← Home

Privacy Policy

Last updated: 1 July 2026

This Privacy Policy explains how Anthropos (“we”, “us”), available at anthropos.dev, processes personal data when you use the Service. It is written to be compatible with the EU General Data Protection Regulation (GDPR), the UK GDPR and comparable privacy laws.

1. Data controller

The data controller is the Operator of Anthropos. For any privacy question or to exercise your rights, contact us at: hello@anthropos.dev.

2. What we collect

  • Nickname you choose (stored in our database and on your device).
  • Country / cultural context you enter, and the archetype derived from your quiz answers.
  • Chat messages and check-in inputs you send to the AI, and the AI responses.
  • Derived signals such as an emotional-state summary and a "living portrait" the AI updates over time, stored locally in your browser and (in anonymised form) on our backend to preserve conversation memory.
  • Approximate location (country only) derived from your IP address or Cloudflare geolocation headers, used to pre-select the interface language.
  • Technical data: IP address, user agent, timestamps, error logs — used for security, abuse prevention and debugging.
  • Donation data: if you donate, Stripe processes the payment. We receive limited metadata (amount, currency, timestamp, Stripe reference). We do not receive or store your full card number.

We do not ask for and do not want you to submit: government IDs, health records, biometric data, financial account numbers, sexual life data, or other special-category data. If you voluntarily include such data in a chat message, you do so at your own risk and grant us the right to process it solely to deliver the Service.

3. Legal bases (GDPR Art. 6)

  • Performance of a contract (Art. 6.1.b) — to provide the Service you request (chat, archetype, memory).
  • Legitimate interest (Art. 6.1.f) — security, abuse prevention, product improvement, aggregated analytics.
  • Consent (Art. 6.1.a) — where required, e.g. optional analytics cookies.
  • Legal obligation (Art. 6.1.c) — accounting/tax records related to donations.

4. How your messages are used with AI

Your messages are sent to third-party large-language-model providers through the Lovable AI Gateway solely to generate a response. We contractually require these providers to not use your inputs to train their models. We do not sell your data. We do not use your conversations for advertising.

5. Storage and retention

  • Local storage on your device: nickname, chat history, portrait and state snapshot — kept until you clear your browser storage or use “Restart”.
  • Backend database (Lovable Cloud / Supabase infrastructure, EU region where available): nickname uniqueness records, minimal operational data — kept as long as your nickname is active.
  • Chat logs: transient processing only; if any logging is retained for debugging it is minimised and deleted within 30 days.
  • Donation records: retained by Stripe and by us for the period required by tax and accounting law (typically up to 10 years).

6. Sub-processors

  • Lovable — hosting and platform.
  • Cloudflare — CDN, DDoS protection, geolocation.
  • Supabase-based infrastructure (via Lovable Cloud) — database and auth.
  • AI model providers accessed through the Lovable AI Gateway — LLM inference.
  • Stripe — donation processing.

Where data is transferred outside the EU/EEA, transfers are protected by Standard Contractual Clauses or equivalent safeguards under GDPR Chapter V.

7. Cookies

We use only strictly necessary browser storage (local storage for your session, language and progress) and any cookies required to operate the Service and process donations. We do not use advertising or tracking cookies. If in the future we add analytics that require consent, we will ask for it first.

8. Your rights (GDPR)

You have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase your data (“right to be forgotten”);
  • restrict or object to processing;
  • data portability;
  • withdraw consent at any time (without affecting past processing);
  • lodge a complaint with a supervisory authority (in Italy: the Garante per la protezione dei dati personali — garanteprivacy.it).

To exercise any of these rights, email hello@anthropos.dev. You can also self-erase most of your data at any time by clicking Restart in the app, which clears your local storage.

9. Security

We use HTTPS everywhere, keep secrets on the server side, apply row-level security on database tables, and follow the security guidance of our infrastructure providers. No system is 100% secure; you use the Service at your own risk and must keep your device and nickname secure.

10. Children

The Service is not intended for children under 16. If we discover that we have collected data from a child under 16 without valid parental consent, we will delete it.

11. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date reflects the most recent change. Material changes will be communicated in-app or by a notice on this page.

12. Contact

Privacy questions or GDPR requests: hello@anthropos.dev.

This page is maintained by the Operator of Anthropos to explain how personal data is handled. It describes practices in place today and is not legal advice.