CCPConditioning Control Panel
legal.dir / privacy_policy.txt

Privacy Policy

How Conditioning Control Panel handles your data

Summary

This summary provides key points from our privacy policy. You can find full details in the sections below. See also our Terms of Service, our Refund and Cancellation Policy, and the company details in our Legal Notice.

  • What we collect: Display name, your email address (stored only as a one-way hash on the desktop rail; held by Supabase Auth on the web rail so it can send magic-link sign-in emails), OAuth provider IDs, progression data, and application settings - only if you opt into cloud features.
  • Day log (signed-in only): Once signed in, the desktop app also syncs a per-day record of how much you used each feature (eleven counters, the quests you completed that day, and the day each achievement was first unlocked). It is shown only to you on your own Spiral, never sold, never sent to third-party analytics, kept for 400 days, and deleted with your account. Anonymous use sends nothing.
  • What we don't collect: IP addresses, media file content, browsing history, or any sensitive personal information. Card numbers never reach our servers: payments are handled by PayPal.
  • Offline by default: The application works fully offline. Cloud sync, leaderboards, and accounts are entirely optional.
  • Open source: Our source code is publicly available so you can verify exactly how your data is handled.
  • Self-service data control: You can export or permanently delete all your data at any time directly from the app - no need to contact us.
  • No analytics or advertising: We do not use Google Analytics, behavioral tracking, or advertising cookies. The website can embed one third-party service (Google Fonts); it does not load until you consent via the cookie banner.
  • Payments: Subscriptions are billed by CC Labs S.r.l.s. through PayPal. PayPal holds your name, email, billing or payer details and payment method; we receive an identifier, the plan, the country and whether it is paid.
  • Where data is stored: Server-side data is stored in the United States via Vercel, Upstash, and Supabase. All data is transmitted over HTTPS.
  • Age requirement: You must be at least 18 years old to use this application.

Data Controller

The data controller is:

CC Labs S.r.l.s.
Via Marconi 60, 80056 Ercolano (NA), Italy
P.IVA and codice fiscale IT11045351217 · REA NA-1150672 · Registro delle Imprese, CCIAA Napoli
PEC: cclabs@pec.it

Contact for data protection matters, including any request about your rights: support@cclabs.app. Full registry details are on the Legal Notice page.

CC Labs S.r.l.s. is the controller for personal data processed through the Conditioning Control Panel application, the cclabs.app and app.cclabs.app websites, and subscription billing.

Data Protection Officer

CC Labs S.r.l.s. has not appointed a Data Protection Officer and is not required to appoint one. Our processing does not meet the conditions in Article 37 of the GDPR: we are not a public authority, our core activity is not large-scale regular and systematic monitoring of individuals, and it is not large-scale processing of special categories of data. Send data protection questions and requests to support@cclabs.app.

The application is open source; the source code is publicly available on GitHub, so you can check how data is handled.

What Data We Collect

Account Information (Cloud Features)

CCP supports four login methods: Discord OAuth, Patreon OAuth, an in-app invite-code account (display name + password), and web sign-in at app.cclabs.app (Patreon, Discord, or email magic link). Depending on which method you used, we store some subset of:

  • Display name - your chosen username
  • Email - on the desktop rail (Discord OAuth, Patreon OAuth, invite-code accounts, and the CCP sync server) your email address is stored only as a one-way HMAC-SHA256 hash; the plaintext address is not stored there. On the web rail (app.cclabs.app), Supabase Auth holds your email address so it can send you magic-link sign-in emails; the CCP sync server still stores only the one-way hash of it.
  • Discord ID / Patreon ID - used to link your account when you signed in with one of those providers
  • Patreon subscription tier - to verify premium access (Patreon login only)
  • Avatar URL - Discord profile picture, if you opt in to sharing it
  • Password hash - bcrypt hash for invite-code accounts (we never store plaintext passwords)
  • Privacy preferences - online status visibility, profile picture sharing
  • Auth token hash - SHA-256 hash of your session token (not the plaintext token)
  • Timestamps - account creation, last seen, last synced, client version

Storage is split across two backends: the CCP desktop server (Upstash Redis on Vercel) holds desktop-rail accounts and progression; Supabase (Postgres + Auth) holds the web-rail accounts and powers magic-link email sign-in at app.cclabs.app. When you link the two rails together via the device-code flow, both records reference the same unified ID but remain in their respective databases.

Progression Data

When cloud sync is active, we store:

  • Level, XP, and seasonal statistics (flash clicks, video watches, bubble pops, etc.)
  • Achievement progress and unlock status
  • Quest completion data
  • Skill tree data (skill points and unlocked skills)
  • Total lifetime conditioning minutes
  • Companion AI progression (per-companion level and XP)
  • All-time aggregate statistics across seasons

Day Log (Signed-In Desktop Only)

Starting with desktop version 6.9.2, the app keeps a per-calendar-day record of feature usage and syncs it to your account alongside the progression data above. For each day it stores eleven counters: XP earned, conditioning minutes, flash images shown, bubbles popped, pink filter minutes, spiral minutes, video minutes, lock cards completed, attention checks passed, bubble-count games played, and sessions started. It also stores the IDs of the quests you completed that day, and the day each achievement was first unlocked.

  • Tied to your account. It is only synced while you are signed in. If you are not signed in, nothing is sent.
  • Shown only to you. It powers the day-by-day view of your own Spiral. The public Spiral other people can see shows only the daily fill dots, never these counters.
  • Not analytics. It is never sold and never sent to any third-party analytics service.
  • Retained 400 days. Older days are dropped, and the whole log is deleted with your account.

Payment Data (Paid Subscriptions)

If you buy a subscription from CC Labs S.r.l.s., the payment is processed by PayPal, which acts as our processor and collects and holds your payment details directly. Card numbers and PayPal account credentials never reach our servers.

How the payment works

The PayPal subscription button runs in your browser using PayPal's own SDK, and you complete the payment on PayPal's side. PayPal holds your PayPal account details and whatever card or bank instrument sits behind it. Your CCP user ID is attached to the subscription so the payment can be matched to your account, and PayPal sends us webhook notifications when the subscription changes. What we receive and store is:

  • a PayPal subscription ID and payer ID;
  • the plan you are on (CCP Basic or CCP Prime) and the subscription status;
  • the payer country, which is needed to work out VAT.

We do not receive your PayPal login, your card number, or the balance of your PayPal account.

We use this to unlock the paid features on your account, to answer billing questions, and to meet our invoicing and tax obligations. Invoices and payment records are kept for the period Italian tax law requires (see Data Retention).

If you subscribe through Patreon or SubscribeStar instead, that platform handles the payment and holds the billing data under its own privacy policy; we receive only your subscription tier from their API.

Settings Backup

If you use the cloud settings backup feature, your application preferences are stored on the server so they can be restored on a fresh install.

Anti-Cheat Data

To maintain fair leaderboards, we monitor XP earning rates, session timing, and statistics consistency. Sessions are signed with HMAC to verify integrity. This data is used solely for detecting anomalies and is not shared with other users.

Eye Tracking (Optional Webcam Feature)

If you enable the optional eye tracking feature, CCP uses your webcam to detect approximate gaze direction, blink events, and basic facial gestures (mouth open) for interactive purposes. Important properties of this feature:

  • Local-only processing. Webcam frames are processed entirely in your computer's memory and discarded after each frame. Frames are never written to disk, never transmitted over the network, and never sent to CC Labs S.r.l.s. or any third party.
  • No biometric identification. The system computes gaze coordinates and basic facial gesture states only. It does not perform facial recognition, does not create or store biometric templates, and does not identify individuals.
  • Calibration data only. The only persisted data is a small set of numerical regression coefficients (gaze-to-screen mapping) stored locally in your application data folder. This file contains no images and no biometric templates.
  • Consent-gated. The feature is disabled by default and requires explicit user consent at activation. You can revoke consent at any time, which immediately stops capture and clears calibration data.

Automatically Collected Data

Our application does not log IP addresses or device fingerprints, and it does not send usage data to any third-party analytics service. The only record of how you use the app is the signed-in day log described above; anonymous use sends nothing. However, our hosting infrastructure (Vercel) may temporarily retain standard connection metadata (such as IP addresses) in their own server logs as part of normal operations. This is governed by Vercel's privacy policy and is outside our control. We do not access or use this infrastructure-level data.

What We Do NOT Collect

  • Plaintext email addresses on the CCP sync server (only one-way hashes are stored there; web-rail email addresses are held by Supabase Auth for magic-link sign-in)
  • IP addresses (not logged by the application)
  • Content of your media files (images, videos, sounds stay local)
  • Browsing history or screen content
  • System information beyond what's needed for the app
  • Patreon billing name - used transiently during login for verification but NOT stored on the server
  • Card numbers, CVC codes, full payment method details or PayPal account credentials - these are collected and held by PayPal, never by us
  • Webcam frames, images, or biometric templates (eye tracking is local-only)
  • Sensitive personal information (race, religion, health data, biometrics, etc.)

Why We Collect It

Purpose Data Used
Account sync across devices Discord/Patreon ID, display name, email hash (email address on the web rail)
Leaderboards Display name, level, XP, statistics
Anti-cheat XP rate, session timing, statistics consistency
Patreon tier verification Patreon ID, subscription status
Subscription billing and unlocking paid features PayPal subscription and payer ID; plan, status, period dates, billing or payer country
Invoicing and tax compliance Payment records and invoices held by us and by the payment processor
Your own Spiral (day-by-day view) Day log: per-day feature counters, quest IDs, achievement unlock days (signed-in desktop only)
Settings backup/restore Application preferences
AI companion chat Messages sent to OpenRouter for AI responses (not stored on our server)

How Data Is Stored

Server-Side

Cloud data is stored in Upstash Redis, a managed database service. The server runs on Vercel (serverless functions). Web-rail accounts and magic-link sign-in are held in Supabase (managed Postgres + Auth). Data is transmitted over HTTPS.

Client-Side

  • Settings and progress are stored as JSON files in %APPDATA%/ConditioningControlPanel/
  • OAuth tokens (Discord/Patreon) are encrypted locally using Windows DPAPI (Data Protection API), tied to your Windows user account
  • Auth tokens for the sync server are stored in application settings and validated via SHA-256 hashing

International Data Transfers

Our servers and infrastructure are located in the United States. If you are accessing our services from outside the United States - including from the European Economic Area (EEA), United Kingdom (UK), Switzerland, or Canada - your data will be transferred to, stored, and processed in the United States.

The United States may not have data protection laws as comprehensive as those in your country. However, we take the following measures to protect your data:

  • All data is transmitted over HTTPS (TLS encryption in transit)
  • Email addresses are hashed before storage on the CCP sync server (not stored there in plaintext); on the web rail the address is held by Supabase Auth so it can deliver magic-link sign-in emails
  • Auth tokens are stored as SHA-256 hashes (not plaintext)
  • OAuth tokens are encrypted locally with Windows DPAPI
  • Our source code is open source, allowing public verification of data handling practices

Transfer mechanism

Transfers of personal data to our processors in the United States rely on:

  • the EU-US Data Privacy Framework, where the processor is certified under it; and
  • Standard Contractual Clauses approved by the European Commission, together with supplementary technical measures, where it is not.

This applies to Vercel, Upstash, Supabase and OpenRouter. A copy of the relevant safeguards is available on request at support@cclabs.app.

Our third-party infrastructure providers maintain their own data protection practices and compliance measures. Please refer to their respective privacy policies linked in the Third-Party Services section.

If you are located in the EEA or UK and believe your data is being processed unlawfully, you have the right to lodge a complaint with your local data protection authority.

Third-Party Services

Service Purpose Data Shared
Patreon OAuth login, subscription verification OAuth tokens (via their API)
SubscribeStar OAuth login, subscription verification OAuth tokens (via their API)
Discord OAuth login, account linking OAuth tokens (via their API)
PayPal Payment processing and subscription billing Your PayPal account details and payment instrument are collected and held by PayPal. Your CCP user ID is attached to the subscription so payments can be matched to your account. We receive a subscription ID, a payer ID, the payer country and the subscription status, by webhook.
OpenRouter AI companion chat (cloud path), routed via stateless CC Labs S.r.l.s. proxy server. OpenRouter is configured at both account level and per-request level to opt out of training data use. Chat messages forwarded in real time. CC Labs S.r.l.s. proxy does not retain content.
Vercel Server hosting API requests are processed through Vercel
Upstash Database hosting (Redis) All server-side user data is stored here
Supabase Database and authentication hosting (Postgres + Auth) for web-rail accounts; powers magic-link sign-in at app.cclabs.app Web-rail account records are stored here, including your email address so magic-link sign-in emails can be sent
GitHub Auto-updates, source code hosting Update check requests

Business Transfers

If this project is transferred to a new owner or organization, your data may be transferred as part of that transition. In such an event, the new data controller will be bound by this privacy policy or will notify you of any changes before they take effect. You will always retain the right to delete your account and data.

Cookies & Tracking Technologies

The website is a static site hosted on Vercel. We do not run analytics, advertising, or behavioral-tracking scripts of any kind, and the desktop application sends nothing to any third-party analytics or telemetry service. While you are signed in, the desktop application syncs your progression and the per-day log described under What Data We Collect to your own account; while you are not signed in, it sends nothing.

First-party storage we set ourselves

  • rc_last_code - localStorage entry on the remote-control page (/remote/) only. Remembers the last code you entered so the field pre-fills next time. Stored in your browser, never transmitted to us. Strictly necessary for that page to be useful.
  • rc2.name, rc2.patterns.v1, rc2.muted, rc2.coach.v1 - localStorage entries on the same page only. They keep the nickname you give the person you control, the patterns you save, whether the pad sounds are off, and which tips you have seen. Stored in your browser. The nickname also travels through our server to the person you control when you connect, and is dropped when the session ends.
  • ccp_consent_v1 - localStorage entry that records your cookie banner choice so we don't ask again on every page load. Strictly necessary for the consent banner itself.
  • ccp_age_v1 - localStorage entry recording that you confirmed you are 18 or older: a boolean, a version number and a timestamp, with no birthdate. Stays in your browser. Strictly necessary for the age gate.
  • ccp_intake_* and ccp_intake2_* - localStorage entries for the optional questionnaire on the homepage and on one further page: a random local ID, and whether you finished or dismissed it. They stay in your browser and are never sent to us.

Third-party content (blocked until you consent)

One service can load from outside our infrastructure. It is not loaded until you consent to third-party content via the cookie banner or the “Cookie preferences” footer link. Until then it ships as an inert placeholder and no request is made to it. Your choice persists, and you can withdraw it at any time.

  • Google Fonts - on some pages the Poppins typeface is fetched from fonts.googleapis.com and fonts.gstatic.com. The stylesheet reference ships inert and is only activated once you have consented; loading it transmits your IP address to Google. Without consent, those pages use your system font.

Managing your choice

The first time you visit, a banner offers Accept all, Reject all, and Customize. You can change your decision at any time using the “Cookie preferences” link in the footer of every page, or by clearing site data for cclabs.app in your browser. Your stored choice expires after 12 months, after which we will ask again.

Third-party services you interact with intentionally (Discord, Patreon, GitHub) may set their own cookies when you authenticate or click through to them. Those cookies are set on their own domains and are governed by their respective privacy policies.

Data Retention

  • Active accounts: Data is retained as long as your account is active and you continue using the application.
  • Inactive accounts: Accounts with no sign-in for 24 months are deleted. Before that happens we email the address on the account, and you have 30 days to sign in and keep it. Signing in resets the clock.
  • Billing records: Invoices and payment records are kept for 10 years, as required by Italian fiscal law. This applies even after you delete your account, and only to the records themselves: it does not keep your progression data or your day log alive.
  • Day log: Kept for 400 days per account; older days are dropped automatically. The whole log is removed when you delete your account.
  • Deleted accounts: When you delete your account, all associated data (user record, index entries, leaderboard entries, day log, legacy keys) is removed immediately and permanently.
  • IP addresses: The application does not log IP addresses. Standard Vercel infrastructure logs may briefly retain connection metadata per their own policy.
  • AI chat messages: Messages sent to the AI companion are forwarded to OpenRouter in real-time and are not stored on our server. Refer to OpenRouter's privacy policy for their retention practices.

Age Requirement

You must be at least 18 years of age to use this application. By using Conditioning Control Panel, you represent and warrant that you are 18 years of age or older.

We do not knowingly collect personal information from anyone under 18. If we become aware that a user is under 18, we will:

  • Deactivate the account immediately
  • Delete all associated data from our servers
  • Remove all leaderboard entries and index records

If you believe that we have inadvertently collected data from someone under 18, please contact us immediately at support@cclabs.app so we can take appropriate action.

Your Rights

Depending on your location, you may have some or all of the following rights regarding your personal data:

Access & Export Your Data

You can export a full copy of your data at any time using the Export Data button in the app's Settings tab (under Account). This calls the /v2/user/export-data endpoint and returns all stored data associated with your account.

Rectification

You can update your display name through the application. If other data is incorrect, contact us and we will correct it.

Delete Your Account

You can permanently delete your account and all associated data using the Delete Account button in the app's Settings tab. This removes:

  • Your user record and all progression data
  • Your day log (per-day feature counters, quest IDs, achievement unlock days)
  • All index entries (email hash, display name, Discord ID, Patreon ID)
  • All leaderboard entries across all seasons
  • Settings backups
  • Legacy data from previous versions
Deletion Is Permanent

Account deletion cannot be undone. All data is removed immediately from the server.

Restrict or Object to Processing

If you are in the EEA, UK, or Switzerland, you may request that we restrict or stop processing your personal data. Contact us at support@cclabs.app to make such a request.

Data Portability

The Export Data feature provides your data in a structured, machine-readable JSON format that you can take to another service.

Withdraw Consent

See Withdrawing Consent in the Legal Bases section above.

Offline Use

You are not required to create an account or use any cloud features. The application works fully offline - cloud sync, leaderboards, and account features are entirely optional.

Lodge a Complaint

If you are in the EEA, UK, or Switzerland and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection authority.

California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you specific rights regarding your personal information.

Categories of Personal Information Collected

Category Collected? Examples
A. Identifiers YES (limited) Display name, email address (stored hashed on the desktop rail), Discord/Patreon IDs
B. Personal info (CA Customer Records) NO -
C. Protected classifications NO -
D. Commercial information YES (limited) Subscription tier, purchase and renewal dates, billing or payer country. Card and PayPal account data is handled by PayPal and never reaches our servers.
E. Biometric information NO -
F. Internet/network activity YES (limited, in-app only) Per-day feature-usage counters inside the app, signed-in accounts only (see Day Log). No browsing history, no cross-site tracking.
G. Geolocation data NO -
H. Audio/visual information NO -
I. Professional/employment info NO -
J. Education information NO -
K. Inferences NO -
L. Sensitive personal information NO -

Your California Rights

  • Right to Know: You can request what personal information we have collected about you. Use the Export Data button in the app for immediate access.
  • Right to Delete: You can request deletion of your personal information. Use the Delete Account button in the app for immediate deletion.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
  • Right to Opt Out of Sale: We do not sell or share your personal information with third parties for monetary or other valuable consideration. There is nothing to opt out of.

To exercise any of these rights, you can use the self-service tools in the app or contact us at support@cclabs.app.

Do-Not-Track

We do not track users across websites or applications. We do not run analytics or behavioral-tracking scripts, and the third-party content we embed (Google Fonts) only loads after you opt in via the cookie banner - so a Do-Not-Track (DNT) signal would not change anything we send. We respect your privacy regardless of your DNT settings.

Compliance Policies

Additional details on AI-specific data handling, content moderation, and detection logging are available in our policy portal:

Detection event logging: when CCP's moderation layers fire on detected prohibited content attempts, CC Labs S.r.l.s. logs metadata only (timestamp, category, feature surface). The content of the attempted prompt or output is not stored. See the AI Content Policy for the full logging architecture.

Changes to This Policy

We may update this privacy policy from time to time. When we do:

  • The "Last updated" date at the bottom of this page will be revised
  • Material changes (e.g., new data collection, new third-party sharing) will be communicated via an in-app notification or announcement in our Discord server
  • The previous version of this policy will remain accessible in our public git history

We encourage you to review this policy periodically. Your continued use of the application after changes are posted constitutes acceptance of the updated policy.

Contact

If you have questions about your data, want to exercise your privacy rights, or have concerns about this policy:

CC Labs S.r.l.s.
Ercolano (NA), Italy
P.IVA and codice fiscale IT11045351217 · REA NA-1150672 · PEC cclabs@pec.it
Full registry details on the Legal Notice page.

Community help is also available on GitHub Issues and the Discord server. Those are community channels and are not monitored for privacy, legal or billing requests.

We will respond to privacy-related requests within 30 days.

Last updated: 14 September 2026