&
back & forth
← HOME
// TRUST & SECURITY · UPDATED NOVEMBER 22, 2026

Trust & Security

This page is maintained by Toby the Doby, LLC to answer common security and privacy questions about Back & Forth. It describes the controls we actually run — not certifications, not audit outcomes.

1. We don't sell your data

We never sell your questions, uploads, debate transcripts, name, or email. We don't use your data for advertising. It is used only to run the debate you asked for and to keep your account working.

We may use fully anonymized, aggregated usage statistics to improve the Service. We never share your personal or debate content publicly.

2. Where your data lives

Back & Forth is hosted on a major cloud provider with data centers in the United States and the European Union. Uploaded images are stored in a private storage bucket and are only accessible to your account.

3. Encryption

  • In transit: All traffic between your browser and our servers is encrypted with TLS 1.2+ (HTTPS). Look for the padlock in your browser's address bar.
  • At rest: Databases, backups, and uploaded files are encrypted at rest with AES-256.
  • Access control: Per-user data isolation is enforced at the database layer. You can only read your own threads, uploads, and account data.

4. Who sees your prompts

To run a debate, we send your prompt (and any files you attach) to the AI providers selected for that debate. Each provider processes the request under its own terms and privacy policy. Do not submit information you are not authorized to share with them.

5. What we store

  • Account: your email address and (if you use Google sign-in) your name and a Google account ID. Used to sign you in and address you.
  • Debate content: the questions, briefs, agent replies, and verdicts produced for you.
  • Uploads: any images or files you attach to a debate.
  • Operational: minimal logs and timestamps needed to run and debug the Service.

6. Retention

  • Uploaded images and files: automatically deleted 30 days after upload. Delete sooner from the thread page any time.
  • Debates and reports: kept for as long as your account exists so you can revisit them. Delete individual debates from the sidebar at any time.
  • Account deletion: when you delete your account, we remove your threads, uploads, and account data. Backups may persist for a short recovery window (up to 30 days) and are then overwritten.

7. Your controls

  • Delete any debate from the sidebar — the transcript, verdict, and any attached images are removed.
  • Export your data as a single JSON file from Settings.
  • Delete your account and all associated data from Settings.

8. Cookies and browser storage

We only use browser storage for functional purposes: keeping you signed in, remembering your theme (light or dark), and holding in-progress prompts between pages. No advertising or third-party trackers.

9. Sensitive topics

Back & Forth can produce interpretive analysis for medical images, legal questions, and financial situations. This is not medical, legal, or financial advice. It does not create a doctor–patient, attorney–client, or fiduciary relationship. For anything with real consequences, take the report to a qualified professional.

10. What we are not

  • Not HIPAA compliant. We are not a Covered Entity or Business Associate.
  • Not independently certified under GDPR, SOC 2, or ISO 27001. The architecture is aligned with GDPR principles, but this is a description of our practices — not an audit.
  • Not a substitute for a licensed medical, legal, or financial professional.

11. Security contact

Report a suspected vulnerability, data-handling concern, or account-security issue to security@backandforth.ai. For privacy requests and data-subject rights, email privacy@backandforth.ai.

Toby the Doby, LLC · Operator of Back & Forth · hello@backandforth.ai