Privacy
After the breach and the rotation, we cut leftover access and prove it bounced. This page is a plain-language summary of how LingerCut handles information. It is not legal advice, not a GDPR certification, and not a SOC 2, ISO, or FedRAMP claim.
Controller
The controller for this public SaaS evaluation is Ugochukwu Solomon Eneh / LingerCut (founder Ugochukwu Solomon Eneh). We have not appointed an EU Article 27 representative. Do not treat this page as GDPR-certified.
What LingerCut is for
LingerCut is a defensive Residual Trust Assurance product: inventory leftover sessions, OAuth grants, refresh tokens, and API keys; cut them when an authorized operator decides; prove the old credential bounced; keep a kill receipt. Offensive use, unauthorized access, or attacking systems you do not control is not permitted.
Who authorizes cuts
Cuts are initiated by operators you configure (for example with operator lock and, when enabled, dual-control approval). LingerCut does not silently cut production trust without that control plane. You are responsible for authorizing operators and for complying with your org’s policies and applicable law.
Data we may process
Depending on how you deploy and which connectors you enable:
- Operator authentication state (session cookie when operator lock is on)
- OAuth tokens and grant metadata from providers you connect (Google, Microsoft, GitHub, etc.) — used to inventory and cut leftover trust you authorize
- Kill receipts, signatures, and related export artifacts you generate
- Optional webhook payloads if you configure a SIEM URL
- Optional LLM prompts for ranking narrative / guide / support phrasing only (never stamp CUT)
Demo inventory rows are illustrative product data, not your production tenant.
Support tickets
When you confirm a handoff, LingerCut stores a queued ticket so a trained operator can respond: name, work email, company, and chat transcript. Secrets that look like passwords, tokens, or API keys are redacted before storage. Support chat is not a kill receipt.
Storage and retention
On Vercel SaaS, durable receipts and Support tickets may use a Redis provider you configure (for example Upstash); otherwise they stay in process-local storage that does not survive every deploy. Sovereign / self-host deploys keep data in infrastructure you control.
Retention intent: Support tickets are kept so an operator can follow up, then deleted or anonymized when the thread is closed or after a reasonable follow-up window. Kill receipts stay until you export or delete them. This is operational intent — not a certified retention schedule.
We do not sell data
LingerCut does not sell personal data. We do not run default third-party product analytics. Optional LLM calls happen only if an operator sets an API key, and those prompts are for phrasing — never to stamp leftover trust gone.
Cookies and telemetry
Operator session cookies may be used when operator lock is enabled. Public Support may set a conversation-id cookie (lc_support_cid) so the thread can be queued with a human. LingerCut ships with no default third-party product analytics. Do not add analytics IDs unless you intentionally choose to.
Contact
Use the Support widget or page until MX for hello@lingercut.com exists. That brand address is not a live mailbox yet. See also Terms of use.