Privacy Policy
Last updated: August 14, 2026
01Introduction
This policy covers the CueSync desktop application, CueSync Studio, and the website at https://www.cuesync.live (together, the "Service"). CueSync is a music-based stage automation platform: it analyses audio in real time and drives lighting, video and show-control systems during live events.
It is written to be checked rather than skimmed. Every category of data below corresponds to something the software actually stores or sends, every purpose names the lawful basis we rely on, and the retention periods are the ones our cleanup jobs enforce — with the one exception marked as such in Section 14. Where a detail belongs to another document — the full sub-processor list, the full retention schedule — this policy links to it instead of restating it, so the two cannot drift apart.
This policy is provided as a best-effort transparency document. It is not a substitute for professional legal advice. We encourage you to consult with a legal professional if you have specific questions about your rights.
02Who Controls Your Data
The controller of the personal data described in this policy — the party that decides why and how it is processed — is:
- Legal entity: to be confirmed — write to contact@cuesync.live, trading as CueSync
- Address: to be confirmed — write to contact@cuesync.live
- Registration number: to be confirmed — write to contact@cuesync.live
- Country of establishment: to be confirmed — write to contact@cuesync.live
EU representative (Art. 27 GDPR): to be confirmed — write to contact@cuesync.live
UK representative (Art. 27 UK GDPR): to be confirmed — write to contact@cuesync.live
Data protection officer: No DPO appointed. Privacy enquiries: privacy@cuesync.live
Privacy questions and rights requests go to privacy@cuesync.live. Security reports go to security@cuesync.live. Anything else goes to contact@cuesync.live.
If you use Studio to run a production, you are the controller of your crew's data and we are your processor for it. See Section 11 and the Data Processing Agreement.
03What We Collect
This list is built from the database schema rather than from memory, so it names things you would not otherwise know we hold.
Account and authentication data
Your email address, when you registered, and whether the address is verified. The address is held in our database and protected by encryption in transit, access control on the database itself, and encryption of the backups it appears in. We have built envelope encryption for this field — AES-256-GCM under a per-row key wrapped by a master key held only in the server's environment — but it is not yet switched on for existing accounts. We will update this page when it is.
If you set a password we store a bcrypt hash of it, never the password, plus hashes of your previous passwords so a reset cannot reuse one. If you switch on two-factor authentication we store your TOTP secret in encrypted form and hashes of your recovery codes. We also hold your notification preferences, your plan tier, and short-lived hashed tokens for email verification, password resets, magic-link sign-in and email-change confirmations.
Sign-in with Google or Apple
If you sign in with Google or Apple we store which provider you used, the account identifier that provider gives us, and the email address it returns. We never receive your password for those accounts.
Device records
When you activate CueSyncon a machine we store a SHA-256 hash of the device identifier (never the raw identifier), the device name you or your operating system supplies, the platform, when it was activated and when it was last seen. We also store the desktop client's own assessment of how strongly that identifier is bound to the hardware, and the furthest-forward clock reading the device has reported, which is how we detect a clock being wound back to extend an offline grace period.
Licence data
Your licence key is stored in two forms: a keyed hash used for lookup and verification, and an encrypted copy (same envelope scheme as your email address) that exists so support can re-send you your own key. We also store the key prefix, the edition and billing cycle, the key type, activation counts, and whether and why a key was revoked.
Session records
Web sessions use an httpOnly cookie; the session record holds the identifiers needed to validate and revoke it. Desktop sessions additionally record the app version, operating system, edition, a hashed IP address, the country that IP resolves to, heartbeat counts and total active seconds — this is what powers the "active sessions" list and the "sign out everywhere" button. Revoked sessions and revoked tokens are kept on a blocklist until they could no longer be presented.
Billing and transaction records
Your Paddle customer and subscription identifiers, the edition, billing cycle, status, period dates, any scheduled change or cancellation, and dunning state if a payment fails. We keep an append-only ledger of completed transactions: amount, tax component, currency, status, the date, and the Paddle transaction reference printed on your receipt. We never receive or store card details.
Support, contact and chat content
Your name, email address, the content of your message, your IP address, and Cloudflare Turnstile verification tokens for bot protection. Alongside a contact-form message we send the campaign details of your visit — any UTM tags or Google click ID in the link you followed, the page you first landed on, and the site that referred you. That tells us which channels bring people who get in touch. It is never used to build a profile of you or shared with advertisers, and it is deleted with the rest of your record on request.
Newsletter subscription
Your email address, when you subscribed and confirmed, whether you have unsubscribed, and the attribution of the signup: UTM source, medium, campaign, content and term, plus which placement on the site you signed up from.
Studio content and collaborator data
If you use CueSync Studio, we store the show projects you create and everything in them: project name, venue, author and schedule, cues (numbers, names, notes, intent and the actions they fire), sections and acts, snapshots, comments, audio track configuration, and per-project activity. Uploaded audio, waveform data, spec documents, images and cover art are stored as objects in Cloudflare R2 with their filename, size, content type and checksum recorded in our database. We also store project membership and pending invitations, which include the email address of the person invited, and a short-lived presence record showing who currently has a project open.
Security, audit and anti-piracy records
An audit log of security-relevant events — activations, sign-ins, subscription changes, admin actions — each with the action, your user ID, a hashed device identifier, the IP address, and event details. Hashed IP addresses you have signed in from before, which is how we can tell a new-device sign-in from a routine one. Anomaly signals scored by our sharing detector, tamper signals reported by the desktop app, and the per-install watermark identifier described in Section 08.
Analytics, advertising and error-diagnostic data
Subject to your cookie choices: pages viewed, interactions, web-vitals measurements, session recordings, advertising click identifiers (gclid, gbraid, wbraid, fbclid and their equivalents), and — on purchase — a hashed copy of your email address sent to ad platforms so they can match the sale to a click.
Not subject to your cookie choices: errors thrown by the website, with the IP address they came from, the browser context, and a masked replay of the session the error happened in. Section 07 sets both out in full and explains the difference.
Technical logs
Our servers log IP addresses, browser user-agent strings and request timestamps for security monitoring, rate limiting and abuse prevention. Our hosting providers keep their own request logs.
04Why We Use It, and Our Lawful Basis
Under the GDPR and UK GDPR every purpose needs a lawful basis, and where that basis is legitimate interests we have to say what the interest is. Here is the full set.
| Purpose | Lawful basis | Notes |
|---|---|---|
| Creating and running your account; issuing, validating and re-sending licence keys; activating devices; hosting your Studio projects | Performance of a contract (Art. 6(1)(b)) | This is the service you bought. We cannot provide it without this data. |
| Transactional email: licence keys, verification, password resets, receipts, subscription and security notices | Performance of a contract (Art. 6(1)(b)) | These are not marketing and cannot be switched off while your account exists. |
| Anti-piracy, licence enforcement, device-limit enforcement, abuse prevention, rate limiting, security and audit logging | Legitimate interests (Art. 6(1)(f)) | Our interest: protecting a paid product from unlicensed copying, and protecting accounts and infrastructure from takeover and abuse. See Section 09. |
| Keeping the app working: update checks, install-failure diagnostics, service monitoring | Legitimate interests (Art. 6(1)(f)) | Our interest: shipping a product that installs and runs, and knowing when it does not. |
| Answering support requests, including through our CRM and support chat | Performance of a contract, or legitimate interests where you are not yet a customer (Art. 6(1)(b) / (f)) | Our interest: answering people who ask us questions. |
| Desktop crash reporting | Consent (Art. 6(1)(a)) | Off until you switch it on. See Section 08. |
| Desktop product analytics | Consent (Art. 6(1)(a)) | A separate choice from crash reporting, also off until you switch it on. |
| Website analytics and analytics session replay | Consent (Art. 6(1)(a)) | Nothing loads until you accept analytics cookies. |
| Website error monitoring and performance diagnostics, including the error-triggered replay described in Section 07 | Legitimate interests (Art. 6(1)(f)) | Our interest: knowing when the site breaks for a real person, and being able to see what they did to break it. This is not consent-gated; you can object under Section 15. |
| Advertising, conversion measurement and remarketing, including server-side conversion APIs | Consent (Art. 6(1)(a)) | Denied by default under Google Consent Mode v2 and equivalents. |
| Marketing email and product-update newsletters | Consent (Art. 6(1)(a)) | One-click unsubscribe in every message. |
| Tax, accounting and invoicing records; responding to lawful requests | Legal obligation (Art. 6(1)(c)) | Survives an erasure request for as long as the law requires. See Section 14. |
| Establishing, exercising or defending legal claims, including chargeback and dispute evidence | Legitimate interests (Art. 6(1)(f)) | Our interest: being able to show what happened when a payment or a licence is disputed. |
Do you have to give us this data? Some of it, yes. An email address and a payment through Paddle are a contractual requirement of buying a licence: we cannot deliver a key or a receipt without them. A hashed device identifier is a contractual requirement of activating the desktop app, because that is what a per-device licence is enforced against. If you withhold either, we cannot provide the software. Everything else — your name in a support message, a newsletter subscription, analytics, advertising, crash reports, product analytics — is optional, and refusing costs you nothing but the feature it powers.
Where we rely on legitimate interests you have the right to object, and we will stop unless we can show compelling grounds that override your interests. See Section 15.
05Payment Processing
All payments are processed by Paddle.com as our Merchant of Record. Paddle handles card processing, invoicing, sales tax and compliance, and is the seller of record for your purchase. We never receive, store or process your card or payment method details. For those, Paddle is its own controller — see Paddle's Privacy Policy.
What reaches us from a purchase is your email address, the edition and billing cycle, the Paddle customer, subscription and transaction identifiers, the amount and tax, and the country Paddle computed your tax from.
When a purchase completes we record it in ClientFlow, our customer-relationship platform, so that support requests can be matched to your licence. What is recorded is your email address, the edition and billing cycle you bought, and the Paddle subscription reference — never card or payment-method details, which we never receive in the first place.
06Support, Contact & the AI Assistant
Contact form and support tickets
Submissions are forwarded to ClientFlow, the customer-relationship platform we use to track and answer support requests, so that your message reaches a person and does not depend on a single email delivery. Campaign details of your visit travel with it, as described in Section 03; they are stored in your browser for the session (30 days for the campaign tag).
Support chat
The support chat in the corner of this site is operated for us by ClientFlow. Messages you type are sent from your browser directly to ClientFlow's servers, along with your IP address, and are stored there as a conversation record. If you choose to leave an email address for a follow-up, that address is stored with the conversation.
Replies are generated by an automated assistant, not a person — the chat window says so before you type. To produce a reply, ClientFlow sends your message to a third-party large-language-model provider. ClientFlow removes recognisable personal details (such as phone numbers, email addresses, and card-like number sequences) from the message before it leaves their servers, but you should still avoid putting sensitive information into the chat. You can ask to speak to a human at any time.
Your conversation is also stored in your own browser for 24 hours so it survives a page reload. You can erase it at any time with the “Clear conversation” button in the chat header, which deletes both the local copy and the session it belongs to. See our Cookie Policy for the exact storage entries, and our AI Use Statement for where else automated systems are involved.
08Desktop Application Telemetry
What the app does regardless of your choices
The desktop app contacts our servers to validate your licence (roughly every 30 days for token renewal, and when you activate or deactivate a device) and to check for updates. It also reports anti-piracy tamper signals — see Section 09, which explains what those are and why they are not covered by the switches below.
Audio analysis is local. Beat and tempo detection runs on your machine and the audio itself is never uploaded. Unless you use Studio, your show files stay on your disk.
Two separate switches, both off until you answer
Crash reporting and product analytics are two independent choices. Both are off until you make them. CueSync asks once, when you first run the app, and you can change either at any time in Settings > Advanced. Turning one on does not turn the other on.
Crash reporting — what it actually sends
If you switch crash reporting on, CueSync sends errors and crashes to Sentry, together with the trail of events leading up to them. That trail is more detailed than "a crash report" suggests, so here is what is in it:
- Fired cues, including the cue number, the cue name and how it was triggered
- Device connect and disconnect events, and MIDI, OSC and other protocol traffic events
- Settings changes, project open and save events, timeline and venue-profile actions
- Tempo changes, and — unless you turn off "include track metadata in crash reports" — the title and artist of loaded tracks
- Licence activation, validation and revocation events, and detected clock rollbacks
- Your operating system, Java version, app version, connected protocol count and whether the licence is a paid one
Your account email is not sent in the clear from the desktop app: the user attached to a desktop crash report is identified by your device identifier and by a salted SHA-256 hash of your email address. The website is different — if you are signed in on this site, our web-side error reporting is given your email address itself. Both are described in the processor table in Section 12.
Crash reports also carry the per-install watermark described in Section 09, as a tag. File paths, exception messages and stack frames are scrubbed of your home directory before anything is sent. When you are offline — which, in a venue, is often — pending reports are cached in a folder under your home directory until the app can send them.
Product analytics — what it actually sends
If you switch product analytics on, the app reports two funnel milestones: that an update finished installing (with the version it came from, the version it went to, whether it succeeded, any error code and how long it took), and that you fired your first cue. Both carry a hashed device identifier, your subscription reference and the watermark prefix. Neither carries cue names, show content or audio.
Turning it off later
Switching either of them off stops the sending immediately. Product analytics is read from your settings at the moment an event would be sent, so there is nothing left in flight; crash reporting no longer waits for a restart either — withdrawing it drops the user context, discards the trail collected so far, and closes every path that would send, including the one that forwards logged errors on their own. The asymmetry runs the other way. Switching crash reporting back on may not take effect until the next launch, because the reporter is built once at startup and a session that began without your consent has nothing to re-arm. Neither switch retroactively deletes what was already sent — for that, ask us under Section 15 and we will delete it.
09Anti-Piracy, Licence Enforcement & Security Logging
CueSync is a paid product with a per-device licence, and a meaningful part of the system exists to keep it that way. We rely on legitimate interests for this, and the interest is specific: protecting a small paid product against unlicensed copying and key sharing, and protecting customer accounts against takeover.
The install watermark
Each installation of the desktop app mints a persistent identifier — a watermark — that stays with that install. A short prefix of it is attached to crash reports as a tag, to update and tamper telemetry as a field, and it names the app's local log and crash-cache folders. Its purpose is to tie a leaked or tampered build back to the install it came from. It is not a hardware identifier and it does not survive a clean removal of the app's data directory. Every place it is stored is enumerated in code specifically so that it can be included in a data request and deleted on request.
Tamper signals
If the app detects that its own binary, its integrity baseline or its licence storage has been modified, it reports a tamper signal: the signal type, when it was first and last seen, a hashed device identifier, your subscription reference and the watermark prefix. It does not report file contents, show data or anything about your machine beyond that.
This path is deliberately not gated by the crash-reporting or analytics switches, because a copy-protection signal that a tamperer can switch off is not a copy-protection signal. It is processed on legitimate interests, it is stored separately from analytics, and you can object to it under Section 15.
Anomaly detection
On activation and validation we score a small set of sharing signals: repeated device takeovers, activation churn beyond the 2 registrations a solo plan allows, widely dispersed IP addresses, live output claimed from two machines at once from distant locations, and clocks wound backwards. Each signal is stored with a score and the evidence behind it.
These signals are observed, not acted on automatically. They never block an activation. They are surfaced in an internal review queue and nothing in production converts a score into a suspension or a revocation on its own — a person reviews any enforcement decision before it takes effect. Where a signal is strong enough to be worth asking about, the most that happens automatically is a single "was this you?" email with a link you can use to confirm it was.
Rate limits, lockouts and audit logs
Some protections are ordinary rules and do apply immediately and automatically: a limit of 5 activation attempts per hour per IP address, a lockout after 20 failed attempts against the same key prefix within 24 hours, per-endpoint rate limits, and the device-registration cap and live-output lease themselves. These are mechanical, they apply the same way to everyone, and if one has caught you unfairly, write to us and we will lift it.
Every security-relevant event is written to an audit log that records the action, your user ID, a hashed device identifier, the IP address and the event details. The log is append-only and chained so that a modified or deleted entry is detectable.
What enforcement can lead to
In order of severity: a confirmation email; a licence key re-issued so the old one stops working; deactivation of a device; suspension or revocation of a licence for sustained, corroborated sharing. You can contest any of these by writing to privacy@cuesync.live or contact@cuesync.live, and we will explain what we saw and review it.
10Automated Decision-Making
We do not make decisions that produce legal effects for you, or similarly significantly affect you, solely by automated means within the meaning of Art. 22 GDPR. The anomaly pipeline described in Section 09 scores signals automatically, but the score is an input to a human review, not a verdict: a suspension or revocation is taken by a person.
The mechanical limits — rate limits, prefix lockouts, the device cap and live-output lease, and revocation that follows automatically when a subscription lapses or a payment is charged back — are automated and immediate. They are rule-based rather than profiling, and they are reversible. In every case you can ask for human review, put your point of view, and contest the outcome by writing to privacy@cuesync.live.
We do not use your data for credit scoring, and we do not sell or share anti-piracy signals with anyone.
11CueSync Studio
CueSync Studio is the hosted half of the product, and using it changes where your show lives. Projects, cues, sections, snapshots, comments and project activity are stored in our PostgreSQL database. Uploaded audio, waveform data, spec documents and images are stored as objects in Cloudflare R2. This is the deliberate exception to "your show stays on your machine": if you put a show in Studio, we hold it.
Collaborators are invited by email address. An invitation stores that address, the role and disciplines you assigned, and who sent it, until it is accepted or expires. Once accepted, we hold that person's account, their membership of your project, what they changed and when, any comments they wrote, and a short-lived presence record while they have the project open.
If you are using Studio to run a production, then for your crew's data you are the controller and we are your processor: we act on your instructions, and you are responsible for having a basis to invite them. Our Art. 28 terms — including sub-processors, security measures, breach notification and deletion on exit — are in the Data Processing Agreement, which you can sign there. The service terms specific to Studio are in the Studio Terms.
12Third Parties That Process Your Data
Every third party below receives personal data from us or from your browser. The full list, with the location each one processes in and the transfer mechanism that applies, is at /legal/subprocessors.
| Service | Purpose | Data Shared |
|---|---|---|
| Paddle | Merchant of record: payment processing, invoicing, sales tax | Email, payment details, billing country |
| Hetzner | Server hosting for the API, the PostgreSQL database and the short-lived key-value tables, plus the off-site encrypted backups | Everything in Section 03 that we store, plus IP and request logs |
| Vercel | Hosting and edge delivery for the marketing site and account pages | IP address, user agent, request paths and edge request logs |
| Cloudflare | Bot protection (Turnstile) and object storage for Studio content (R2) | IP, browser signals used by Turnstile; all Studio uploads — audio, waveform data, spec documents, images — with their filenames and checksums |
| Sentry | Crash and error reporting and error-triggered session replay, from both the website and the desktop app | From the website: your IP address, the error and its context, a replay of the session it happened in with inputs masked, and — when you are signed in — your email address. From the desktop app (only if you switch crash reporting on): a salted hash of your email, the device identifier, the install watermark, and the breadcrumb trail listed in Section 08 including cue numbers and cue names |
| PostHog | Product analytics and session replay (consent-based) | Page views, interactions, web vitals, session recordings with inputs masked; when signed in, your email address as identifier plus edition, tier, billing cycle and subscription status |
| Google Analytics 4 & Google Ads | Analytics, advertising, conversion measurement, remarketing (consent-based) | Page views, click IDs (gclid, gbraid, wbraid), hashed email on purchase (Enhanced Conversions), purchase value and country |
| Meta Platforms (Facebook, Instagram) | Advertising, conversion measurement, remarketing (consent-based) | Page views, click IDs (fbclid), hashed email and hashed country on purchase (Conversions API) |
| Insight Tag (client-side) + Conversions API (server-side, on purchase) for advertising, conversion measurement, and Matched Audiences retargeting (consent-based) | Page views, interactions, hashed email on purchase (Conversions API) | |
| Microsoft (Bing UET) | Advertising and conversion measurement for Microsoft Ads (consent-based) | Page views, interactions, conversion events |
| X (Twitter) | Website tag (client-side) + Conversions API (server-side, on purchase) for advertising and conversion measurement (consent-based) | Page views, hashed email on purchase, purchase value and currency |
| Google and Apple | Sign-in identity providers, only if you choose to use them | They tell us your provider account ID and email address; we tell them nothing about your use of CueSync |
| Resend | Transactional and newsletter email delivery | Email address, message content, delivery and bounce events |
| ClientFlow | Support chat, contact/support ticket handling, and customer-relationship records. ClientFlow uses its own third-party AI providers to generate chat replies — see ClientFlow's sub-processor list | Name, email address, message and chat content, IP address, the campaign details of your visit (UTM tags, Google click ID, the page you landed on, and the site that referred you), and — when you buy — your edition, billing cycle and Paddle subscription reference. No payment-card details ever reach ClientFlow |
13Where Your Data Is Held & International Transfers
The API, the PostgreSQL database that holds your account, licence, billing and audit data, and the short-lived key-value tables used for sessions and rate limiting all run on a single virtual server rented from Hetzner. (There is no separate cache service: what used to be a Redis instance is now expiring rows in that same database.) Encrypted backups are written off-site to a Hetzner Storage Box. Hetzner operates data centres in Germany, Finland and the United States; the location of the specific server that runs CueSync is recorded in the sub-processor list, which currently records it as to be confirmed rather than guessing at it. We deliberately do not restate a region here that we cannot evidence, and we are not going to paper over the gap by implying the record is more complete than it is: the honest position today is that the specific data centre has not been verified, and the sub-processor list is where it will appear when it has.
The marketing site and account pages are served by Vercel, whose functions our deployment configuration pins to Vercel's Frankfurt (fra1) region. Studio uploads are stored in Cloudflare R2. The remaining processors in Section 12 operate their own infrastructure in their own locations.
Where a processor is established outside the EEA or the UK, one of three mechanisms applies to the transfer, and which one it is depends on the processor:
- An adequacy decision — for transfers to a country the European Commission (or the UK government) has found to provide an equivalent level of protection.
- EU–US Data Privacy Framework certification — for US processors that are certified under the Framework and, where relevant, its UK extension.
- Standard contractual clauses — the European Commission's clauses (with the UK addendum where the UK regime applies), together with a transfer risk assessment and the supplementary measures set out in that processor's data processing agreement.
The sub-processor list is where the applicable mechanism is recorded per processor. It currently marks them as to be confirmed: the mechanisms above are the ones available to us, but we have not yet verified and dated which one governs each individual processor, and we would rather say that than assert a legal basis we have not checked. You can ask us for a copy of the clauses we rely on for any of them at privacy@cuesync.live.
14How Long We Keep It
These are the periods our scheduled cleanup jobs enforce, not aspirations — and where one is applied by hand rather than by a job, this page says so rather than letting the difference pass. The full schedule, table by table, is at /legal/retention.
| Data | Kept for | Why |
|---|---|---|
| Account, licence and subscription records | While a subscription is live, plus 90 days after the last paid period ends — or until you ask us to delete, whichever comes first | You keep your licence history and can come back within the window. After it, a dormant account with no live entitlement and no sign of use is anonymised. How that window is applied today is set out below and in the retention schedule. |
| Financial transaction records | The statutory accounting and tax retention period | A legal obligation, not a choice. These survive an erasure request until the period expires; Paddle keeps its own records as merchant of record. |
| Audit log | 90 days live, then archived; the archive is deleted at 12 months | Security forensics and chargeback evidence. |
| Update-install events and first-cue events | 365 days | A full seasonal cycle of release and activation data. |
| Studio project activity | 365 days | Change history for a production. |
| Tamper signals and anomaly signals | 730 days | Abuse and chargeback disputes reach back further than analytics. |
| Webhook event log and settled email-delivery records | 90 days | Enough to investigate a billing or delivery problem after the fact. |
| Hashed sign-in IP addresses | 180 days from last use | Recognising a new-device sign-in. |
| Ended desktop sessions, revoked sessions and revoked tokens | 30 days | Longer than any token that could still be presented. |
| Studio presence (who has a project open) | 7 days | Ephemeral by design. |
| Verification, password-reset and magic-link tokens | Until they expire, or 7 days after use | One-shot credentials. |
| Rate-limit and lockout counters | 1 hour to 24 hours | They expire on their own. |
| Studio content (projects, cues, uploads) | Until you delete it or close the account | It is your work; we do not garbage-collect it behind you. |
| Support chat and CRM records (held by ClientFlow) | Until deleted on request — no automatic expiry | The copy of a chat in your own browser clears after 24 hours, or immediately via “Clear conversation”. |
| Analytics events and session recordings (held by PostHog) | PostHog's retention for our plan; recordings expire sooner than events | We do not set this individually. The current periods are recorded in the retention schedule. |
| Crash reports, error events and error replays (held by Sentry) | Sentry's retention for our plan | Same — recorded in the retention schedule rather than guessed at here. |
| Newsletter subscription | Until you unsubscribe or ask us to delete it | Unsubscribing is one click in every message. |
Deleting your account is a soft delete: the personal fields on your user record are anonymised, every device is deactivated, every licence key is revoked, every Paddle subscription in your billing footprint is cancelled and all sessions are destroyed. Rows we are obliged to keep — the transaction ledger above all — remain, without your identity attached where that is possible.
The same erasure is what the 90-day window triggers, and a job on our server runs nightly to find the accounts it applies to. That job is deliberately cautious and refuses on anything ambiguous: it will not touch an account with a live subscription, a subscription still inside its paid period, an unrevoked Studio or AI add-on grant, an active licence key, or any sign of use inside the window — a device seen, a session heartbeat, a login, a download, a support action. An account that never subscribed at all is not in scope of the 90 days, because there is no cancellation for them to run from.
One such account is covered by a shorter window of its own: a signup whose email address was never confirmed. We have to record the address before you confirm it — the confirmation link has to be sent somewhere — so a typo or an abandoned signup would otherwise leave that address on file indefinitely. Where the address was never confirmed and there is no subscription, licence or add-on of any kind, the account is deleted after 30 days. Confirming the address, signing in, or asking for a new confirmation email resets that clock. Accounts created by signing in with Google or Apple are outside this entirely — the provider confirms the address. The same report-not-erase caveat below applies to this window too.
One thing about that job we would rather state than let you infer. It is installed and running, but enforcement has not been switched on in production yet: today it reports the accounts that are past the window instead of erasing them, and the erasure is applied by hand. So do not read the row above as a promise that your dormant account has already been erased on schedule — ask us and we will erase it immediately, which we will do at any point in the window as well. When enforcement is switched on, the nightly run does it without anyone asking, and this paragraph will say so.
15Your Rights, and How to Use Them
If you are in the European Economic Area, the United Kingdom or Switzerland you have the following rights. We will respond within one month of receiving a request, as Art. 12(3) requires, and will tell you if we need to extend that because the request is complex.
- Right of access: a copy of the personal data we hold about you
- Right to rectification: correction of inaccurate or incomplete data
- Right to erasure: deletion of your personal data, subject to what we are legally obliged to keep
- Right to restriction: a pause on processing while a dispute is resolved
- Right to data portability: your data in a structured, machine-readable format
- Right to object: to processing based on legitimate interests, including the anti-piracy processing in Section 09, and at any time to direct marketing
- Right to withdraw consent: at any time, where processing is based on consent — withdrawing does not affect processing that already happened
- Right to lodge a complaint: with your local supervisory authority, at any time, whether or not you have raised it with us first
What you can do yourself, right now
Several of these do not need a request at all:
- Devices: see every activated device and deactivate any of them, from the Devices section of your account dashboard.
- Sessions: see every active session and sign out everywhere else, under Security in the same dashboard. Changing your password revokes them too.
- Password and two-factor authentication: set, change or enrol under Security.
- Cookies, analytics and advertising: change or withdraw consent at any time in cookie preferences.
- Marketing email: every message carries a one-click unsubscribe link, which needs no sign-in. If you no longer have one to hand, email us and we will remove you. Transactional email about your licence and your account is not affected by unsubscribing.
- Desktop crash reporting and product analytics: two independent switches in Settings > Advanced, as described in Section 08.
Access, portability and erasure
Ask at privacy@cuesync.live from the address on your account. For access and portability we produce a single machine-readable file containing your account record, linked sign-in providers, subscriptions, payment history, Studio and add-on entitlements, licence keys (prefix and state — we do not put a working key in an export), devices, the last 90 days of your audit log, your desktop sessions, update-install and first-cue events, and any tamper signals recorded against your installs. For erasure we run the account deletion described in Section 14.
An erasure does not stop at our own database. Four processors hold something keyed to your email address, and they are not all reachable the same way, so here is which is which. Resend, which sends our email, is automatic: your contact is removed from the sending list as part of the deletion. PostHog publishes a person-deletion API that also removes the events attached to that person, and our code calls it wherever the credentials for it are configured; where they are not, the erasure is recorded as outstanding rather than assumed done, and it is made by hand. Sentry and ClientFlow publish no per-person deletion endpoint at all, so for those two it is a request a person files with the provider. We would rather tell you that than describe a call that is not being made.
Whichever route applies, the outcome for each processor is written to the audit log — deleted, nothing to delete, no automated route, or failed — so if you ask us to prove the deletion happened we can show you processor by processor rather than assert it. A processor that is unreachable at that moment does not block your deletion — a vendor outage must not leave you with an account you believe is gone — but the failure is recorded rather than swallowed, so it can be chased. If you want the manual steps confirmed in writing once they are done, say so in your request and we will come back to you.
We will ask you to confirm the request from the account address, and may ask for more if we have real doubt about who is asking. That check exists to stop someone else obtaining your data, and it is not a delaying tactic.
If two-factor authentication is blocking you
Account deletion requires a second factor when two-factor authentication is enforced on your account. If you have lost your authenticator and your recovery codes, that gate will refuse — by design, because it is the same gate that stops someone else deleting your account. In that case email privacy@cuesync.live from the address on the account. We will verify you another way and complete the deletion manually, within the same one month.
16California Privacy Rights
If you are a California resident, the CCPA as amended by the CPRA gives you the rights to know what we collect and why, to obtain a copy, to correct it, to delete it, to opt out of the sale or sharing of your personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. Exercising them costs you nothing and changes nothing about your price or your licence.
We do not sell your personal information for money. We do share it for cross-context behavioural advertising, which the CPRA treats as a "share" and which the CCPA's broad definition of "sale" may also cover. That happens in two ways: advertising tags in your browser (Google, Meta, LinkedIn, Microsoft Bing, X), and server-side conversion APIs that report completed purchases to the same platforms.
The categories involved are:
- Identifiers: cookie and advertising identifiers, click IDs, IP address, and a SHA-256 hash of your email address on purchase
- Commercial information: that a purchase happened, the edition and billing cycle, the value, the currency and the country
- Internet activity: pages viewed and interactions on this site
We do not share the contents of your shows, your cue data, your Studio uploads, your licence key or your audit history with any advertising platform, and we do not knowingly share the personal information of anyone under 16.
To opt out, use Do Not Sell or Share My Personal Information or turn off advertising in cookie preferences. Both take effect immediately and apply to the client-side tags and the server-side conversion fires alike. You can also send a request to privacy@cuesync.live, including through an authorised agent.
We honour Global Privacy Control. A browser or extension asserting the GPC signal is treated as an opt-out of sale and sharing without your having to click anything, and it stays in force unless you overrule it yourself. Section 17 explains exactly how that works.
We do not collect personal information for the purpose of inferring characteristics about you, and we do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit.
17Do Not Track & Global Privacy Control
We honour both the Do Not Track signal and Global Privacy Control. Either one is treated as a standing refusal of analytics and of advertising: PostHog is never initialised, no analytics session recording is made, no analytics or advertising storage is set, and nothing is shared with an advertising platform. Essential functionality — signing in, licence validation, bot protection — continues to work.
That applies to what our servers do as well as to what your browser does. The signal travels as a request header, our back end reads it before it reads any stored choice, and an asserted signal denies. This matters because the server-side fires described in Section 07 happen where there is no browser to ask — including the purchase report, whose answer is captured at the moment the checkout opens and carried with the transaction.
Analytics and advertising are opt-in here in any case. Nothing non-essential loads and nothing is shared until you accept it, and every non-essential category starts denied. A browser that never accepts is never shared with, whatever signals it sends.
A signal only stops being a refusal if you overrule it yourself in the preference centre, and that override is recorded per signal. If you overruled Do Not Track at some point and later switch on Global Privacy Control, the new signal is a new instruction and we treat it as one rather than assuming the old override still speaks for you. If we cannot read what you decided — private browsing, cleared storage — the refusal stands.
Global Privacy Control is the opt-out preference signal named in the California regulations, so for California residents sending it is also a valid opt-out of sharing under Section 16. You can make the same request explicitly on the Do Not Sell or Share page.
18Children's Privacy
Our Service is not directed to individuals under the age of 16, and our Terms of Service require you to be at least 16 to use it. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16 without parental consent, we will delete it promptly. If you believe that has happened, tell us at privacy@cuesync.live.
19Data Security
The measures below are the ones actually implemented, not a wish list:
- Envelope encryption at rest for licence keys — AES-256-GCM under a per-row key, itself wrapped by a master key that lives only in the server environment and never in the database. The same mechanism is built for email addresses but is not yet switched on; see “Account and authentication data” above.
- AES-256-GCM encryption for two-factor secrets, and bcrypt hashing for two-factor recovery codes, which are one-time-use
- bcrypt password hashing, with password history to block reuse on reset
- Keyed hashes for lookups that must not require decryption — licence key verification, device and IP identifiers
- Ed25519 signatures on licence tokens and update manifests
- Append-only, hash-chained audit logging, so a deleted or edited entry is detectable
- Rate limiting on every endpoint, brute-force prefix lockout, and CSRF protection with step-up re-authentication on sensitive actions
- Optional two-factor authentication (TOTP), which you can enrol in from the Security section of your account
- HTTPS everywhere, httpOnly secure session cookies, and certificate pinning on the desktop app's connection to our API
No system is perfect. If you find a vulnerability, report it to security@cuesync.live and we will not pursue you for having looked.
20If Something Goes Wrong
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as Art. 33 requires.
If the breach is likely to result in a high risk to you, we will tell you directly and without undue delay, at the email address on your account. We will say what happened, what data was involved, what we are doing about it and what you should do. We will not wait until we have a complete picture to warn you about something you can act on now.
If you are a Studio customer and the breach affects data we process on your behalf, we will notify you without undue delay so that you can meet your own obligations, on the terms in the Data Processing Agreement.
21Changes to This Policy
We update this policy when the system it describes changes. Every version carries the date it took effect at the top of this page.
For a material change — a new purpose, a new category of data, a new processor that receives your personal data, a change of lawful basis, or a materially longer retention period — we will email account holders at the address on their account before or when the change takes effect. We will not rely on a changed date at the top of a page as notice.
Where a change requires your consent, we will ask for it rather than assume it, and the previous behaviour continues until you answer. If you object to a change that we rely on legitimate interests for, tell us and we will handle it as an objection under Section 15.
22Contact Us
Questions, rights requests and complaints about this policy or our data practices:
- Privacy and rights requests: privacy@cuesync.live
- Security reports: security@cuesync.live
- Everything else: contact@cuesync.live
- Contact form: https://www.cuesync.live/contact
- Postal address: to be confirmed — write to contact@cuesync.live, to be confirmed — write to contact@cuesync.live
You always have the right to complain to your local data protection supervisory authority, and you do not have to come to us first. We would prefer that you did, because we can usually fix it faster.