Skip to content
Legal

Privacy Policy

Last updated JULY 16, 2026

Cue is a product of Naberhub Inc. (“Naberhub,” “we,” “us”). This policy explains what information we handle when you use the Cue app and the cuebar.app website, why, and the choices you have. Cue is local-first: the substance of your work lives on your own Mac, and this policy reflects that.

The short version

  • Your drafts, the people you write to, your voice profiles, your memory, and your tracked promises are stored in a database on your Mac. We do not receive or store them, unless you turn on memory sync, which stores an encrypted copy we have no key for so your other devices can pull it.
  • To draft, answer, transcribe, and search on your behalf, the app sends only the specific text or audio needed for that request to our AI providers over a secure connection. It is processed to produce a result and is not kept in a durable store by us (a multi-step action that pauses for your confirmation may be held in temporary storage for up to an hour so it can resume, then it expires automatically).
  • We keep the minimum needed to run accounts and billing: your email, your subscription status, and a count of how many AI actions you have used (a number, not the content of those actions).
  • Live conversation is the one exception to everything going through our backend: while a live conversation is open, your microphone audio streams from your device directly to a realtime voice provider. It does not pass through our servers. Cue names that provider and asks for your permission before the first one, and you can withdraw it at any time in Settings or Privacy.
  • If you connect another tool (like Google Calendar or Slack), our managed-connections provider securely holds the access token on your behalf so Cue can read the context you asked for, until you disconnect it. Cue only reads; it never sends, posts, or deletes on your behalf.
  • We do not sell your information and we do not use it for advertising. We reach every AI provider through its paid business API, whose published terms say customer content is not used to train models, and we never use your content to train anything ourselves.

What stays on your device

The following is created and stored on your Mac, in a local database, and is not transmitted to Naberhub:

  • Drafts Cue has written and the on-screen context around them.
  • Relationship cards (the people you write to) and per-person voice and style profiles.
  • Memory facts, tracked promises, and your screen-activity work log.
  • Your settings, personal dictionary, and quick commands.

You can view, edit, and delete this data at any time inside the app, and removing the app removes it. Screenshots are never sent unless you turn that setting on.

Memory sync is the one exception, and it is off until you turn it on. With it on, your relationship cards, memory facts, promises, learned style, and drafts history are encrypted on your device and an unreadable copy is stored on our servers so your other devices can pull it. The key stays in your keychain and reaches your devices through iCloud, so Naberhub holds the data without being able to read it. Your meetings and their transcripts sync the same way. Audio recordings never leave your Mac. Deleting your account destroys the stored copy.

What we collect, and why

Account information. When you sign in, our authentication provider collects your email address and basic sign-in metadata so we can create your account and issue the secure tokens the app uses. We use this to operate your account and contact you about the service.

Billing information. Paid plans are processed by our payment processor, which collects and stores your payment details; Naberhub does not see or store your full card number. We keep your subscription tier and status so we can provide the plan you paid for.

Usage metering. We count how many cloud AI actions you take in a billing period to enforce plan limits. This is a tally by count, not a record of what you wrote or asked.

Request content (transient).When you use a cloud feature, the app sends the text or audio that feature needs (the message you’re drafting, the screen text you asked about, or a voice clip to transcribe) to our AI providers to generate the result. We do not keep a durable copy of your request content. For a multi-step action that pauses to ask you something, the in-progress request is held in temporary storage for up to one hour so it can resume, and then it expires automatically.

Website. The cuebar.app site uses only the cookies necessary for sign-in and security, plus privacy-friendly, cookieless analytics (aggregate page views and performance) that does not track you across sites. We do not run third-party advertising or cross-site tracking.

When you connect other tools

Cue can connect to tools you already use (for example Gmail, Google Calendar, Google Drive, Google Docs, Google Sheets, Outlook, Slack, Notion, Linear, Jira, or GitHub) so it can read the context you ask it to use. Connecting is optional, and you start it from within the app.

When you connect a tool, the sign-in (OAuth) and the resulting access token are handled and stored by our managed-connections provider, acting on your behalf; we do not hold that token ourselves. Cue reads from a connected tool through that provider’s secure gateway only to fulfill a request you make, and the content it retrieves is passed to our AI provider to generate the result and is not kept in a durable copy. We request read-focused access, and Cue never sends, posts, replies, or deletes through a connected tool; the actions that could do so are blocked at the gateway. You can disconnect at any time from the app, which revokes the connection and its stored token. Deleting your account disconnects every connected tool for you.

Web search and browsing. When you ask Cue to look something up or research on the web, your query, and the content of any page it fetches to answer, are processed through the same connections provider and our AI provider to produce the answer. This does not require connecting any account.

Service providers

We rely on a small set of processors, each handling only what their function requires. They are contractually limited to using your information to provide their service to us:

  • AI model provider: runs the models that draft, answer, summarize, and plan. Receives the field text, on-screen text, thread context, and selected memory a request needs. Reached through our backend.
  • Speech-to-text provider: transcribes voice dictation and meeting audio. Receives the audio clip and returns text. Reached through our backend, which keeps neither the clip nor the text.
  • Text-to-speech provider: turns an answer into speech. Receives the answer text to be spoken. Reached through our backend.
  • Realtime voice provider: runs live conversation. Receives your microphone audio continuously while a live conversation is open. Your device connects to it directly on a short-lived token our backend issues, so this audio does not traverse our servers.
  • Managed-connections provider: manages the secure connections to any tools you link (handling the OAuth sign-in, custodying the access tokens on your behalf, and running the gateway Cue reads through) and powers web search and page browsing. Receives the requests needed to read the tools you connected or the searches you asked for.
  • Authentication provider: account identity and sign-in (your email, name, and sign-in metadata).
  • Payment processor: subscription payments and card processing. We never see your card number.
  • Infrastructure provider: short-lived auth codes, token rotation, usage counters, in-progress action state for up to an hour, and waitlist or contact submissions.
  • Hosting and analytics provider: hosts the website and backend that route your requests, and provides the cookieless website analytics.
  • Error tracking provider: receives a stack trace and the route involved when something breaks, and crash reports from the Mac app (a signal name, stack frames and version numbers). Never receives request content, cookies, or your email.

We reach every AI provider through its paid business API, whose published terms say customer content is not used to train models, and we never use your content to train anything ourselves.

We identify each provider by the function it performs rather than by name. If you need the names, ask and we will give you the current list: email hello@cuebar.app. Business customers who need advance notice of a change of provider can ask for that in writing too.

Live conversation: your voice does not pass through us

Every other cloud feature in Cue reaches a provider through our backend. Live conversation does not. When you open one, your device opens a connection to a realtime voice provider and streams your microphone audio to it directly, using a short-lived token our backend issues for that session. Cue names that provider in the app when it asks you to allow the first one. Naberhub never receives that audio, and we cannot see or store it.

Because of that, live conversation is consent-gated. Cue asks you before the first live conversation on your account, tells you where the audio goes, and does nothing further if you decline. Your answer is stored with that account’s settings on your own device, so a second account on the same Mac is asked separately. You can withdraw consent at any time in Settings or Privacy, which ends any conversation in progress. The microphone runs only while a conversation is open, and stops the moment you end it. Dictation, drafting, and your memory are unaffected: they stay on your device or go through our backend as described above.

International transfers

Naberhub Inc. is incorporated in Ontario, Canada. Some of our service providers process data on servers located in the United States or other countries. Where information is transferred outside Canada, we use providers that apply comparable safeguards, and that information may be subject to the laws of the countries where it is processed.

How long we keep it

  • Account and subscription data: for as long as your account is active, and for a reasonable period afterward to meet legal, tax, and accounting obligations.
  • Usage counters: reset each billing period; historical tallies are kept only as needed for billing.
  • Request content: not kept in a durable store. An in-progress multi-step action may persist in temporary storage for up to one hour, then expires automatically.
  • Live-conversation audio: never received by us, so we keep none of it. It is handled by the realtime voice provider under its API data policies for the life of the session.
  • Connected-tool tokens: kept (encrypted) until you disconnect that tool, then revoked and deleted.
  • Contact form and waitlist submissions: kept for 90 days so we can reply or let you know when something you asked about ships, then deleted.
  • On-device data: retained on your Mac until you delete it or remove the app, entirely under your control.

Security

Connections between the app and our backend use TLS. Secret keys (our AI provider keys) live only on our servers and are never sent to the app. Because the substance of your work stays on your device, there is no central store of your drafts, screens, or messages for an attacker to reach.

Your rights

Under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable law, you may:

  • Access the personal information we hold about you and ask how it is used.
  • Correct information that is inaccurate or incomplete.
  • Withdraw consent and close your account, subject to legal and contractual limits.
  • Ask us to delete your account information. Most of what Cue learns about you already lives on your Mac and is deleted when you delete it there.

To exercise any of these, email hello@cuebar.app. We will respond within the timeframes required by law.

Children

Cue is not directed to children and is not intended for anyone under the age of majority in their jurisdiction. We do not knowingly collect information from children.

Changes to this policy

We may update this policy as the product evolves. We will revise the “Last updated” date above and, for material changes, provide notice through the app or the website. Continuing to use Cue after an update means you accept the revised policy.

Contact

Naberhub Inc. is responsible for the personal information under its control and has designated a contact for privacy questions. Reach us at hello@cuebar.app.

Questions? We’reeasy to reach.

Email us at hello@cuebar.app and a human at Naberhub Inc. will get back to you.