Cessio← Back

Privacy Policy

Last updated 16 August 2026

Cessio is a confidential request-for-quote (RFQ) desk on Canton Network. This policy explains what the desk stores about you, why it stores it, who else can see it, and what you can remove. It covers the web app, the public API and the documentation site.

The short version

  • No passwords, no legal name — an account is a passkey, a contact email and a Canton party.
  • No analytics, no advertising, no third-party trackers. Nothing is sold or shared for marketing.
  • Your trades are private by construction: on the ledger only you and your counterparty see them.
  • Your trading history is kept under your handle so you can read it back from any device you sign in from.

What the desk stores

Your account. When you create one we store the handle you pick, your display name, your Canton party id, your passkey’s public key and credential id, an encrypted copy of your party key, and the date you registered. That copy is unlocked by a secret your passkey derives on your device — we cannot decrypt it, and it is useless without your device or your backup key.

Your email. Creating an account asks for a contact address. It is used to reach you about your account and your support requests. It is unverified, never sold and never used for marketing. You can change or clear it in Profile at any time; clearing it deletes it from our database.

Your access request. Cessio is invite-only. If you ask for access we store the address you gave us, and the name, roles and note if you added them. We use them to decide who to invite, to confirm the request once, and to send the invite itself — two messages in total, never a newsletter. The request is kept after you join, recording that the invite was used and by which account. Ask us and we delete it.

The live auction. While an RFQ is open the desk stores it and the quotes it draws — instruments, size, deadline, the makers you invited, their prices — under your handle. It cannot run the auction otherwise. About ten minutes after an RFQ closes, that record and its quotes are deleted from the desk.

Trade and RFQ history. What outlives a closed RFQ is its outcome. Settled trades and RFQ results are stored under your handle, so any device you sign in from — and the API — can list them. They stay until you ask us to remove them.

Technical data. Our servers log requests — IP address, time, endpoint, result — to keep the service running and to rate-limit registration and sign-in. Rate-limit counters are held in memory and disappear when the service restarts.

API keys are stored hashed. We cannot show you a key again after it is issued; we can only issue a new one.

Cookies and local storage

One cookie: your session token, set when you sign in. It is httpOnly, SameSite=Lax, sent only to the desk, and it expires. It exists to keep you signed in — nothing else. There are no analytics or advertising cookies on any Cessio site.

Local storage on your device holds your interface preferences.

What is on the ledger

Settlement happens on Canton Network. The contracts that move your assets are recorded on the participant node that hosts your party, and Canton shows each contract only to its parties: your counterparty sees the trade you did together, and nobody else does — not the other makers, not other users, not the wider network. As the operator of the desk, we see the trades routed through it.

Ledger records are immutable. We cannot edit or delete them, and neither can you. Your party id is a pseudonymous identifier rather than your name, but it is stable — treat it as public.

Why we process this

To run the desk (route RFQs, deliver quotes, settle trades), to keep your account secure, to prevent abuse, to answer your support requests, and to meet legal obligations that apply to us. We do not profile you, advertise to you, or sell your data.

Who else sees it

  • Your counterparty — by design, and only for the trade you did together.
  • The infrastructure we run on — our hosting provider, our database and the Canton participant/validator infrastructure the desk uses. They process this data on our behalf.
  • Nobody else. The market-data sources we query for reference prices receive nothing about you or your trades. We would disclose data if a valid legal order compelled us to.

How long we keep it

  • Open RFQs and their quotes: while live, then deleted about ten minutes after the RFQ closes.
  • Trade and RFQ history: until you ask us to delete your account.
  • Sessions: until they expire or you sign out.
  • Account data: until you ask us to delete it.
  • Server logs: a short operational window.
  • On-ledger records: permanent, and outside our control.

Your choices

  • Add, change or clear your email in Profile.
  • Ask us for a copy of what we hold about your account, or ask us to delete it, at support@cessio.cc. Deleting an account removes the account record, its email, its sessions and any history stored under your handle. It cannot remove ledger records, and it does not touch your party key — that key is yours, not ours.
  • Depending on where you live you may have further rights over your data (access, correction, erasure, objection). Write to us and we will honour them as far as the ledger allows.

Security

Your party key is generated in your browser and never leaves it unencrypted; the copy we hold is sealed with a secret only your passkey can derive. API keys are hashed at rest and traffic is TLS-encrypted. Sign-in is passkey-based, so there is no password to steal or reuse. No system is perfectly secure, and Cessio is early-stage software — see the Terms of Use.

Children

Cessio is not intended for anyone under 18, and we do not knowingly hold data about children.

Changes to this policy

We update this page when the desk changes what it stores, and the date at the top changes with it. Material changes are announced on our social accounts and in the documentation.

Contact

Privacy questions and data requests: support@cessio.cc. Anything else: hello@cessio.cc.