Legal
Privacy policy.
Inward asks you about something real in your life, so it handles genuinely personal material. The demo handles it for one conversation. The signed-in product keeps it, on purpose, because advice gets closer the more of you it knows. This is the whole of what happens to it, on both.
Effective 31 August 2026 · Version 12
The short version
- The demo is anonymous. No account, no name, no password. We only learn your email address if you choose to give it, for the waitlist or to have a record of your session sent to you.
- The signed-in product remembers you, which is the point of it. If you have an invitation and sign in at /home, we keep one continuing conversation with Sherp, what he learns about you, and the plans the two of you are working on. Section 3.5 is the full list of what that holds.
- A person here can reach your conversation, and rarely does. It sits on our own infrastructure, so we are able to read it. What actually happens is narrower: specific moments looked at while we chase a specific problem, with identifiers and sensitive detail abstracted out first. Section 5.3 separates the two.
- What you write is not training data. We do not train models on it, and our model providers are contractually barred from training on API content.
- Your conversation is logged to our analytics provider. The full text of what you write and what Sherp answers goes to PostHog so we can find where the product is failing people. We do not sell any of it. Section 5 is about only this.
- Two advertising companies run code on these pages.Meta and Google each place a small script on our home page, our essays and the demo — the same script they run on much of the web — so they can tell that their ads are working. They see that you visited and which page. They do not see a word of what you write to Sherp, and we never hand them your email address or your IP address. Section 3.3 is the detail, and section 8.1 is how to switch it off. Neither script runs on any signed-in page.
- You can have it all deleted. Email us, no reason needed. There is no delete button, so a person does it, which is why section 7 says within 30 days rather than instantly.
01Who we are
Inward is operated by Inward Journeys, Inc., a Delaware corporation based in Brooklyn, New York. Where this document says “Inward”, “we”, “us” or “our”, it means Inward Journeys, Inc.
For anything about privacy, including a deletion request, write to privacy@getinward.com.
02What this covers
This policy covers everything at getinward.com. That is two surfaces. The public one is the home page, the essays at /notes, the waitlist, and the web demo at /try, and anyone can use it without telling us who they are. The signed-in one is the product at /home, which you reach by invitation and a sign-in link sent to your email address, along with the pages that hang off it: your Plans shelf, your session summaries, and the emails Sherp sends you. It does not cover other companies’ services you reach through links we publish, which have their own policies.
Inward is a research preview. The product is changing quickly, and this document changes with it. Section 11 says how you will hear about that.
03What we collect
Read this section in two halves. Sections 3.1 to 3.3 are the public pages and the demo, 3.4 is what we collect nowhere, and 3.5 is the signed-in product, which holds more than any of the rest and gets the same level of detail.
3.1 What you tell the demo
- Your messages.The full text of what you write to Sherp, and Sherp’s replies.
- Voice notes, if you use the microphone. The recording is transcribed to text as it arrives and is then discarded. We never write the audio to disk and we never store it. The transcript is kept and treated exactly like a typed message.
- What you pick. The cards you select, where you place the sliders, and the confirmations you give along the way.
- What the demo makes of it. The reading it builds of you and of your situation, and the advice it returns.
3.2 Your email address, if you give it
- To join the waitlist.
- To have a record of your session emailed to you at the end of the demo.
Neither is required to use the demo, and we do not ask for anything else: no name, no phone number, no payment details. There is nothing to pay for yet.
3.3 How the pages get used
- A visitor identifier.When you first arrive we generate a random identifier and store it in a cookie on your device for one year, with a copy kept in your browser’s own storage. It is a random string, generated by us and shared with nobody. It is not your name, not your email address, and not your IP address, and we make no attempt to work out who you are from it. What it buys is the ability to tell that the person who read an essay on Tuesday and tried the demo on Thursday is one person and not two, which is most of what we know about whether any of this is working. Our analytics provider keeps a matching identifier in your browser for the same purpose, on this site only. Clearing cookies and site data for this site removes both, and you return as a new visitor. If you would rather we never set them at all, see 8.1.
- Product events. Which step of the demo you reached, how long each part took, where you stopped. This is how we find the places the demo loses people.
- Approximate location and device type. We pass your IP address to our analytics provider so it can work out a rough location (country, region, city) and tell automated crawlers apart from real visitors. The IP address itself is then discarded and is never stored alongside the event. Only the approximate location is kept. We also record your browser and whether you were on a phone, a tablet or a computer, so we can tell whether the demo works on the device you actually used.
- Masked session recordings. We record how the page is used: scrolling, cursor movement, taps, and which controls are used. All text and all form inputs are masked before the recording leaves your browser. The recording shows blocked-out shapes moving, not words. What you type is never captured by it, and neither are the contents of any network request.
- Advertising tags, from Meta and from Google.Both companies run a small script of their own on our home page, our essays and the demo. It is their code, not ours, and it reports your visit to them directly: which of our pages you opened, and whether you got as far as sending Sherp a message or leaving your email address. Each also sets cookies of its own on your device, for up to 90 days: one is an identifier for this browser, set on every visit, and another records an ad click if there was one. All of this runs whether or not an ad brought you here, which is the part worth being plain about — it is a wider disclosure than the one below, and it is new as of version 6 of this document. What these scripts do not do is read what you write. We turn off Meta’s automatic collection of form fields and clicks, none of what you tell Sherp is ever in a page address, and neither company is sent your email address or your IP address by us. They are not on the legal pages, including this one. Section 8.1 is how to switch them off entirely.
- Which ad brought you, if one did.Separately from the tags, and this part is unchanged: advertising platforms add their own tracking code to the links in their ads. If you arrive through one, we keep that code in a cookie on your device for 90 days. It identifies the click it sold, not you, and we cannot read anything out of it. When you reach the demo, our server hands it back to that platform so it knows the ad worked and can show our ads to more people the demo is actually for. What goes with it is your browser type and which page you were on, both of which that platform already saw when you clicked. Nothing else does — not your email address, not your IP address, not anything you wrote. If no ad brought you here, this half sends nothing.
- Errors and crashes. Stack traces and request metadata when something breaks.
- Standard server logs. IP address, browser, timestamps. Retained briefly for security and abuse prevention.
3.4 What we do not collect
- No passwords, on either surface. The demo has no account at all and does not know who you are. The signed-in product knows you by a one-time link sent to your email address, so there is no password for us to store, for you to reuse, or for anyone to steal.
- No advertising script on the legal pages. Versions 1 to 5 of this document said there were no third-party scripts anywhere on the site. That was true when it was written and it is no longer true: 3.3 describes the two that now run, and rather than soften the old sentence we have replaced it. What remains true is that they are kept off the pages you read to find out what we do with your data, that no advertising company is given anything you wrote, and that a Global Privacy Control signal stops them loading at all.
- No content in an advertising tag, ever. Meta and Google are told that a visit happened and how far through the demo it got. They are never told the subject you brought, a sentence of it, the cards you chose, the reading the demo built, or the advice it gave. Those live in the places section 5 and section 6 describe and go nowhere near an ad platform.
- The only identifier we generate is our own, it is described in 3.3, and it feeds our own analytics and nothing else. It is never sent to an advertising platform. One other thing is kept in your browser rather than collected by us: if you leave a conversation unfinished, your browser keeps a pointer to it for up to 30 days so you can pick up where you left off. It names the conversation, not you, and choosing to start a new one discards it.
- No stored IP addresses in our analytics. The address is used once, to derive an approximate location and to filter out bot traffic, and is discarded at that point. We never derive a precise location, and we never ask your device for one.
- Coarse location for the weather, and no permission prompt.When you open the app on a new day, its opening page shows your city and the temperature there. Where you are comes from the same coarse, IP-derived reading described just above — a city name and a rough latitude and longitude that our host works out from the request, never a precise position, and never a question put to your device. Your browser then asks Open-Meteo, a free public forecast service, what the temperature is at those rough coordinates; it is sent no account, no identifier, and nothing you have written. The rough coordinates themselves are never stored. What we do keep, once per day, is the answer as three plain facts written into that day’s own page: the city name shown to you, a code for what the sky was doing, and the temperature. They are written the first time the page is drawn that day and never revised, so when you look back at an earlier day you see the morning it actually was. That is the whole of it, and it is listed in 3.5 with everything else we hold.
- No text in session recordings, ever. See 3.3.
- No advertising script of any kind on the signed-in product. The tags described in 3.3 run on the pages that bring people to us, and being signed in is not a thing we advertise on. No advertising company is told that you are a member, that you opened the app, or anything at all about what happens inside it.
- No recording, and no measurement code running in your browser, on the signed-in product. Nothing watches how you move through /home: the masked recordings in 3.3 are the public pages and the demo, and the product pages load no third-party script of any kind. Two kinds of counting do happen, both of them on our side of the wire, and both about what the product did rather than about how you moved through it. The first is the morning cover: when the opening page offers its three small options, we count which one you picked, or that you skipped, so we can learn which of the options deserves its place. Four counters, kept on our own servers, holding nothing but the tap and its moment. The second is a short, fixed list of moments the product notes as they happen, such as a day opening or a session finishing. Those are described exactly in 5.2, they carry no words you wrote, and nothing Sherp is ever shown comes from either.
- No streaks, no attendance score, no record of how often you show up used to grade you. Sherp keeps track of which questions you have not answered so that he asks at most twice and then leaves the topic alone, and that is the whole of it. Whether you came back is not something the product scores, shows you, or uses to push you.
- No open tracking in anything we email you. Our emails carry no pixel and no way for us to learn that you opened one. If you tap a link in the morning note, Sherp knows that much, so that he continues the conversation instead of repeating himself.
- No contacts, photos, camera, health data, or stored audio.
- We do not sell personal information, and we never have. We do share advertising signals, and we would rather name them than let a sentence here imply otherwise: Meta and Google observe your visit through their own scripts on our pages, and any platform that sold us the click that brought you is also told, by our server, that the click arrived. California law counts both as sharing for cross-context behavioural advertising, so we call it that, even though what travels is a visit and a platform’s own code rather than anything you gave us. 3.3 is what it contains and 8.2 is how to stop it.
3.5 What the signed-in product holds
Everything above describes a visit. This describes a relationship, and it is the longest list on this page for a plain reason: the product is built to get closer the more of you it knows, and keeping what it learns is how it does that. Here is all of it.
- Your account.Your email address, and the timezone your browser reports each time you open the app, so that the morning note and the day’s opening arrive in your morning rather than ours.
- One conversation, kept in full. There is a single thread with Sherp per account and it never starts over. Every message you send and every reply is stored as written, along with the cards he draws in it when something changes.
- Photos you attach to a message. You can put one photo or screenshot beside what you write. It is stored privately and shown back only to you, inside your own conversation: there is no public address for it, and the link your browser uses to load it is made fresh for you each time and expires within minutes. Sherp is shown it once, on the turn it arrives, so that he can answer what is in it; from then on the conversation keeps your words and a note that a photo was there. It goes with everything else when you ask us to delete your data (section 8.1).
- A running summary of that conversation. As the thread grows we keep a written summary of the older part of it, which is what Sherp reads instead of rereading years of messages. The original messages are kept too. The summary is his working memory, not a replacement for the record.
- Notes about your life. When the older part of the conversation folds into the running summary, a background pass also writes down the plain facts a good friend would keep: your work, the people you mention, the standing situations around each problem, each noted with the day it was learned and the person or part of life it belongs to. Sherp reads them so that day thirty knows what day three learned. They are written from what you actually said, never your personality (that is the map, which only you can write) and never your plans (those live on their own shelf). There is no screen for them yet: they are part of what section 8.1 sends you if you ask, and until the page that makes them visible and editable ships, deleting one is an email away.
- Your Inner Map.Where you sit on the framework’s dimensions: each placement, the sentence you chose, and which session or moment it came from. It carries over from the demo when you sign in with the same email address, and it thickens as you use the product.
- Your plans. For each one: a title, a short summary, the longer arc, the next step, and where it stands. A plan is active, or parked with the date Sherp will bring it back, or closed as accomplished or set aside. Every change is dated.
- The steps inside a plan, and the working note behind each one. A step has the line you see, whether it is still to do, done, or dropped, and sometimes a note about what usually gets in the way. It also has a working note Sherp keeps for himself: what you tried, how it went, why the step is shaped the way it is. That note is written for his memory rather than for the screen, so you will not see it in the app. It is yours, it is part of what section 8.1 sends you if you ask, and it is disclosed here rather than left to be discovered.
- Promises with a date on them. When Sherp says he will bring something back on a particular day, that becomes a row holding the date and the thing. It is the only dated object in the product, it is made in conversation with you, and it is what stops a promise quietly evaporating.
- One page per day, with its name and its weather.The conversation is kept as days, and each day has a page: when it began, a short title Sherp writes for it once it is over, and the three facts from that morning’s opening page — how many days you have been here, the city, and the weather. The title is written from that day’s own conversation and is meant to be yours to recognise; the facts are written once and never revised, which is what lets an earlier day keep its own morning instead of borrowing today’s. It is how the list of your days is drawn, and there is nothing else on the page: no count of how long you spent, no record of whether you came back.
- The day’s bookkeeping. Which day the app last opened for you, when you were last here, what it opened with, and which topics you have left unanswered so that a question is asked at most twice and then rests. This is how the product avoids nagging. It is not shown to you and it is not a score. See 3.4.
- Feedback about the product, flagged two ways.Typing “/feedback” followed by what you think flags that message for us to read. Separately, after each of your turns a model reads it once more and flags it when you have said something about the product without using the command. Both put your words on an internal list, both are read by us, and section 5.2 covers what that second read is.
- The emails Sherp has sent you. Which mail went out and when, and the morning note queued for your next morning, including its text, so the conversation can continue it instead of asking you the same thing twice.
- Your demo session, connected to the account. Signing in with the address you used on the demo links that session to you, which is how the advice you already got stays part of what Sherp knows.
- A log at the sign-in door. Each attempt to sign in writes one line: the email tried, whether it was on the invite list, whether the link went out, and what happened when it was clicked. It exists so a friend stuck at the door gets noticed rather than lost. It is readable only by us, and nothing in the product, Sherp included, ever sees it.
- A sign-in cookie. Signing in sets a cookie that keeps you signed in and is refreshed as you use the app. It is functional rather than analytical, which is why it is set even for a browser sending the signal described in 8.1: honouring that signal should not sign you out of a product you chose to log into. Signing out removes it.
04What we use it for
| Purpose | What we use |
|---|---|
| Run the demo: understand your problem, build a reading of you, return advice | Your messages, your selections, the session the demo builds |
| Send you the record of your session, if you ask for it | Your email address and the session |
| Tell you when a place opens up | Your email address, if you joined the waitlist |
| Sign you in to the product, and keep you signed in | Your email address, a one-time link, and the sign-in cookie in section 3.5 |
| Be your advisor over time: carry the conversation, keep your map, move your plans along | Everything in section 3.5 |
| Open your day in the app, and write the morning note Sherp sends you | Your plans and their next steps, your recent turns, promises that have come due, and the timezone your browser reports |
| Notice feedback you gave in passing, so you never have to stop and file it | Your message, read once more by a model after the turn (see section 5.2) |
| Judge whether the advice is any good, catch it getting worse, and find prompting bugs | The full text of your conversation, on the demo and in the product, read by us (see section 5) |
| Find where the demo confuses people | Masked session recordings, with all text and inputs blocked out |
| Tell whether the demo works on the device someone actually used, and keep bots out of our numbers | Approximate location and device type, derived from your IP address and browser and then stored without the IP address |
| Let Meta and Google see that our ads are working, so they find more of the people the demo is actually for | Their own scripts on our pages: which page you opened, and whether you sent Sherp a message or left an email address. Never a word of what you wrote |
| Tell an advertising platform, from our own server, that one of its clicks reached the demo | The click code that platform put in its own link, your browser type, and which page you were on |
| Diagnose bugs and crashes | Error reports |
| Comply with the law and prevent abuse | Server logs |
05Your conversation, and where it goes
This is the most personal thing that happens in Inward, so it gets its own section rather than a line in a table.
5.1 The demo
Every time the demo calls a model, the full text of what went in and what came back is sent to PostHog, our analytics provider, as an event. PostHog stores it. That includes what you wrote and what Sherp answered. We use it to:
- Read real sessions and judge whether the advice was actually good
- See whether quality is getting worse as we change the product
- Find prompting bugs, such as Sherp ignoring something you told it
- Track what each conversation costs us to run
- Reproduce a specific problem when you report one
PostHog is a third-party processor and does not use your content for anything except providing the service to us. These events are deleted automatically after one year, or sooner: asking us to delete your data removes them within 30 days (section 8.1).
There is no way to opt out of this and still use the demo. Reading real sessions is how a product this young gets better, and we would rather say so plainly than offer a toggle that does nothing. If that is not a trade you want to make, please do not use the demo, and consider joining the waitlist instead.
5.2 The signed-in product
The same thing happens in your conversation at /home, with your account attached instead of an anonymous session. Every turn Sherp takes sends the full text of that turn, and the material he was given to answer it with, to PostHog as an event. The model behind that conversation is OpenAI, which sees the same text in order to write the reply.
A photo you attach goes to OpenAI too, on the turn you send it and only that turn, because looking at it is how Sherp answers what is in it. The event that records the same turn carries a marker where the image was rather than the image itself, so the picture reaches the model and nothing else.
A second model reads each of your turns once more, straight afterwards, to notice when you have said something about the product itself. That read exists to catch feedback you would otherwise have to stop and file. It writes nothing into the conversation, changes nothing Sherp says to you, and its only effect is putting the moment on the internal list described in 3.5.
Alongside those, the product notes what it does as it does it. The list is short, fixed, and written down in advance: a day opening, a turn answered, a voice note transcribed, the You page opened, a promise made or released, a plan changing state, a session offered, opened or finished, a placement asked for or written to your map, a message flagged as feedback. Each note carries your account’s identifier, the day it happened on, labels chosen from lists we wrote (which register of the You page, which reason a plan closed), and counts (how many words were in a turn, how many turns a session ran). One of them carries a single word for which part of life a finished session was about, picked by a model from a fixed list of eight. None of them carries a sentence you wrote, the title of a plan, the wording of a promise, or a topic in your own words.
These notes go to PostHog, the same analytics company named in 3.3, into a project of its own that holds nothing from the public site. They exist so that we can see how the product is going without reading every conversation to find out, and because a product built to be useful over months has to be able to tell whether it is. Nothing about them runs in your browser, and Sherp never sees them.
As on the demo, this is not something you can switch off and keep using the product. Reading real conversations is how the advice gets better, and the invitation says so before you accept it.
5.3 Who can reach your conversation
Two things are worth separating here, because only one of them is a promise. The first is what is possible, and we would rather say it plainly than let you assume otherwise. The second is what actually happens, which is much narrower, and that is the part we hold ourselves to.
What is possible: your conversation sits on infrastructure we run, in a database we administer. It is not encrypted in a way that locks us out of it. A person at Inward can reach the raw text of what you wrote if they set out to. The page that makes that possible is internal: it is protected by a secret held by the company rather than by any member account, it is linked from nowhere public, and it is kept out of search engines. Members have no access to it at all, so no member can reach another member’s conversation.
What actually happens: nobody here sits down and reads a member’s conversation in detail. When we look closely at one account, it is because we are chasing a specific problem or a bug, and what we are looking for is the handful of moments that bear on it. That work is run by coding agents rather than by a person scrolling a transcript, and what they surface to us has identifiers and anything sensitive to you abstracted out of it before we read it. Reading a conversation end to end is not how the work is done. The one deliberate exception is the feedback list described in 3.5: a message flagged there is something said about the product itself, and we read those as you wrote them.
The tools we use to see how the product is going never receive your words at all. In them you are a codename rather than a name or an email address, and the mapping between the two lives on one machine: it is not in our code, not in our issue tracker, and not in anything we publish. What those tools get is counts and categories. That a day opened, how many turns it ran, that a session was about work or about health. Never a line of what you wrote. Section 5.2 lists exactly what is in those notes and what is kept out of them.
None of this changes why any of it exists, which 5.2 states: nobody at Inward reads what you write to Sherp for any purpose other than making Inward better at helping you.
When the invitation-only period ends, this page changes before that practice does, which is the promise in section 11.
06Who else sees it
We use the following service providers to operate the site and the demo. Each one receives only what its job needs, and none of them sell your data.
| Provider | What it does, and what it sees |
|---|---|
| OpenAI | Generates most of Sherp’s replies and the advice, and transcribes voice notes. Sees your messages, our prompts, and the model’s responses. In the signed-in product it is the only model provider, and what it sees each turn includes the parts of section 3.5 Sherp needs to answer you well. |
| Anthropic | The other model provider. Which of the two handles a given call is a setting we change as we test them against each other. Sees the same, when it is the one being used. |
| Supabase | Database and file storage. Holds your session, your email address if you gave one, and, if you have an account, everything listed in section 3.5. Also handles the sign-in itself. |
| Vercel | Hosting and the compute the site runs on. Sees requests in flight, plus server logs. |
| PostHog | Product analytics, AI quality monitoring, and masked session recording. Sees product events, approximate location, and conversation content from both the demo and the signed-in product (section 5). The recording half never runs on a signed-in page. |
| Sentry | Error and crash monitoring. Sees stack traces and request metadata, never conversation content. |
| Resend | Sends the record of your session, if you ask for it. Sees your email address and the contents of that email. It also carries the product’s mail: your sign-in link and the morning note, which it holds until your local morning and then delivers. Those notes are written from your plans, so their contents are personal and Resend sees them. |
| Meta | Runs our ads on Facebook and Instagram, and runs its own script on our pages. Through that script it sees your visit whether or not an ad brought you: which page you opened, and whether you sent Sherp a message or left an email address. Separately, if one of its ads did bring you, our server tells it that the click reached the demo, along with your browser type and which page you were on. It is never told your email address, your IP address, your visitor identifier, or anything you wrote, and its automatic collection of form fields and clicks is switched off. |
| Runs our ads on Google Search, and runs its own script on our pages. Same as Meta: through that script it sees your visit whether or not an ad brought you, and how far through the demo you got. Its tag also adds this browser to Google’s own advertising audience lists, which is what lets our ads reach people who have been here before. Nothing about you is sent to Google from our own server. It is never told your email address, your IP address, your visitor identifier, or anything you wrote. | |
| Runs our ads on Reddit, and runs no script on this site at all. Only if one of its ads brought you here: our server tells it that its click reached the demo, and nothing else — no email address, no IP address, no visitor identifier, no browser type, and nothing you wrote. If you did not arrive through a Reddit ad, Reddit is told nothing at all and receives no request about you. |
On AI training.OpenAI’s API terms (openai.com/enterprise-privacy) and Anthropic’s (anthropic.com/legal/commercial-terms) both prohibit using API content to train their models. This is a different arrangement from their consumer products such as ChatGPT and claude.ai. Inward uses only the API path. We do not train models on your content either.
On where it lives. All of these providers store data primarily in the United States. If you are in the EU, the UK or another region with cross-border transfer rules, see section 8.3.
On the three advertising platforms. They do not all hear about you the same way, so their rows above say which. Meta and Google run their own script on our pages and see your visit directly, whether or not an ad brought you. Reddit runs no script here at all and hears from us only if one of its own ads brought you. On top of that, our server tells Meta or Reddit that a click they sold reached the demo, and tells each of them the least its own system will accept: Meta requires a browser type and a page URL alongside its click code, Reddit requires neither and gets neither. None of the three is ever told anything you gave us or anything you wrote.
On the signed-in product, and which of these it reaches.Five of the providers above serve it: OpenAI writes Sherp’s side of the conversation, Supabase holds everything in 3.5, Vercel runs it, PostHog receives the conversation as section 5.2 describes, and Resend carries your sign-in link and the notes Sherp sends you. Sentry sees errors there as it does everywhere. The three advertising platforms reach none of it. They run no script on any signed-in page and are told nothing about your membership or your use of it, ever.
On changes. This list changes as the product does. The current list is always the one on this page.
07How long we keep it
| What | How long |
|---|---|
| Your demo session | Kept while the demo is in research preview, because studying real sessions is how we improve it. Deleted whenever you ask. |
| Your email address on the waitlist | Kept until you ask to come off it |
| Your account and everything in section 3.5 | Kept until you ask us to remove it, because a product built to know you over time keeps what it learns. Nothing here expires on a timer. Section 8.1 is the request and what it removes. |
| The sign-in cookie (3.5) | Until you sign out. It refreshes while you are using the app; when it does lapse, you sign in again with a fresh link. |
| Conversation content in PostHog, from the demo and from the product | One year from the event, then deleted automatically |
| Product events in PostHog | One year from the event |
| Session recordings in PostHog (masked, no text) | 30 days, then deleted automatically |
| The advertising click code we keep in your browser (3.3) | 90 days from the click, then your browser discards it. Clearing cookies and site data removes it sooner. |
| The cookies Meta’s and Google’s own scripts set (3.3) | Up to 90 days, set by them rather than by us, and set on every visit rather than only on one that came from an ad. Clearing cookies and site data removes them sooner, and a Global Privacy Control signal means they are never set at all. What each company then keeps on its own systems is governed by its own policy, not this one. |
| Model provider logs (OpenAI, Anthropic) | Up to 30 days for abuse monitoring under their API terms, then deleted |
| Server logs | 30 days |
| Error reports | 90 days |
| Database backups | Rotating, maximum age 30 days |
We act on deletion requests within 30 days. Some records may be kept longer where the law requires it.
On the signed-in product, the honest answer is that we keep it. A product whose whole promise is that it gets closer the more of you it knows would be lying if it quietly aged your conversation out from under you, so nothing in 3.5 expires on a timer. It stays until you ask us to remove it, and 8.1 is how.
08Your rights
8.1 Everyone
Wherever you live, you can:
- See what we hold. Email privacy@getinward.comand we will send you a copy. If you are signed in at /home, that copy is everything in 3.5, including the parts the app does not show you: the working notes behind your steps, the running summary, and the day’s bookkeeping.
- Have it deleted. Email privacy@getinward.com. No reason needed, and we will not ask for one. There is no delete button in the product, so this is a person doing it rather than a switch you flip, which is why section 7 promises 30 days rather than instantly. What that removes is your account and everything attached to it: the conversation and every message in it, your Inner Map, your plans and their steps, the promises, the bookkeeping, and the record of the emails we sent you. Two more things go with it, stated because neither happens as a technical side effect and both are done by hand on the same request: the demo session you originally ran (a separate record rather than part of the account), and the copies described in section 5, which we remove from our analytics provider within the same 30 days rather than leaving them to age out on section 7’s schedule.
- Have the account closed instead, if you want to stop rather than erase. Closing leaves what we hold exactly as it is and shuts the door on it: a closed account stays closed, because signing in again with the same address does not reopen it. Ask for deletion instead and the paragraph above is what happens.
- Have it corrected if something we hold about you is factually wrong.
- Ask not to be remembered.If your browser sends a Global Privacy Control signal, we honour it automatically. We set no identifier, keep no copy of one, make no recording of how you moved through the page, and send nothing to any advertising platform — including for an ad click that happened before you turned the signal on. Meta’s and Google’s scripts are not loaded at all under this signal. They are not loaded and silenced; the pages are served without them, so neither company learns that you were here. If you turn the signal on part-way through a visit, we stop reporting to them from that moment. The demo itself works exactly the same. Some browsers send this signal by default and others offer it as a setting or an extension.
- Stop. Closing the tab stops any further collection. To remove the identifier described in 3.3 as well, clear cookies and site data for this site.
Because the demo is anonymous, we may need something to find your session by, usually the email address you gave us. If you gave us none, tell us roughly when you used the demo and we will do our best. If you are signed in at /home, write from the address you sign in with and that is all we need.
8.2 California residents (CCPA / CPRA)
If you live in California, you also have:
- The right to know what categories of personal information we collect, where they come from, what we use them for, and who we share them with. This document discloses all of it.
- The right to delete your personal information, subject to narrow legal exceptions.
- The right to correct inaccurate personal information.
- The right to limit use of sensitive personal information. We treat everything you tell Sherp as sensitive personal information, on the demo and in the signed-in product alike, along with everything the product concludes about you and keeps in section 3.5. We use it to give you advice and to make the product better, and for nothing else. We never use it to infer characteristics for advertising.
- The right not to be treated differently for exercising any of these.
- No sale. Two advertising shares, and you can opt out of both.We do not sell your personal information. We do share two advertising signals. The first is Meta’s and Google’s own scripts on our pages, which report your visit and how far through the demo you got, to them, directly. The second is our server telling a platform that a click it sold reached the demo; what travels there is that platform’s own click code, your browser type and the page URL. Your email address is never part of either, your IP address is never part of either, and neither is anything you wrote. Both shares belong to the public pages and the demo. Nothing about the signed-in product is shared with anyone for advertising, in any form.
- An opt-out we honour automatically,rather than one you have to go and find. We treat a Global Privacy Control signal from your browser as a valid opt-out of both of those shares and everything in 8.1, and we act on it without you having to ask us — which is why there is no “Do Not Sell or Share” link on this site to click. Under that signal the advertising scripts are never loaded in the first place, so this is a real opt-out and not a promise about what we do afterwards. You can also simply email us. See 8.1 for what the signal changes.
To exercise any of these, email privacy@getinward.com.
8.3 EU, UK and other GDPR-aligned regions
- Access, rectification, erasure, restriction, portability and objection under GDPR Articles 15 to 22.
- The right to complain to your local data protection authority.
- Legal basis. We process what you give the demo on the basis of the service you asked for, and analytics and security on the basis of legitimate interests.
- International transfers. Your data is stored in the United States. We rely on the EU-US Data Privacy Framework where available, and on Standard Contractual Clauses otherwise.
- On the advertising scripts, and why you are not being asked to consent. We advertise in the United States only, where the law treats a Global Privacy Control signal as a valid opt-out and does not require us to ask first. That is the whole reason this site has no cookie banner. If we ever advertise in the EU or the UK, the rule is the opposite and consent has to come first — so this page will be revised and a genuine choice will appear before either script loads, rather than the two being treated as though they were the same situation. Section 11 is the promise that the page changes before the practice does.
09Children
Inward is for adults. We do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and believe a child under 13 has used the demo, contact privacy@getinward.com and we will delete whatever we hold.
10Security
- Encrypted in transit. All traffic to and from the site uses TLS 1.2 or higher.
- Encrypted at rest. Our database is encrypted where it is stored.
- Row-level access control. The database itself enforces which rows a request can read, rather than trusting the application to remember.
- Limited access. Only authorised engineers can reach production systems, and only when the work needs it.
No system is perfect. If we find a security incident affecting your data, we will tell you as the law requires.
11Changes to this policy
We update this document as the product changes. The effective date at the top is the date of the most recent revision, and material changes, meaning a new provider, a new category of data, or a new use, will be reflected here before they take effect.
Version 7 is what that looks like in practice. Two of the things listed in 3.5, the working note behind each step and the dated promise, are described here as the product gains them rather than afterwards, because a page that catches up later is a page nobody can trust to be current.
Version 8 is the same promise kept a step earlier. The weather on the app’s opening page, and the forecast service named in 3.4, are described here in the release that builds them, before a single member has seen that page.
Version 9 narrows a word so it stays exactly true. The signed-in product now counts one thing — which of the opening page’s three options you pick, or that you skip it — so “no measurement code” in 3.4 became “no third-party measurement code,” and the four counters are described there in the same release that ships them.
Version 10 withdraws a promise rather than adding one. Version 8 said the weather on the app’s opening page was stored nowhere at all; your days are now pages you can look back through, and each keeps its own morning — the city, the sky, the temperature — so an earlier day shows the weather it had. Written once a day, never revised. Sections 3.4 and 3.5 changed in the release that builds it.
Version 11 widens something version 9 narrowed. The signed-in product now notes a short, fixed list of moments as they happen, and sends them to the analytics company named in 3.3 rather than counting them only on our own servers. Section 5.2 lists what is in those notes and what is deliberately kept out of them, and 3.4 no longer says the cover’s four counters are the only counting the product does. Nothing new runs in your browser, and nothing you wrote leaves in them. Both sections changed in the release that builds it.
Version 12 corrects a description of ourselves rather than announcing a new capability. Section 5.3 used to say that our team reads the conversations members have with Sherp, not summaries of them but the conversations. That was a fair account of what we are able to do and a poor account of what we do. It now separates the two: a person here can reach the raw text, and what actually happens is narrower, which is specific moments surfaced while chasing a specific problem, with identifiers and sensitive detail abstracted out of them before we read, and no reading of whole conversations. The same section now describes what the tools we watch the product with receive, which is a codename, counts and categories, and never a line you wrote. The narrower description is the one we hold ourselves to, and it is the one Sherp will give you if you ask him.
Privacy questions
Inward Journeys, Inc. · Brooklyn, NY
