Ci Moment privacy surface

What is stored and why.

Ci Moment keeps only the data needed to preserve one sealed decision moment, verify its payment-dependent artifact, operate the product, and measure how users reach the product.

Production data

Artifact and payment evidence are stored to support verification.

  • the decision moment and the Control, Intention, and Timing selections used to seal it
  • the resulting signal, artifact ID, verification hash, sealed timestamp, and verification state
  • order and payment-state references needed to prove that an artifact was created only after verified payment
  • limited technical, acquisition, and product events used to operate the service and understand the conversion path

Infrastructure

External systems process only their part of the product flow.

Supabase stores the production sessions, orders, events, and verified artifact records used by Ci Moment.

Vercel hosts and serves the Ci Moment application and may process ordinary request metadata needed to deliver and protect the service.

Paddle processes the public payment as Merchant of Record. Ci Moment does not ask users to send card numbers, CVV codes, payment-provider passwords, or one-time security codes to Ci Moment support.

A Google Ads tag is present on public product pages for advertising measurement. Provider-side measurement may use browser identifiers or cookies according to the provider and browser settings.

Public verification

A verification link is a shareable lookup surface.

Verification route

A valid verification hash can resolve the corresponding verified SealedArtifactCard. Anyone who receives that link may be able to open the artifact shown by that route. Do not share a verification link if the sealed decision should remain private.

Sensitive information

Do not place highly sensitive personal, medical, legal, financial, authentication, or confidential third-party information into the decision moment. Ci Moment is a decision-closure product, not a confidential-record system.

Payment recovery

A short-lived essential browser cookie connects checkout to its pending order.

During checkout, Ci Moment uses an HttpOnly pending-order cookie so the server can reconcile the user's payment flow with the correct local order. It is not the payment credential and it does not contain card data.

Support

Payment and privacy questions have one contact route.

For a payment, refund, or privacy-related question, contact cimoment.pay@gmail.com. Include only the minimum order or artifact reference needed to locate the issue. Never email payment passwords, card security codes, or one-time authentication codes.

Boundary

This page describes the implemented product, not a certification.

This notice describes the current Ci Moment production flow. It does not claim a formal GDPR, CCPA, PCI, or other certification that has not been independently established.