Privacy Policy
Last updated: July 18, 2026
1. Introduction
Ancor Technologies ("Ancor," "we," "us," or "our") operates the Ancor OS platform at getancor.com. This Privacy Policy explains what we collect, why we collect it, who we share it with, and how you can control it, across our marketing site, the Ancor app, the client portal, and related services (together, the "Service").
We follow applicable data protection laws, including India's Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000, and, where they apply to you, the GDPR and CCPA.
2. Information We Collect
2.1 Information You Provide
- Account Information: Full name, email address, password (hashed), organization name, role, and department.
- Profile Information: Skills, job title, profile photo, and reporting structure.
- Project and Task Data: Project names, descriptions, budgets, timelines, task assignments, and status updates.
- Time Tracking Data: Hours logged, work session timestamps, and associated task details.
- Wellbeing Check-ins: Optional self-reported mood and energy entries (see Section 3).
- Financial Information: Project budgets, hourly rates, compensation data entered by your workspace, and billing-related data.
- Resume Uploads: If you upload a resume during profile setup, we process the file in memory to extract skills. The extracted text is sent to our AI provider for skill extraction; the file itself is not stored.
2.2 Information Collected Automatically
- Device and Browser Information: IP address, browser type, operating system, and device identifiers.
- Usage Data: Pages visited, features used, and interaction patterns.
- Log Data: Server access logs, error logs, and referral URLs.
- Cookies and Similar Technologies: See the cookie table in Section 13 for the full list.
2.3 Gmail and Email Data (Google API Services)
Ancor's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you choose to connect your Gmail account to Ancor Assistant, we request the https://www.googleapis.com/auth/gmail.readonly scope. This scope allows Ancor to:
- Read email messages in your Gmail inbox (including message headers: sender, recipient, subject, timestamp; and message bodies)
- List and search your emails
- Access email thread metadata
How we use Gmail data:
- Our AI (Gemini models on Google Vertex AI) analyzes your emails to automatically identify action items, project deadlines, and tasks mentioned by clients or colleagues
- We analyze sender patterns and email frequency to detect client communication risks and team burnout signals
- We extract suggested tasks and sprint items directly from your inbox content
- Email content is processed in real-time and is not permanently stored - we store only the extracted structured data (task titles, suggested priorities) that you choose to save
Limitations on Gmail data use:
- Gmail data is used only to provide in-app AI analysis features directly to you
- We do not share, sell, transfer, or disclose Gmail message content to any third party, except to our AI processing provider (Google Vertex AI) solely to perform the analysis you requested
- We do not use Gmail data for advertising or to build advertising profiles
- We do not allow humans to read your Gmail content unless you explicitly provide consent for support purposes
- OAuth tokens (access and refresh tokens) are encrypted at rest using AES-256 and stored securely in our database
Revoking Gmail access: You can disconnect Gmail at any time from the Ancor Assistant page (Settings → Disconnect Gmail) or by visiting your Google Account permissions page and revoking Ancor's access. Upon disconnection, your stored OAuth tokens are immediately deleted from our database.
3. Workspace Analytics and Team-Health Data
If you use Ancor as part of a team, the platform records work patterns to power team-health features. This includes:
- Task timing: When tasks are started, completed, and how long they take against estimates.
- Login and work sessions: Session timestamps, including an indicator when work happens outside your workspace's business hours.
- Wellbeing check-ins: Self-reported mood and energy entries, if you choose to submit them.
- Wellbeing scores and burnout-risk indicators: Computed from the signals above.
- Estimate-accuracy metrics: How logged time compares to estimated time.
This data is visible to your workspace's admins and owners. It exists so agencies can spot overload and burnout early, not to grade individuals.
Who is responsible: The agency (our customer) is the data controller and data fiduciary for its team's workspace data, and is responsible for informing its team members about this processing. Ancor processes this data on the agency's behalf to provide the features.
4. AI Features
Ancor's AI features (the AI Planner, assistant, report drafts, and skill extraction) run on Google Vertex AI, Google Cloud's enterprise AI platform, using Gemini models. Three things matter here:
- No training on your data: Google does not use customer data submitted through Vertex AI to train its models.
- Secrets are stripped: We remove secrets, API keys, and credential-like values from context before any AI call.
- Resume uploads are not stored: Resume files are processed in memory for skill extraction. The extracted text goes to the AI; the file itself is not stored.
We log AI requests (prompt metadata, token counts, and cost data) for billing and abuse prevention. See Section 9 for how long these logs are kept.
5. How We Use Your Information
- To provide, maintain, and improve the Service
- To create and manage your account and organization
- To process project, task, and time tracking data
- To generate AI-powered reports, analytics, and recommendations
- To power team-health features for your workspace (Section 3)
- To send notifications, alerts, and service-related communications
- To provide customer support
- To detect, prevent, and address security issues and fraud
- To comply with legal obligations
- To send marketing communications (with your consent; you may opt out at any time)
6. Legal Basis for Processing (GDPR)
If you are in the EEA, we process your personal data based on:
- Contract Performance: Processing necessary to provide the Service.
- Legitimate Interest: Fraud prevention and service improvement.
- Consent: Marketing communications, analytics and marketing cookies, and optional data collection (including Gmail integration and wellbeing check-ins).
- Legal Obligation: Compliance with applicable laws.
7. Data Sharing and Subprocessors
We do not sell your personal information. We use these subprocessors to run the Service:
- Google Cloud: Hosting (India, Mumbai region) and AI processing via Vertex AI.
- Supabase: Database.
- Resend: Email delivery.
- Sentry: Error tracking.
- Razorpay: Payment processing. We do not store full card details; payment information is handled by Razorpay under its own privacy policy.
- PostHog (EU): In-app product analytics.
- Microsoft Clarity, Google Analytics, LinkedIn: Marketing-site analytics only (see Section 13).
We may also share data:
- Within Your Organization: Team members can see project, task, and team data per your role and access settings.
- Legal Requirements: When required by law, court order, or government request.
- Business Transfers: In connection with a merger or acquisition, under confidentiality obligations.
8. Hosting and International Data Transfers
Ancor Technologies is based in Mumbai, India, and the Service is hosted on Google Cloud in the Mumbai region. Some subprocessors listed above operate in other countries (for example, PostHog in the EU), so limited data may be processed outside India. We put data processing agreements and encryption in place for these transfers, and Standard Contractual Clauses where required.
9. Data Retention
- Trial expiry: When a trial ends, the workspace becomes read-only for 30 days. After that, it is eligible for deletion.
- Account deletion: Deleted accounts have a 30-day restore window, after which data is permanently removed by our purge process.
- Database backups: Retained for 14 days, then rotated out.
- Audit logs: Kept for 2 years.
- AI request logs: Kept for 1 year.
- Gmail OAuth tokens: Deleted immediately upon disconnection or account deletion.
- Email-extracted tasks: Retained until you delete them, subject to your account data retention.
- Legally required data: Retained as mandated by law.
10. Your Rights
- Access and correct your personal data
- Export your data in a portable format (one-click JSON export from Settings)
- Delete your account and associated data
- Disconnect Gmail and revoke all associated tokens at any time
- Opt out of marketing communications
- For EEA/UK users: right to restrict or object to processing, right to lodge a complaint with a supervisory authority
- For California residents (CCPA): right to know, right to delete, right to opt out of sale (we do not sell data)
- For Indian users (DPDPA): right to access, correction, erasure, and grievance redressal
To exercise any of these rights, contact us at [email protected].
11. Grievance Redressal (India)
Under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, you can raise a grievance about how your personal data is handled. Write to our Grievance Officer:
Rushabh Porwal, Founder, Ancor
Ancor Technologies, Vile Parle, Mumbai, Maharashtra, India
Email: [email protected]
We acknowledge grievances promptly and aim to resolve them within the timelines set by applicable law. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
12. Security
Security measures we run in production:
- Encryption in transit (TLS 1.2+)
- AES-256 encryption of sensitive fields at rest, including OAuth tokens, MFA secrets, and compensation data
- Multi-factor authentication (TOTP with backup codes)
- Secure password hashing (bcrypt)
- CSRF protection, rate limiting, and brute-force protection
- Role-based access control and tenant isolation
- Audit logging of sensitive actions, including access to compensation data
No internet service can promise perfect security. If you find a vulnerability, report it to [email protected].
14. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect data from children. If we become aware of such data, we will delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by email or by posting a notice on our website. Continued use after changes constitutes acceptance.
16. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights:
Ancor Technologies
Email: [email protected]