Legal & Compliance
Privacy Policy
Questions: hello@anku.app
1. Overview
Anku is built on data minimization. It requests read-only access to your PostHog instance, processes event data in memory during diagnosis, and stores only the deliverables it produces for you — never your raw telemetry or your end-users' identities.
2. What We Collect
Account information (your email address, sign-in records); integration data (your PostHog region and project id, and, only if you opt in, your Personal API Key, encrypted at rest); deliverables (briefs containing computed metrics, classifications, and the prescribed change); outreach drafts keyed to hashed, non-reversible identifiers; and your own weekly digest email subjects. If you use the free audit, we also receive the website URL and email address you submit.
3. Key Encryption & Deletion
Your PostHog key is encrypted at rest with AES-256-GCM — a fresh 128-bit IV and authentication tag per row — and you can delete it at any time from Dashboard → Settings → Disconnect.
4. Zero PII to LLMs
Zero PII to the LLM: only a strict field allowlist — computed numbers and classification fields, never raw telemetry or identifiers — is ever sent to the synthesis model.
5. Draft-Only Outreach & Digest Scans
Outreach is draft-only: Anku writes your user feedback email draft and stores it in your account — it is never sent to your users, and nothing is emailed to your end-users by Anku, ever. The only email Anku sends is your digest scan — only while your opt-in schedule is active. You can turn it off anytime in Dashboard → Settings, which stops scheduled runs.
6. Retention Windows
Anku retains what it stores only as long as it serves you: free audit leads for 24 months, outreach drafts for 12 weeks, and weekly digest records for 12 weeks. Public landing page URL audits are cached for up to 7 days to protect server resources, or until re-scanned or purged. Older records are deleted automatically by weekly maintenance runs.
7. Deleting or Exporting Your Data
You can delete your account anytime directly in Dashboard → Settings by typing DELETE. When you delete your account, your encrypted credentials, diagnostic briefs, outreach drafts, email logs, and cached landing page audit results are deleted immediately and permanently erased from our database and cache with zero residual copies. For an export of the deliverables we hold about you, use the Export button in Settings or email hello@anku.app.
8. Subprocessors
Anku uses a small set of providers to run the Service: PostHog (your telemetry source, accessed read-only), OpenAI (synthesis of drafts; never receives raw telemetry), Supabase (authentication and encrypted database), Vercel (application hosting), Resend (delivery of your own weekly digest), and Polar (payments — our Merchant of Record processes your subscription; card data never touches Anku systems). No provider is permitted to use your data to train models.
10. Why We Process Your Data (Legal Basis)
Contract: we process your account data and integration data because you asked us to run diagnostics — it's the service itself. Legitimate interests: security logs and abuse prevention keep the service safe for everyone. Consent: scheduled weekly scans run only while you've opted in, and turning them off in Settings withdraws that consent. We don't sell your data, and we don't process it for any other purpose than the ones above.
11. Controller & International Transfers
The data controller is Anku. Reach the controller at hello@anku.app for any privacy matter. Anku runs on US-hosted infrastructure (Vercel, Supabase); where providers serve EU/UK users they rely on Standard Contractual Clauses or equivalent safeguards, documented in their Data Processing Agreements.
12. Your Privacy Rights (US States & GDPR)
Depending on where you live, you may have rights to access, correct, delete, or port your data, and to opt out of any targeted advertising (we do none). You can exercise all of them yourself: §7 covers export and deletion without emailing anyone first. If anything requires a human — corrections you can't make in Settings — email hello@anku.app and we'll handle it within 30 days. GDPR/UK users get the same rights through the same mechanics.
13. Contact
Questions, privacy requests, or security reports: hello@anku.app. We'll respond within 48 hours.