Access request — stored on the server, not mailto

Talk leftover trust after a vendor incident

Assume the trusted app is already compromised. Prove and cut what it left behind. Ugochukwu Eneh runs LingerCut. Submit this form: we persist the request first, then email the founder if a mailer is configured. If mail fails, the lead is still stored. Confirmation stays on this page. This is not a kill receipt.

Demo, design partner, or pilot

Purpose: so the founder can reply about Residual Trust Assurance (leftover sessions, OAuth grants, kill receipts). We collect only name, work email, company, country/region, why you are contacting, and consent. We do not ask for tokens, cookies, or API keys. Access-request records are kept until we reply or for 24 months, then deleted or anonymized, unless a later contract requires longer. You can withdraw consent, request a copy, or ask us to delete sooner at hello@lingercut.com. Withdrawing consent does not affect replies already sent.

Public mailbox hello@lingercut.com still receives mail. The form is the product path so a request is not lost when no mail client is installed.

Public SaaS (lingercut.com) runs on Vercel in iad1 — Washington, D.C., United States. Access-request leads and kill receipts persist to Upstash Redis REST when those env keys are set (founder SaaS intends a US-East database alongside the app); otherwise they write local .data files, which are ephemeral on Vercel. LingerCut does not operate an EU-only region today.