Privacy Policy
Last updated: July 15, 2026 · Effective immediately
Summary: Cue keeps local copies of your data. If you sign in, account data including thread messages, preferences, and skills is synced through Cue so it can follow you across devices. Raw dictation history and screenshots are not included in account sync. Voice, screen, and selected-text context is sent to service providers only when needed to fulfill a request. Cue does not use request content to train models; provider processing and retention are governed by the provider terms linked below.
Analytics & crash reporting: We use PostHog (US Cloud) and Sentry for anonymous product analytics and crash reporting. You can disable analytics in Settings → Privacy. We do not collect screenshots, voice content, or text you dictate.
Cue ("we", "our", or "us") is a desktop AI assistant for macOS and Windows developed by Sophon LLC. This Privacy Policy explains what information we collect, how we use it, your rights, and the choices you have.
1. Information We Collect
We collect only what is necessary to operate the service:
- Email address — collected when you redeem an invite code or join the waitlist, used to manage beta access.
- Invite code activity — which codes have been redeemed and by whom, to power the referral system.
- Product and diagnostic metadata — feature events, timing, error codes, app version, platform details, and a device or account identifier, processed by PostHog (US Cloud) and Sentry. Product analytics is designed not to include transcripts, screenshots, selected text, or dictated text. You may disable in-app analytics collection in Settings → Privacy.
- Website measurement data — page URL, referrer, campaign and click parameters, download events, approximate location, and browser or device details processed by PostHog, Google Analytics 4, and Google Ads when you visit heycue.io.
- Signed-in account data — thread indexes and messages, preferences, settings, skills, domains, user memory/tool notes, and aggregate activity statistics are synced when you sign in so Cue can restore them across devices.
- Payment information — if you subscribe to Cue Plus, payment is processed by Stripe. We do not store your card number or billing details.
We do not ask for your phone number or biometric identifiers. Service providers may process IP address, approximate country, and other operational metadata needed to deliver and secure the service.
2. Local Data, Account Sync, and Request Processing
The following data stays local and is not included in Cue account sync:
- Raw dictation and activity history — entries stored in
~/.cue/history/. Cue may sync aggregate counts, but not these raw history entries.
- Screenshots — not included in account sync. A relevant screenshot may be sent at request time when a screen-aware task needs it.
- User-provided provider API keys — stored in the operating-system credential store and not included in Cue account sync.
When you sign in, Cue syncs the account data listed in Section 1 through Cue's infrastructure. To carry out a request, the following may also be sent to AI or speech providers (see Third-Party Services below):
- Screenshots — captured only for a screen-aware task and sent as request context.
- Voice audio — sent for speech-to-text or meeting transcription.
- Selected text, clipboard content, prompts, and relevant thread context — sent when needed to fulfill the request.
Cue does not use this content to train its own models. Provider-side processing and retention depend on the provider, plan, and applicable terms linked in Section 5.
3. How We Use Your Information
- To grant and manage access to the Cue beta program.
- To operate the invite code and referral system.
- To send product updates and important service announcements (no marketing email without your explicit consent).
- To understand aggregate usage patterns and improve the product.
- To sync signed-in account data and restore it across devices.
- To process payments for Cue Plus subscriptions.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases:
- Contract performance — processing account, sync, and request data to provide Cue.
- Legitimate interests — product analytics, reliability, fraud prevention, and service security.
- Consent — marketing communications and any optional analytics or advertising storage you choose to enable, which you may withdraw at any time.
5. Third-Party Services
Cue uses the following third-party services. Each has its own privacy policy governing its data practices:
- Anthropic API — prompts and relevant request context may be sent to Claude models to generate responses. See the Anthropic Privacy Center.
- OpenAI API — prompts or audio may be processed by OpenAI models on supported routes. See OpenAI's business-data privacy information.
- Deepgram — real-time speech-to-text and meeting transcription. See Deepgram's Privacy Policy.
- Groq — Whisper speech-to-text on supported routes. See Groq's Privacy Policy.
- Google (Gemini API) — used for fast-path text tasks. See Google's Privacy Policy.
- Stripe — payment processing for Plus subscriptions. We never see your full card details. See Stripe's Privacy Policy.
- Cloudflare — CDN, infrastructure, and edge compute. See Cloudflare's Privacy Policy.
- PostHog (US Cloud) — product and website analytics using event names, timing, technical metadata, and a device or account identifier. Product analytics is designed not to include request content. On the website, PostHog uses memory-only persistence with autocapture, automatic page-view capture, and session recording disabled. See PostHog's Privacy Policy.
- Google Analytics 4 and Google Ads — website visit and conversion measurement using page and referrer information, campaign or click parameters, download events, and technical browser or device metadata. Google storage is denied by default through Consent Mode; cookieless measurement pings may still be sent. See Google's Privacy Policy.
- Sentry — application crash and error reporting. Stack traces and diagnostic metadata may be sent so we can fix bugs. See Sentry's Privacy Policy.
We do not use Meta Pixel and we do not sell personal data. Google Ads is used for conversion measurement, not to include Cue request content in advertising audiences.
6. Cookies and Tracking
Our website (heycue.io) uses PostHog, Google Analytics 4, and Google Ads conversion measurement. PostHog is configured with memory-only persistence and with autocapture, automatic page-view capture, and session recording disabled. Google Consent Mode defaults analytics and advertising storage, ad user data, and ad personalization to denied. Even with storage denied, Google may receive cookieless measurement pings and technical, page, referrer, campaign, or click metadata. The website may also use local storage for technical functionality such as remembering an invite-code session state.
7. Data Retention
- Beta email and invite data — retained for the duration of the beta program, and for up to 12 months after the beta ends.
- Subscription records — retained for 7 years as required by financial regulations.
- Signed-in account sync data — retained while your account is active or until you request deletion, subject to limited backup, fraud-prevention, security, and legal retention.
- Anonymized analytics — retained indefinitely in aggregate form.
You may request deletion of your personal data at any time (see Your Rights below).
8. Your Rights
Depending on your location, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request that we delete your data ("right to be forgotten").
- Portability — request your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — unsubscribe from communications at any time.
California residents (CCPA): You have the right to know what personal information we collect, the right to delete it, the right to opt out of its sale (we do not sell personal data), and the right to non-discrimination for exercising these rights.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
9. Data Security
We use industry-standard measures to protect your data, including TLS encryption in transit and access controls on our infrastructure. However, no system is 100% secure. If you believe your data has been compromised, please contact us immediately.
10. Children's Privacy
Cue is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. International Transfers
Your data may be processed in the United States and other countries where our service providers operate. By using Cue, you consent to the transfer of your information to these countries, which may have different data protection laws than your country of residence.
12. Changes to This Policy
We may update this policy as the product evolves. If changes are material, we will notify you via email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of Cue after changes take effect constitutes acceptance of the revised policy.
13. Contact
Questions or requests regarding your privacy? Contact us at [email protected]. We aim to respond within 3 business days.