Privacy Policy
Last updated: 2026-10-01
CueBank helps your agent look up shared facts we publish, and keep your own short notes. This page says what we store, why, how long, and what you can delete.
Who this is for
People and teams who sign in to CueBank and connect an agent. We are not a consumer social network.
What we collect
| What | Why |
|---|---|
| Your Google account id and email | So you can sign in and own the account |
| Stripe customer and subscription status | So paid access works and billing is correct |
| A hashed access key | So your agent can connect; we show the key once when you Issue or set up an access key, and only the browser you got it in keeps a copy |
| Notes you (or your agent) save | The notes feature you asked for — private to your account |
| Coarse call logs (which tool, when, success/fail — not full note text) | Debug, quotas, and abuse prevention |
| IP address on free-test signup and failed sign-ins | Abuse prevention |
We do not ask you to paste OpenAI, Voyage, or other model API keys on the normal path.
What we do not do
- We do not send your notes through an AI model to “understand” them.
- We do not sell your notes.
- We do not mix your notes into the shared fact bank other customers search.
- We do not show one customer’s notes to another customer.
How long we keep things
Your notes
- You can delete them yourself anytime in Delete my notes on the dashboard Settings page (
/settings) after typing the exact case-sensitive confirmationWIPE. - Free test: after you use the free call quota, if you do not subscribe within 3 days, we delete those notes.
- Paid: while you are subscribed (or in the short payment-failure window), we do not auto-delete notes for inactivity.
- After subscription ends and access is revoked, we keep notes 30 days, then delete them unless you come back and renew in time.
Call logs
- Normal counted-call and quota-reject logs: 30 days, then hard-deleted.
- Failed auth attempts: about 14 days.
Operational backups
We keep operational backups of the database and your notes for 7 days, then delete older backup copies.
Access keys
After you Issue a new access key (or access is revoked), the old key stops working. Upgrading to Paid also stops your free-test key — issue your paid access key on Connection. We keep only hashes, never a long-lived plaintext access key. The browser you got a key in keeps its own copy so the connect snippet stays filled; to add a machine, copy it from that browser.
Shared facts
Those are our published knowledge for all customers. Deleting your notes never removes anything from the shared bank.
Your controls
- Delete your notes anytime in Delete my notes on the dashboard Settings page (
/settings). - Issue a new access key anytime on Connection (
/devices). - Manage billing in the Stripe customer portal (cancel, payment method, invoices).
- Sign out / stop using the product; retention rules above still apply to leftover notes and logs.
Who we share with
- Google — sign-in only.
- Stripe — payments and subscription status.
- Hosting providers that run CueBank (they process data to keep the service up — not to train models on your notes).
We do not sell personal data.
Security (short)
Secrets are hashed at rest. Access to customer notes is limited to your account. We rate-limit and block obvious abuse. No system is perfect; if we learn of a breach that affects you, we will notify you as the law and our process require.
Children
CueBank is for adults and business use. We do not knowingly collect data from children under 16.
Changes
If we change this policy in a meaningful way, we will update the date on this page and, for material changes, notice in the dashboard or by email when we can.
Contact
Questions about privacy: vimantas1@gmail.com. Account / product (private beta): same mailbox.
Terms pointers (privacy-related)
Paid plan, cancel, and refunds live on the Terms of Service. These privacy-related pointers stay true alongside this Privacy Policy:
- Your notes are yours to delete; CueBank may auto-delete them under the free 3-day and post-cancel 30-day rules above.
- Shared published facts are CueBank’s corpus; customers do not own that bank by searching it.
- You must not try to extract or republish the shared corpus as a competing dataset.
- Abuse (credential stuffing, scraping at scale, sharing secrets) may get access revoked.
For the full privacy picture, use this page. The auth door “Terms of Service” link points at /terms.
