An assistant that learns your voice only works if you can trust where that learning lives. Cue’s answer: on your Mac, in a database you can see, behind switches you control. Here is the whole picture.
The master switch for everything Cue learns from your sent messages. Off means sent text is never stored or analysed, and you can exclude specific apps (a personal messenger, a password manager) while leaving it on elsewhere.
What Cue notices lands in a review inbox first. You accept or dismiss. The only automatic case is a promise quoting your own words near-verbatim, and it arrives with an Undo. What you accept becomes a typed row in a graph of facts, people and promises, and every row carries its provenance, so you can read where Cue learned it and delete that line on its own.
Drafts show up in a review card before anything touches your field. And Cue never sends a message. There is no auto-send code path at all.
So answers use what's actually on screen, Cue sends a screenshot with screen questions by default. Turn it off in Settings and Cue works from accessible text only. Screenshots are never kept after the reply.
Cue can operate apps on your Mac when you ask, and it does nothing of the sort until you turn this on. It is a beta: it works app by app, it is strongest in scriptable Mac apps, and it cannot reach inside a browser tab at all. “Watch me” is on with it, so Cue asks before every step, not only the risky ones. Deleting, removing and archiving are blocked outright in this version, and Cue refuses to type into a credential field. Every action is written to an audit trail on the same screen, with Undo and Clear. Shell steps have their own switch, also off.
Double-tapping the key opens a spoken conversation, and that is the one path where audio leaves your Mac without passing through us: it streams straight to a realtime voice provider. So Cue asks before the first one, on each account separately, naming them and saying plainly where the audio goes. Decline and it simply drafts instead. Say yes and you can still withdraw it in Settings or Privacy, which ends any conversation in progress and makes Cue ask again next time. The mic runs only while a conversation is open.
Hides Cue's windows from screen sharing and screen capture. The app itself stays visible in the Dock and the menu bar, and windows that belong to macOS rather than Cue, like the sign-in sheet and the file picker, cannot be covered. Max only, off until you turn it on.
Security posture: the app talks only to Cue's backend, over TLS, and holds no credentials for anything beyond it. Sign-in and payments are handled by dedicated providers, so we never see your password or your card number. Accessibility access is used to read the field you invoke Cue in and to type the reply back; what it reads is used for that request and not stored.
What actually happens when you hold the key, in order, with nothing left out.
Nothing leaves your Mac until you tap, double-tap, or hold the key. Idle means silent.
Only the moment's text or audio goes, encrypted, through our backend. A live conversation is the exception: your Mac connects to a realtime voice provider directly and streams your microphone there for as long as that conversation is open. It never reaches our servers.
The reply streams straight back into the field your cursor is already in.
When actioning is on, every step is classified twice: once on the server, once locally on your Mac against a policy the model cannot talk its way past. The stricter answer wins, and the step waits for you.
The request is processed and discarded. No server-side history of it exists.
Updates are cryptographically signed, and the signature is verified before anything installs.
Every function that can receive something of yours, what it gets, and the route it takes. Nothing else is in the path. The companies behind each one are named in the privacy policy.
Field text, on-screen text, thread context, selected memory
Your Mac → Cue's backend → the model. Drafting, answers, summaries, planning.
Dictation and meeting audio clips
Your Mac → Cue's backend → the transcriber. Processed for the text, then dropped.
The answer text to be spoken
Your Mac → Cue's backend → the voice service.
Your microphone audio, continuously, while a live conversation is open
Your Mac → the voice provider directly. Does not traverse Cue's servers, and Cue names them and asks before the first one.
The requests needed to read an account you connected, or to run a search you asked for
Your Mac → Cue's backend → the connections broker. Your third-party tokens are never held by the app.
Your email, your name, and an account id
Your browser or Mac → the identity provider.
Your card details, which go straight to the payment processor
Your browser → the payment processor. Cue never sees a card number.
Short-lived sign-in codes, usage counters, and the state of an action still in progress
Cue's backend only. Numbers and identifiers, not the content of your requests.
The privacy policy names each company and what it is contractually limited to doing with what it receives.
There is no history of your drafts, screens, or messages to leak, because we never keep one. Not encrypted, not anonymized, not retained for a while. Nonexistent.
Join the early access list for macOS 14 and later. Questions about data? Ask us anything before you do.