Account, session, and optional checkout data
CTL Web processes registration and sign-in inputs, account and entitlement context returned from control-plane services, and optional checkout prefill fields you choose to enter.
This Privacy Policy describes how Core Trail Labs processes personal and technical information on CTL Web, including account flows, checkout prefill state, desktop auth handoff, and limited diagnostics artifacts.
CTL Web processes registration and sign-in inputs, account and entitlement context returned from control-plane services, and optional checkout prefill fields you choose to enter.
The current implementation uses auth cookies, browser session storage, and a limited diagnostics store that is designed to avoid raw JWTs, full claims, cookies, headers, and secrets.
We use data to authenticate users, render workspace and subscription state, send verification emails, support desktop launcher sign-in, and maintain service availability and security.
This policy is written against the repository's actual data paths rather than a generic template. It focuses on browser storage, auth and account flows, launcher handoff support, email verification, and operational diagnostics.
This Privacy Policy applies to CTL Web and related Core Trail Labs surfaces implemented with this repository, including the public website, account registration and login pages, user and admin pages, checkout review and optional prefill flows, desktop auth handoff routes, and CTL Web diagnostics artifacts.
A separate authentication, billing, or third-party service may apply additional privacy terms if you are redirected away from CTL Web.
You may provide account and operational information directly when using CTL Web.
In the current implementation, CTL Web does not intentionally collect payment card numbers on this surface, and the review flow states that payment and full billing details are handled separately when secure checkout is active.
CTL Web receives account and subscription context from linked control-plane and authentication endpoints in order to render the correct user state and enforce access boundaries.
CTL Web uses cookies and browser session storage to preserve login state, synchronize auth context, and keep temporary checkout state across pages.
These values are controlled by the browser session, explicit logout or clearing actions, and token expiry settings used by the application.
CTL Web records limited operational diagnostics to help with debugging, integrity checks, and support workflows. The diagnostics policy in this repository is intentionally bounded.
The repository's diagnostics policy is designed to avoid persisting raw secrets or full identity payloads in its operational store.
Specifically, CTL Web diagnostics are intended not to store raw JWTs, JWT signatures, subject identifiers, full claim payloads, session cookies or headers, private keys, or other secrets.
Core Trail Labs uses the information processed by CTL Web to operate the service, authenticate users, render the correct account and subscription state, verify email ownership, support desktop auth handoff, and protect the integrity of the platform.
We also use limited diagnostics and telemetry to detect failures, abuse, authorization problems, and runtime readiness issues.
We may share data with the control-plane, authentication, hosting, logging, and email-delivery services that are needed to operate CTL Web.
For example, verification emails may be sent through configured SMTP infrastructure, and account or entitlement reads may be fulfilled by linked CTL backend services.
This repository does not describe CTL Web as selling personal information.
Browser-side tokens and session state generally remain until they expire, are refreshed, are cleared by the application, or are removed by you. Short-lived access cookies are configured for approximately fifteen minutes, while refresh cookies may persist longer when enabled.
Checkout prefill and related browser session values persist only in client-side session storage unless moved to another system by a later authenticated flow.
Diagnostics files are treated as operational artifacts. The repository guidance states they should not be committed as environment-specific runtime dumps unless needed for QA evidence workflows.
CTL Web uses technical and architectural controls such as bounded diagnostics, token handling, authorization checks, and fail-closed integration patterns to reduce risk.
No system is perfectly secure, so you should also protect your credentials, devices, and local browser session.
You can choose not to provide optional checkout prefill information, sign out to clear active session state, and clear relevant browser cookies or session storage on your device.
Core Trail Labs may update this Privacy Policy from time to time. When it does, it will post the revised version here and update the effective date.
For privacy questions about CTL Web, use the official contact, support, or account-management channels published by Core Trail Labs on its website or within authenticated workspace surfaces.
This draft is intentionally narrower than a generic enterprise privacy policy. It reflects the current repo behavior, including bounded diagnostics and the fact that CTL Web itself does not intentionally collect payment card details in its present public flow.