Privacy Policy

This policy explains what information Anchor collects, how we use it, and what choices you have. We wrote it in plain language so you can understand it without a law degree.

Who we are

Anchor Advance Care LLC is a Maryland limited liability company (EIN 42-3094520).

Email: contact@anchoradvance.care
Website: anchoradvance.care

What Anchor does

Anchor is an advance care planning platform. We help patients create legally valid advance directives — documents that describe your healthcare wishes if you cannot speak for yourself.

Anchor is not a medical provider. We do not give medical advice, diagnose conditions, or make clinical decisions for you or your care team.

What data we collect

When you use Anchor, we may collect:

  • Account information — your name, date of birth, email address, and phone number when you sign up
  • Directive content — healthcare preferences and wishes you enter in the directive wizard
  • Contacts you provide — healthcare agent and emergency contact information
  • Physician questions — questions and your responses when a doctor gives you a referral code
  • Signatures — signature data when you or your physician execute or confirm a directive
  • Uploaded documents — signed scans when a physician uploads a paper-signed copy
  • Login sessions — information needed to keep you signed in securely

How we use your data

We use your data to run the features you actually use: creating and storing your directive, matching you with the provider who referred you, and letting you and your authorized providers retrieve it.

When you use the assistant chat or the voice-to-directive feature, an AI assistant reads what you type or say, along with relevant context from your directive, to generate a response or turn your speech into directive text. When you use a read-aloud feature, your directive text is sent to a text-to-speech service to generate the audio. Both are named, with what each one receives, in Service providers below.

What we do not collect

  • We do not run advertising or tracking cookies
  • We do not sell your data to any third party, ever
  • We do not use your data for marketing, advertising, or any purpose beyond running the features described above and in Service providers below

Service providers

Anchor runs on infrastructure and services operated by other companies. We do not sell your data to any of them, and each one receives only what it needs to provide the feature described here.

  • Supabase hosts our database and file storage. Your account information, directive content, signatures, and uploaded documents are stored there.
  • Vercel hosts and runs the Anchor application, including the servers that handle every request you make to the site.
  • Anthropic provides the AI behind the in-app assistant and the voice-to-directive feature. When you use either one, what you type or say, along with relevant context from your directive, is sent to Anthropic's API to generate a response or convert your speech into text.
  • ElevenLabs provides text-to-speech. When you use a read-aloud feature, the directive text being read is sent to ElevenLabs to generate the audio.
  • Epic is the electronic health record system used by partner health systems. When a clinician connects Anchor to a patient's Epic chart, Anchor reads that patient's demographic information from Epic to find the correct record, and, if the clinician files a completed directive, sends that directive document into the patient's Epic chart.
  • Resend sends email on our behalf, including the notification we send ourselves when someone logs into the prototype access gate. Those notifications include the email address entered and the IP address of the login attempt.

Cookies

Anchor uses several strictly necessary cookies. None are used for advertising, analytics, or tracking, and none can be turned off without breaking the features they support:

  • A gate session cookie that remembers you have entered the prototype access password
  • A Supabase auth session cookie that keeps you signed into your account
  • An Epic connection cookie that keeps a provider's connection to Epic active once they have connected, set only for providers who use that feature
  • A short-lived Epic sign-in cookie used only during the moments a provider is connecting to Epic, then cleared
  • A per-launch grant cookie, set only when a clinician opens Anchor from inside a patient's chart in Epic, scoped to that one chart session and expiring with it
  • A theme preference cookie that remembers whether you prefer light or dark mode

How we store your data

Patient data is stored in Supabase, a cloud database provider, and encrypted in transit whenever it moves between your device and our servers. At rest, it relies on Supabase's platform-level disk encryption. Anchor does not add its own application-level or column-level encryption on top of that today.

Only you and healthcare providers you authorize can access your directive content.

Who can see your data

  • You can always see your own data when you log in
  • A provider who issued your referral code can see your directive
  • A provider you authorize to confirm your directive can see it and sign it with you
  • Anchor staff may access data only to provide technical support or when required by law
  • The service providers named above see the specific data described there, and nothing else. We do not share your data with any other third party without your clear permission, except when the law requires it.

Your rights

  • View your directive anytime by logging into your account
  • Update or revoke your directive anytime
  • Request deletion of your account and all associated data by emailing contact@anchoradvance.care
  • Request a copy of all data we hold about you by emailing contact@anchoradvance.care

HIPAA notice

Anchor Advance Care LLC is building HIPAA compliance infrastructure, including Business Associate Agreements with our technology vendors.

The current prototype is for demonstration purposes only. Do not use it to store real protected health information until we confirm full HIPAA compliance. We will update this policy when that work is complete.

Children

Anchor is not intended for anyone under the age of 18.

Changes to this policy

We may update this policy as the platform grows. If we make important changes, we will let you know by email or with a notice in the app.

Contact

For privacy questions or data requests, email contact@anchoradvance.care.

Effective date: August 24, 2026 · Anchor Advance Care LLC · Maryland