Anchor Privacy Policy
Numbered notes like [1] point to state-law variations collected in Appendix A. The body of this policy tells you what we actually do; the appendix tells your lawyer (or your curiosity) which state laws say what.
1. Who we are
Anchor is a focus timer built for brains that don't queue tasks neatly — ADHD brains especially. It runs on Windows, Android, and the web. It helps you pick one thing, break it into steps, and start.
Anchor is made and operated by [ANCHOR ENTITY NAME, LLC — TO BE CONFIRMED BY COUNSEL], a Utah limited liability company. In this policy, "Anchor," "we," and "us" mean that company, and "you" means you — the person using the app.
This policy covers the Anchor desktop app, the Anchor Android app, the Anchor web app, and the sync service behind them. It does not cover third-party websites we might link to.
One thing to know up front: Anchor works locally first. If you never create a sync account, your data lives on your device and almost none of this policy comes into play.
2. The short version
We collect what we need to hand you your next step. Nothing more.
- Anchor works on your device first. Nothing leaves it until you create a sync account and sign in.
- When you sync, we store your account basics and the content you create: tasks, focus sessions, daily check-ins, personality test results, game completions, and the profile fields you choose to fill in.
- When you ask the AI to break down a task, we send the task text (plus your profile fields, if you set them) to Anthropic, get the steps back, and keep neither the request nor the response.
- We do not sell your data. We show no ads. We run no analytics or tracking of any kind.
- Some of what you create — check-ins, personality results, ADHD notes — is health-adjacent. We treat it that way: you choose to create it, you choose to sync it, and you can delete it.
- Everyone gets the same rights, no matter where you live: see your data, fix it, export it, delete it. Email us and we'll do it.
The rest of this policy is the same story with the precision a legal document needs.
3. What we collect (and what we do not)
If you never sign in
Anchor stores everything in a local database on your device: tasks, sessions, check-ins, settings, all of it. We can't see any of it. The only network calls the app makes without an account are checking for app updates and pulling shared content (insight articles, toolkit exercises, the game catalog) — requests that don't include your content or identity (like any internet request, they necessarily expose your IP address to our server).
When you create a sync account
We store, on our server:
- Account basics: your email address, your password (stored only as a bcrypt hash — we never keep the password itself), and an optional display name.
- Content you create, synced so your devices agree:
- your tasks;
- your focus sessions (what you worked on, when, for how long);
- your daily check-in responses (the question, your 1–5 rating, the rating's label, and the question's category — covering things like focus, sleep, anxiety, emotions, energy, and impulsivity);
- your personality test results (scores and the primary result);
- your game completions (which quick game, when);
- your profile fields, all optional: preferred name, ADHD notes (free text), energy pattern, and life context.
- Active-session presence: while a focus session is running, your other signed-in devices can see that — including the task title and the name of the device the session is running on. This exists so your devices stay in step; it isn't kept as a long-term log beyond the session record itself.
- Usage metadata: when you use AI task breakdown, we record token counts — numbers describing how much text was processed, never the text itself (see Section 5).
What stays on your device, always
Some things never sync, by design: brain dump items, distraction entries, and mobile crash logs. They live only in your local database (or, for crash logs, a local file) and we never receive them.
What we do not collect
We do not collect your location, contacts, browsing history, or advertising identifiers. We use no analytics or tracking SDKs, no advertising networks, and no tracking cookies.
There is no hidden second list. California residents: a notice-at-collection table mapping categories to purposes, recipients, and retention is in Section 12. [1]
4. How we use it
We use the data above for exactly four things:
- Running the service. Storing your content, syncing it between your devices, keeping your account working, and answering you when you write to us.
- AI task breakdown. Sending your task text (and profile fields, if set) to our AI provider to generate suggested steps — only when you ask for a breakdown. Details in Section 5.
- Billing, when you choose a paid plan. When you purchase a subscription, payment is processed by Stripe — we never see your card number. We use your email and subscription status to know what plan you're on.
- Keeping the service safe. Watching for abuse, debugging failures, and enforcing usage quotas (that's what the token counts are for).
And the things we don't do: We do not sell your personal data. We do not share it for targeted advertising. Your task content is never used to train AI models. [2]
5. AI processing disclosure
When you press the breakdown button, here is exactly what happens:
- We send your task text, plus your four profile fields if you've set them (preferred name, ADHD notes, energy pattern, life context), to Anthropic (api.anthropic.com), the company whose AI model generates the suggested steps. The profile fields go along so the suggestions fit how you actually work.
- Anthropic processes the request under its commercial API terms, which prohibit using your data to train AI models.
- We store neither the request nor the response on our server. The steps come back to your device and live in your local database (and sync with your tasks, like anything else you create). The only thing we keep is token-count usage metadata — how much text was processed, as a number.
This only happens when you ask for a breakdown. Type your own steps and nothing is sent anywhere.
Anthropic is currently our only AI provider. We will update this policy before adding any other AI provider.
Because your ADHD notes and other profile fields can ride along in a breakdown request, the consent you give for health-adjacent data (Section 6) covers this transmission too. [3]
6. Sensitive data & consent
Some of what Anchor invites you to create is, candidly, health-related or close to it: daily check-in responses (which ask about anxiety, sleep, emotions, and similar), personality test results, and your ADHD notes and other profile fields. Several states treat data like this as "sensitive data" or "consumer health data" and require your affirmative consent before a company processes it. [4] Washington, Nevada, and (from July 1, 2026) Connecticut have health-data laws that cover this kind of data and apply to us at any size — Section 12 has their specific disclosures. (Virginia has a fourth any-size health law, but it's narrower and doesn't reach anything Anchor asks you for; Appendix A explains.) [3]
Here is our consent model, plainly:
- You choose to create it. Check-ins, tests, and profile fields are all optional. Skip them and they don't exist.
- You choose to sync it. Sync is off until you create an account and sign in. Until then, sensitive data never leaves your device.
- You can take it back. Clear a profile field anytime, or ask us to delete specific check-ins — or your whole account (Section 8) — and we delete our copy (Section 9).
We use this data for one purpose: showing it back to you and tailoring the app to you (which insights you see first, how breakdowns are phrased). We never use it for advertising, never sell it, and never disclose it except as Section 7 describes.
7. Sharing
We share personal data with the small set of companies that help us run Anchor ("processors") — plus, for completeness, where your data actually lives — and in two narrow legal situations. That's the whole list of companies that receive your content.
| Who | What they receive | Why | When |
|---|---|---|---|
| Anthropic | Task text + profile fields (if set) for a breakdown request | Generates AI task-breakdown suggestions; barred from training on the data; we store neither request nor response | Only when you request a breakdown |
| Stripe | Payment details (card number, billing info) — handled by Stripe directly; we never see your card number | Payment processing for subscriptions | When you purchase a subscription |
| Resend | Your email address and the contents of the message | Delivering transactional email (e.g., password resets, receipts) | When we send you account email |
| Our own server | Everything in Section 3's synced list | Anchor's sync service and database run on infrastructure we operate ourselves — there is no third-party cloud provider with access to your content | While you have a sync account |
One infrastructure note: the web version of Anchor loads its runtime files (the Blazor framework) from Microsoft's content delivery network — a standard framework download that carries no Anchor account data, though like any web request it exposes your IP address to Microsoft. The desktop and Android apps make no such request. [FLAG FOR COUNSEL: confirm the Microsoft CDN framework-load disclosure is sufficient (web client only)]
Two legal situations:
- Legal compulsion. If a court order, subpoena, or other legally binding demand requires us to disclose data, we will comply — narrowly, after verifying the demand is valid, and we'll tell you unless the law forbids it.
- Business transfer. If Anchor is ever acquired or merged, your data may transfer with the service. The new owner would be bound by this policy, and we would notify you before the transfer takes effect.
No one else. We do not sell personal data, and we do not share it for cross-context behavioral advertising. [2]
8. Your rights & how to exercise them
State privacy laws grant different rights to residents of different states. We think that's a silly way to treat people, so we grant the same set to every Anchor user, wherever you live:
- Access — ask what data we hold about you and get a copy.
- Correction — ask us to fix data that's wrong. [5] (Most of your data you can correct yourself, in the app, instantly.)
- Deletion — ask us to delete your data or your whole account.
- Portability — get your data in a portable, machine-readable format you can take elsewhere.
- Appeal — if we decline a request, you can appeal the decision, and we'll have someone other than the original decision-maker review it and reply in writing with reasons. [6]
How to exercise them: email wordsmith.alex@gmail.com from the email address on your account and tell us what you want. You can also have someone act for you (an authorized agent) if you give them written permission — we'll verify with you directly before acting. [7]
How we verify it's you: we match the request to the email address on the account; if anything looks off, we'll ask you to confirm a detail about the account (such as your plan or a recent sign-in) before acting. We will never ask for your password.
How fast: we respond within 45 days. If a request is genuinely complicated, the law lets us take one extension of another 45 days — if we need it, we'll tell you within the first 45 and explain why. [8]
Browser privacy signals: some browsers send a universal opt-out signal such as Global Privacy Control, which tells companies not to sell or share your data. [9] Since we don't sell or share personal data for advertising in the first place, the signal asks for something that's already true — you're covered whether your browser sends it or not.
No retaliation: exercising any of these rights will never cost you features, quality, or price. [10]
9. Retention & deletion
We keep your synced data for as long as your account is active, so the service can do its job. We don't have a "keep it just in case" pile — what's listed in Section 3 is what exists.
When you ask us to delete your account (Section 8), we delete your data from our live systems within 30 days of verifying the request. That includes soft-deleted rows — records the sync system has marked deleted but not yet physically removed. Deleted means deleted, not hidden.
One honest caveat: copies of data may persist in our routine backups for a short period after live deletion, until those backups rotate out and are destroyed in the ordinary course. Backups are used only for disaster recovery — we will not restore your deleted data into live systems, and if a restore from backup ever happened, we would re-delete your data as part of it. Washington residents have a statutory right to deletion that reaches backups; see Section 12.
Data that never synced (Section 3) is yours to delete locally — uninstalling the app or clearing its data removes it, and we never had a copy.
10. Security
Here is where security stands today, honestly:
- Your data travels between your device and our server over TLS (transport encryption).
- Your password is stored only as a bcrypt hash — we never store, and cannot recover, the password itself.
- The server is access-controlled and operated by us, not by a third party.
- Server-side data is not yet encrypted at rest at the application layer. We rely on transport encryption, hashed credentials, and access controls today, and we are continuing to expand at-rest protections.
- No method of transmission or storage is 100% secure, and we won't pretend otherwise. If a breach ever affects your data, we will notify you as applicable law requires.
If you find a security problem in Anchor, please tell us at wordsmith.alex@gmail.com — we read those first.
11. Children & teens
Anchor is for people 13 and older. We do not knowingly collect personal data from anyone under 13. If we learn we have — for example, a parent writes in, or an account self-identifies — we will delete the account and its data promptly.
If you are under 18, our Terms of Service require a parent or guardian to accept them on your behalf.
Some states give extra protections to minors under 16 or under 18 — typically requiring opt-in consent before a company sells their data or shows them targeted advertising, and in some states banning those practices for minors outright. [11] Because we sell no one's data and show no one targeted advertising, those protections are already built into how Anchor works for every user, of every age.
12. US state-specific disclosures
Many state privacy laws apply only to companies above certain size thresholds, which Anchor is currently below. Rather than make you figure out which law covers you, we extend the rights in Section 8 to everyone and honor the state-law standards voluntarily. Four data-privacy laws apply to us regardless of size — Washington's and Nevada's consumer-health-data laws, Virginia's reproductive- and sexual-health-data law (whose narrow scope covers data Anchor does not ask you for — details in Appendix A), and (from July 1, 2026) Connecticut's data privacy act (threshold-free minor-protection laws are covered in Section 11 and note [11]). Disclosures for Washington, Nevada, and Connecticut are below; Virginia's, given that narrow scope, lives in Appendix A. The full state-by-state mapping, including statute citations and which laws bind us today, is in Appendix A and Appendix B.
California (notice at collection) [1]
California residents are entitled to know, at or before collection, the categories we collect, why, who receives them, and how long we keep them:
| Category | What it includes | Why we collect it | Who receives it | How long we keep it |
|---|---|---|---|---|
| Identifiers | Email address, optional display name, preferred name | Account creation, sign-in, contacting you | Us; Resend when we email you; Stripe if you subscribe; Anthropic (profile fields, when you request a breakdown) | While your account is active; deleted within 30 days of a verified deletion request |
| Account credentials | Password (bcrypt hash only) | Authentication | Us only | Same as above |
| Content you create | Tasks, focus sessions, game completions | Providing and syncing the service | Us; Anthropic receives task text only when you request a breakdown | Same as above |
| Sensitive personal information (health-adjacent) | Daily check-in responses, personality test results, ADHD notes, energy pattern, life context | Showing your data back to you; tailoring the app; phrasing AI breakdowns | Us; Anthropic receives profile fields only when you request a breakdown | Same as above |
| Device information | Device name in active-session presence | Keeping your devices in sync | Us only | For the life of the session record |
| Usage metadata | AI breakdown token counts | Quota enforcement, abuse prevention | Us only | While your account is active |
We do not "sell" or "share" personal information as the CCPA defines those terms — including "sharing" for cross-context behavioral advertising — and have not in the preceding 12 months. [2] We use sensitive personal information only to provide the service you asked for, which means California's right to limit its use is already satisfied by default. [4] We honor Global Privacy Control signals as described in Section 8. [9]
Washington and Nevada (consumer health data) [3]
Washington's My Health My Data Act and Nevada's SB 370 protect "consumer health data" — and they apply to businesses of every size, with no small-business exemption, so they bind Anchor today. Your daily check-in responses, personality test results, and ADHD notes qualify as consumer health data under these laws.
For Washington and Nevada residents, with respect to that data:
- What we collect and why: exactly the health-adjacent items listed in Sections 3 and 6, used only to provide the service you asked for. We collect nothing beyond what that requires.
- Consent: we collect and share consumer health data only with your consent — the opt-in model in Section 6 (you create it, you enable sync, you sign in). Sharing means only the processor disclosures in Section 7 (including Anthropic when you request a breakdown).
- No sale: we do not sell consumer health data, and we will never do so without the separate, signed authorization these laws require — which, to be clear, we have no plans to ever ask for.
- Your rights: access your consumer health data, including a list of who we've shared it with; withdraw consent to its collection or sharing at any time; and delete it — including from our backups and archives as they rotate, and with deletion instructions passed to our processors.
- No geofencing: we collect no location data at all, so we cannot and do not geofence anything.
To exercise these rights, use the process in Section 8.
Connecticut (from July 1, 2026)
From July 1, 2026, Connecticut's Data Privacy Act applies to any company that processes sensitive data — with no size threshold — and your check-ins, personality results, and ADHD notes are sensitive data under it (data concerning mental or physical health condition or diagnosis). For Connecticut residents: we process sensitive data only with your opt-in consent (Section 6) and only as reasonably necessary to provide the service; we do not and will not sell sensitive data; and you have all the rights in Section 8, including appeal. [3] [4]
Everyone else
Residents of every other state get the same rights (Section 8) and the same practices (Sections 3–11). The numbered notes throughout this policy, resolved in Appendix A, document where individual state laws differ from the defaults stated here — including consent models [4], correction and appeal variations [5] [6], opt-out signal mandates [9], and minors' provisions [11].
13. EEA, United Kingdom, and Switzerland
If you are in the European Economic Area, the UK, or Switzerland, this section supplements the rest of the policy. The data controller is [ANCHOR ENTITY NAME, LLC — TO BE CONFIRMED BY COUNSEL], reachable at wordsmith.alex@gmail.com.
Legal bases (GDPR Article 6). We process personal data on these bases, mapped to purpose:
- Performance of a contract (Art. 6(1)(b)): providing the app, syncing your content between devices, account administration, and billing when you subscribe.
- Consent (Art. 6(1)(a)): the optional profile fields, daily check-in responses, and personality test results you choose to create and sync. You can withdraw consent at any time by deleting the data or your account; withdrawal doesn't affect the lawfulness of processing before it.
- Legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing abuse, and enforcing usage quotas — interests we've balanced against your rights and which involve only the minimal metadata described in Sections 3 and 4.
Special category data (Article 9). Check-in responses, personality test results, and ADHD notes can constitute health data. We process them only with your explicit consent (Art. 9(2)(a)), given through the deliberate, optional steps described in Section 6 — creating the data, enabling sync, signing in. You can withdraw that consent at any time.
Your rights (Articles 15–22). Access, rectification, erasure, restriction of processing, data portability, objection (including to legitimate-interest processing), and the right not to be subject to solely automated decisions producing legal or similarly significant effects — which Anchor does not make; AI breakdown produces suggestions you are free to ignore. Exercise any of these via the process in Section 8.
International transfers. Our servers are in the United States, so your data is transferred there. We rely on Standard Contractual Clauses with our processors for onward transfers. [FLAG FOR COUNSEL: confirm transfer mechanism — SCCs vs. EU–US Data Privacy Framework certification — before publication.]
Complaints. You have the right to lodge a complaint with a supervisory authority — in the EEA, the authority of your member state; in the UK, the Information Commissioner's Office. We'd appreciate the chance to fix the problem first, but you don't owe us that.
14. Changes to this policy
When we change this policy in a way that matters — new data collected, new sharing, new purposes — we will email you and show a notice in the app at least 30 days before the change takes effect, so you can read it, ask us about it, or request an export of your data and leave before it applies to you. Minor clarifications that don't change what we do may take effect on posting, with the version number and date updated above.
We keep prior versions in version control; ask and we'll show you exactly what changed.
15. Contact
Questions, requests, complaints, corrections: wordsmith.alex@gmail.com. A human reads it — the same one who built the app.
Postal address: available on request while our registered address is being finalized with the entity formation noted in the header.
Appendix A — State Law Notes
These notes resolve the numbered markers [1]–[11] in the body. They are written for attorney review, not for warmth. Research basis: internal roster docs/legal/research/state-law-roster-2026-06.md, verified 2026-06-10 against the IAPP US State Privacy Legislation Tracker (snapshot 2026-06-08), the Termly 50-state tracker, MultiState's 2026 effective-dates roundup, and per-state primary or law-firm sources. Open items are marked [FLAG FOR COUNSEL: …] throughout.
Citation caveat (applies to every note below): bill numbers, effective dates, and thresholds were web-verified 2026-06-10. Code-section citations (e.g., "Va. Code § 59.1-575 et seq.") are standard published citations carried from a training-data baseline and spot-checked, not independently re-pulled from each state code — [FLAG FOR COUNSEL: confirm pin cites before publication].
Open items for counsel — every unresolved item in this document, indexed:
- Entity name:
[ANCHOR ENTITY NAME, LLC — TO BE CONFIRMED BY COUNSEL]placeholder — header, §1, §13. - Effective date:
[to be set at publication]— header. - Confirm the Microsoft CDN framework-load disclosure is sufficient (web client only) — §7.
- Confirm international transfer mechanism (SCCs vs. EU–US Data Privacy Framework) before publication — body §13, International transfers.
- Confirm code-section pin cites before publication — Appendix A preamble (citation caveat).
- Confirm the notice-at-collection pin cite — note [1].
- Confirm no other state imposes a notice-at-collection duty in California's form — note [1].
- Confirm which states define "sale" more narrowly than California — note [2].
- Confirm the treatment of user-volunteered in-scope free text under VA SB 754 — note [3], Virginia bullet.
- Confirm the tailoring uses in §6 satisfy MODPA's strictly-necessary standard — note [4].
- Confirm Louisiana's appeal and portability rights against the enrolled bill, and Alabama's portability right — note [6].
- Confirm per-state authorized-agent provisions if precision is needed — note [7].
- Confirm whether any state's initial-response or extension clock differs from 45 + 45 — note [8].
- Confirm per-state non-discrimination clauses — note [10].
- Confirm the scope of Montana's reasonable-care duty for a 13+ general-audience service — note [11], Montana bullet.
- Confirm Anchor's obligations under Arkansas Act 952 — note [11], Arkansas bullet.
- Assess AADC applicability (Nebraska LB 504, Vermont Act 63) before the Vermont effective date — note [11], design-code bullet.
- Review the Act 952 minors regime — Appendix B, Arkansas row (same substance as item 16).
- Assess AADC applicability — Appendix B, Vermont row (same substance as item 17).
- Publication step: strip or rehost the internal repository path cited in this appendix before publication (research roster).
[1] CALIFORNIA NOTICE AT COLLECTION. ↩ California alone requires a business to tell consumers, at or before the point of collection, the categories of personal information collected, the purposes, the recipients, and the retention period for each category. The Section 12 California table exists to satisfy that duty; no other state requires the disclosure in that form. The exclusivity of this duty is carried from the drafting spec, not verified state-by-state — [FLAG FOR COUNSEL: confirm no other state imposes a notice-at-collection duty in this form]. Citations: CCPA as amended by CPRA, Cal. Civ. Code § 1798.100 et seq.; 2026 additions (CCPA ADMT and risk-assessment regulations, SB 361 data brokers, AB 45 health/geofencing) effective 2026-01-01. The roster carries the citation at the "§ 1798.100 et seq." level — [FLAG FOR COUNSEL: confirm the notice-at-collection pin cite]. Anchor's practice: the §12 table is published for all users, not gated by residence. Applicability: Anchor is far below every CCPA threshold ($25M-indexed annual revenue (~$26.6M) OR 100k consumers/households OR 50%+ revenue from selling/sharing personal information) — honored voluntarily.
[2] "SALE" AND "SHARE" DEFINITIONS. ↩ California has the broadest definitions, and the body is drafted to hold under them:
- Definitions: under the CCPA, "sale" is any disclosure for monetary or other valuable consideration, and "sharing" (disclosure for cross-context behavioral advertising) is separately regulated — the CCPA frames the two opt-outs as a single opt-out of "sale or sharing." Some states define "sale" more narrowly (monetary consideration only).
- Drafting posture: the body's no-sale/no-share statements (§§4, 7, 12) are drafted to hold under that broadest definition: Anchor receives no money or other valuable consideration for personal data and does no cross-context behavioral advertising. Anchor's disclosures to Anthropic, Stripe, and Resend are processor/service-provider disclosures — not a sale and not sharing for cross-context behavioral advertising — under the analysis in the research roster.
- Open item: the roster did not tabulate sale definitions state by state — [FLAG FOR COUNSEL: confirm the narrower-definition states; the drafting is unaffected because the statements satisfy the broadest definition].
Citations: Cal. Civ. Code § 1798.100 et seq. Anchor's practice: no sale, no sharing, and task content never used to train AI models (Anthropic's commercial API terms prohibit training on the data). Applicability: California below threshold — honored voluntarily; the no-sale posture also discharges the surviving small-business sensitive-data-sale consent rules in Texas (TDPSA), Nebraska (NDPA), and Minnesota (MCDPA), and moots Maryland's flat ban on selling sensitive data (note [4]).
[3] CONSUMER-HEALTH-DATA LAWS THAT BIND AT ANY SIZE (WA / NV / CT / VA). ↩ Anchor's daily check-in responses, personality test results, and free-text ADHD notes are "consumer health data" or sensitive health data under the laws below, all of which apply with no revenue or volume threshold:
- Washington — My Health My Data Act (MHMD), HB 1155 (2023), RCW ch. 19.373. Effective 2024-03-31 (small-business phase-in ended 2024-06-30; geofencing ban since 2023-07-23). No threshold and no small-business exemption; applies to any entity conducting business in WA or targeting WA consumers that determines purposes/means of processing consumer health data, which expressly includes mental health status and conditions. Duties: opt-in consent to collect or share beyond what is necessary for a requested service; a separate, distinct signed authorization to sell; consumer rights to access, withdraw consent, and delete (including from processors and as backups rotate); strict data-sharing contracts; geofencing ban. Enforcement: private right of action via the WA Consumer Protection Act, plus the AG — the highest-risk statute on the roster.
- Nevada — SB 370 (2023), codified in NRS ch. 603A. Effective 2024-03-31. MHMD-modeled; no threshold, no small-business exemption. Affirmative consent for collection/sharing beyond necessity; authorization for sale; access and deletion rights; geofencing ban. AG-enforced only (deceptive trade practice) — no private right of action.
- Connecticut — CTDPA, SB 6 (2022), Conn. Gen. Stat. § 42-515 et seq., health provisions from SB 3 (2023), overhauled by SB 1295 (2025). From 2026-07-01 the CTDPA applies without any volume threshold to any controller that processes consumers' sensitive data — and mental or physical health condition, diagnosis, or treatment data is sensitive. Anchor is therefore bound from that date if it has even one Connecticut user. Sale of sensitive data is prohibited without consent; geofencing ban near health facilities.
- Virginia — SB 754 (2025), amending the Virginia Consumer Protection Act, effective 2025-07-01. This is the explanation promised in body §§6 and 12. SB 754 applies to any "supplier" with no threshold and carries a private right of action (greater of actual damages or $500; treble damages or $1,000 if willful) — but its subject matter is narrow: opt-in consent before obtaining, disclosing, selling, or disseminating personally identifiable reproductive or sexual health information (including inferences and location). Mental-health data per se is out of scope, and Anchor solicits nothing within scope: check-ins, tests, and profile fields concern focus, sleep, anxiety, emotions, energy, and ADHD. The only exposure vector is user-volunteered free text (ADHD notes; brain-dump items never leave the device): a user could type in-scope information into a free-text field. Mitigation is the §6 consent model plus the §7 no-disclosure posture — [FLAG FOR COUNSEL: confirm this treatment of user-volunteered in-scope free text].
Adjacent items from the same research: California AB 45 (2025, effective 2026-01-01) adds health-data geolocation/geofencing protections within the CCPA framework — not applicable today because Anchor collects no location data (§3). New York: no consumer-health-data law in force — see the New York row in Appendix B (NYHIPA vetoed; successor S9269 pending — re-check before each revision).
Anchor's practice: §6's opt-in-by-design consent (you create the data, you enable sync, you sign in) covers collection and the Anthropic transmission (§5); §12 carries the WA/NV/CT-specific disclosures; §9's deletion commitment reaches backups for Washington residents. Applicability: WA MHMD and NV SB 370 are binding today; CT CTDPA is binding from 2026-07-01; VA SB 754 is technically binding today but scoped to data Anchor does not solicit.
[4] SENSITIVE-DATA CONSENT MODELS. ↩ The states split four ways on processing sensitive data (which, for Anchor, means the health-adjacent items in §6):
- Opt-in / affirmative consent before processing: Colorado, Connecticut (plus a reasonably-necessary requirement and a ban on selling sensitive data without consent), Delaware, Florida, Indiana, Kentucky, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and Virginia today; Oklahoma and Louisiana from 2027-01-01 and Alabama from 2027-05-01. Louisiana is the outlier within the opt-in camp: Act 502 grants no right to revoke consent once given.
- Opt-out only (notice plus opportunity to opt out): Iowa and Utah — weaker than their peers.
- California: no general opt-in; instead a consumer right to limit the use and disclosure of sensitive personal information.
- Maryland — strictest in the country: sensitive data may be processed only when strictly necessary to provide the requested service, and the sale of sensitive data is flatly banned — consent cannot cure it.
Citations: the statutes listed per state in Appendix B (e.g., Colorado CPA, C.R.S. § 6-1-1301 et seq.; CTDPA, Conn. Gen. Stat. § 42-515 et seq., as amended by SB 1295; MODPA, Md. Code, Com. Law § 14-4601 et seq.; Iowa Code ch. 715D; Utah Code § 13-61-101 et seq.; LA SB 386 / Act 502 (2026); OK SB 546 (2026); AL HB 351 (2026)). Anchor's practice: §6 is opt-in by design — sensitive data exists only if you create it, leaves your device only if you sign in to sync, and is deletable at any time — which satisfies the strictest models on the spectrum: Maryland's strictly-necessary standard fits (the processing is necessary to deliver the service the user requested) — [FLAG FOR COUNSEL: confirm the tailoring uses in §6 satisfy MODPA's strictly-necessary standard], California's right to limit is satisfied by default (§12), and the no-sale posture moots Maryland's sale ban. Anchor also allows consent withdrawal everywhere, exceeding Louisiana's no-revocation floor. Applicability: every comprehensive law here is below threshold for Anchor — honored voluntarily — except Connecticut, binding from 2026-07-01; the WA/NV health-data consent duties (note [3]) are binding today.
[5] RIGHT-TO-CORRECT GAPS. ↩ Iowa grants no correction right at all — the only enacted state besides pre-amendment Utah without one. Utah lacks a correction right until its amendment takes effect 2026-07-01. Every other enacted state grants correction. Citations: Iowa Consumer Data Protection Act, SF 262 (2023), Iowa Code ch. 715D; Utah Consumer Privacy Act, SB 227 (2022), Utah Code § 13-61-101 et seq. (correction amendment effective 2026-07-01). Anchor's practice: §8 grants correction to every user regardless of state, and most data is correctable in-app instantly. Applicability: both states' laws are below threshold for Anchor (Iowa: 100k consumers or 25k + 50% sale revenue; Utah: $25M revenue AND a volume prong, conjunctive) — honored voluntarily, and exceeded.
[6] APPEAL-RIGHT VARIATIONS. ↩ Most enacted states require controllers to offer an appeal process for denied requests; the variations:
- No statutory appeal right: California (a business must explain a denial, but the CCPA mandates no formal appeal mechanism), Utah, and Alabama (effective 2027-05-01).
- 60-day appeal-response clock confirmed where appeal is mandated: Florida, Iowa, and Oklahoma.
- Unverified roster cells: Louisiana's appeal and portability rights (the Act 502 analysis reviewed does not list them and the enrolled bill was not independently pulled) and Alabama's portability right (not mentioned in the source reviewed) — [FLAG FOR COUNSEL: confirm Louisiana's appeal and portability rights against the enrolled bill, and Alabama's portability right].
Citations: Cal. Civ. Code § 1798.100 et seq.; Utah Code § 13-61-101 et seq.; AL HB 351 (2026); Fla. Stat. § 501.701–.722; Iowa Code ch. 715D; OK SB 546 (2026); LA SB 386 / Act 502 (2026). Anchor's practice: §8 grants appeal — review by someone other than the original decision-maker, answered in writing with reasons — to every user. Applicability: all below threshold — honored voluntarily.
[7] AUTHORIZED AGENTS. ↩ The verified outlier is Oklahoma: SB 546 contains no authorized-agent provision at all. The affirmative agent provisions elsewhere (California's express authorized-agent mechanism; the VCDPA-model states' agent provisions for opt-out requests) are carried from the training-data baseline and were not re-verified in the roster — [FLAG FOR COUNSEL: confirm per-state agent provisions if precision is needed; Anchor's uniform practice meets or exceeds all of them]. Citation: OK SB 546 (2026), effective 2027-01-01. Anchor's practice: §8 accepts authorized agents with the user's written permission plus direct verification with the account holder, for all users and all request types. Applicability: below threshold everywhere — honored voluntarily.
[8] RESPONSE DEADLINES. ↩ Anchor commits in §8 to the dominant statutory clock: a response within 45 days, with one 45-day extension on notice and explanation. The roster confirmed 60-day appeal-response windows where an appeal is mandated in Florida, Iowa, and Oklahoma; it did not tabulate the initial-response clock state by state — [FLAG FOR COUNSEL: confirm whether any state's initial-response or extension clock differs from 45 + 45; none surfaced in this research]. Citations: Fla. Stat. § 501.701–.722; Iowa Code ch. 715D; OK SB 546 (2026). Anchor's practice: 45 days plus one disclosed 45-day extension for requests; appeals answered in writing with reasons, within any statutory appeal window. Applicability: below threshold — honored voluntarily.
[9] UNIVERSAL OPT-OUT SIGNALS (GPC). ↩ As of 2026, twelve states require recognition of universal opt-out preference signals such as Global Privacy Control, all in force by 2026-01-01: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas (California, Colorado, and Connecticut have explicitly confirmed GPC qualifies). Louisiana becomes the thirteenth when Act 502 takes effect 2027-01-01. Oklahoma and Alabama expressly omit the requirement. Citations: the statutes listed per state in Appendix B; LA SB 386 / Act 502 (2026); OK SB 546 (2026); AL HB 351 (2026). Anchor's practice: Anchor does not sell personal data and does not share it for cross-context behavioral advertising, so the signal's request is honored by default — there is nothing to opt out of (§8). Applicability: below threshold in all twelve mandate states (Connecticut binding from 2026-07-01); the posture satisfies the duty as written either way.
[10] NON-DISCRIMINATION / NON-RETALIATION. ↩ Enacted comprehensive state privacy laws prohibit discriminating against consumers for exercising privacy rights — denying service, charging different prices, or degrading quality. The roster did not separately verify a non-discrimination clause statute by statute — [FLAG FOR COUNSEL: confirm per-state non-discrimination clauses; the duty is standard across the enacted laws]. Citations: the statutes listed per state in Appendix B. Anchor's practice: §8's no-retaliation commitment — no loss of features, quality, or price — applies unconditionally to every user and every request, so per-state variance does not change the drafting. Applicability: comprehensive-law duties below threshold — honored voluntarily.
[11] MINORS' PROVISIONS. ↩ Anchor's floor is 13+ (§11), under-18 users require parent/guardian acceptance of the Terms of Service, and Anchor sells no data and serves no targeted advertising — so the consent-gated practices below simply never occur. The state-by-state variation, for completeness:
- Known child's (<13) data treated as sensitive, COPPA-aligned parental consent: Alabama (2027-05-01), Indiana, Iowa, Kentucky, Minnesota, Nebraska, Oklahoma (2027-01-01), Rhode Island, Tennessee, Texas, and Virginia; Utah requires parental consent for known <13; Connecticut applies a willful-disregard standard for <13.
- Teen consent regimes: California — opt-in consent to sale/share for consumers under 16 (parental consent under 13); Delaware — consent for targeted ads/sale for known consumers 13–17; New Hampshire — consent for targeted ads/sale for known 13–16; New Jersey — no targeted ads, sale, or profiling for known 13–16 without consent.
- Flat bans consent cannot cure: Connecticut — sale and targeted advertising to under-18s prohibited regardless of consent (plus profiling/geolocation limits); Maryland — no targeted advertising and no sale for known under-18s.
- Montana — threshold-free minor provisions: SB 297 (2025, effective 2025-10-01) applies its minor protections with no volume threshold to anyone doing business in Montana: a duty of reasonable care to avoid heightened risk of harm to under-18s, plus consent for targeted ads/sale/profiling. The consent duties are vacuous for Anchor (it does none of those things); the duty of reasonable care applies to known minor users — [FLAG FOR COUNSEL: confirm the scope of the reasonable-care duty for a 13+ general-audience service].
- Oregon: HB 2008 bans the sale of data of consumers under 16 from 2026-01-01.
- Arkansas: Children & Teens' Online Privacy Protection Act, HB 1717 / Act 952 (2025), effective 2026-07-01 — a COPPA-style regime covering under-13s plus teens 13–16, applying with no volume threshold to operators directed at, or with actual knowledge of, child or teen users; includes a targeted-ads collection ban — [FLAG FOR COUNSEL: confirm Anchor's obligations as a 13+ general-audience service with potential actual knowledge of 13–16 users].
- Design-code laws: Nebraska AADC (LB 504), effective 2026-01-01; Vermont AADC, S.69 / Act 63 (2025), effective 2027-01-01 (AG rulemaking spring 2026) — high-privacy defaults and collection/sharing limits for services likely accessed by minors. The roster carries headline detail only — [FLAG FOR COUNSEL: assess AADC applicability to Anchor before the Vermont effective date].
- Florida: strong minor provisions, including the separate HB 3 online protections for minors.
Citations: the statutes listed per state in Appendix B; MT SB 384 as amended by SB 297 (2025); OR SB 619 as amended by HB 2008; AR HB 1717 / Act 952 (2025); NE LB 504; VT S.69 / Act 63 (2025); FL HB 3. Anchor's practice: 13+ floor, prompt deletion of any discovered under-13 account, parental ToS acceptance for under-18s, no sale, no targeted advertising, no profiling producing legal effects — the gated practices are absent by construction (§11). Applicability: the comprehensive-law minor provisions are below threshold — honored voluntarily; the threshold-free regimes (Montana minors, Arkansas Act 952, Connecticut from 2026-07-01, and the Nebraska/Vermont AADCs) are flagged above for attorney confirmation.
Appendix B — State Coverage Table (50 States + DC)
Status of comprehensive consumer privacy legislation in every US state and the District of Columbia, verified 2026-06-10 (sources and method per the Appendix A preamble; the same pin-cite caveat applies). Counting note: 23 comprehensive(-style) statutes are enacted including Florida (whose $1B threshold leads some trackers to exclude it); 20 are in force today — Oklahoma and Louisiana take effect 2027-01-01 and Alabama 2027-05-01; states without one are marked with exactly one of two status terms — "No state law" or "No comprehensive law (sectoral only)" where sectoral statutes were the reason for the distinction. The Washington and Nevada rows also carry their consumer-health-data laws, which are not "comprehensive" statutes but bind Anchor today at any size (note [3]).
| State | Statute | Effective | Threshold | Applies to Anchor today? | Note refs |
|---|---|---|---|---|---|
| Alabama | Alabama Personal Data Protection Act (APDPA), HB 351 (2026) | Enacted; effective 2027-05-01 | >25k consumers OR >25% gross revenue from sale | Not yet effective; below threshold once effective — will honor voluntarily | [4] [6] [9] [11] |
| Alaska | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Arizona | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Arkansas | No comprehensive law. Minors-only: Children & Teens' Online Privacy Protection Act, HB 1717 / Act 952 (2025) | Act 952: 2026-07-01 | Act 952: no volume threshold (operators directed at / actual knowledge of child or teen users) | No comprehensive law (sectoral only); [FLAG FOR COUNSEL: review the Act 952 minors regime] (note [11]) | [11] |
| California | CCPA as amended by CPRA, Cal. Civ. Code § 1798.100 et seq.; 2026: ADMT regs, SB 361, AB 45 | 2020-01-01 (CPRA 2023-01-01; 2026 additions 2026-01-01) | ~$26.6M indexed revenue OR 100k consumers/households OR 50%+ revenue from sale/share | Below threshold — honored voluntarily | [1] [2] [3] [4] [6] [7] [9] [11] |
| Colorado | Colorado Privacy Act (CPA), SB 21-190, C.R.S. § 6-1-1301 et seq. | 2023-07-01 | 100k consumers/yr OR 25k + any revenue/discount from sale | Below threshold — honored voluntarily | [4] [9] |
| Connecticut | Connecticut Data Privacy Act (CTDPA), SB 6 (2022), Conn. Gen. Stat. § 42-515 et seq.; overhauled by SB 1295 (2025) | 2023-07-01; SB 1295 changes 2026-07-01 | From 2026-07-01: 35k consumers, OR no threshold if processing sensitive data or offering personal data for sale | BINDING from 2026-07-01 (Anchor processes sensitive data); below threshold until then | [3] [4] [9] [11] |
| Delaware | Delaware Personal Data Privacy Act (DPDPA), HB 154 (2023), 6 Del. C. ch. 12D | 2025-01-01 | 35k consumers OR 10k + >20% revenue from sale | Below threshold — honored voluntarily (HB 380 amendment pending — re-check) | [4] [9] [11] |
| Florida | Florida Digital Bill of Rights (FDBR), SB 262 (2023), Fla. Stat. § 501.701–.722 | 2024-07-01 | $1B+ global revenue AND ad/app-store/smart-speaker criteria | Below threshold — honored voluntarily | [4] [6] [8] [11] |
| Georgia | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Hawaii | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Idaho | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Illinois | No comprehensive law (SB 340 passed Senate 2026-05-21 but not enacted). Sectoral: BIPA (biometrics), GIPA (genetic) | — | — | No comprehensive law (sectoral only) — rights honored voluntarily | — |
| Indiana | Indiana Consumer Data Protection Act (ICDPA), SB 5 (2023), Ind. Code art. 24-15 | 2026-01-01 | 100k consumers OR 25k + >50% revenue from sale | Below threshold — honored voluntarily | [4] [11] |
| Iowa | Iowa Consumer Data Protection Act, SF 262 (2023), Iowa Code ch. 715D | 2025-01-01 | 100k consumers OR 25k + >50% revenue from sale | Below threshold — honored voluntarily | [4] [5] [6] [8] [11] |
| Kansas | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Kentucky | Kentucky Consumer Data Protection Act (KCDPA), HB 15 (2024), KRS § 367.3611 et seq.; amended by HB 473 | 2026-01-01 | 100k consumers OR 25k + >50% revenue from sale | Below threshold — honored voluntarily | [4] [11] |
| Louisiana | Louisiana Data Privacy Act, SB 386 / Act 502 (2026) | Enacted; effective 2027-01-01 | $25M+ revenue OR 75k consumers/households/devices OR 50%+ revenue from sale | Not yet effective; below threshold once effective — will honor voluntarily | [4] [6] [9] |
| Maine | No comprehensive law. Sectoral: broadband/ISP privacy, 35-A M.R.S. § 9301 | — | — | No comprehensive law (sectoral only) — rights honored voluntarily | — |
| Maryland | Maryland Online Data Privacy Act (MODPA), SB 541 (2024), Md. Code, Com. Law § 14-4601 et seq. | 2025-10-01 (processing from 2026-04-01) | 35k consumers OR 10k + >20% revenue from sale | Below threshold — honored voluntarily | [4] [9] [11] |
| Massachusetts | No comprehensive law. Sectoral: 201 CMR 17.00 data-security regulations | — | — | No comprehensive law (sectoral only) — rights honored voluntarily | — |
| Michigan | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Minnesota | Minnesota Consumer Data Privacy Act (MCDPA), HF 4757 (2024), Minn. Stat. ch. 325O | 2025-07-31 | 100k consumers OR 25k + >25% revenue from sale; SBA small businesses exempt except sensitive-data-sale consent | Exempt (SBA small business); sensitive-sale rule N/A (no sale) — honored voluntarily | [4] [9] [11] |
| Mississippi | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Missouri | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Montana | Montana Consumer Data Privacy Act (MTCDPA), SB 384 (2023), Mont. Code Ann. tit. 30, ch. 14, pt. 28; amended by SB 297 (2025) | 2024-10-01; SB 297 changes 2025-10-01 | 25k consumers OR 15k + >25% revenue from sale; minor provisions: no volume threshold | Below threshold for general provisions — honored voluntarily; threshold-free minor provisions flagged (note [11]) | [4] [9] [11] |
| Nebraska | Nebraska Data Privacy Act (NDPA), LB 1074 (2024); separate AADC (LB 504) effective 2026-01-01 | 2025-01-01 | No volume threshold (TX model); SBA small businesses exempt except sensitive-data-sale consent | Exempt (SBA small business); sensitive-sale rule N/A (no sale) — honored voluntarily; AADC flagged (note [11]) | [4] [9] [11] |
| Nevada | No comprehensive law. Sectoral: NRS 603A website-operator sale opt-out. Health: SB 370 (2023), NRS ch. 603A — consumer health data | SB 370: 2024-03-31 | SB 370: no threshold, no small-business exemption | SB 370 BINDING today (check-ins, test results, ADHD notes are consumer health data; AG-enforced); no comprehensive law otherwise | [3] |
| New Hampshire | New Hampshire Privacy Act, SB 255 (2024), RSA ch. 507-H | 2025-01-01 | 35k consumers OR 10k + >25% revenue from sale | Below threshold — honored voluntarily | [4] [9] [11] |
| New Jersey | New Jersey Data Privacy Act (NJDPA), SB 332 (2024), N.J. Stat. § 56:8-166.4 et seq. | 2025-01-15 | 100k consumers OR 25k + any revenue/discount from sale | Below threshold — honored voluntarily | [4] [9] [11] |
| New Mexico | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| New York | No comprehensive law. NYHIPA vetoed 2025-12-19; successor S9269 pending. Sectoral: SHIELD Act (data security), GBL 399-ddd | — | — | No comprehensive law (sectoral only) — rights honored voluntarily; re-check S9269 before each revision (note [3]) | [3] |
| North Carolina | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| North Dakota | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Ohio | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Oklahoma | Oklahoma consumer privacy law, SB 546 (2026) | Enacted; effective 2027-01-01 | 100k consumers OR 25k + >50% revenue from sale | Not yet effective; below threshold once effective — will honor voluntarily | [4] [6] [7] [8] [9] [11] |
| Oregon | Oregon Consumer Privacy Act (OCPA), SB 619 (2023), ORS 646A.570 et seq.; amended by HB 2008 | 2024-07-01; HB 2008 changes 2026-01-01 | 100k consumers OR 25k + >25% revenue from sale | Below threshold — honored voluntarily; HB 2008 geolocation-sale ban N/A (no geolocation, no sale) | [4] [9] [11] |
| Pennsylvania | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Rhode Island | RI Data Transparency and Privacy Protection Act (RIDTPPA), H 7787 / S 2500 (2024), R.I. Gen. Laws ch. 6-48.1 | 2026-01-01 | 35k consumers OR 10k + >20% revenue from sale | Below threshold — honored voluntarily | [4] [11] |
| South Carolina | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| South Dakota | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Tennessee | Tennessee Information Protection Act (TIPA), HB 1181 (2023), Tenn. Code § 47-18-3201 et seq. | 2025-07-01 | $25M+ revenue AND (175k consumers OR 25k + >50% revenue from sale) | Below threshold — honored voluntarily | [4] [11] |
| Texas | Texas Data Privacy and Security Act (TDPSA), HB 4 (2023), Tex. Bus. & Com. Code ch. 541 | 2024-07-01 | No volume threshold; SBA small businesses exempt (consent still required to sell sensitive data) | Exempt (SBA small business); sensitive-sale rule N/A (no sale) — honored voluntarily | [4] [9] [11] |
| Utah | Utah Consumer Privacy Act (UCPA), SB 227 (2022), Utah Code § 13-61-101 et seq. | 2023-12-31; correction amendment 2026-07-01 | $25M+ revenue AND (100k consumers OR 25k + 50% revenue from sale) | Below threshold (fails conjunctive revenue prong) — honored voluntarily | [4] [5] [6] [11] |
| Vermont | No comprehensive law (S.71 pending). Minors-only: AADC, S.69 / Act 63 (2025). Sectoral: data-broker registration | AADC: 2027-01-01 | AADC: services likely accessed by minors | No comprehensive law (sectoral only); [FLAG FOR COUNSEL: assess AADC applicability] (note [11]) | [11] |
| Virginia | Virginia Consumer Data Protection Act (VCDPA), SB 1392 (2021), Va. Code § 59.1-575 et seq. Health: SB 754 (2025), amending the VA Consumer Protection Act — reproductive/sexual health | VCDPA: 2023-01-01; SB 754: 2025-07-01 | VCDPA: 100k consumers OR 25k + >50% revenue from sale; SB 754: no threshold | VCDPA below threshold — honored voluntarily. SB 754 binding today but scoped to data Anchor does not solicit (note [3]) | [3] [4] [11] |
| Washington | No comprehensive law. Health: My Health My Data Act (MHMD), HB 1155 (2023), RCW ch. 19.373 — consumer health data | MHMD: 2024-03-31 (small businesses 2024-06-30; geofencing ban 2023-07-23) | MHMD: no threshold, no small-business exemption | MHMD BINDING today (check-ins, test results, ADHD notes are consumer health data; private right of action); no comprehensive law otherwise | [3] |
| West Virginia | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Wisconsin | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| Wyoming | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
| District of Columbia | No comprehensive law (as of 2026-06) | — | — | No state law — rights honored voluntarily | — |
In every state and DC — including every "no comprehensive law" row above — Section 5 of the FTC Act (unfair or deceptive acts or practices) applies to Anchor's privacy representations: the promises in this policy are federally enforceable everywhere, with or without a state statute.