Last updated: TODO set on publication
OnBall is a small, invite-only beta. This page says what it collects, who else handles it, how long it is kept, and how to get rid of it. It is written to be read, not to be survived.
Your email address. It is your account. Signing in sends a one-time code to that address, so there is no password: OnBall has never stored one and never will.
Your name. First and last name are both required when you sign up. OnBall greets you by your first name, and the two together make the initials on your avatar.
A profile photo, if you add one. Entirely optional. The file is uploaded to and hosted by Clerk (below). OnBall keeps no copy.
Your conversations. Every question you ask, every answer OnBall gives, and every chart it draws are stored against your account, along with the stats each answer was built from. That storage is what makes history, resuming a conversation, and titles work. It is also what lets OnBall prove where a number came from.
Turns that broke. When an answer streams but fails to save, OnBall records the failure and the answer that did not persist, so the turn can be retried rather than lost.
Your marketing consent, if you give it. Not merely a yes or a no: the time, the context of the request, and the exact wording you were shown. A bare true would be worth nothing later, to you or to us.
What OnBall does not collect: no payment details (the beta is free), no advertising identifiers, no analytics scripts and no advertising trackers. There is one third-party script on the site, and it is the human check on the join form: Cloudflare Turnstile, described below. OnBall sets no cookies of its own; the only cookie it relies on is Clerk's session cookie, which is what keeps you signed in. The human check works by handing back a one-time token rather than by setting a cookie, and Cloudflare states that Turnstile does not use cookies at all. Your browser separately remembers whether the history drawer is open. That preference stays on your device.
OnBall runs on other companies' infrastructure. These are all of them, and what each one sees:
TODO: link each processor's own privacy policy, and confirm this list at ship time against any service added since.
One detail worth being exact about, because most privacy policies are vague here. The log line OnBall writes for each answer records timing, token counts, cost, which model replied, and whether the turn succeeded. It does not contain your question or the answer. Clerk and Vercel do record ordinary request metadata, including IP address and browser, as part of serving and securing the app.
Service email is part of the product. Sign-in codes, waitlist confirmation, your invite when a place opens, and security notices. You cannot switch these off while you hold an account, for the plain reason that without the sign-in code you cannot sign in.
Marketing email is opt-in only. It means product updates and nothing else. The box is never ticked for you, it is always separate from the box that agrees to the Terms, and nothing about your access to OnBall depends on it. Leave it untouched and you get precisely the same product.
You can withdraw marketing consent at any time, by the unsubscribe link at the foot of any marketing email or from email preferences in your account settings. Both do the same thing. TODO: state the turnaround (CAN-SPAM allows ten business days; the intent is immediate).
Unsubscribing never touches service email. Your sign-in code still arrives. That separation is deliberate: unticking a marketing box should never cost anyone the ability to log in.
When you withdraw, the consent record is kept rather than deleted. The record of having opted in, and then out, is the evidence that the mail stopped when you said so.
Ask and it is deleted. Write to TODO contact address. Deleting the account removes the account row, and the database cascades from there: your conversations, your messages, your charts, and your failed-turn records all go with it. Your Clerk identity (email, name, photo) is a separate record and is removed alongside it.
One record deliberately survives: your marketing consent. If you ever ticked the marketing box, the evidence of it (the exact wording you were shown, when, and from where) stays in the database after the account is gone, with its link to your account row broken. That is a decision, not an oversight. The consent record is the proof that mailing you was lawful, and clearing out an old account must not be able to destroy it. If you want that erased too, say so and it will be, as a separate and explicit step.
You can delete your account yourself, from the account page. It takes effect immediately and there is no undo. You can also ask for a copy of what is held about you, or ask for it to be corrected, at the same address. If you want the surviving consent record erased too, that is the separate step described above: ask, and it will be done.
If this page changes in a way that matters, we will say so. The marketing consent record keeps the wording that was in force when you agreed, so a later edit here cannot quietly rewrite what you agreed to.
TODO: legal entity name, postal address (required in marketing email under CAN-SPAM), contact email, and the data controller named for GDPR purposes.