Privacy

After the breach and the rotation, we cut leftover access and prove it bounced. This page is a plain-language summary of how LingerCut handles information. It is not legal advice, not a GDPR certification, and not a SOC 2, ISO, or FedRAMP claim.

Controller

The controller for this public SaaS evaluation is Ugochukwu Solomon Eneh / LingerCut (founder Ugochukwu Solomon Eneh). We have not appointed an EU Article 27 representative. Do not treat this page as GDPR-certified.

What LingerCut is for

LingerCut is a defensive Residual Trust Assurance product: inventory leftover sessions, OAuth grants, refresh tokens, and API keys; cut them when an authorized operator decides; prove the old credential bounced; keep a kill receipt. Offensive use, unauthorized access, or attacking systems you do not control is not permitted.

Who authorizes cuts

Cuts are initiated by operators you configure (for example with operator lock and, when enabled, dual-control approval). LingerCut does not silently cut production trust without that control plane. You are responsible for authorizing operators and for complying with your org’s policies and applicable law.

Data we may process

Depending on how you deploy and which connectors you enable:

  • Operator authentication state (session cookie when operator lock is on)
  • OAuth tokens and grant metadata from providers you connect (Google, Microsoft, GitHub, etc.) — used to inventory and cut leftover trust you authorize
  • Kill receipts, signatures, and related export artifacts you generate
  • Optional webhook payloads if you configure a SIEM URL
  • Optional LLM prompts for ranking narrative / guide / support phrasing only (never stamp CUT)

Demo inventory rows are illustrative product data, not your production tenant.

Support tickets

When you confirm a handoff, LingerCut stores a queued ticket so a trained operator can respond: name, work email, company, and chat transcript. Secrets that look like passwords, tokens, or API keys are redacted before storage. Support chat is not a kill receipt.

Storage and retention

On Vercel SaaS, durable receipts and Support tickets may use a Redis provider you configure (for example Upstash); otherwise they stay in process-local storage that does not survive every deploy. Sovereign / self-host deploys keep data in infrastructure you control.

Retention intent: Support tickets are kept so an operator can follow up, then deleted or anonymized when the thread is closed or after a reasonable follow-up window. Kill receipts stay until you export or delete them. This is operational intent — not a certified retention schedule.

We do not sell data

LingerCut does not sell personal data. We do not run default third-party product analytics. Optional LLM calls happen only if an operator sets an API key, and those prompts are for phrasing — never to stamp leftover trust gone.

Cookies and telemetry

Operator session cookies may be used when operator lock is enabled. Public Support may set a conversation-id cookie (lc_support_cid) so the thread can be queued with a human. LingerCut ships with no default third-party product analytics. Do not add analytics IDs unless you intentionally choose to.

Contact

Use the Support widget or page until MX for hello@lingercut.com exists. That brand address is not a live mailbox yet. See also Terms of use.