Trust & Security
This page is maintained by Toby the Doby, LLC to answer common security and privacy questions about Back & Forth. It describes the controls we actually run — not certifications, not audit outcomes.
1. We don't sell your data
We never sell your questions, uploads, debate transcripts, name, or email. We don't use your data for advertising. It is used only to run the debate you asked for and to keep your account working.
We may use fully anonymized, aggregated usage statistics to improve the Service. We never share your personal or debate content publicly.
2. Where your data lives
Back & Forth is hosted on a major cloud provider with data centers in the United States and the European Union. Uploaded images are stored in a private storage bucket and are only accessible to your account.
3. Encryption
- In transit: All traffic between your browser and our servers is encrypted with TLS 1.2+ (HTTPS). Look for the padlock in your browser's address bar.
- At rest: Databases, backups, and uploaded files are encrypted at rest with AES-256.
- Access control: Per-user data isolation is enforced at the database layer. You can only read your own threads, uploads, and account data.
4. Who sees your prompts
5. What we store
- Account: your email address and (if you use Google sign-in) your name and a Google account ID. Used to sign you in and address you.
- Debate content: the questions, briefs, agent replies, and verdicts produced for you.
- Uploads: any images or files you attach to a debate.
- Operational: minimal logs and timestamps needed to run and debug the Service.
6. Retention
- Uploaded images and files: automatically deleted 30 days after upload. Delete sooner from the thread page any time.
- Debates and reports: kept for as long as your account exists so you can revisit them. Delete individual debates from the sidebar at any time.
- Account deletion: when you delete your account, we remove your threads, uploads, and account data. Backups may persist for a short recovery window (up to 30 days) and are then overwritten.
7. Your controls
8. Cookies and browser storage
We only use browser storage for functional purposes: keeping you signed in, remembering your theme (light or dark), and holding in-progress prompts between pages. No advertising or third-party trackers.
9. Sensitive topics
Back & Forth can produce interpretive analysis for medical images, legal questions, and financial situations. This is not medical, legal, or financial advice. It does not create a doctor–patient, attorney–client, or fiduciary relationship. For anything with real consequences, take the report to a qualified professional.
10. What we are not
- Not HIPAA compliant. We are not a Covered Entity or Business Associate.
- Not independently certified under GDPR, SOC 2, or ISO 27001. The architecture is aligned with GDPR principles, but this is a description of our practices — not an audit.
- Not a substitute for a licensed medical, legal, or financial professional.
11. Security contact
Report a suspected vulnerability, data-handling concern, or account-security issue to security@backandforth.ai. For privacy requests and data-subject rights, email privacy@backandforth.ai.