← Anatome

anatome Platform — Privacy Policy (v0.1, draft)

Who this is for: API customers (apps building on platform.anatome.dev). ChatGPT / personal accounts: the policy that governs you is https://anatome.dev/privacy — NextSolutions is the controller there, including Article 9(2)(a) explicit consent for health-adjacent body metrics. Status (this API-customer document): Draft, pending review by a qualified attorney. Source Markdown: /privacy?format=md.

1. Who we are

anatome is operated by NextSolutions. We are a data processor for the data our customers (app developers) submit via the API on behalf of their end-users, and a data controller only for the minimal operator data (your developer account email, billing, usage aggregates).

2. What we collect

3. Lawful basis (GDPR)

4. Your rights (GDPR Articles 15–20)

You can access, rectify, or port your operator data via the dashboard. For end-user data you submitted via per-user endpoints, use the corresponding DELETE endpoint (see TOS §5 for the 30-day rollback + hard-delete sweep). To exercise other rights, email support@anatome.dev.

5. Data retention

See TOS §5. Summary: request logs 90d → aggregated; inactive demo accounts 60 days without key activity → may be hard-deleted; deleted user data 30d rollback → hard-deleted; backups purged on next rotation; idempotency cache 24h.

6. Sub-processors

We do not sell your data. We do not use your data to train AI models.

7. International transfers

Data is processed in the EU (Hetzner Falkenstein) + US (Cloudflare). Transfers are under Standard Contractual Clauses where required. If you self-host, no transfer occurs.

8. Security

Postgres RLS per app_id/app_user_id. API keys are SHA-256 hashed (we store only the hash). Constant-time compares for admin tokens. Rate-limiting per key. Scoped keys (read/write/ai/ users/admin). Bound keys (bound_app_user_id) for per-user isolation. The cross-tenant isolation is covered by an automated test run before every deploy.

9. Self-hosting

There is no self-hosted edition of this platform, so NextSolutions is always the processor for data held here. The exercise/anatomy wiki at wiki.anatome.dev is a separate, Apache-2.0 product with its own storage and its own privacy terms; this policy does not describe it. If you self-host that wiki, this policy does not apply to your instance — publish your own.

10. Contact

support@anatome.dev. We have not appointed a Data Protection Officer; privacy questions go to that address. Do not use dpo@anatome.dev — that mailbox is not staffed.