privacy notice

terms

effective august 13, 2026

who we are · AVALON RESET LLC operates cto-legends.

information we collect · we collect email address; consent, authorization, notice-version, receipt, cancellation, and billing records, including selected amount, currency, billing interval, and stripe customer, checkout, subscription, invoice, payment-status, refund, dispute, and receipt identifiers; browser, device, IP address, host, security, and request-log information; and optional community identifiers used only for access classification.

email gate · when you use google or github sign-in, we add the provider-verified address to the cto-legends email list, associate it with your profile, prevent abuse, and send the first quest invitation. if you reply or otherwise ask to continue, we may send quests and information about cto-legends offerings, including free or paid skool communities.

authentication · if you choose google or github sign-in, that provider gives us the account identifier and the profile fields shown on its authorization screen, such as your email address, name, username, and avatar. we use them only to authenticate you, create or protect your cto-legends account, classify access, prevent abuse, and provide support. when google and github provide the same verified email, we may treat them as linked sign-in methods for one account. when they provide different verified emails, we keep them as separate accounts and the latest successful sign-in becomes active in that browser. marketing email follows that active address: the previous address stops receiving marketing unless you later sign in with it again. an explicit unsubscribe on an address stays in force if you return to it; signing in again does not undo that unsubscribe. stripe billing stays with the email that authorized it and does not move when the browser session switches. we do not receive your provider password or send this authentication data to google analytics. google and github independently process sign-in data under their own privacy notices.

voice messages · if you leave a voice message through cto-amp after google or github sign-in, we collect the audio file, duration, technical format, voice-message consent record, the provider-verified email and profile identifiers for that session, approximate time, and basic request metadata (such as user agent and remote address). we store the audio in private object storage (cloudflare r2 when configured, or a private offline vault on the application host for local/staging) and keep a ledger of message metadata. we use this to deliver messages to Benjamin and, under the terms license you accept at send, to use or publish recordings. we do not sell voice messages. we do not use voice messages to identify speakers biometrically or create voiceprints. access to stored audio is limited to operators; it is not a public gallery. we keep voice audio and related ledger rows only as long as reasonably necessary for those purposes, legal compliance, security, and license defense, unless a longer period is required by law. when no longer needed, we delete the audio and delete or de-identify ledger data, except records we must retain to document consent, protect rights, prevent abuse, or comply with law. you may request access, correction, or deletion of a voice message by emailing quest@cto-legends.com; we may verify identity. deletion does not undo uses already made or revoke rights already granted under the terms.

payment information · stripe receives and processes full payment-card details. AVALON RESET LLC does not receive or store full card numbers or CVC codes. stripe may collect legal name, billing address, issuer-authentication information, and fraud-prevention information under stripe's own privacy notice.

how we use information · we use information to operate the site, document consent and billing, prevent fraud and abuse, send transactional or legally required notices, honor choices, provide support, keep accounting and tax records, measure the limited site use described below, and comply with law.

who receives information · we disclose only what is reasonably necessary to providers supporting hosting and logging, stripe payment processing, google analytics, CRM or waitlist storage, google and github when you use their sign-in, accounting and security, and separately used community services such as skool; to professional advisers; or to authorities when legally required.

marketing · google or github sign-in adds the provider-verified address to the cto-legends email list and causes us to send the first quest invitation. if you later sign in with a different verified email, marketing follows the latest active address and stops to the previous one unless you return to it. if you reply or otherwise ask to continue, we may send quests and information about cto-legends offerings, including free or paid skool communities. marketing messages identify AVALON RESET LLC, include our postal address and a working unsubscribe link, and come from quest@cto-legends.com. using that link or the site unsubscribe control immediately suppresses future marketing email. signing in again does not remove that explicit unsubscribe; only the explicit subscribe control does. payment, account, security, transactional, and legally required messages are separate.

no sale or behavioral advertising · we do not sell personal information or share it for cross-context behavioral advertising. google analytics advertising features, google signals, user-id, user-provided data, remarketing, ad personalization, enhanced conversions, and google ads linking are disabled. any later advertising use requires a separate review and privacy update before activation.

analytics and cookies · google analytics is off unless this browser affirmatively chooses allow limited analytics. after that choice, and only on an exact clean apex GET request to https://cto-legends.com/, we use google analytics 4 property G-BCER6T3T04 to understand visits, sessions, and coarse interactions on that one surface. automatic page-view sending is disabled, and enhanced measurement for form interactions and outbound clicks is off. when limited analytics is allowed, cto-legends may emit only these named application events without parameters: email_gate_view, email_gate_complete, tip_option_selected, checkout_redirect, checkout_return_confirmed, and checkout_return_canceled. google may receive the canonical root address and title, event and session timing, general browser, device, and operating-system information, approximate geographic information, and pseudonymous client and session identifiers. it may set first-party _ga and _ga_<id> cookies, configured to expire no later than 12 months and not to extend on later visits. a browser necessarily sends its IP address to google at collection; google states GA4 uses it to derive approximate location and then discards it before storage in analytics. we do not receive the full IP address through GA4. google retains analytics data under the configured property settings; we keep standard aggregated reports only while reasonably needed to measure and operate the site. we do not send names, emails or hashes, form contents, skool data, exact creator-tip amounts, payment or billing data, stripe identifiers, cancellation tokens, or URLs containing those values, and we do not join analytics identities to stripe, skool, CRM, email, or accounting records.

regional access · cto-legends serves the public application worldwide through the trusted edge. we do not currently apply a country-based block at the application layer for ordinary browsing. ip geolocation is imperfect and is not proof of residence. stripe-hosted checkout and skool are separate services and are not governed by this analytics control.

analytics settings · analytics is off until this browser affirmatively allows it. the cto_analytics_choice and cto_analytics_opt_out preference cookies last no more than one year and exist solely to remember cto-legends analytics choices for this browser. continuing without analytics, turning analytics off, or sending a recognized global privacy control signal suppresses the google analytics tag and pings and deletes controllable _ga* cookies. allowing analytics does not override gpc. google's explanation of its role: https://policies.google.com/technologies/partner-sites.

independent services · payments complete on stripe-hosted checkout at pay.cto-legends.com. stripe independently processes payment, device, cookie, authentication, and fraud-prevention information under its own privacy terms; no cto-legends google analytics tag runs there. skool is a separate community platform with its own analytics and cookies; no cto-legends google analytics tag runs in skool, and cto-legends does not send skool member identities, onboarding answers, access state, activity, or payments into its google analytics property.

us state disclosures · analytics information falls principally within identifiers, internet or other electronic network activity, approximate geolocation, and device information. we collect it from the browser, disclose it to google for website analytics, and retain it as described above. we do not sell it or share it for cross-context behavioral advertising. additional rights may apply depending on residence and whether a privacy law covers AVALON RESET LLC.

record retention · we keep recurring-charge consent verification for at least three years or one year after termination, whichever is longer. we keep payment and tax records for the period required by law, suppression records as long as needed to honor opt-outs, and other information only as long as reasonably necessary for the purposes above.

your choices · use the analytics settings above to control cto-legends google analytics for this browser and https://cto-legends.com/cancel to stop the recurring creator tip. use the unsubscribe link in an email or the unsubscribe control on the site to stop future marketing email. unsubscribing does not sign you out or remove website access. signing in again does not resubscribe the address; only the explicit subscribe control does. you can clear this site's cookies in your browser, or use https://cto-legends.com/clear-cookies to reset this browser's cto-legends cookies. you may ask to access, correct, or delete information by emailing quest@cto-legends.com. we may verify identity and retain information required for payment, tax, fraud prevention, consent, suppression, or legal purposes.

security · we use reasonable administrative and technical safeguards, but no internet system is guaranteed secure.

children · cto-legends is intended for adults 18 and older.

changes · we will post a new effective date and describe material changes here. we will provide direct notice when required by law. posting alone will not retroactively authorize a materially different use.

contact · quest@cto-legends.com