PRIVACY NOTICE
Your device is the default boundary.
CueMeThen can be used anonymously and offline. This notice explains what remains local, what is processed only after you choose an online feature, and how to exercise your rights.
- Last updated
- 29 July 2026
- Contact
- support@cuemethen.com
Who this notice covers
This notice covers the CueMeThen website and installable web app, the delayed Android app, and the CueMeThen API. CueMeThen is operated from the United Arab Emirates. The service is intended for people aged 16 and older and is not directed to children.
For privacy questions or requests, email support@cuemethen.com.
Information that stays on your device
Anonymous cards, note text, Boards, Today and Inbox state, local search indexes, drafts, photos, voice notes, reminders, notification delivery state, settings, and local backup files remain in app storage on your device. CueMeThen does not receive them merely because you use the app.
Your browser or operating system may process notifications, camera or microphone input, and app storage according to its own platform rules. Today remains authoritative even when a browser or Android does not deliver a notification.
Information processed when you choose online features
Account and authentication
If you sign in, CueMeThen processes an opaque account identifier, the chosen sign-in method, session records, verification state, and—when relevant—your email address or Google authentication subject. Email and Google are separate permanent identities; matching email text does not link them.
Paid cloud
Cloud storage begins only after you preview and confirm cloud adoption for selected local records. It may include card and Board data, reminder schedules, cloud settings, and selected attachments. Cloud replicas are owner-scoped and conflict copies remain visible and recoverable.
Cloud data uses encrypted transport and encrypted provider connections, but is not end-to-end encrypted. CueMeThen’s server can technically process cloud plaintext to sync, export, recover, and delete it.
Purchases
Paddle processes website payment details; Google Play will process Android payment details when that app is published. RevenueCat processes an opaque billing customer identifier, product and entitlement state, renewal or expiry information, and store events needed to verify Pro access. CueMeThen does not receive your payment-card number and does not place note content in RevenueCat metadata.
Optional browser notifications
If you explicitly enable browser reminder delivery, CueMeThen stores a random installation identifier, a hashed capability, encrypted browser push endpoint and keys, random delivery identifiers and times, consent and expiry state, and delivery status. It does not send reminder text, card identifiers, reminder type, account identity, or billing identity to this notification system. Alerts are generic and open Today. Removing browser reminders deletes the installation and its schedule.
Optional online AI
AI runs only after separate consent and an explicit request. CueMeThen sends the text of the owner-scoped cloud cards you selected, the task or query you entered, and limited context such as locale and time zone to OpenRouter and the selected model provider. Device-only content is not eligible for AI context. See the AI disclosure.
Optional diagnostics
If you opt in, CueMeThen may send sanitized crash or operational fields to Sentry, such as app version, operation name, duration, error type, and coarse status. Diagnostics are designed to exclude note text, attachments, searches, prompts, model responses, email addresses, tokens, purchase evidence, and signed attachment URLs.
Integrity and abuse prevention
Play-installed builds use Google Play Integrity. Google and CueMeThen process an integrity token and verdict information needed to check app identity, licensing, certificate, version, request binding, and device integrity. The backend also uses keyed, pseudonymous network or installation signals for bounded rate limiting and free-AI abuse prevention.
Why information is processed
- To provide features you request, including authentication, cloud sync, export, account recovery, purchases, and AI suggestions.
- To perform a contract, verify entitlements, and maintain account and billing records.
- With your consent, to provide online AI or optional diagnostics.
- To protect CueMeThen, its users, and providers against fraud, abuse, unauthorized access, and data loss.
- To comply with legal obligations and respond to valid legal requests.
Where local law requires a specific legal basis, the applicable basis may be consent, contract, legitimate interests, or legal obligation.
Service providers and international processing
CueMeThen’s launch configuration uses service providers for limited purposes:
- Linode-hosted infrastructure for the API, database, cache, and object storage.
- Paddle for website checkout, payment, tax, and subscription management.
- Google for authentication and, after Android publication, distribution, Play Integrity, and Play Billing.
- RevenueCat for subscription verification and entitlement events.
- Resend for sign-in email delivery.
- OpenRouter and approved model providers for optional AI requests.
- Sentry for optional, sanitized diagnostics.
- UptimeRobot for public service-availability checks without note content.
Providers may process data in other countries under their own terms and safeguards. CueMeThen limits the fields sent and does not sell personal information or use it for behavioral advertising.
Retention and deletion
- Device-only data remains until you delete it, clear app storage, uninstall, or restore a different local backup.
- Active cloud data remains while the account and paid cloud relationship require it.
- After paid access ends, cloud data becomes read-only for a 90-day recovery period and is then purged.
- Cloud export archives expire after 24 hours; their private download links expire after five minutes.
- Account deletion is reversible for 30 days. Sync stops immediately; final deletion removes cloud data, sessions, attachments, AI metadata, allowances, and the RevenueCat customer.
- Security, billing, and operational records may be retained as needed for fraud prevention, legal compliance, dispute handling, and reliable service operation.
Deleting a CueMeThen account does not cancel a Paddle or Google Play subscription. Manage the subscription separately through the provider that sold it.
Your choices and rights
You can use the offline core without an account, decline cloud adoption, revoke AI consent, disable optional diagnostics, export cloud data, schedule account deletion, and undo deletion during the 30-day window.
Depending on where you live, you may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent, and may complain to a competent data-protection authority. To make a request, follow the account-deletion instructions or email support. CueMeThen may need to verify your identity without asking for note content.
Security and changes
CueMeThen uses owner-scoped authorization, bounded inputs, encrypted transport, private object storage, secure browser cookies, secure native session storage, encrypted Web Push routing, and fail-closed production configuration. No system is perfectly secure. Please report concerns through the security page.
Material changes to this notice will be dated and presented through the website or app before they take effect where required.