CELLCTRL

Privacy Notice

Last updated: 8 September 2026

1. Data we process

Depending on how you use CELLCTRL, we may process your account email, authentication status, account/user ID, license key, package/access entitlements, expiry dates, order history, support messages, device binding information and administrative audit records.

2. Trial anti-abuse data

To protect the one-time 20-minute trial from repeated account creation, CELLCTRL creates cryptographic hashes derived from the browser/device identifier and network address. These anti-abuse values are stored as hashes rather than the raw trial device fingerprint or raw network address in the trial claim record.

3. Runtime device data

The CELLCTRL Loader creates a local random device identifier in browser storage. For paid access, that identifier can be bound to the license so the same license is not freely shared across unrelated devices. Trial runtime binding is tracked separately from normal paid license device binding.

4. Local browser storage

CELLCTRL and the Loader use localStorage for items such as the license key, random device identifier, UI state, hotkeys, selected Cell Spawn sector, Buddy name/preferences and other local interface settings. Clearing browser storage can remove those local preferences and may cause the Loader to ask for the license again.

5. Why we use the data

We use this data to create and secure accounts, verify email, deliver trial/Core/Pro access, enforce expiry, bind licenses where required, prevent trial abuse, process orders/refunds, provide support, investigate errors and protect the service against misuse.

6. Service providers

CELLCTRL currently uses third-party infrastructure including Supabase for authentication/database/storage, Vercel for website/runtime hosting and Lemon Squeezy for hosted checkout, payment processing and Merchant of Record services. Those providers process data under their own terms and privacy notices.

7. Lemon Squeezy checkout and payment information

CELLCTRL does not store your full payment-card details. Payment credentials and checkout are handled by Lemon Squeezy. CELLCTRL sends the logged-in account email and internal account/SKU identifiers to checkout so the resulting signed order event can be matched to the correct CELLCTRL account and package. CELLCTRL receives the order information required to activate, audit or revoke the related paid access.

8. Retention

Account, order, license, access, trial and security records are kept for as long as reasonably necessary to provide the service, prevent abuse, handle disputes, meet accounting/legal obligations and maintain auditability. Support and operational records may be removed or anonymized when no longer needed.

9. Sharing and sale of data

CELLCTRL does not sell personal data to advertisers. Data is shared only where needed with infrastructure/payment providers, where required by law, or where necessary to protect the service and its users.

10. Security

We use server-side access controls, signed Lemon Squeezy webhook verification, hashed anti-abuse identifiers, authenticated admin routes and license/access checks. No online system is perfectly secure, so users should also protect their account password and license key.

11. Your rights

Depending on your location, you may have rights to access, correct, delete or restrict certain personal data and to object to some processing. Use the CELLCTRL support route from Dashboard to make a privacy/account request. Some transaction, fraud-prevention or legal records may need to be retained even after account deletion.

12. Changes

This notice may be updated when CELLCTRL adds controls, providers or legal requirements. The current version will be published on this page.

← Back to CELLCTRL