A little clarity.
Invite-only beta · 28 September 2026.
This early release is for invited testers. The information below describes the current implementation, not a completed general-availability legal review. Provider arrangements and international child-privacy requirements still need review before a broader launch.
Privacy · draft
The operator is James Cazzetta, using the studio name Fiebertraum Studio. Contact details appear in the imprint.
On this device
In the earlier browser-only beta, your journal stays in this browser and does not sync. Where account sign-in is enabled, saved goals, entries, confirmed measurements, saved assessments and journal preferences sync to your account through Cloudflare D1. A working copy remains in your browser; unfinished drafts remain local. An earlier browser journal is uploaded only when you explicitly choose to import it. Clearing browser storage can remove unsynced changes and drafts. Exported JSON backups are readable and unencrypted; keep them somewhere safe.
Accounts and sign-in
WorkOS AuthKit provides account sign-in. thusfar stores an internal user ID, a WorkOS user ID, email address, optional display name, profile preferences, session records and your saved journal. Email is not used as a journal ownership key. Essential, HTTP-only session cookies keep you signed in for up to seven days; access may end earlier if the session is revoked. Signing in does not enable Jev checks or marketing messages. See the WorkOS privacy policy.
Live checks are online processing
After the entry questions and your explicit acknowledgement, a typing pause can send an unsaved draft, the goal and selected earlier entries through our backend to Jev (TypeSafe AI). Entry dates, time-zone context, relevant measurements and interpretation preferences may accompany the text. They are used to interpret the goal or action and provide personalised feedback. Ordinary interface rendering does not need a Jev call.
When logging from the home screen, connection checks compare your draft with each eligible goal separately. Strong matches can be selected before you save; you can remove them or choose other goals. Tracking options can exclude a goal from automatic discovery. Saving an entry does not authorise later automatic connections. An entry connected to several goals has one shared source; changing that source updates all its connections. Removing a connection keeps the entry in Your activity. Use Delete entry everywhere to remove the shared record.
Any personal or sensitive information you include in those words can be transmitted too. Avoid including another person’s private details. On-device storage does not mean the application works entirely offline or that all processing stays on your device.
The hosted app runs on Cloudflare. Account journals and profiles are stored separately from short-lived live-check quota records. The account database is configured in Cloudflare’s EU jurisdiction; this does not mean all authentication, network or Jev processing stays in the EU. The quota database stores UTC day/hour, keyed hashes of an account (or a session in the earlier browser-only beta), and a separate keyed hash of the connection IP. IPv6 addresses are grouped by network prefix. Hashes change daily. No journal text, raw IP address or cookie value is stored in the quota database. An hourly cleanup removes quota records before the previous UTC day; infrastructure backups can retain them longer.
Cloudflare also processes network and security information needed to serve the app. The app does not deliberately log journal bodies, provider replies, cookies or credentials. Live checks have account/session, shared-network and whole-beta allowances; reaching a limit pauses checks, not journal access. These are security controls, not behavioural analytics. Cloudflare’s infrastructure processing is described in its privacy policy.
TypeSafe AI
TypeSafe’s published privacy policy describes US processing and its own retention practices. No zero-retention promise is made here. The applicable customer agreement, subprocessors, transfer arrangements and retention settings must be confirmed before public launch. See the TypeSafe privacy policy and data processing addendum.
Entry permission and essential storage
Entry asks for an adult declaration, not a date of birth or verified proof of age. Account sign-in and permission for Jev checks are separate. Account-based beta access stores invitation admission and a versioned live-check acknowledgement; you can withdraw it in Data & backups. During a sign-in redirect, an invitation may be retained temporarily in this tab and is cleared when the page returns. The earlier browser-only beta uses a signed, HTTPS-only permission cookie that expires within 24 hours. An invitation is not proof of identity.
Under-18 visitors and visitors who decline the age question see an illustrative preview without personal-entry fields or Jev checks. This is a temporary live-feature restriction pending provider clarification and child-privacy review—not a claim that a simple declaration resolves those requirements.
No advertising trackers or optional product analytics are added. Cloudflare provides essential security and operational instrumentation. No zero-retention promise is made for infrastructure or Jev processing.
Your controls
Use Data & backups to export, restore or turn off live checks. Turning them off stops new checks from this page; it cannot recall requests already transmitted. You can delete goals and entries in the journal. Local deletion does not, by itself, request deletion from a processor.
Where accounts are enabled, Your account lets you export the working journal, sign out, or delete the account after a recent sign-in. Account deletion removes the active server journal and profile details and revokes access. Minimal identity and deletion markers are retained to prevent stale sessions from recreating deleted data. Offline copies on other devices and downloaded exports must be removed separately. Cloudflare recovery history may retain deleted data for up to 30 days; this is not instant erasure from every backup. See Cloudflare’s backup documentation. Account journal content is not end-to-end encrypted.
For questions or access/deletion requests, contact beta@thusfar.me. We cannot retrieve unsynced browser data. Processor-held information must be handled separately. Applicable legal bases, safeguards, processor terms, international transfers and retention settings still require review before general availability.
Imprint · draft
James CazzettaOberstrasse 159
9000 St. Gallen
Switzerland
Fiebertraum Studio is the operator’s studio name, not a separately registered company.
Beta contact and privacy requests: beta@thusfar.me. This address is forwarded by Cloudflare to the operator’s Gmail inbox. Avoid sending sensitive journal content unless it is needed for your request.
Beta terms · draft
The intended first public version is free. No payment, subscription or automatic renewal is implemented. Future admission limits or paid offers are undecided and would be explained separately; this is not a promise of permanent free access.
The application is a personal goal journal with Jev-assisted interpretation. Feedback may be incomplete or mistaken. Alignment scores describe an estimated relationship to a goal, not proof of achievement, safety, medical benefit or future success. It is not medical, financial or other professional advice.
Keep your own backups and review suggested measurements before keeping them. Beta behaviour and features may change. Nothing in this draft attempts to exclude mandatory consumer rights.
The current entry flow temporarily limits live checks to people who declare they are 18 or older and acknowledge the processing notice. A static example remains available otherwise. Appropriate support for younger users is unresolved.
Final service terms, contact information and applicable international requirements still need review before a public release.