloud and never passes through our servers, we never hold it and so cannot encrypt it — its durable copy rests unencrypted in your own cloud, while the text we derive from it stays encrypted with your per-user key like everything else. This is by design: your life's material stays under your control, in storage you own.

How we use what we collect

Only to provide the service to you: to authenticate you, to store and render your law and its history, to locate your content in your own storage, to run the ceremonies and the constitutionality check, and to keep the system secure and working. We use your information to serve you — never to profile you or to sell access to you.

AI processing

AI processing is paused right now. While we complete a privacy review of our AI provider, Anor sends nothing you write to any model — the surfaces that would use it show a pause notice instead. This section describes what will happen when it resumes.

Conversations you have inside Anor — writing your Law, talking with your counsel, the ceremonies — are sent over an encrypted connection to xAI, which runs the model that generates the replies. They will be sent under zero data retention: your words exist on the provider's systems only for as long as it takes to answer, are deleted when the reply is returned, and are kept in no log, backup, or durable copy afterwards. They are not used to train models. If we ever needed to move to a provider or a setting that keeps your material for longer, we would say so on this page, with a new effective date, before it took effect.

If you volunteer a perceptual Source — an image, audio, or video, at any size (we impose no limit) — its raw media uploads straight from your device to your own connected cloud; the bytes never pass through our servers. So an AI provider can read and describe what the media contains, the provider fetches it directly from your cloud through a short-lived, single-use link (or, where that is not possible, your device sends it to the provider directly) — in neither case do the bytes pass through our servers. The text derived from it (a transcript, and our own described observations) is stored back in your own cloud, encrypted with your per-user key. Because the raw media never transits our servers, we cannot encrypt it: its durable copy rests unencrypted in your own cloud, unlike that derived text. Any copy the provider makes to read it is transient and removed after ingestion where its API allows. This sending of the raw media to the AI provider is the only point your media leaves your own storage, and it happens only to serve your session.

Security

Every database query runs as a restricted role scoped to your verified identity, so one account's data is structurally walled off from another's (row-level security is the tenant boundary, not a convention). Your storage-authorization token is encrypted at rest. Access to production is limited and audited. No system is perfectly secure, but the architecture is built so that a bug in one place cannot quietly expose another user's law.

Keeping, removing, and deleting

Within the product, removing governed content tombstones it rather than destroying it — your history stays legible and your Law is never released. That is a product guarantee, not a barrier to leaving: if you ask us to delete your account, we remove your account record and the governance state we hold, and you disconnect or delete the app folder in your own Drive to remove the content bodies you own. We keep ordinary backups and logs for a limited period for security and recovery.

Your choices

You can view and edit your law inside the product, disconnect your storage at any time, and request access to or deletion of the account data we hold — including the law versions we store. The content bodies in your own Drive are already yours to hold, copy, or delete directly. To make a request, write to the address below.

Changes & contact

If this policy changes materially, we will update this page and, where it matters, tell you directly. Questions, access requests, or deletion requests: lloyd@anor.world.