- Summary
- Data Controller
- What Data We Collect
- Why We Collect It
- Legal Bases for Processing
- How Data Is Stored
- International Data Transfers
- Third-Party Services
- Cookies & Tracking
- Data Retention
- Age Requirement
- Your Rights
- California Privacy Rights
- Do-Not-Track
- Compliance Policies
- Changes to This Policy
- Contact
Summary
This summary provides key points from our privacy policy. You can find full details in the sections below. See also our Terms of Service, our Refund and Cancellation Policy, and the company details in our Legal Notice.
- What we collect: Display name, your email address (stored only as a one-way hash on the desktop rail; held by Supabase Auth on the web rail so it can send magic-link sign-in emails), OAuth provider IDs, progression data, and application settings - only if you opt into cloud features.
- Day log (signed-in only): Once signed in, the desktop app also syncs a per-day record of how much you used each feature (eleven counters, the quests you completed that day, and the day each achievement was first unlocked). It is shown only to you on your own Spiral, never sold, never sent to third-party analytics, kept for 400 days, and deleted with your account. Anonymous use sends nothing.
- What we don't collect: IP addresses, media file content, browsing history, or any sensitive personal information. Card numbers never reach our servers: payments are handled by PayPal.
- Offline by default: The application works fully offline. Cloud sync, leaderboards, and accounts are entirely optional.
- Open source: Our source code is publicly available so you can verify exactly how your data is handled.
- Self-service data control: You can export or permanently delete all your data at any time directly from the app - no need to contact us.
- No analytics or advertising: We do not use Google Analytics, behavioral tracking, or advertising cookies. The website can embed one third-party service (Google Fonts); it does not load until you consent via the cookie banner.
- Payments: Subscriptions are billed by CC Labs S.r.l.s. through PayPal. PayPal holds your name, email, billing or payer details and payment method; we receive an identifier, the plan, the country and whether it is paid.
- Where data is stored: Server-side data is stored in the United States via Vercel, Upstash, and Supabase. All data is transmitted over HTTPS.
- Age requirement: You must be at least 18 years old to use this application.
Data Controller
The data controller is:
CC Labs S.r.l.s.
Via Marconi 60, 80056 Ercolano (NA), Italy
P.IVA and codice fiscale IT11045351217 · REA NA-1150672 · Registro delle Imprese, CCIAA Napoli
PEC: cclabs@pec.it
Contact for data protection matters, including any request about your rights: support@cclabs.app. Full registry details are on the Legal Notice page.
CC Labs S.r.l.s. is the controller for personal data processed through the Conditioning Control Panel application, the cclabs.app and app.cclabs.app websites, and subscription billing.
Data Protection Officer
CC Labs S.r.l.s. has not appointed a Data Protection Officer and is not required to appoint one. Our processing does not meet the conditions in Article 37 of the GDPR: we are not a public authority, our core activity is not large-scale regular and systematic monitoring of individuals, and it is not large-scale processing of special categories of data. Send data protection questions and requests to support@cclabs.app.
The application is open source; the source code is publicly available on GitHub, so you can check how data is handled.
What Data We Collect
Account Information (Cloud Features)
CCP supports four login methods: Discord OAuth, Patreon OAuth, an in-app invite-code account (display name + password), and web sign-in at app.cclabs.app (Patreon, Discord, or email magic link). Depending on which method you used, we store some subset of:
- Display name - your chosen username
- Email - on the desktop rail (Discord OAuth, Patreon OAuth, invite-code accounts, and the CCP sync server) your email address is stored only as a one-way HMAC-SHA256 hash; the plaintext address is not stored there. On the web rail (
app.cclabs.app), Supabase Auth holds your email address so it can send you magic-link sign-in emails; the CCP sync server still stores only the one-way hash of it. - Discord ID / Patreon ID - used to link your account when you signed in with one of those providers
- Patreon subscription tier - to verify premium access (Patreon login only)
- Avatar URL - Discord profile picture, if you opt in to sharing it
- Password hash - bcrypt hash for invite-code accounts (we never store plaintext passwords)
- Privacy preferences - online status visibility, profile picture sharing
- Auth token hash - SHA-256 hash of your session token (not the plaintext token)
- Timestamps - account creation, last seen, last synced, client version
Storage is split across two backends: the CCP desktop server (Upstash Redis on Vercel) holds desktop-rail accounts and progression; Supabase (Postgres + Auth) holds the web-rail accounts and powers magic-link email sign-in at app.cclabs.app. When you link the two rails together via the device-code flow, both records reference the same unified ID but remain in their respective databases.
Progression Data
When cloud sync is active, we store:
- Level, XP, and seasonal statistics (flash clicks, video watches, bubble pops, etc.)
- Achievement progress and unlock status
- Quest completion data
- Skill tree data (skill points and unlocked skills)
- Total lifetime conditioning minutes
- Companion AI progression (per-companion level and XP)
- All-time aggregate statistics across seasons
Day Log (Signed-In Desktop Only)
Starting with desktop version 6.9.2, the app keeps a per-calendar-day record of feature usage and syncs it to your account alongside the progression data above. For each day it stores eleven counters: XP earned, conditioning minutes, flash images shown, bubbles popped, pink filter minutes, spiral minutes, video minutes, lock cards completed, attention checks passed, bubble-count games played, and sessions started. It also stores the IDs of the quests you completed that day, and the day each achievement was first unlocked.
- Tied to your account. It is only synced while you are signed in. If you are not signed in, nothing is sent.
- Shown only to you. It powers the day-by-day view of your own Spiral. The public Spiral other people can see shows only the daily fill dots, never these counters.
- Not analytics. It is never sold and never sent to any third-party analytics service.
- Retained 400 days. Older days are dropped, and the whole log is deleted with your account.
Payment Data (Paid Subscriptions)
If you buy a subscription from CC Labs S.r.l.s., the payment is processed by PayPal, which acts as our processor and collects and holds your payment details directly. Card numbers and PayPal account credentials never reach our servers.
How the payment works
The PayPal subscription button runs in your browser using PayPal's own SDK, and you complete the payment on PayPal's side. PayPal holds your PayPal account details and whatever card or bank instrument sits behind it. Your CCP user ID is attached to the subscription so the payment can be matched to your account, and PayPal sends us webhook notifications when the subscription changes. What we receive and store is:
- a PayPal subscription ID and payer ID;
- the plan you are on (CCP Basic or CCP Prime) and the subscription status;
- the payer country, which is needed to work out VAT.
We do not receive your PayPal login, your card number, or the balance of your PayPal account.
We use this to unlock the paid features on your account, to answer billing questions, and to meet our invoicing and tax obligations. Invoices and payment records are kept for the period Italian tax law requires (see Data Retention).
If you subscribe through Patreon or SubscribeStar instead, that platform handles the payment and holds the billing data under its own privacy policy; we receive only your subscription tier from their API.
Settings Backup
If you use the cloud settings backup feature, your application preferences are stored on the server so they can be restored on a fresh install.
Anti-Cheat Data
To maintain fair leaderboards, we monitor XP earning rates, session timing, and statistics consistency. Sessions are signed with HMAC to verify integrity. This data is used solely for detecting anomalies and is not shared with other users.
Eye Tracking (Optional Webcam Feature)
If you enable the optional eye tracking feature, CCP uses your webcam to detect approximate gaze direction, blink events, and basic facial gestures (mouth open) for interactive purposes. Important properties of this feature:
- Local-only processing. Webcam frames are processed entirely in your computer's memory and discarded after each frame. Frames are never written to disk, never transmitted over the network, and never sent to CC Labs S.r.l.s. or any third party.
- No biometric identification. The system computes gaze coordinates and basic facial gesture states only. It does not perform facial recognition, does not create or store biometric templates, and does not identify individuals.
- Calibration data only. The only persisted data is a small set of numerical regression coefficients (gaze-to-screen mapping) stored locally in your application data folder. This file contains no images and no biometric templates.
- Consent-gated. The feature is disabled by default and requires explicit user consent at activation. You can revoke consent at any time, which immediately stops capture and clears calibration data.
Automatically Collected Data
Our application does not log IP addresses or device fingerprints, and it does not send usage data to any third-party analytics service. The only record of how you use the app is the signed-in day log described above; anonymous use sends nothing. However, our hosting infrastructure (Vercel) may temporarily retain standard connection metadata (such as IP addresses) in their own server logs as part of normal operations. This is governed by Vercel's privacy policy and is outside our control. We do not access or use this infrastructure-level data.
What We Do NOT Collect
- Plaintext email addresses on the CCP sync server (only one-way hashes are stored there; web-rail email addresses are held by Supabase Auth for magic-link sign-in)
- IP addresses (not logged by the application)
- Content of your media files (images, videos, sounds stay local)
- Browsing history or screen content
- System information beyond what's needed for the app
- Patreon billing name - used transiently during login for verification but NOT stored on the server
- Card numbers, CVC codes, full payment method details or PayPal account credentials - these are collected and held by PayPal, never by us
- Webcam frames, images, or biometric templates (eye tracking is local-only)
- Sensitive personal information (race, religion, health data, biometrics, etc.)
Why We Collect It
| Purpose | Data Used |
|---|---|
| Account sync across devices | Discord/Patreon ID, display name, email hash (email address on the web rail) |
| Leaderboards | Display name, level, XP, statistics |
| Anti-cheat | XP rate, session timing, statistics consistency |
| Patreon tier verification | Patreon ID, subscription status |
| Subscription billing and unlocking paid features | PayPal subscription and payer ID; plan, status, period dates, billing or payer country |
| Invoicing and tax compliance | Payment records and invoices held by us and by the payment processor |
| Your own Spiral (day-by-day view) | Day log: per-day feature counters, quest IDs, achievement unlock days (signed-in desktop only) |
| Settings backup/restore | Application preferences |
| AI companion chat | Messages sent to OpenRouter for AI responses (not stored on our server) |
Legal Bases for Processing
We only process your personal data when we have a valid legal reason to do so. Depending on your location, the following legal bases apply:
If You Are in the EU, EEA, or UK (GDPR / UK GDPR)
Each purpose has its own legal basis:
| Purpose | Legal basis |
|---|---|
| Your account, cloud sync, leaderboards and shared sessions | Contract - Art. 6(1)(b). Once you create an account, this processing is what delivers the service you asked for. |
| Subscription billing, unlocking paid features | Contract - Art. 6(1)(b), and legal obligation - Art. 6(1)(c) for invoicing and tax records. |
| Anti-cheat and service integrity | Legitimate interests - Art. 6(1)(f): keeping leaderboards fair and the service working. The data is minimal and is not shared externally. |
| Optional features you switch on, such as eye tracking, the microphone, and third-party web content on the site | Consent - Art. 6(1)(a). Off by default, and you can withdraw consent at any time. |
| Responding to lawful requests, keeping records we are required to keep | Legal obligation - Art. 6(1)(c). |
Using the application offline, without an account, involves no processing by us at all.
If You Are in Canada
We process your information based on your express consent when you create an account and enable cloud features. You may withdraw consent at any time. In limited circumstances, we may process data without consent as permitted by Canadian law (e.g., fraud prevention, legal compliance).
If You Are in Switzerland
Processing is based on your consent and our legitimate interests as described above. You may contact the Federal Data Protection and Information Commissioner if you believe your data is being processed unlawfully.
Withdrawing Consent
You can withdraw your consent to data processing at any time by:
- Deleting your account using the Delete Account button in Settings - this removes all server-side data immediately
- Disabling cloud sync to stop ongoing data transmission while keeping your account
- Contacting us at support@cclabs.app to request data deletion or processing restrictions
Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal. The application will continue to work fully offline after consent is withdrawn.
Where processing rests on contract rather than consent - your account and, if you have one, your subscription - withdrawing consent is not the right route. Cancel the subscription or delete the account instead. See the Refund and Cancellation Policy and Your Rights.
How Data Is Stored
Server-Side
Cloud data is stored in Upstash Redis, a managed database service. The server runs on Vercel (serverless functions). Web-rail accounts and magic-link sign-in are held in Supabase (managed Postgres + Auth). Data is transmitted over HTTPS.
Client-Side
- Settings and progress are stored as JSON files in
%APPDATA%/ConditioningControlPanel/ - OAuth tokens (Discord/Patreon) are encrypted locally using Windows DPAPI (Data Protection API), tied to your Windows user account
- Auth tokens for the sync server are stored in application settings and validated via SHA-256 hashing
International Data Transfers
Our servers and infrastructure are located in the United States. If you are accessing our services from outside the United States - including from the European Economic Area (EEA), United Kingdom (UK), Switzerland, or Canada - your data will be transferred to, stored, and processed in the United States.
The United States may not have data protection laws as comprehensive as those in your country. However, we take the following measures to protect your data:
- All data is transmitted over HTTPS (TLS encryption in transit)
- Email addresses are hashed before storage on the CCP sync server (not stored there in plaintext); on the web rail the address is held by Supabase Auth so it can deliver magic-link sign-in emails
- Auth tokens are stored as SHA-256 hashes (not plaintext)
- OAuth tokens are encrypted locally with Windows DPAPI
- Our source code is open source, allowing public verification of data handling practices
Transfer mechanism
Transfers of personal data to our processors in the United States rely on:
- the EU-US Data Privacy Framework, where the processor is certified under it; and
- Standard Contractual Clauses approved by the European Commission, together with supplementary technical measures, where it is not.
This applies to Vercel, Upstash, Supabase and OpenRouter. A copy of the relevant safeguards is available on request at support@cclabs.app.
Our third-party infrastructure providers maintain their own data protection practices and compliance measures. Please refer to their respective privacy policies linked in the Third-Party Services section.
If you are located in the EEA or UK and believe your data is being processed unlawfully, you have the right to lodge a complaint with your local data protection authority.
Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| Patreon | OAuth login, subscription verification | OAuth tokens (via their API) |
| SubscribeStar | OAuth login, subscription verification | OAuth tokens (via their API) |
| Discord | OAuth login, account linking | OAuth tokens (via their API) |
| PayPal | Payment processing and subscription billing | Your PayPal account details and payment instrument are collected and held by PayPal. Your CCP user ID is attached to the subscription so payments can be matched to your account. We receive a subscription ID, a payer ID, the payer country and the subscription status, by webhook. |
| OpenRouter | AI companion chat (cloud path), routed via stateless CC Labs S.r.l.s. proxy server. OpenRouter is configured at both account level and per-request level to opt out of training data use. | Chat messages forwarded in real time. CC Labs S.r.l.s. proxy does not retain content. |
| Vercel | Server hosting | API requests are processed through Vercel |
| Upstash | Database hosting (Redis) | All server-side user data is stored here |
| Supabase | Database and authentication hosting (Postgres + Auth) for web-rail accounts; powers magic-link sign-in at app.cclabs.app |
Web-rail account records are stored here, including your email address so magic-link sign-in emails can be sent |
| GitHub | Auto-updates, source code hosting | Update check requests |
Business Transfers
If this project is transferred to a new owner or organization, your data may be transferred as part of that transition. In such an event, the new data controller will be bound by this privacy policy or will notify you of any changes before they take effect. You will always retain the right to delete your account and data.
Data Retention
- Active accounts: Data is retained as long as your account is active and you continue using the application.
- Inactive accounts: Accounts with no sign-in for 24 months are deleted. Before that happens we email the address on the account, and you have 30 days to sign in and keep it. Signing in resets the clock.
- Billing records: Invoices and payment records are kept for 10 years, as required by Italian fiscal law. This applies even after you delete your account, and only to the records themselves: it does not keep your progression data or your day log alive.
- Day log: Kept for 400 days per account; older days are dropped automatically. The whole log is removed when you delete your account.
- Deleted accounts: When you delete your account, all associated data (user record, index entries, leaderboard entries, day log, legacy keys) is removed immediately and permanently.
- IP addresses: The application does not log IP addresses. Standard Vercel infrastructure logs may briefly retain connection metadata per their own policy.
- AI chat messages: Messages sent to the AI companion are forwarded to OpenRouter in real-time and are not stored on our server. Refer to OpenRouter's privacy policy for their retention practices.
Age Requirement
You must be at least 18 years of age to use this application. By using Conditioning Control Panel, you represent and warrant that you are 18 years of age or older.
We do not knowingly collect personal information from anyone under 18. If we become aware that a user is under 18, we will:
- Deactivate the account immediately
- Delete all associated data from our servers
- Remove all leaderboard entries and index records
If you believe that we have inadvertently collected data from someone under 18, please contact us immediately at support@cclabs.app so we can take appropriate action.
Your Rights
Depending on your location, you may have some or all of the following rights regarding your personal data:
Access & Export Your Data
You can export a full copy of your data at any time using the Export Data button in the app's Settings tab (under Account). This calls the /v2/user/export-data endpoint and returns all stored data associated with your account.
Rectification
You can update your display name through the application. If other data is incorrect, contact us and we will correct it.
Delete Your Account
You can permanently delete your account and all associated data using the Delete Account button in the app's Settings tab. This removes:
- Your user record and all progression data
- Your day log (per-day feature counters, quest IDs, achievement unlock days)
- All index entries (email hash, display name, Discord ID, Patreon ID)
- All leaderboard entries across all seasons
- Settings backups
- Legacy data from previous versions
Deletion Is Permanent
Account deletion cannot be undone. All data is removed immediately from the server.
Restrict or Object to Processing
If you are in the EEA, UK, or Switzerland, you may request that we restrict or stop processing your personal data. Contact us at support@cclabs.app to make such a request.
Data Portability
The Export Data feature provides your data in a structured, machine-readable JSON format that you can take to another service.
Withdraw Consent
See Withdrawing Consent in the Legal Bases section above.
Offline Use
You are not required to create an account or use any cloud features. The application works fully offline - cloud sync, leaderboards, and account features are entirely optional.
Lodge a Complaint
If you are in the EEA, UK, or Switzerland and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection authority.
California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you specific rights regarding your personal information.
Categories of Personal Information Collected
| Category | Collected? | Examples |
|---|---|---|
| A. Identifiers | YES (limited) | Display name, email address (stored hashed on the desktop rail), Discord/Patreon IDs |
| B. Personal info (CA Customer Records) | NO | - |
| C. Protected classifications | NO | - |
| D. Commercial information | YES (limited) | Subscription tier, purchase and renewal dates, billing or payer country. Card and PayPal account data is handled by PayPal and never reaches our servers. |
| E. Biometric information | NO | - |
| F. Internet/network activity | YES (limited, in-app only) | Per-day feature-usage counters inside the app, signed-in accounts only (see Day Log). No browsing history, no cross-site tracking. |
| G. Geolocation data | NO | - |
| H. Audio/visual information | NO | - |
| I. Professional/employment info | NO | - |
| J. Education information | NO | - |
| K. Inferences | NO | - |
| L. Sensitive personal information | NO | - |
Your California Rights
- Right to Know: You can request what personal information we have collected about you. Use the Export Data button in the app for immediate access.
- Right to Delete: You can request deletion of your personal information. Use the Delete Account button in the app for immediate deletion.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
- Right to Opt Out of Sale: We do not sell or share your personal information with third parties for monetary or other valuable consideration. There is nothing to opt out of.
To exercise any of these rights, you can use the self-service tools in the app or contact us at support@cclabs.app.
Do-Not-Track
We do not track users across websites or applications. We do not run analytics or behavioral-tracking scripts, and the third-party content we embed (Google Fonts) only loads after you opt in via the cookie banner - so a Do-Not-Track (DNT) signal would not change anything we send. We respect your privacy regardless of your DNT settings.
Compliance Policies
Additional details on AI-specific data handling, content moderation, and detection logging are available in our policy portal:
- AI Content Policy - detailed AI infrastructure, moderation controls, and data handling
- Prohibited Content Policy - enumerated prohibitions and enforcement
- Content Removal Policy - removal procedures for user-submitted content
- Copyright Policy - DMCA and EU DSA notice procedures
- Complaints Policy - general complaint submission and escalation
Detection event logging: when CCP's moderation layers fire on detected prohibited content attempts, CC Labs S.r.l.s. logs metadata only (timestamp, category, feature surface). The content of the attempted prompt or output is not stored. See the AI Content Policy for the full logging architecture.
Changes to This Policy
We may update this privacy policy from time to time. When we do:
- The "Last updated" date at the bottom of this page will be revised
- Material changes (e.g., new data collection, new third-party sharing) will be communicated via an in-app notification or announcement in our Discord server
- The previous version of this policy will remain accessible in our public git history
We encourage you to review this policy periodically. Your continued use of the application after changes are posted constitutes acceptance of the updated policy.
Contact
If you have questions about your data, want to exercise your privacy rights, or have concerns about this policy:
- Data protection, and any request about your rights: support@cclabs.app
- Legal and copyright notices: legal@cclabs.app
CC Labs S.r.l.s.
Ercolano (NA), Italy
P.IVA and codice fiscale IT11045351217 · REA NA-1150672 · PEC cclabs@pec.it
Full registry details on the Legal Notice page.
Community help is also available on GitHub Issues and the Discord server. Those are community channels and are not monitored for privacy, legal or billing requests.
We will respond to privacy-related requests within 30 days.
Last updated: 14 September 2026
Conditioning Control Panel