Skip to content
Privacy & security

Local-first isn’t a setting.It’s the architecture.

An assistant that learns your voice only works if you can trust where that learning lives. Cue’s answer: on your Mac, in a database you can see, behind switches you control. Here is the whole picture.

Where your data lives

Three places.Nothing hidden.

01

On your Mac, and only there

  • Your drafts history, relationship cards, promises, and memory facts
  • Voice samples: the sent messages Cue learns your tone from
  • Your personal dictionary and settings
  • A meeting's transcript, written to your Mac. The audio is pruned once the transcript exists
  • Each account gets its own local database; switching users switches databases
  • Your Cue sign-in, and nothing else of yours: macOS does not let Cue read what other apps put in the Keychain
02

Sent over TLS, processed, discarded

  • The text needed for the request you triggered (the thread you're replying to, your dictated audio)
  • The model is reached through Cue's backend rather than from your Mac, so the app never holds the credentials for it
  • Sent for the request you triggered and nothing else: we do not store it on our servers and we keep no copy of it afterwards
  • Screenshots are sent with screen questions by default; you can turn them off in Settings
  • One exception, and it skips us entirely: a live conversation streams your microphone audio from your Mac straight to a realtime voice provider, never through our servers. Cue asks first, naming them, and you can withdraw that at any time
03

On our servers

  • Your account (your email) and your subscription state
  • Anonymous usage counters for rate limits and fair use: numbers, not content
  • If you turn on memory sync: your memory graph and your meeting transcripts, encrypted on your Mac before they leave. We store the ciphertext and hold no key for it, so we cannot read it. Off unless you turn it on, and audio recordings never leave your Mac at all
  • Delete your account from inside the app and this column empties: every session is revoked, the subscription is cancelled, the usage counters are purged, your synced memory is destroyed, and the account record is deleted
  • That's the list.
You hold the brakes

Every learning behaviorhas a switch.

Switch 01

Learn from what I send

The master switch for everything Cue learns from your sent messages. Off means sent text is never stored or analysed, and you can exclude specific apps (a personal messenger, a password manager) while leaving it on elsewhere.

Switch 02

Review before it remembers

What Cue notices lands in a review inbox first. You accept or dismiss. The only automatic case is a promise quoting your own words near-verbatim, and it arrives with an Undo. What you accept becomes a typed row in a graph of facts, people and promises, and every row carries its provenance, so you can read where Cue learned it and delete that line on its own.

Switch 03

Preview before insert

Drafts show up in a review card before anything touches your field. And Cue never sends a message. There is no auto-send code path at all.

Switch 04

Screenshots, on by default

So answers use what's actually on screen, Cue sends a screenshot with screen questions by default. Turn it off in Settings and Cue works from accessible text only. Screenshots are never kept after the reply.

Switch 05

Let Cue act on my Mac, off by default (beta)

Cue can operate apps on your Mac when you ask, and it does nothing of the sort until you turn this on. It is a beta: it works app by app, it is strongest in scriptable Mac apps, and it cannot reach inside a browser tab at all. “Watch me” is on with it, so Cue asks before every step, not only the risky ones. Deleting, removing and archiving are blocked outright in this version, and Cue refuses to type into a credential field. Every action is written to an audit trail on the same screen, with Undo and Clear. Shell steps have their own switch, also off.

Switch 06

Live conversation, and the consent it needs

Double-tapping the key opens a spoken conversation, and that is the one path where audio leaves your Mac without passing through us: it streams straight to a realtime voice provider. So Cue asks before the first one, on each account separately, naming them and saying plainly where the audio goes. Decline and it simply drafts instead. Say yes and you can still withdraw it in Settings or Privacy, which ends any conversation in progress and makes Cue ask again next time. The mic runs only while a conversation is open.

Switch 07

Hide Cue from screen sharing

Hides Cue's windows from screen sharing and screen capture. The app itself stays visible in the Dock and the menu bar, and windows that belong to macOS rather than Cue, like the sign-in sheet and the file picker, cannot be covered. Max only, off until you turn it on.

Security posture: the app talks only to Cue's backend, over TLS, and holds no credentials for anything beyond it. Sign-in and payments are handled by dedicated providers, so we never see your password or your card number. Accessibility access is used to read the field you invoke Cue in and to type the reply back; what it reads is used for that request and not stored.

The data path

One request,end to end.

What actually happens when you hold the key, in order, with nothing left out.

01

You trigger

Nothing leaves your Mac until you tap, double-tap, or hold the key. Idle means silent.

02

It travels over TLS

Only the moment's text or audio goes, encrypted, through our backend. A live conversation is the exception: your Mac connects to a realtime voice provider directly and streams your microphone there for as long as that conversation is open. It never reaches our servers.

03

The model runs

The reply streams straight back into the field your cursor is already in.

04

If a step wants to act

When actioning is on, every step is classified twice: once on the server, once locally on your Mac against a policy the model cannot talk its way past. The stricter answer wins, and the step waits for you.

05

Nothing is written down

The request is processed and discarded. No server-side history of it exists.

06

The app that runs it

Updates are cryptographically signed, and the signature is verified before anything installs.

Who receives what

Everything thatcan receive it.

Every function that can receive something of yours, what it gets, and the route it takes. Nothing else is in the path. The companies behind each one are named in the privacy policy.

The model

Field text, on-screen text, thread context, selected memory

Your Mac → Cue's backend → the model. Drafting, answers, summaries, planning.

Speech to text

Dictation and meeting audio clips

Your Mac → Cue's backend → the transcriber. Processed for the text, then dropped.

Spoken answers

The answer text to be spoken

Your Mac → Cue's backend → the voice service.

Live conversation

Your microphone audio, continuously, while a live conversation is open

Your Mac → the voice provider directly. Does not traverse Cue's servers, and Cue names them and asks before the first one.

Connected accounts and the web

The requests needed to read an account you connected, or to run a search you asked for

Your Mac → Cue's backend → the connections broker. Your third-party tokens are never held by the app.

Sign-in

Your email, your name, and an account id

Your browser or Mac → the identity provider.

Payments

Your card details, which go straight to the payment processor

Your browser → the payment processor. Cue never sees a card number.

Hosting and rate limits

Short-lived sign-in codes, usage counters, and the state of an action still in progress

Cue's backend only. Numbers and identifiers, not the content of your requests.

The privacy policy names each company and what it is contractually limited to doing with what it receives.

Nothing stored

You can’t leak whatdoesn’t exist.

There is no history of your drafts, screens, or messages to leak, because we never keep one. Not encrypted, not anonymized, not retained for a while. Nonexistent.

Read the deep dive
No stored drafts: every request is processed, streamed back, and discarded
No screen history: screenshots are sent with screen questions and never kept after the reply
No message archive on our side: what Cue learns lives in a local database you can open

Private enough toactually learn you.

Join the early access list for macOS 14 and later. Questions about data? Ask us anything before you do.