Version 1.0. Effective July 2, 2026.
In plain terms: We collect only what SharedAnchor needs to work - your email, the expense, payment, and calendar records you enter, and a child's first name and birth year if you add one. We do not sell your data, we do not show ads, and we never hold your money. Card billing is handled by Stripe on the web and by Apple in the iPhone app; we never see your full card number.
This Privacy Policy ("Policy") explains how SharedAnchor LLC ("SharedAnchor," "we," "our," or "us") collects, uses, discloses, and retains personal information when you use the SharedAnchor web application at app.sharedanchor.com and the SharedAnchor iOS and Android mobile apps (collectively, the "Service").
This Policy applies to individuals who create accounts or use the Service. SharedAnchor is available only to individuals who are at least 18 years of age and reside in the United States.
SharedAnchor is a co-parenting financial record-keeping platform. SharedAnchor does not hold, transmit, transfer, escrow, settle, or take custody of user funds at any time. SharedAnchor is not a bank, money transmitter, money services business, payment processor, or escrow agent.
For website subscription billing, including website subscriptions used from Android accounts, SharedAnchor uses Stripe, Inc. Stripe stores the subscribing co-parent's payment card details. SharedAnchor receives and stores only the card brand (for example, Visa) and last four digits for display purposes. SharedAnchor does not receive or store card numbers, expiration dates, or CVVs. For iPhone in-app subscription purchases, Apple processes and holds the payment details as merchant of record, and RevenueCat verifies the App Store purchase receipt; SharedAnchor receives only the subscription status, not your card number.
SharedAnchor does not collect:
SharedAnchor uses the information it collects for the following purposes only:
SharedAnchor does not use your personal information for targeted advertising, behavioral profiling, cross-context behavioral advertising, or to train SharedAnchor's AI models. Our AI subprocessors are not all engaged on identical terms: the text you send to the AI assistant is handled by Anthropic under commercial API terms that do not use it to train Anthropic's models, while receipt images sent to Google for text extraction are subject to Google's own terms, which SharedAnchor does not control. This difference is explained in Section 6.
SharedAnchor applies the following structural privacy and security protections to every account:
These same protections are stated in our Terms of Service Section 9.
SharedAnchor uses the following third-party service providers to operate the Service. Each subprocessor handles data under its own terms and privacy policy.
Active at launch:
| Subprocessor | Role | Data sent |
|---|---|---|
| Stripe, Inc. | Website subscription billing and payment card storage | Subscriber email, billing address, and payment card details (card data is stored by Stripe; SharedAnchor does not receive or store card numbers) |
| Apple | App Store billing and merchant of record for iPhone in-app subscription purchases | For iPhone in-app purchases, Apple processes the charge and holds the payment details; SharedAnchor receives only the subscription status, not your card number |
| RevenueCat | In-app-purchase receipt verification and subscription-status management for the iPhone app | The App Store purchase receipt and an app-generated user identifier, used to verify and track your iPhone subscription status |
| Cloud hosting providers (US) | Application, database, cache, and web-app hosting | All application data, at rest and in transit, hosted in US regions, plus web app static assets and page-load request metadata |
| File storage provider | Receipt and PDF file storage (encrypted at rest) | Uploaded receipt files and generated PDF exports |
| Email delivery provider | Transactional email delivery | Recipient email address and message body for account, billing, and notification emails |
| Error-monitoring and uptime providers | Error tracking and uptime monitoring (payment amounts and names excluded) | For error tracking: stack traces, error metadata, and account UUID. For uptime monitoring: request logs and uptime probes, with no user identifier. Payment amounts, names, and message content are excluded |
| Anthropic (Claude) | AI assistant features, where enabled (messages are not used to train AI models) | Text of your messages to the AI assistant and SharedAnchor's AI responses |
| Google (Gemini) | AI features, where enabled (receipt images are not used to train AI models) | Receipt images (photos or PDFs of receipts) submitted for OCR text extraction |
Deferred, not active at launch:
| Subprocessor | Role | Data sent |
|---|---|---|
| Twilio | SMS alerts (activation planned at 100+ co-parent pairs; not active at launch) | Not active at launch. When activated: recipient phone number and short message body |
SharedAnchor will update this list when subprocessors are added or removed. Material changes will be communicated in accordance with Section 14 (Changes to This Privacy Policy).
SharedAnchor does not sell your personal information. SharedAnchor does not share your personal information for cross-context behavioral advertising.
SharedAnchor may disclose your personal information to law enforcement, government agencies, or other third parties when required to do so by law, subpoena, court order, or other legal process, or when SharedAnchor in good faith believes disclosure is necessary to protect SharedAnchor's legal rights, to protect the safety of any person, or to prevent illegal activity. SharedAnchor will attempt to notify you of such requests to the extent permitted by law.
If SharedAnchor is involved in a merger, acquisition, reorganization, sale of assets, or similar transaction, your personal information may be transferred as part of that transaction. SharedAnchor will notify you before your personal information is transferred and becomes subject to a different privacy policy.
SharedAnchor uses two separate third-party AI providers for distinct purposes.
When you use the SharedAnchor AI assistant, the text of your messages and SharedAnchor's responses are sent to Anthropic, our AI subprocessor, so Anthropic can generate replies. Under Anthropic's commercial API terms, these messages are not used to train Anthropic's AI models. SharedAnchor does not send your receipt images, expense records, or custody-calendar data to Anthropic except as text content you choose to include in a message.
AI conversation content is retained only as long as needed to operate the conversation.
Your AI chat history and activity are private to you. SharedAnchor does not share one co-parent's AI conversations or AI activity with the other co-parent, and does not use one co-parent's AI history to personalize the other co-parent's experience.
AI suggestions are generated by software and may be incomplete or inaccurate. The AI assistant does not provide legal, tax, financial, medical, or safety advice, and does not create any professional or advisory relationship between you and SharedAnchor.
When you upload a receipt photo or PDF, SharedAnchor sends the image to Google Gemini, our OCR subprocessor, to extract merchant, date, total, and line-item text. Under the Google Gemini API terms we use, the receipt image sent for OCR is not used to train Google's AI models. Beyond this no-training commitment, Google's handling of the image is subject to Google's Gemini API terms; SharedAnchor does not control how Google retains or uses the image beyond what those terms permit. The text Gemini extracts is shown to you as a draft pre-fill; SharedAnchor does not write the extracted text to the append-only ledger until you accept the draft.
We want to be clear and honest about how this differs from the AI assistant described above. For the Anthropic assistant, SharedAnchor makes an affirmative commitment that your message text is not used to train AI models, because that is backed by Anthropic's commercial API terms. SharedAnchor does not make that same no-training commitment for the receipt images sent to Google. This is a deliberate difference, not an oversight: receipt images can contain real financial detail, so rather than imply a protection SharedAnchor has not contractually secured, this policy states plainly that those images are governed by Google's terms. If SharedAnchor later confirms equivalent no-training terms for the receipt-OCR provider, this section will be updated to state that commitment directly.
The receipt image itself continues to be stored with our file-storage provider, encrypted at rest. If you do not want a particular receipt processed by a third-party AI provider, do not attach that receipt; expenses can be recorded without an attached receipt.
SharedAnchor offers an optional connector that lets you authorize a third-party AI assistant (such as Claude or ChatGPT) to read your SharedAnchor records on your behalf. This is separate from the SharedAnchor AI assistant described above: here, you choose to link your own account to an outside AI service.
coparent.read scope: your expenses, payment records (including external payment records), and custody calendar. The assistant cannot create, modify, or delete any record.The connector is optional. You do not need to connect any AI assistant to use SharedAnchor.
SharedAnchor does not collect, store, or process your bank credentials, bank account or routing numbers, Venmo login credentials, Venmo balances, or Venmo transaction history. When you use "Pay via Venmo," SharedAnchor opens the Venmo app or website with a pre-filled recipient handle, amount, and memo; the payment itself happens entirely inside Venmo under Venmo's own terms and privacy policy. SharedAnchor receives no confirmation back from Venmo. The only payment information SharedAnchor stores is what you and your co-parent type into SharedAnchor: the external payment record (amount, date, memo, recipient handle) and any confirmation or dispute event either of you submits. Subscription billing is separate: on the website, Stripe stores the subscribing co-parent's payment card information for the pair subscription; in the iPhone app, Apple processes the subscription charge and RevenueCat verifies the receipt. See Terms of Service Sections 5 and 6 for the full payment-role disclosure.
SharedAnchor's financial and custody records, including expenses, external payment records, custody schedules, day overrides, swap requests, and related events, are stored as append-only records. SharedAnchor does not update or delete these records once created. Corrections and amendments are made by appending new entries that supersede earlier entries; the original entry remains in the ledger.
Each legal-fact record carries a SHA-256 hash of the prior record in its table, forming a continuous hash chain. A daily Merkle root is computed at 00:05 UTC and recorded to provide a tamper-evident snapshot of the ledger at that point in time. SharedAnchor makes no representation that this structure makes records "court-admissible"; admissibility is determined by the rules of evidence applicable in your jurisdiction.
For records that are part of SharedAnchor's append-only legal-fact ledger (expenses, external payment records, custody schedules, day overrides, swap requests, and related events), correction is performed by appending a new entry that supersedes the original; the original entry is preserved.
In plain terms: When you delete your account, we erase your everyday account details (your email address, display name, password hash, and device tokens) right away. But the shared expense, payment, and custody entries you and your co-parent made are kept, because they belong to both of you and neither of you can erase the other's copy on your own. We keep those entries for up to six years.
This six-year hold is SharedAnchor's own retention policy, not a banking or financial-records law that applies to you. We chose it for three reasons: the shared append-only ledger is relied on by both co-parents and cannot be unilaterally erased by one of them; records may be needed for a litigation hold or court-ordered preservation; and keeping them supports security and fraud detection. When you ask us to delete your account, we do not remove these ledger rows. Instead, we anonymize them in place - we strip the direct identifiers (name, email, and other direct identifiers) to the extent feasible, while the row itself stays in the ledger. Leaving the row in place is what preserves the integrity of the tamper-evident hash chain and daily Merkle root described in Terms of Service Section 7; deleting the row would break that chain for both co-parents.
If you are a California resident, you have the following rights regarding your personal information:
To exercise any of these rights, email privacy@sharedanchor.com. We will respond within 45 days as required by California law. You may also designate an authorized agent to make a request on your behalf; we will require reasonable verification of the agent's authority.
SharedAnchor honors access and deletion requests for all users, not only California residents. Email privacy@sharedanchor.com from any state and we will process your request on the same terms, subject to the retention carve-out described above.
SharedAnchor does not collect sensitive personal information as defined under the California Privacy Rights Act.
Children are not users of SharedAnchor. A child cannot create an account, cannot log in, and cannot use the Service. The Service is available only to individuals who are at least 18 years of age.
When you add a child to your co-parenting record, SharedAnchor stores only that child's first name and birth year. That information is entered by you, an adult parent, about the child - it is never collected from the child. SharedAnchor does not collect a child's full date of birth, Social Security number, school name, address, or photograph. Birth year is stored at year granularity only; no more granular date is kept.
Because SharedAnchor never collects information directly from a child, the Children's Online Privacy Protection Act (COPPA), which governs the online collection of personal information from children, does not apply. If you believe SharedAnchor has somehow received information directly from a child under 13, please contact us at privacy@sharedanchor.com and we will delete it promptly.
SharedAnchor takes reasonable technical and organizational measures to protect your personal information, including:
No security measure is perfect or impenetrable. SharedAnchor cannot guarantee that unauthorized third parties will never be able to defeat these measures. In the event of a data security incident, SharedAnchor will notify affected users as required by applicable state law.
SharedAnchor uses session cookies that are strictly necessary for authentication and maintaining your logged-in state. These cookies are not used for advertising.
SharedAnchor does not deploy third-party advertising trackers, social media pixels, or cross-site analytics at launch. Our error-monitoring and uptime providers, disclosed in Section 5, receive limited technical metadata (error events and uptime probe results) for service reliability purposes.
SharedAnchor does not use cookies to build behavioral profiles or to serve targeted advertising.
SharedAnchor's services are operated and hosted in the United States. If you access the Service from outside the United States, your personal information will be transferred to, processed, and stored in the United States. By using the Service, you consent to the transfer of your personal information to the United States. SharedAnchor is not currently offered in the European Union or United Kingdom.
SharedAnchor may update this Policy from time to time. When we do, we will post the updated Policy at app.sharedanchor.com/privacy and update the Effective Date at the top of this document. For material changes, we will provide additional notice by email to your registered address.
Your continued use of the Service after the effective date of the revised Policy constitutes your acceptance of the changes. If you do not agree to the revised Policy, you must stop using the Service and close your account before the effective date.
Privacy and data-rights requests: privacy@sharedanchor.com
Support and account matters: support@sharedanchor.com
SharedAnchor LLC. Mailing address available upon written request to support@sharedanchor.com.
Version 1.0. Effective July 2, 2026.