Privacy policy

What we collect, and what we don't.

Two systems, one form, no trackers. This page describes exactly what ciphercut.com and the client portal do with your information.

Effective June 1, 2026 · Questions: Info@Ciphercut.com

The short version

CipherCut runs two things: a public website and an invite-only client portal. We collect only what those two need. There are no advertising trackers and no analytics scripts on this site. We do not sell, rent, or share personal information for marketing.

What we collect, and why

Contact form (the public site). When you send the form on the Contact page we store what you type: your name, work email, company, the tier you are interested in, and, if you add them, a footage link and a note about your goal. We use it to reply to you and to scope the work. It is saved in our database and, when email notifications are configured, a copy is emailed to us.

  • Portal account data. Client accounts are created by us, by invitation only. An account holds your name, work email, company, service tier, account status, and a password stored only as a bcrypt hash. We never store or can read the password itself.
  • Portal workspace content. Footage share links you paste in (Google Drive, Dropbox, YouTube, Frame.io or similar), deliverable records (title, type, status, and links to unlisted previews and downloads hosted on your or our third-party video hosting), your revision comments, and strategy documents (PDFs) we upload for Pipeline and Scale clients.
  • Session data. A single cookie, session_token, keeps you signed in to the portal for up to seven days. It is httpOnly and Secure. Signing out deletes it on the server.
  • Password reset and invite tokens. When we invite you or you request a reset, a random single-use token is created, stored only as a hash, and expires (72 hours for invites, 60 minutes for resets).
  • Billing records (clients). When we invoice you through Stripe we store your Stripe customer and invoice identifiers, the invoice lines, amount, due date, status, and, once paid, the payment date and method type (bank transfer or card). Bank and card numbers are entered on Stripe's hosted pages and never reach our servers.
  • Email log. Every notification the system sends (or fails to send) is recorded with the recipient address, subject, provider, outcome and time so nothing is lost silently.
  • Lead status. We keep a simple pipeline note on each contact-form submission (new, contacted, booked call, sample sent, closed, lost) so we can follow up properly.
  • Security logs. The server keeps short-lived, in-memory counts of sign-in, reset and form attempts by IP address and account to limit abuse. Server logs may record your email address alongside notification events.

What we do not collect

No advertising pixels, no analytics or heat-mapping scripts, no fingerprinting, no third-party marketing cookies. The site ships a Content Security Policy that only allows our own scripts to run, so even a performance beacon injected by the hosting edge is blocked in your browser. Video files themselves never touch our servers: you share a link from your own storage, and you control access to it. We do not collect payment card details through this site.

Emails we send

  • To us: a notification when a contact form is submitted.
  • To you (submitter): one confirmation that your sample request arrived, with the timeline and the optional plan-call link. It is not a subscription.
  • To you (portal clients): a notice when a deliverable is marked DELIVERED, confirmation when we receive a revision request, your portal invitation, password-reset links you ask for, invoices, payment receipts, and a notice if a payment fails.
  • To us: a notification when a revision request or a failed payment comes in.
  • All of these are transactional. There is no marketing list. If you do not want delivery notices, tell us at Info@Ciphercut.com and we will turn them off for your account; invite and reset emails are only sent when you or we trigger them.

Processors and third parties

These are the services that touch data as part of running the site. Each receives only what is needed for its function.

  • Emergent (application hosting and deployment) and the MongoDB database that runs with it: all site and portal data lives here.
  • Cloudflare (edge network in front of the hosting): may set a short-lived security cookie (for example __cf_bm) to filter automated traffic. That cookie is essential and not used for advertising.
  • Google Fonts: the site loads three typefaces from fonts.googleapis.com and fonts.gstatic.com, which means Google receives your IP address and browser details when the page loads.
  • YouTube (privacy-enhanced youtube-nocookie.com embed) on the homepage demo, and YouTube or Vimeo players inside the portal for deliverable previews. Those services apply their own privacy policies when you play a video.
  • Resend (transactional email delivery) for the emails above; Resend receives the recipient address and message content in order to deliver it.
  • Stripe (invoicing and payments). Stripe processes bank-transfer (ACH) and card payments on its own hosted invoice, checkout and billing pages, and stores your payment details under its own privacy policy. We receive confirmation events and identifiers only.
  • Calendly (optional booking). The plan-call widget on the Contact and Book pages loads Calendly's script only when you scroll to it; if you arrived from the form we pass your name and email into the widget to save typing. Booking is subject to Calendly's privacy policy. Nothing loads if you never reach the widget.
  • LinkedIn, Google Drive, Dropbox, Frame.io and similar: only when you follow a link out of this site or paste a link in. We do not integrate with their accounts.

Cookies

Essential cookies only: session_token (portal sign-in, up to seven days) and any security cookie set by Cloudflare. Nothing else. Because there are no non-essential cookies there is no consent banner; this section is the disclosure.

How long we keep things

  • Contact form submissions: until we have finished following up, and in any case deleted on request.
  • Footage link records: purged automatically 31 days after submission. Revoke the share on your side at any time.
  • Portal account and workspace content (deliverable records, revision comments, strategy documents): for the duration of your retainer plus 90 days so late downloads and hand-offs still work, then deleted, or sooner on request.
  • Sessions: expire after seven days or at sign-out. Reset and invite tokens: expire as stated above and are deleted automatically.

Your rights

You can ask to see the personal information we hold about you, correct it, or have it deleted. Email Info@Ciphercut.com. We honor these requests regardless of where you live, and we reply within one working day. Deleting a portal account removes the account, its sessions, and its workspace content; finished deliverables you have already downloaded remain yours.

Security

Passwords are hashed with bcrypt. Sessions use httpOnly, Secure cookies. Sign-in and reset endpoints are rate-limited and return the same message whether or not an account exists. Every portal request is checked server-side so a client can only ever read or change their own workspace. Traffic is served over HTTPS. No system is perfectly secure; if you believe your account has been accessed without authorization, email us immediately and we will revoke its sessions.

Children

This site and the portal are for businesses and are not directed at anyone under 18. We do not knowingly collect information from minors.

Governing law and changes

This policy is governed by the laws of the State of Florida. If we change it, the effective date at the top changes and portal account holders are told by email when the change is material. The current version is always at ciphercut.com/privacy.