Privacy at C10N Labs
We collect only what is needed to operate this website, distribute requested insights, and support invited client work. This notice requires human legal and operational review before production launch.
Public website and contact
The contact form does not submit information to C10N Labs or a website backend. It constructs a draft addressed to hello@c10n.ai in your email application. Your email provider and ours process the message only if you choose to send it.
Vercel hosts the site and provides infrastructure analytics. Sentry receives error diagnostics only when configured; default personal-information collection, tracing, replay, and logging are disabled.
Insights email
If you subscribe, Cloudflare Turnstile first checks the request for abuse. Resend sends a confirmation email and becomes the source of truth for your subscription after you confirm. Resend stores the email address, topic status, delivery events, and unsubscribe state needed to operate the list. We do not copy the subscriber list into the client database.
You can unsubscribe using the link in any broadcast. Unconfirmed requests expire after 24 hours.
Client portal
Client access is invite-only. Better Auth processes invitations, magic links, sessions, organization membership, and security rate limits. Magic-link tokens are hashed at rest, expire after ten minutes, and are single-use. Neon stores structured portal information such as client profiles, contacts, engagement intake, and links and status metadata for contracts and invoices.
When configured, Better Auth Infrastructure receives authentication, session, user, and organization events to provide C10N operators with a hosted management dashboard and audit history. It is not the authentication database. Activity tracking, managed messaging, and additional security profiling are disabled in the initial integration.
The portal does not store uploaded documents, signatures, payment details, or native invoices. Access is scoped to the client organization; C10N global administrators can operate the registry. Internal activity events record who changed an entity and the kind of change without copying sensitive field values.
Processors
Retention and rights
We retain client records while they are needed for an engagement, legitimate operational history, or legal obligations. Contacts may be archived rather than hard-deleted to preserve that history. Authentication and invitation records expire according to the security periods described above. Resend retains confirmed contacts until they unsubscribe or we remove them.
To ask about, correct, or request deletion of your information, email hello@c10n.ai. Some records may need to be retained for contractual, financial, security, or legal reasons.
Changes
We will update this notice when the portal, processors, or data practices materially change and revise the date above.