Onward home

Last updated August 10, 2026

Privacy, in plain language

Onward asks about something emotionally personal. This page explains what the current product does with that information, how long it stays, and what deletion can and cannot reach.

The short version

  • You can begin without giving an email. A temporary guest account is created only after you submit a valid, non-crisis story request, not when you land on the site.
  • Crisis screening runs before sign-in, storage, rate limiting, or any AI-provider request. If it triggers, Onward shows reviewed resources and does not save that submission.
  • A temporary guest account and every story in it are deleted about six hours after the latest story creation or saved reading progress in that account. Sending a confirmation email does not save anything by itself. Using its confirmation link makes the same account permanent; that account-wide change covers stories already there and stories created later until you delete them.
  • You can delete one story or your whole account yourself. No support request is required.
  • Onward does not intentionally log story requests, generated story text, raw IP addresses, or raw provider errors in application telemetry.

What Onward keeps

Age, situation, and optional story limits

These are used to find and prepare a relevant story. The situation, selected limits, and closed clarification stay only on the original session; daily cleanup clears them after its fixed 60-day deadline unless deleting the guest account, story, or account removes them earlier. The age currently stays with a kept story until that story or the account is deleted.

Story, reading place, and generated copy

These let the story remain stable and reopen where you stopped. For a guest, the account-wide cleanup clock runs from the latest story creation or saved reading progress in that account; when it expires, the guest account and every story in it are deleted. After an email is confirmed, the same account keeps every current and future story, including its generated wording and age, until you delete the story or account. Confirmation does not extend the original fixed 60-day deadline for what you wrote before the story.

Account-wide save state

Onward records whether a guest account became permanent through the Save confirmation and—for current-policy transitions—the exact confirmation time. This state belongs to the account rather than one story. The sign-in page cannot create a new account. Older permanent accounts have an honest legacy record without an invented historical transition time.

Short-lived working material

Reduced emotional shapes, raw AI responses, matching query vectors, and rejected composition plans are used only while preparing a request. Onward does not save them as stories, feedback, events, or editorial records. Only validated generated wording enters the saved story.

Email and password

Supabase Auth handles sign-in and email confirmation. Onward's product tables store the account identifier and the account-wide save state, not your password. Password recovery uses a one-time email link.

Essential cookies

Onward uses cookies for authentication and short-lived security handoffs, including confirmation and same-device reauthentication. The application does not install an advertising or third-party behavioral-analytics SDK.

Story feedback

The product accepts a closed close/not-close answer and one closed reason, not a free-text note. Feedback carries a 90-day expiry and is removed by daily cleanup, or earlier with its story or account.

Operational records

Salted IP rate-limit windows become eligible for daily cleanup after two days. Closed product events and identifier-free daily totals carry an at-most 30-day expiry; provider-attempt records contain no account, story, or content identifier and carry an at-most 14-day expiry. Daily cleanup removes expired rows.

AI and infrastructure providers

For a non-crisis request, the age, situation, and any closed clarification may be sent to the configured matching provider. The approved production retrieval mode is keyword-based: Gemini receives curated historical-library text when embeddings are seeded, not a reader's situation. A future or non-production semantic-retrieval configuration would send the situation to the embedding provider. The opening-copy and bounded composition paths receive a reduced emotional shape rather than the raw situation.

Onward currently uses Cerebras for language-model requests, Gemini for library embeddings when enabled, Supabase for authentication and database services, Vercel for hosting, and Resend/custom SMTP to deliver sign-in and confirmation email. The email provider receives the delivery address and message needed for that purpose, not your story request.

Provider processing is governed by the operator's plan, configuration, contract, and the provider's current terms. It is outside Onward's application database, so an in-app deletion cannot recall a request already processed there. Review the current Cerebras privacy policy, Gemini API retention guide, Supabase privacy notice, Vercel privacy notice, and Resend privacy policy. Production configuration and contracts still require a formal privacy review before public launch.

What deletion does—and what may remain

Account deletion hard-deletes from Onward's active database the sign-in, owned stories, generated story copies, reading places, private context, saved feedback, recovery state, the account-wide save state, account-linked product events, and per-account rate limits. Deleting an original story also deletes its alternate; deleting only an alternate keeps the original.

Account-free records can remain on their own schedules: salted-IP rate-limit windows and retry decisions become eligible for daily cleanup after two days; provider-attempt records carry 14-day expiries; and deletion events, opaque flow-revocation tombstones, other closed product events, or counts already combined into daily totals carry roughly 30-day expiries. None of these records contains your account, story text, or disclosure.

A historical concern report stays attached to shared historical-library source, story-template, and fact identifiers, with a closed reason, status, count, and timestamps. It contains no account, session, saved-story, artifact, disclosure, or generated-prose identifier and currently has no automatic expiry. Provider processing and infrastructure backups follow their own terms and schedules; an in-app deletion does not claim to erase those copies immediately.

Controlled beta limits

This is a product-behavior guide for the current preview, not a completed market-specific legal notice. The controlled beta accepts adults ages 18–100 only. People under 18 cannot start a story while youth safety, privacy, and consent requirements remain under review. Before public launch, Onward still needs a named privacy contact and controller, a formal provider and backup-retention privacy review, and jurisdiction-specific rights language.