Privacy
After the breach and the rotation, we cut leftover access and prove it bounced. This page is a plain-language summary of how LingerCut handles information. It is not legal advice, not a GDPR certification, and not a SOC 2, ISO, or FedRAMP claim.
Controller
The controller for this public SaaS evaluation is Ugochukwu Eneh / LingerCut. We have not appointed an EU Article 27 representative. This is not a GDPR certification.
Founder: Ugochukwu Eneh. Contact hello@lingercut.com or the access-request form.
Data residency
Public SaaS (lingercut.com) runs on Vercel in iad1 — Washington, D.C., United States. Access-request leads and kill receipts persist to Upstash Redis REST when those env keys are set (founder SaaS intends a US-East database alongside the app); otherwise they write local .data files, which are ephemeral on Vercel. LingerCut does not operate an EU-only region today.
Access-request form
The public form on /access, the homepage, /demo, and /pricing collects: name, work email, company, country/region, why you are contacting (intent and optional note), and a required consent box that starts unchecked. We use those details only to reply to the enquiry and notify the founder if a mailer key is configured. Lawful basis for this list is consent. We do not rely on legitimate interests for this form.
The box people tick is a short first layer: I agree LingerCut may contact me about this Residual Trust Assurance enquiry, using only the details I submit on this form. You can read how we handle this in our Privacy notice, or email hello@lingercut.com to stop contact or delete this request. This page is the full notice: fields, retention, and rights.
Access-request records are kept until we reply or for 24 months, then deleted or anonymized, unless a later contract requires longer. You can withdraw consent, request a copy, or ask us to delete sooner at hello@lingercut.com. Withdrawing consent does not affect replies already sent.
Your rights
You can withdraw consent, ask for a copy of access-request data we hold about you, ask us to correct it, or ask us to delete it by emailing hello@lingercut.com. Withdrawing consent does not affect replies already sent. You can also complain to your local data protection authority. We do not sell personal data.
What LingerCut is for
LingerCut is a defensive Residual Trust Assurance product: inventory leftover sessions, OAuth grants, refresh tokens, and API keys; cut them when an authorized operator decides; prove the old credential bounced; keep a kill receipt. Offensive use, unauthorized access, or attacking systems you do not control is not permitted.
Who authorizes cuts
Cuts are initiated by operators you configure (for example with operator lock and, when enabled, dual-control approval). LingerCut does not silently cut production trust without that control plane. You are responsible for authorizing operators and for complying with your org’s policies and applicable law.
Customer credentials
LingerCut does not hold a vault of customer passwords, PATs, refresh tokens, session cookies, or API keys. Connector OAuth for a live cut lives in AES-GCM sealed operator-session cookies, not a long-lived LingerCut secret store. Public pages never ask visitors to paste live credentials. Kill receipts record cut metadata and the probe result — not the secret material.
Data we may process
Depending on how you deploy and which connectors you enable:
- Access-request fields listed above (consent recorded with a timestamp)
- Operator authentication state (session cookie when operator lock is on)
- OAuth tokens in sealed operator-session cookies from providers you connect — used to inventory and cut leftover trust you authorize; not a LingerCut secret vault
- Kill receipts, signatures, and related export artifacts you generate
- Optional webhook payloads if you configure a SIEM URL
- Optional LLM prompts for ranking narrative / guide / support phrasing only (never stamp CUT)
Demo inventory rows are illustrative product data, not your production tenant.
Support tickets
When you confirm a handoff, LingerCut stores a queued ticket so a trained operator can respond: name, work email, company, and chat transcript. Secrets that look like passwords, tokens, or API keys are redacted before storage. Support chat is not a kill receipt.
Logging, retention, sharing, deletion
We log access-request fields you submit, support tickets (name, work email, company, redacted transcript), operator audit rows (login, cut, dual-control — never passwords), and kill-receipt metadata. Optional LLM prompts for Support phrasing exist only if an operator sets OPENAI_API_KEY; those prompts never stamp VALID. No default third-party product analytics.
We do not sell personal data. Sharing is limited to the subprocessors below, and to the founder mailbox when a notify is sent. Kill receipts stay until you export or delete them. Support tickets are kept so an operator can follow up, then deleted or anonymized when the thread is closed or after a reasonable follow-up window.
To delete access-request or support personal data, email hello@lingercut.com. This is operational intent — not a certified retention schedule.
Subprocessors
- Vercel — App hosting and serverless API routes (the backend is those routes, not a separate AWS service). Region: Vercel iad1 (Washington, D.C., United States).
- Upstash — Redis REST for durable receipts, leads, and rate limits when configured. Region: Operator-chosen Upstash database; founder SaaS intends US East alongside iad1.
- Resend — Transactional founder notify only if RESEND_API_KEY is set. Proton hello@ is a mailbox, not SMTP. Region: Resend’s mail infrastructure; notify goes to the founder mailbox.
- OpenAI — Optional Support / Live Desk phrasing. Never cuts. Never stamps VALID. Unset = grounded FAQ only. Region: OpenAI processing region for the configured API.
- Cloudflare — DNS / MX for lingercut.com as configured. Region: Cloudflare anycast.
Self-host
Buyer-host Docker Compose (Sovereign) is documented. It is not a one-click self-host product, and LingerCut does not operate a dedicated VPC for you. Until a buyer runs Compose on their host, the public product is Vercel SaaS.
Cookies and telemetry
Operator session cookies may be used when operator lock is enabled. Connector OAuth uses sealed cookies for the operator session. Public Support may set a conversation-id cookie (lc_support_cid) so the thread can be queued with a human. LingerCut ships with no default third-party product analytics. Do not add analytics IDs unless you intentionally choose to.
Contact
Contact hello@lingercut.com (Live mailbox), use the access-request form, or Support. See also Terms of use and Trust.