Passwordless sign-in
Verified email access avoids password reuse risk and removes the need to store password hashes for user accounts.
Your Inner Synthesis protects sensitive self-reflection by collecting less by default, keeping provider credentials server-side, using verified account access, and routing payments through hosted checkout.
Verified email access avoids password reuse risk and removes the need to store password hashes for user accounts.
Session cookies are signed and kept out of JavaScript-readable browser storage.
AI provider keys and billing credentials stay on the server. Browser code calls same-origin app endpoints.
Checkout and subscription management run through hosted payment pages, so card details are not collected by this app.
Guided reflection and paid features are checked against plan limits before higher-cost processing is returned.
Assessment and reflection data starts locally. Account-backed continuity requires a verified profile and clear user choice.
Production releases should pass the build, restart cleanly under PM2 and respond through the public domain before being considered live.
Keep access to your email account secure, use trusted devices for sensitive reflection, and avoid sharing exported reports with people who should not see them.