CC10 Guide

Know where to start.
Know what happens next.

CC10 behaves like one ecosystem without hiding where your data lives. This guide covers the everyday user view first and owner tasks second.

Your first ten minutes

  1. 1
    Open CC10

    Go to cong42.de, select Open CC10 and sign in with your own identity. Accounts are never shared.

  2. 2
    Add a passkey

    Use the device screen lock. Add a second recovery factor and store it somewhere separate from this device.

  3. 3
    Install the home app

    Install the CC10 PWA or add it to the home screen. It is the stable doorway even when individual apps change.

  4. 4
    Open Drive, Chat and Passwords

    Confirm that each opens under your identity. Only install the additional apps you actually use.

  5. 5
    Verify recovery

    Know which trusted device and offline factor you would use if this device disappeared today.

Which app does what?

NeedUseWhat belongs there
Files, photos, OfficeDrivePrivate originals, shared folders, documents, calendar and contacts.
Private messagesChatMatrix conversations, rooms, calls and files shared in chat.
Short public postsSocialText posts, threads, replies and the wider Fediverse.
Public photo feedPixelfedSelected public photos, captions and federated discovery.
Research and content plansNotebookSources, cited notes, grounded scripts and film planning.
Videos, reels and podcastsVideo StudioScripts, smooth narration, reviewed renders and private Drive exports.
Passwords and passkeysPasswordsUnique credentials, recovery material and secure notes.
Owned musicMusicYour library and selected offline downloads.
Development and operationsOperatorOwner-only, audited work on code and system actions.

Avoid duplicate data masters. Editors may process a copy, but reviewed source files and exports return to Drive.

Two social views, two clear jobs

Social

The Threads/X-style view for short posts, threads, replies and following people across the Fediverse. On first web sign-in, enter social.cong42.de as your server. Afterwards install CC10 Social or use the approved mobile app day to day.

Open Social

Pixelfed

The Instagram-style view for a photo-first public feed. Publish selected, reviewed media here—not the entire private camera archive.

Open Pixelfed

Add another person safely

Only an owner performs this flow. The private CC10 Guide in Drive contains the operator commands and validation record; this public guide contains no administrative route or secret.

  1. 1
    Choose the smallest role

    Member gets everyday apps, Creator adds Studio/Git work, Operator adds system tools, and Guest receives explicit shares only.

  2. 2
    Create a separate identity

    Use the person's real display name and a unique username. Never clone or share the owner account.

  3. 3
    Issue a one-use invitation

    Set a short expiry and send it through a different trusted channel. Close unused invitations after onboarding.

  4. 4
    Enrol two recovery paths

    Add a passkey and a separately stored recovery factor before adding apps or private files.

  5. 5
    Validate the assigned apps

    Confirm allowed apps work and owner-only apps do not appear. Record the result without storing credentials.

Add a phone, tablet or computer

  1. 1
    Secure and update it

    Install current OS updates, enable a strong screen lock and device encryption, then open this page.

  2. 2
    Install CC10 Start

    Use the PWA on Android, iPhone, iPad, macOS, Windows or Linux. It gives every device the same navigation.

  3. 3
    Sign in and add a device passkey

    Do not copy another device's session or recovery secret.

  4. 4
    Add apps by need

    Use the browser or installed web app for Notebook, Video Studio, Social and Pixelfed. Add native Passwords, Drive or Chat clients only when background sync, offline files or notifications require them.

  5. 5
    Enrol private network access only if assigned

    Use a one-use, short-lived key. Ordinary guests do not receive mesh access.

  6. 6
    Keep storage selective

    Mark only current work offline. Verify upload and download, notifications, calendar/contact sync and one recovery action.

  7. 7
    Close setup access

    Revoke the enrolment key. On Android, disable USB debugging and Developer options after bootstrap.

Android / GrapheneOS

Browser or CC10 signed shells first. Keep native sync clients and permissions minimal; no emulator, model or rendering workload belongs on the phone.

iPhone / iPad

Browser or installed CC10 web apps first. Add official Drive, Chat and password clients only when needed, and store recovery outside the Apple-only account path.

macOS / Windows / Linux

Browser-first. Keep local VMs, models and media toolchains on CC10; add Drive sync only where a working copy is genuinely useful.

Remove access without losing data

Only an owner performs this flow. Suspension comes before deletion, so access stops while ownership, retention and recovery stay reversible.

  1. 1
    Name a data custodian

    Confirm which Drive files, shared work, calendars and collaborative content need transfer. Preserve relevant audit evidence.

  2. 2
    Suspend the identity

    Disable sign-in and remove role groups first. Do not delete the account while data ownership is unresolved.

  3. 3
    Revoke every device path

    End sessions and revoke passkeys, recovery tokens, mesh nodes, app passwords, sync clients and notification credentials.

  4. 4
    Transfer or export content

    Move private work to the named custodian. Export federated posts when required; remote servers may retain previously public content.

  5. 5
    Prove recovery, then archive

    Restore representative data from backup and record the result. Permanent deletion needs a separate owner decision after the retention period.

Five habits that matter

  • Use passkeys and a separate recovery factor. A passkey on a lost device is not a recovery plan.
  • Keep public and private media separate. Drive stores originals; Social and Pixelfed are publishing destinations.
  • Install less. Every extra client, browser extension and broad permission adds risk.
  • Check unusual sign-ins. Revoke sessions you do not recognise and tell the owner immediately.
  • Test restore, not only backup. A green timer is useful; a successful restore is evidence.

Read the security model

If a device is lost

  1. 1
    Use another trusted device

    Do not wait for the missing device to reconnect.

  2. 2
    Lock or wipe it if that capability was configured

    Do not assume remote wipe exists unless it was tested before the loss.

  3. 3
    Revoke identity sessions and the device passkey

    Then revoke mesh access, app passwords, sync tokens and notification credentials belonging to that device.

  4. 4
    Rotate exposed recovery material

    Change only credentials that may have been accessible; preserve evidence of suspicious activity.

  5. 5
    Restore to a clean replacement

    Enrol it as a new device. Verify Drive data and account recovery before considering the incident closed.

When something does not work

An app is empty or signed out

Open CC10 Start, verify that sign-in works, then fully close and reopen the app. Do not delete the account or clear app storage before checking offline files and recovery.

Drive reports a connection error

Check system status, retry on another network and restart Drive. Removing the account also removes local offline markers.

There is no internet connection

Previously selected Drive files, downloaded music and the password-vault cache remain useful. Changes sync after connectivity returns.

I need owner help

Use a known contact channel. Never send a password, recovery phrase, passkey export or one-use enrolment key in a support message.