Anchor Privacy Policy

Version: 1.0 (draft)
Status: DRAFT — PENDING ATTORNEY REVIEW. Not yet in effect.
Effective date: [to be set at publication]
Data controller: [ANCHOR ENTITY NAME, LLC — TO BE CONFIRMED BY COUNSEL], a Utah limited liability company ("Anchor," "we," "us")
Contact: wordsmith.alex@gmail.com

Numbered notes like [1] point to state-law variations collected in Appendix A. The body of this policy tells you what we actually do; the appendix tells your lawyer (or your curiosity) which state laws say what.


1. Who we are

Anchor is a focus timer built for brains that don't queue tasks neatly — ADHD brains especially. It runs on Windows, Android, and the web. It helps you pick one thing, break it into steps, and start.

Anchor is made and operated by [ANCHOR ENTITY NAME, LLC — TO BE CONFIRMED BY COUNSEL], a Utah limited liability company. In this policy, "Anchor," "we," and "us" mean that company, and "you" means you — the person using the app.

This policy covers the Anchor desktop app, the Anchor Android app, the Anchor web app, and the sync service behind them. It does not cover third-party websites we might link to.

One thing to know up front: Anchor works locally first. If you never create a sync account, your data lives on your device and almost none of this policy comes into play.

2. The short version

We collect what we need to hand you your next step. Nothing more.

The rest of this policy is the same story with the precision a legal document needs.

3. What we collect (and what we do not)

If you never sign in

Anchor stores everything in a local database on your device: tasks, sessions, check-ins, settings, all of it. We can't see any of it. The only network calls the app makes without an account are checking for app updates and pulling shared content (insight articles, toolkit exercises, the game catalog) — requests that don't include your content or identity (like any internet request, they necessarily expose your IP address to our server).

When you create a sync account

We store, on our server:

What stays on your device, always

Some things never sync, by design: brain dump items, distraction entries, and mobile crash logs. They live only in your local database (or, for crash logs, a local file) and we never receive them.

What we do not collect

We do not collect your location, contacts, browsing history, or advertising identifiers. We use no analytics or tracking SDKs, no advertising networks, and no tracking cookies.

There is no hidden second list. California residents: a notice-at-collection table mapping categories to purposes, recipients, and retention is in Section 12. [1]

4. How we use it

We use the data above for exactly four things:

  1. Running the service. Storing your content, syncing it between your devices, keeping your account working, and answering you when you write to us.
  2. AI task breakdown. Sending your task text (and profile fields, if set) to our AI provider to generate suggested steps — only when you ask for a breakdown. Details in Section 5.
  3. Billing, when you choose a paid plan. When you purchase a subscription, payment is processed by Stripe — we never see your card number. We use your email and subscription status to know what plan you're on.
  4. Keeping the service safe. Watching for abuse, debugging failures, and enforcing usage quotas (that's what the token counts are for).

And the things we don't do: We do not sell your personal data. We do not share it for targeted advertising. Your task content is never used to train AI models. [2]

5. AI processing disclosure

When you press the breakdown button, here is exactly what happens:

This only happens when you ask for a breakdown. Type your own steps and nothing is sent anywhere.

Anthropic is currently our only AI provider. We will update this policy before adding any other AI provider.

Because your ADHD notes and other profile fields can ride along in a breakdown request, the consent you give for health-adjacent data (Section 6) covers this transmission too. [3]

6. Sensitive data & consent

Some of what Anchor invites you to create is, candidly, health-related or close to it: daily check-in responses (which ask about anxiety, sleep, emotions, and similar), personality test results, and your ADHD notes and other profile fields. Several states treat data like this as "sensitive data" or "consumer health data" and require your affirmative consent before a company processes it. [4] Washington, Nevada, and (from July 1, 2026) Connecticut have health-data laws that cover this kind of data and apply to us at any size — Section 12 has their specific disclosures. (Virginia has a fourth any-size health law, but it's narrower and doesn't reach anything Anchor asks you for; Appendix A explains.) [3]

Here is our consent model, plainly:

We use this data for one purpose: showing it back to you and tailoring the app to you (which insights you see first, how breakdowns are phrased). We never use it for advertising, never sell it, and never disclose it except as Section 7 describes.

7. Sharing

We share personal data with the small set of companies that help us run Anchor ("processors") — plus, for completeness, where your data actually lives — and in two narrow legal situations. That's the whole list of companies that receive your content.

Who What they receive Why When
AnthropicTask text + profile fields (if set) for a breakdown requestGenerates AI task-breakdown suggestions; barred from training on the data; we store neither request nor responseOnly when you request a breakdown
StripePayment details (card number, billing info) — handled by Stripe directly; we never see your card numberPayment processing for subscriptionsWhen you purchase a subscription
ResendYour email address and the contents of the messageDelivering transactional email (e.g., password resets, receipts)When we send you account email
Our own serverEverything in Section 3's synced listAnchor's sync service and database run on infrastructure we operate ourselves — there is no third-party cloud provider with access to your contentWhile you have a sync account

One infrastructure note: the web version of Anchor loads its runtime files (the Blazor framework) from Microsoft's content delivery network — a standard framework download that carries no Anchor account data, though like any web request it exposes your IP address to Microsoft. The desktop and Android apps make no such request. [FLAG FOR COUNSEL: confirm the Microsoft CDN framework-load disclosure is sufficient (web client only)]

Two legal situations:

No one else. We do not sell personal data, and we do not share it for cross-context behavioral advertising. [2]

8. Your rights & how to exercise them

State privacy laws grant different rights to residents of different states. We think that's a silly way to treat people, so we grant the same set to every Anchor user, wherever you live:

How to exercise them: email wordsmith.alex@gmail.com from the email address on your account and tell us what you want. You can also have someone act for you (an authorized agent) if you give them written permission — we'll verify with you directly before acting. [7]

How we verify it's you: we match the request to the email address on the account; if anything looks off, we'll ask you to confirm a detail about the account (such as your plan or a recent sign-in) before acting. We will never ask for your password.

How fast: we respond within 45 days. If a request is genuinely complicated, the law lets us take one extension of another 45 days — if we need it, we'll tell you within the first 45 and explain why. [8]

Browser privacy signals: some browsers send a universal opt-out signal such as Global Privacy Control, which tells companies not to sell or share your data. [9] Since we don't sell or share personal data for advertising in the first place, the signal asks for something that's already true — you're covered whether your browser sends it or not.

No retaliation: exercising any of these rights will never cost you features, quality, or price. [10]

9. Retention & deletion

We keep your synced data for as long as your account is active, so the service can do its job. We don't have a "keep it just in case" pile — what's listed in Section 3 is what exists.

When you ask us to delete your account (Section 8), we delete your data from our live systems within 30 days of verifying the request. That includes soft-deleted rows — records the sync system has marked deleted but not yet physically removed. Deleted means deleted, not hidden.

One honest caveat: copies of data may persist in our routine backups for a short period after live deletion, until those backups rotate out and are destroyed in the ordinary course. Backups are used only for disaster recovery — we will not restore your deleted data into live systems, and if a restore from backup ever happened, we would re-delete your data as part of it. Washington residents have a statutory right to deletion that reaches backups; see Section 12.

Data that never synced (Section 3) is yours to delete locally — uninstalling the app or clearing its data removes it, and we never had a copy.

10. Security

Here is where security stands today, honestly:

If you find a security problem in Anchor, please tell us at wordsmith.alex@gmail.com — we read those first.

11. Children & teens

Anchor is for people 13 and older. We do not knowingly collect personal data from anyone under 13. If we learn we have — for example, a parent writes in, or an account self-identifies — we will delete the account and its data promptly.

If you are under 18, our Terms of Service require a parent or guardian to accept them on your behalf.

Some states give extra protections to minors under 16 or under 18 — typically requiring opt-in consent before a company sells their data or shows them targeted advertising, and in some states banning those practices for minors outright. [11] Because we sell no one's data and show no one targeted advertising, those protections are already built into how Anchor works for every user, of every age.

12. US state-specific disclosures

Many state privacy laws apply only to companies above certain size thresholds, which Anchor is currently below. Rather than make you figure out which law covers you, we extend the rights in Section 8 to everyone and honor the state-law standards voluntarily. Four data-privacy laws apply to us regardless of size — Washington's and Nevada's consumer-health-data laws, Virginia's reproductive- and sexual-health-data law (whose narrow scope covers data Anchor does not ask you for — details in Appendix A), and (from July 1, 2026) Connecticut's data privacy act (threshold-free minor-protection laws are covered in Section 11 and note [11]). Disclosures for Washington, Nevada, and Connecticut are below; Virginia's, given that narrow scope, lives in Appendix A. The full state-by-state mapping, including statute citations and which laws bind us today, is in Appendix A and Appendix B.

California (notice at collection) [1]

California residents are entitled to know, at or before collection, the categories we collect, why, who receives them, and how long we keep them:

Category What it includes Why we collect it Who receives it How long we keep it
IdentifiersEmail address, optional display name, preferred nameAccount creation, sign-in, contacting youUs; Resend when we email you; Stripe if you subscribe; Anthropic (profile fields, when you request a breakdown)While your account is active; deleted within 30 days of a verified deletion request
Account credentialsPassword (bcrypt hash only)AuthenticationUs onlySame as above
Content you createTasks, focus sessions, game completionsProviding and syncing the serviceUs; Anthropic receives task text only when you request a breakdownSame as above
Sensitive personal information (health-adjacent)Daily check-in responses, personality test results, ADHD notes, energy pattern, life contextShowing your data back to you; tailoring the app; phrasing AI breakdownsUs; Anthropic receives profile fields only when you request a breakdownSame as above
Device informationDevice name in active-session presenceKeeping your devices in syncUs onlyFor the life of the session record
Usage metadataAI breakdown token countsQuota enforcement, abuse preventionUs onlyWhile your account is active

We do not "sell" or "share" personal information as the CCPA defines those terms — including "sharing" for cross-context behavioral advertising — and have not in the preceding 12 months. [2] We use sensitive personal information only to provide the service you asked for, which means California's right to limit its use is already satisfied by default. [4] We honor Global Privacy Control signals as described in Section 8. [9]

Washington and Nevada (consumer health data) [3]

Washington's My Health My Data Act and Nevada's SB 370 protect "consumer health data" — and they apply to businesses of every size, with no small-business exemption, so they bind Anchor today. Your daily check-in responses, personality test results, and ADHD notes qualify as consumer health data under these laws.

For Washington and Nevada residents, with respect to that data:

To exercise these rights, use the process in Section 8.

Connecticut (from July 1, 2026)

From July 1, 2026, Connecticut's Data Privacy Act applies to any company that processes sensitive data — with no size threshold — and your check-ins, personality results, and ADHD notes are sensitive data under it (data concerning mental or physical health condition or diagnosis). For Connecticut residents: we process sensitive data only with your opt-in consent (Section 6) and only as reasonably necessary to provide the service; we do not and will not sell sensitive data; and you have all the rights in Section 8, including appeal. [3] [4]

Everyone else

Residents of every other state get the same rights (Section 8) and the same practices (Sections 3–11). The numbered notes throughout this policy, resolved in Appendix A, document where individual state laws differ from the defaults stated here — including consent models [4], correction and appeal variations [5] [6], opt-out signal mandates [9], and minors' provisions [11].

13. EEA, United Kingdom, and Switzerland

If you are in the European Economic Area, the UK, or Switzerland, this section supplements the rest of the policy. The data controller is [ANCHOR ENTITY NAME, LLC — TO BE CONFIRMED BY COUNSEL], reachable at wordsmith.alex@gmail.com.

Legal bases (GDPR Article 6). We process personal data on these bases, mapped to purpose:

Special category data (Article 9). Check-in responses, personality test results, and ADHD notes can constitute health data. We process them only with your explicit consent (Art. 9(2)(a)), given through the deliberate, optional steps described in Section 6 — creating the data, enabling sync, signing in. You can withdraw that consent at any time.

Your rights (Articles 15–22). Access, rectification, erasure, restriction of processing, data portability, objection (including to legitimate-interest processing), and the right not to be subject to solely automated decisions producing legal or similarly significant effects — which Anchor does not make; AI breakdown produces suggestions you are free to ignore. Exercise any of these via the process in Section 8.

International transfers. Our servers are in the United States, so your data is transferred there. We rely on Standard Contractual Clauses with our processors for onward transfers. [FLAG FOR COUNSEL: confirm transfer mechanism — SCCs vs. EU–US Data Privacy Framework certification — before publication.]

Complaints. You have the right to lodge a complaint with a supervisory authority — in the EEA, the authority of your member state; in the UK, the Information Commissioner's Office. We'd appreciate the chance to fix the problem first, but you don't owe us that.

14. Changes to this policy

When we change this policy in a way that matters — new data collected, new sharing, new purposes — we will email you and show a notice in the app at least 30 days before the change takes effect, so you can read it, ask us about it, or request an export of your data and leave before it applies to you. Minor clarifications that don't change what we do may take effect on posting, with the version number and date updated above.

We keep prior versions in version control; ask and we'll show you exactly what changed.

15. Contact

Questions, requests, complaints, corrections: wordsmith.alex@gmail.com. A human reads it — the same one who built the app.

Postal address: available on request while our registered address is being finalized with the entity formation noted in the header.


Appendix A — State Law Notes

These notes resolve the numbered markers [1][11] in the body. They are written for attorney review, not for warmth. Research basis: internal roster docs/legal/research/state-law-roster-2026-06.md, verified 2026-06-10 against the IAPP US State Privacy Legislation Tracker (snapshot 2026-06-08), the Termly 50-state tracker, MultiState's 2026 effective-dates roundup, and per-state primary or law-firm sources. Open items are marked [FLAG FOR COUNSEL: …] throughout.

Citation caveat (applies to every note below): bill numbers, effective dates, and thresholds were web-verified 2026-06-10. Code-section citations (e.g., "Va. Code § 59.1-575 et seq.") are standard published citations carried from a training-data baseline and spot-checked, not independently re-pulled from each state code — [FLAG FOR COUNSEL: confirm pin cites before publication].

Open items for counsel — every unresolved item in this document, indexed:

  1. Entity name: [ANCHOR ENTITY NAME, LLC — TO BE CONFIRMED BY COUNSEL] placeholder — header, §1, §13.
  2. Effective date: [to be set at publication] — header.
  3. Confirm the Microsoft CDN framework-load disclosure is sufficient (web client only) — §7.
  4. Confirm international transfer mechanism (SCCs vs. EU–US Data Privacy Framework) before publication — body §13, International transfers.
  5. Confirm code-section pin cites before publication — Appendix A preamble (citation caveat).
  6. Confirm the notice-at-collection pin cite — note [1].
  7. Confirm no other state imposes a notice-at-collection duty in California's form — note [1].
  8. Confirm which states define "sale" more narrowly than California — note [2].
  9. Confirm the treatment of user-volunteered in-scope free text under VA SB 754 — note [3], Virginia bullet.
  10. Confirm the tailoring uses in §6 satisfy MODPA's strictly-necessary standard — note [4].
  11. Confirm Louisiana's appeal and portability rights against the enrolled bill, and Alabama's portability right — note [6].
  12. Confirm per-state authorized-agent provisions if precision is needed — note [7].
  13. Confirm whether any state's initial-response or extension clock differs from 45 + 45 — note [8].
  14. Confirm per-state non-discrimination clauses — note [10].
  15. Confirm the scope of Montana's reasonable-care duty for a 13+ general-audience service — note [11], Montana bullet.
  16. Confirm Anchor's obligations under Arkansas Act 952 — note [11], Arkansas bullet.
  17. Assess AADC applicability (Nebraska LB 504, Vermont Act 63) before the Vermont effective date — note [11], design-code bullet.
  18. Review the Act 952 minors regime — Appendix B, Arkansas row (same substance as item 16).
  19. Assess AADC applicability — Appendix B, Vermont row (same substance as item 17).
  20. Publication step: strip or rehost the internal repository path cited in this appendix before publication (research roster).

[1] CALIFORNIA NOTICE AT COLLECTION. California alone requires a business to tell consumers, at or before the point of collection, the categories of personal information collected, the purposes, the recipients, and the retention period for each category. The Section 12 California table exists to satisfy that duty; no other state requires the disclosure in that form. The exclusivity of this duty is carried from the drafting spec, not verified state-by-state — [FLAG FOR COUNSEL: confirm no other state imposes a notice-at-collection duty in this form]. Citations: CCPA as amended by CPRA, Cal. Civ. Code § 1798.100 et seq.; 2026 additions (CCPA ADMT and risk-assessment regulations, SB 361 data brokers, AB 45 health/geofencing) effective 2026-01-01. The roster carries the citation at the "§ 1798.100 et seq." level — [FLAG FOR COUNSEL: confirm the notice-at-collection pin cite]. Anchor's practice: the §12 table is published for all users, not gated by residence. Applicability: Anchor is far below every CCPA threshold ($25M-indexed annual revenue (~$26.6M) OR 100k consumers/households OR 50%+ revenue from selling/sharing personal information) — honored voluntarily.

[2] "SALE" AND "SHARE" DEFINITIONS. California has the broadest definitions, and the body is drafted to hold under them:

Citations: Cal. Civ. Code § 1798.100 et seq. Anchor's practice: no sale, no sharing, and task content never used to train AI models (Anthropic's commercial API terms prohibit training on the data). Applicability: California below threshold — honored voluntarily; the no-sale posture also discharges the surviving small-business sensitive-data-sale consent rules in Texas (TDPSA), Nebraska (NDPA), and Minnesota (MCDPA), and moots Maryland's flat ban on selling sensitive data (note [4]).

[3] CONSUMER-HEALTH-DATA LAWS THAT BIND AT ANY SIZE (WA / NV / CT / VA). Anchor's daily check-in responses, personality test results, and free-text ADHD notes are "consumer health data" or sensitive health data under the laws below, all of which apply with no revenue or volume threshold:

Adjacent items from the same research: California AB 45 (2025, effective 2026-01-01) adds health-data geolocation/geofencing protections within the CCPA framework — not applicable today because Anchor collects no location data (§3). New York: no consumer-health-data law in force — see the New York row in Appendix B (NYHIPA vetoed; successor S9269 pending — re-check before each revision).

Anchor's practice: §6's opt-in-by-design consent (you create the data, you enable sync, you sign in) covers collection and the Anthropic transmission (§5); §12 carries the WA/NV/CT-specific disclosures; §9's deletion commitment reaches backups for Washington residents. Applicability: WA MHMD and NV SB 370 are binding today; CT CTDPA is binding from 2026-07-01; VA SB 754 is technically binding today but scoped to data Anchor does not solicit.

[4] SENSITIVE-DATA CONSENT MODELS. The states split four ways on processing sensitive data (which, for Anchor, means the health-adjacent items in §6):

Citations: the statutes listed per state in Appendix B (e.g., Colorado CPA, C.R.S. § 6-1-1301 et seq.; CTDPA, Conn. Gen. Stat. § 42-515 et seq., as amended by SB 1295; MODPA, Md. Code, Com. Law § 14-4601 et seq.; Iowa Code ch. 715D; Utah Code § 13-61-101 et seq.; LA SB 386 / Act 502 (2026); OK SB 546 (2026); AL HB 351 (2026)). Anchor's practice: §6 is opt-in by design — sensitive data exists only if you create it, leaves your device only if you sign in to sync, and is deletable at any time — which satisfies the strictest models on the spectrum: Maryland's strictly-necessary standard fits (the processing is necessary to deliver the service the user requested) — [FLAG FOR COUNSEL: confirm the tailoring uses in §6 satisfy MODPA's strictly-necessary standard], California's right to limit is satisfied by default (§12), and the no-sale posture moots Maryland's sale ban. Anchor also allows consent withdrawal everywhere, exceeding Louisiana's no-revocation floor. Applicability: every comprehensive law here is below threshold for Anchor — honored voluntarily — except Connecticut, binding from 2026-07-01; the WA/NV health-data consent duties (note [3]) are binding today.

[5] RIGHT-TO-CORRECT GAPS. Iowa grants no correction right at all — the only enacted state besides pre-amendment Utah without one. Utah lacks a correction right until its amendment takes effect 2026-07-01. Every other enacted state grants correction. Citations: Iowa Consumer Data Protection Act, SF 262 (2023), Iowa Code ch. 715D; Utah Consumer Privacy Act, SB 227 (2022), Utah Code § 13-61-101 et seq. (correction amendment effective 2026-07-01). Anchor's practice: §8 grants correction to every user regardless of state, and most data is correctable in-app instantly. Applicability: both states' laws are below threshold for Anchor (Iowa: 100k consumers or 25k + 50% sale revenue; Utah: $25M revenue AND a volume prong, conjunctive) — honored voluntarily, and exceeded.

[6] APPEAL-RIGHT VARIATIONS. Most enacted states require controllers to offer an appeal process for denied requests; the variations:

Citations: Cal. Civ. Code § 1798.100 et seq.; Utah Code § 13-61-101 et seq.; AL HB 351 (2026); Fla. Stat. § 501.701–.722; Iowa Code ch. 715D; OK SB 546 (2026); LA SB 386 / Act 502 (2026). Anchor's practice: §8 grants appeal — review by someone other than the original decision-maker, answered in writing with reasons — to every user. Applicability: all below threshold — honored voluntarily.

[7] AUTHORIZED AGENTS. The verified outlier is Oklahoma: SB 546 contains no authorized-agent provision at all. The affirmative agent provisions elsewhere (California's express authorized-agent mechanism; the VCDPA-model states' agent provisions for opt-out requests) are carried from the training-data baseline and were not re-verified in the roster — [FLAG FOR COUNSEL: confirm per-state agent provisions if precision is needed; Anchor's uniform practice meets or exceeds all of them]. Citation: OK SB 546 (2026), effective 2027-01-01. Anchor's practice: §8 accepts authorized agents with the user's written permission plus direct verification with the account holder, for all users and all request types. Applicability: below threshold everywhere — honored voluntarily.

[8] RESPONSE DEADLINES. Anchor commits in §8 to the dominant statutory clock: a response within 45 days, with one 45-day extension on notice and explanation. The roster confirmed 60-day appeal-response windows where an appeal is mandated in Florida, Iowa, and Oklahoma; it did not tabulate the initial-response clock state by state — [FLAG FOR COUNSEL: confirm whether any state's initial-response or extension clock differs from 45 + 45; none surfaced in this research]. Citations: Fla. Stat. § 501.701–.722; Iowa Code ch. 715D; OK SB 546 (2026). Anchor's practice: 45 days plus one disclosed 45-day extension for requests; appeals answered in writing with reasons, within any statutory appeal window. Applicability: below threshold — honored voluntarily.

[9] UNIVERSAL OPT-OUT SIGNALS (GPC). As of 2026, twelve states require recognition of universal opt-out preference signals such as Global Privacy Control, all in force by 2026-01-01: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas (California, Colorado, and Connecticut have explicitly confirmed GPC qualifies). Louisiana becomes the thirteenth when Act 502 takes effect 2027-01-01. Oklahoma and Alabama expressly omit the requirement. Citations: the statutes listed per state in Appendix B; LA SB 386 / Act 502 (2026); OK SB 546 (2026); AL HB 351 (2026). Anchor's practice: Anchor does not sell personal data and does not share it for cross-context behavioral advertising, so the signal's request is honored by default — there is nothing to opt out of (§8). Applicability: below threshold in all twelve mandate states (Connecticut binding from 2026-07-01); the posture satisfies the duty as written either way.

[10] NON-DISCRIMINATION / NON-RETALIATION. Enacted comprehensive state privacy laws prohibit discriminating against consumers for exercising privacy rights — denying service, charging different prices, or degrading quality. The roster did not separately verify a non-discrimination clause statute by statute — [FLAG FOR COUNSEL: confirm per-state non-discrimination clauses; the duty is standard across the enacted laws]. Citations: the statutes listed per state in Appendix B. Anchor's practice: §8's no-retaliation commitment — no loss of features, quality, or price — applies unconditionally to every user and every request, so per-state variance does not change the drafting. Applicability: comprehensive-law duties below threshold — honored voluntarily.

[11] MINORS' PROVISIONS. Anchor's floor is 13+ (§11), under-18 users require parent/guardian acceptance of the Terms of Service, and Anchor sells no data and serves no targeted advertising — so the consent-gated practices below simply never occur. The state-by-state variation, for completeness:

Citations: the statutes listed per state in Appendix B; MT SB 384 as amended by SB 297 (2025); OR SB 619 as amended by HB 2008; AR HB 1717 / Act 952 (2025); NE LB 504; VT S.69 / Act 63 (2025); FL HB 3. Anchor's practice: 13+ floor, prompt deletion of any discovered under-13 account, parental ToS acceptance for under-18s, no sale, no targeted advertising, no profiling producing legal effects — the gated practices are absent by construction (§11). Applicability: the comprehensive-law minor provisions are below threshold — honored voluntarily; the threshold-free regimes (Montana minors, Arkansas Act 952, Connecticut from 2026-07-01, and the Nebraska/Vermont AADCs) are flagged above for attorney confirmation.


Appendix B — State Coverage Table (50 States + DC)

Status of comprehensive consumer privacy legislation in every US state and the District of Columbia, verified 2026-06-10 (sources and method per the Appendix A preamble; the same pin-cite caveat applies). Counting note: 23 comprehensive(-style) statutes are enacted including Florida (whose $1B threshold leads some trackers to exclude it); 20 are in force today — Oklahoma and Louisiana take effect 2027-01-01 and Alabama 2027-05-01; states without one are marked with exactly one of two status terms — "No state law" or "No comprehensive law (sectoral only)" where sectoral statutes were the reason for the distinction. The Washington and Nevada rows also carry their consumer-health-data laws, which are not "comprehensive" statutes but bind Anchor today at any size (note [3]).

State Statute Effective Threshold Applies to Anchor today? Note refs
AlabamaAlabama Personal Data Protection Act (APDPA), HB 351 (2026)Enacted; effective 2027-05-01>25k consumers OR >25% gross revenue from saleNot yet effective; below threshold once effective — will honor voluntarily[4] [6] [9] [11]
AlaskaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
ArizonaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
ArkansasNo comprehensive law. Minors-only: Children & Teens' Online Privacy Protection Act, HB 1717 / Act 952 (2025)Act 952: 2026-07-01Act 952: no volume threshold (operators directed at / actual knowledge of child or teen users)No comprehensive law (sectoral only); [FLAG FOR COUNSEL: review the Act 952 minors regime] (note [11])[11]
CaliforniaCCPA as amended by CPRA, Cal. Civ. Code § 1798.100 et seq.; 2026: ADMT regs, SB 361, AB 452020-01-01 (CPRA 2023-01-01; 2026 additions 2026-01-01)~$26.6M indexed revenue OR 100k consumers/households OR 50%+ revenue from sale/shareBelow threshold — honored voluntarily[1] [2] [3] [4] [6] [7] [9] [11]
ColoradoColorado Privacy Act (CPA), SB 21-190, C.R.S. § 6-1-1301 et seq.2023-07-01100k consumers/yr OR 25k + any revenue/discount from saleBelow threshold — honored voluntarily[4] [9]
ConnecticutConnecticut Data Privacy Act (CTDPA), SB 6 (2022), Conn. Gen. Stat. § 42-515 et seq.; overhauled by SB 1295 (2025)2023-07-01; SB 1295 changes 2026-07-01From 2026-07-01: 35k consumers, OR no threshold if processing sensitive data or offering personal data for saleBINDING from 2026-07-01 (Anchor processes sensitive data); below threshold until then[3] [4] [9] [11]
DelawareDelaware Personal Data Privacy Act (DPDPA), HB 154 (2023), 6 Del. C. ch. 12D2025-01-0135k consumers OR 10k + >20% revenue from saleBelow threshold — honored voluntarily (HB 380 amendment pending — re-check)[4] [9] [11]
FloridaFlorida Digital Bill of Rights (FDBR), SB 262 (2023), Fla. Stat. § 501.701–.7222024-07-01$1B+ global revenue AND ad/app-store/smart-speaker criteriaBelow threshold — honored voluntarily[4] [6] [8] [11]
GeorgiaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
HawaiiNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
IdahoNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
IllinoisNo comprehensive law (SB 340 passed Senate 2026-05-21 but not enacted). Sectoral: BIPA (biometrics), GIPA (genetic)No comprehensive law (sectoral only) — rights honored voluntarily
IndianaIndiana Consumer Data Protection Act (ICDPA), SB 5 (2023), Ind. Code art. 24-152026-01-01100k consumers OR 25k + >50% revenue from saleBelow threshold — honored voluntarily[4] [11]
IowaIowa Consumer Data Protection Act, SF 262 (2023), Iowa Code ch. 715D2025-01-01100k consumers OR 25k + >50% revenue from saleBelow threshold — honored voluntarily[4] [5] [6] [8] [11]
KansasNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
KentuckyKentucky Consumer Data Protection Act (KCDPA), HB 15 (2024), KRS § 367.3611 et seq.; amended by HB 4732026-01-01100k consumers OR 25k + >50% revenue from saleBelow threshold — honored voluntarily[4] [11]
LouisianaLouisiana Data Privacy Act, SB 386 / Act 502 (2026)Enacted; effective 2027-01-01$25M+ revenue OR 75k consumers/households/devices OR 50%+ revenue from saleNot yet effective; below threshold once effective — will honor voluntarily[4] [6] [9]
MaineNo comprehensive law. Sectoral: broadband/ISP privacy, 35-A M.R.S. § 9301No comprehensive law (sectoral only) — rights honored voluntarily
MarylandMaryland Online Data Privacy Act (MODPA), SB 541 (2024), Md. Code, Com. Law § 14-4601 et seq.2025-10-01 (processing from 2026-04-01)35k consumers OR 10k + >20% revenue from saleBelow threshold — honored voluntarily[4] [9] [11]
MassachusettsNo comprehensive law. Sectoral: 201 CMR 17.00 data-security regulationsNo comprehensive law (sectoral only) — rights honored voluntarily
MichiganNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
MinnesotaMinnesota Consumer Data Privacy Act (MCDPA), HF 4757 (2024), Minn. Stat. ch. 325O2025-07-31100k consumers OR 25k + >25% revenue from sale; SBA small businesses exempt except sensitive-data-sale consentExempt (SBA small business); sensitive-sale rule N/A (no sale) — honored voluntarily[4] [9] [11]
MississippiNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
MissouriNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
MontanaMontana Consumer Data Privacy Act (MTCDPA), SB 384 (2023), Mont. Code Ann. tit. 30, ch. 14, pt. 28; amended by SB 297 (2025)2024-10-01; SB 297 changes 2025-10-0125k consumers OR 15k + >25% revenue from sale; minor provisions: no volume thresholdBelow threshold for general provisions — honored voluntarily; threshold-free minor provisions flagged (note [11])[4] [9] [11]
NebraskaNebraska Data Privacy Act (NDPA), LB 1074 (2024); separate AADC (LB 504) effective 2026-01-012025-01-01No volume threshold (TX model); SBA small businesses exempt except sensitive-data-sale consentExempt (SBA small business); sensitive-sale rule N/A (no sale) — honored voluntarily; AADC flagged (note [11])[4] [9] [11]
NevadaNo comprehensive law. Sectoral: NRS 603A website-operator sale opt-out. Health: SB 370 (2023), NRS ch. 603A — consumer health dataSB 370: 2024-03-31SB 370: no threshold, no small-business exemptionSB 370 BINDING today (check-ins, test results, ADHD notes are consumer health data; AG-enforced); no comprehensive law otherwise[3]
New HampshireNew Hampshire Privacy Act, SB 255 (2024), RSA ch. 507-H2025-01-0135k consumers OR 10k + >25% revenue from saleBelow threshold — honored voluntarily[4] [9] [11]
New JerseyNew Jersey Data Privacy Act (NJDPA), SB 332 (2024), N.J. Stat. § 56:8-166.4 et seq.2025-01-15100k consumers OR 25k + any revenue/discount from saleBelow threshold — honored voluntarily[4] [9] [11]
New MexicoNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
New YorkNo comprehensive law. NYHIPA vetoed 2025-12-19; successor S9269 pending. Sectoral: SHIELD Act (data security), GBL 399-dddNo comprehensive law (sectoral only) — rights honored voluntarily; re-check S9269 before each revision (note [3])[3]
North CarolinaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
North DakotaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
OhioNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
OklahomaOklahoma consumer privacy law, SB 546 (2026)Enacted; effective 2027-01-01100k consumers OR 25k + >50% revenue from saleNot yet effective; below threshold once effective — will honor voluntarily[4] [6] [7] [8] [9] [11]
OregonOregon Consumer Privacy Act (OCPA), SB 619 (2023), ORS 646A.570 et seq.; amended by HB 20082024-07-01; HB 2008 changes 2026-01-01100k consumers OR 25k + >25% revenue from saleBelow threshold — honored voluntarily; HB 2008 geolocation-sale ban N/A (no geolocation, no sale)[4] [9] [11]
PennsylvaniaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
Rhode IslandRI Data Transparency and Privacy Protection Act (RIDTPPA), H 7787 / S 2500 (2024), R.I. Gen. Laws ch. 6-48.12026-01-0135k consumers OR 10k + >20% revenue from saleBelow threshold — honored voluntarily[4] [11]
South CarolinaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
South DakotaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
TennesseeTennessee Information Protection Act (TIPA), HB 1181 (2023), Tenn. Code § 47-18-3201 et seq.2025-07-01$25M+ revenue AND (175k consumers OR 25k + >50% revenue from sale)Below threshold — honored voluntarily[4] [11]
TexasTexas Data Privacy and Security Act (TDPSA), HB 4 (2023), Tex. Bus. & Com. Code ch. 5412024-07-01No volume threshold; SBA small businesses exempt (consent still required to sell sensitive data)Exempt (SBA small business); sensitive-sale rule N/A (no sale) — honored voluntarily[4] [9] [11]
UtahUtah Consumer Privacy Act (UCPA), SB 227 (2022), Utah Code § 13-61-101 et seq.2023-12-31; correction amendment 2026-07-01$25M+ revenue AND (100k consumers OR 25k + 50% revenue from sale)Below threshold (fails conjunctive revenue prong) — honored voluntarily[4] [5] [6] [11]
VermontNo comprehensive law (S.71 pending). Minors-only: AADC, S.69 / Act 63 (2025). Sectoral: data-broker registrationAADC: 2027-01-01AADC: services likely accessed by minorsNo comprehensive law (sectoral only); [FLAG FOR COUNSEL: assess AADC applicability] (note [11])[11]
VirginiaVirginia Consumer Data Protection Act (VCDPA), SB 1392 (2021), Va. Code § 59.1-575 et seq. Health: SB 754 (2025), amending the VA Consumer Protection Act — reproductive/sexual healthVCDPA: 2023-01-01; SB 754: 2025-07-01VCDPA: 100k consumers OR 25k + >50% revenue from sale; SB 754: no thresholdVCDPA below threshold — honored voluntarily. SB 754 binding today but scoped to data Anchor does not solicit (note [3])[3] [4] [11]
WashingtonNo comprehensive law. Health: My Health My Data Act (MHMD), HB 1155 (2023), RCW ch. 19.373 — consumer health dataMHMD: 2024-03-31 (small businesses 2024-06-30; geofencing ban 2023-07-23)MHMD: no threshold, no small-business exemptionMHMD BINDING today (check-ins, test results, ADHD notes are consumer health data; private right of action); no comprehensive law otherwise[3]
West VirginiaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
WisconsinNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
WyomingNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily
District of ColumbiaNo comprehensive law (as of 2026-06)No state law — rights honored voluntarily

In every state and DC — including every "no comprehensive law" row above — Section 5 of the FTC Act (unfair or deceptive acts or practices) applies to Anchor's privacy representations: the promises in this policy are federally enforceable everywhere, with or without a state statute.