Privacy policy
Version 2.0.0 — last updated: September 19, 2026
The text below is made of sourced legal sentences, which we have not rewritten: that is why it is more formal than the rest of Ankora.
Data controller
The data controller is Ankora, published by Thierry Vanmeeteren.
You can write to thierryvm@gmail.com.
Requests you send to this address about your personal data are processed there in order to answer you.
This processing is necessary for compliance with a legal obligation: the regulation requires the controller to facilitate the exercise of your rights and to answer your requests.
These messages are kept for as long as necessary to handle your request.
Data collected
Hosting this site produces technical logs, which contain in particular the IP address from which the pages are viewed.
The publisher consults these logs for the security of the service: detecting abuse and intrusion attempts, and diagnosing incidents.
This processing is necessary for the purposes of the legitimate interests pursued by the publisher, namely the security of the service: detecting abuse and intrusion attempts, and diagnosing incidents (Article 6(1)(f)).
These logs are kept for twelve months at most, and pseudonymised as soon as the account is deleted.
user account
This data is used to create and manage your account, and to give you access to it.
This processing is necessary for the performance of the contract to which you are party, or for steps taken at your request prior to entering into it (Article 6(1)(b)).
This data is kept for as long as the account exists.
Providing this data is a condition for creating the account: without it, the account cannot be opened.
content uploaded by the user
This data is used to host the content you upload and to return it to you.
This processing is necessary for the performance of the contract to which you are party, or for steps taken at your request prior to entering into it (Article 6(1)(b)).
This data is kept until you delete it.
audience measurement
This data is used to measure how the application is used.
This processing is based on your consent (Article 6(1)(a) GDPR).
This data is kept for six months.
Supabase — database
Supabase Pte. Ltd
Storing the application’s data and serving the requests that read, modify or delete it, for the development and operation of the application.
(DPA, Schedule 3: nature of the processing “Storage, deletion, rectification, analysis, transfer, aggregation”; purpose “The performance of the Services, namely the provision of database and tooling services for the development and operation of web and mobile applications”.)
Data transmitted: The data the application records, as it sends it, as well as the login credentials of the accounts the application opens for its users.
(DPA, definition of “Covered Data” (a): the data provided by the customer.)
Sub-processors: Amazon Web Services, Inc; Cloudflare, Inc; Google, LLC; Fly.io, Inc; Vercel, Inc; Upstash, Inc
The provider declares other providers — support, technical monitoring, feature enablement, error tracking, data analysis, security, artificial intelligence — without specifying which of them receive this data.
It declares others whose purpose relates to its own operations — status page, customer knowledge, marketplace.
The data is stored and mainly processed in the region chosen by the customer, which does not remove the transfer described below.
The data is transferred outside the European Union, on the basis of: standard contractual clauses (Decision 2021/914).
Where to see these safeguards — https://supabase.com/legal/customer-resources/data-processing-addendum
List published by the provider — https://supabase.com/legal/customer-resources/subprocessor-list, updated on 2026-06-01
Checked on 2026-08-17 — https://supabase.com/privacy
Vercel — hosting
Vercel Inc.
Hosting the application and serving its pages, including building, deployment and distribution over the edge network.
(Privacy Notice, “About Vercel Products and Services”: “a frontend cloud for deploying and scaling frontend applications”.)
Data transmitted: IP address and system configuration information, as well as any content the deployment transmits.
(DPA, Schedule 1 §5: “such as IP address and system configuration information”, the scope being “exclusively determined and controlled by the Customer”.)
Sub-processors: Amazon Web Services (AWS); Google; Microsoft
The provider declares other providers — technical monitoring, security, debugging, logging, search, notification, data analysis, data storage, artificial intelligence — without specifying which of them receive this data.
The data is transferred outside the European Union, on the basis of: EU–US Data Privacy Framework.
The provider is not only a processor of this data. It also processes it for purposes of its own, in particular: providing the service and administering the account; customer support; platform security; legal compliance and trust. For this processing, it acts as a controller.
List published by the provider — https://security.vercel.com, updated on 2026-01-28
Checked on 2026-08-17 — https://vercel.com/legal/privacy-notice dated 2026-06-01
Upstash — security
Data transmitted: your IP address
Declared by the site publisher; Publiable has not checked this service’s documentation.
Vercel Web Analytics — audience measurement
Data transmitted: your IP address, the technical characteristics of your device and browser, the pages you view and the page you came from
Declared by the site publisher; Publiable has not checked this service’s documentation.
Google (sign in with a Google account) — authentication
Data transmitted: your email address, your name
Declared by the site publisher; Publiable has not checked this service’s documentation.
Your rights
You can obtain confirmation as to whether data concerning you is being processed and, where that is the case, access it. A copy of this data is provided to you; a reasonable fee based on administrative costs may be charged for any further copies. This right to obtain a copy must not adversely affect the rights and freedoms of others.
You can obtain the rectification of inaccurate data concerning you. Taking into account the purposes of the processing, you can also have incomplete data completed, including by providing a supplementary statement.
You can obtain the erasure of data concerning you where one of the grounds provided for in Article 17 applies, in particular where the data is no longer necessary for the purposes for which it was collected, or where you withdraw your consent and there is no other legal ground. This right does not apply to the extent that the processing remains necessary, in particular for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
You can obtain the restriction of processing in the situations provided for in Article 18, in particular where you contest the accuracy of the data, for the period needed to verify it, or where you have objected to the processing, pending the examination of your objection.
You can receive the data you have provided in a structured, commonly used and machine-readable format, and transmit it to another controller.
Where data concerning you is rectified or erased, or its processing restricted, each recipient to whom this data has been disclosed is informed, unless this proves impossible or involves disproportionate effort. You can ask to be told who these recipients are.
Where processing is based on your consent, you can withdraw it at any time. This withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
Where there are reasonable doubts about the identity of the person making the request, additional information necessary to confirm that identity may be requested.
An answer is sent to you without undue delay and in any event within one month of receipt of your request. This period may be extended by two further months, taking into account the complexity and number of requests; you are then informed of the extension and the reasons for the delay within one month.
Exercising these rights is free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, a reasonable fee may be charged or the request may be refused; it is then for the controller to demonstrate its manifestly unfounded or excessive character.
If no action is taken on your request, you are informed without delay and at the latest within one month of its receipt, of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
Your right to object
You can object at any time, on grounds relating to your particular situation, to the processing of data concerning you that is based on legitimate interest.
Complaint
Without prejudice to any other administrative or judicial remedy, you can lodge a complaint with a supervisory authority if you consider that the processing of data concerning you infringes the regulation. You can in particular contact the authority of the Member State of your habitual residence, your place of work, or the place of the alleged infringement.
The publisher’s supervisory authority — Autorité de protection des données (APD), Rue de la Presse 35, 1000 Brussels — https://www.autoriteprotectiondonnees.be/citoyen/agir/introduire-une-plainte
Checked on 2026-08-18 — https://www.autoriteprotectiondonnees.be/citoyen/contact
Additional information from the publisher
Ankora does not connect to any bank (no PSD2 aggregation). You enter your bills and expenses yourself.
Deleted account: effective deletion 14 days after your request (cancellable grace period).
Security
Encryption in transit (TLS 1.3) and at rest.
Supabase Row Level Security on every table.
Rate limiting, strict CSP, append-only audit log.
Authentication with a strong password + MFA available.
Cookies
See the cookie policy.
Changes
Any significant change to this policy is announced on this page, with its date, and by email to people who have an account.