Privacy Policy
Effective 10 August 2026
Anticip8 helps you show up for the people who matter to you. That only works if it handles what it learns with more care than any product you use, so this policy is written to be read, not skimmed. The controller of your personal data is Fountech.ai Limited, a company registered in Cyprus. Reach us at privacy@anticip8.ai.
The commitments that define the product
We do not sell personal data, ever, to anyone. Nothing you contribute is ever used to train a model that serves anyone else; where the service learns from your data it learns for your account alone, and that learning is never pooled or shared. Raw content from your connected sources is deleted shortly after we extract the signals we need from it; we keep the signal, not the message. Everything about a private person in your world is visible to you alone; there is no public profile, no score anyone else can see, and no shared surface for private people. Every anticipation shows you its evidence. We infer nothing sensitive: no health, no emotional-state labels, no data about children, and nothing designed to profile a third party rather than help you act.
What we collect
Account data: your email address, a securely hashed password (never the password itself), your plan, and your name if you choose to give one when you sign up. The name is optional; we use it to address you, and to stop somebody else putting your name on our public do-not-process list. Connected data, Google: if you choose to connect Google, we read contacts and calendar with read-only access, and only after Google's consent screen. That Google connection reads no email at all. Connected data, Microsoft: if you choose to connect a Microsoft account, we read contacts, calendar, Outlook mail and Teams chat, all read-only and only after Microsoft's consent screen. From Outlook mail we read the headers and the subject line, which is who wrote to whom and when, and the subject; we do not extract or store the body of any message. From Teams we read that a conversation happened, with whom and when; we do not read or store the text of Teams messages either. Uploaded data: files you import yourself (contacts or calendar exports); the file is deleted after extraction. Derived data: the signals, anticipations, advice and outcome records (receipts) the service builds for you. Usage and billing data: how much of the service you use (for the trial limits and fair use) and your subscription state. Payments are handled by Stripe; we never see or store your card number.
What we use it for, and on what legal basis
To provide the service you asked for (contract): building your dashboard, anticipations, advice and receipts. To bill you (contract). To keep the service secure and honest, including enforcing usage limits (legitimate interests). To meet legal obligations (legal obligation). With your consent where the law requires it, which you can withdraw at any time, for example by disconnecting a source.
Who processes it for us
We use a short list of processors, each doing one job: Amazon Web Services hosts the service and database; Stripe processes payments; OpenRouter is our AI gateway, which passes the short text a card is built from to one of the inference providers that serve the open-weight model we run, and every request we send carries two restrictions on that provider, that it may not keep prompts for its own purposes and that it must retain nothing once it has answered, which is set on the request rather than promised, so it holds whichever provider answers and no provider keeps or learns from what we send; Google provides the contacts and calendar APIs, and Microsoft the contacts, calendar, Outlook mail and Teams APIs, for the sources you connect; Vercel serves this website. Where data leaves the European Economic Area it travels under recognised safeguards such as Standard Contractual Clauses. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
About other people in your data
Your address book and calendar naturally mention other people. Those details stay inside your private space, are used only to help you show up for those relationships, and are never made public, pooled across users, or sold. If you are not an Anticip8 user and want your details excluded from the product entirely, see our Non-user opt-out page; we honour it.
How long we keep things
Raw connected content: deleted shortly after signal extraction, on a fixed schedule. Your derived data: kept while your account is open, because it is the product. Account and billing records: kept as long as the law requires. You can delete the data the service holds for you at any time, from the privacy page in the app, without closing the account. Ask us to close the account and your personal data is deleted with it, save what we must keep for legal or accounting reasons.
Your rights
You can ask for a copy of your data, correction, deletion, restriction, or portability, and you can object to processing based on legitimate interests. Write to privacy@anticip8.ai and we will answer within a month. You can also complain to the Commissioner for Personal Data Protection in Cyprus or your local supervisory authority.
Security
Data is encrypted in transit and at rest, connected-source tokens are encrypted with per-account keys, access is limited to what the service needs, and the production system refuses to start with weak configuration. No system is perfectly secure; if a breach ever puts you at risk we will tell you and the regulator as the law requires.
Changes
If this policy changes in a way that matters, we will tell you by email or in the app before the change takes effect.