Cuepoint

Cuepoint — Privacy Policy

Last updated: September 9, 2026.

1. Data Controller

FLASHLABS, os. Młodości 8/20, 31-908 Kraków, Poland, NIP: PL6782679841.
Contact: hello@cuepoint.fm

2. Data We Collect

DataPurposeLegal Basis (GDPR)
Email addressAccount creation, login, notifications, password resetContract (Art. 6(1)(b))
UsernameDisplay name in comments and projectsContract (Art. 6(1)(b))
Password (hashed)AuthenticationContract (Art. 6(1)(b))
Project dataProject creation, ownership, membership, collaboration, and pending invitesContract (Art. 6(1)(b))
Audio files, stems, revisions, voice notes, and waveform dataCore service functionalityContract (Art. 6(1)(b))
Track Analysis metrics, AI Revision Guidance inputs, outputs, and run metadataGenerating technical audio measurements and optional AI-assisted revision guidance from track metrics, project context, comments, optional user instructions, and previous revision context. Raw audio files are analyzed on Cuepoint servers and are not sent to the AI model.Contract (Art. 6(1)(b))
Comments, mentions, comment resolution state, and review decisionsCore service functionality, collaboration notifications, and approval workflowContract (Art. 6(1)(b))
Guest display names and public share comments/repliesAllowing invited recipients of public preview links to leave timestamped feedback without a Cuepoint account, showing that feedback to other recipients of the same active link and to project members, and notifying project members who enabled comment notificationsLegitimate interest in providing the public review workflow requested by the project owner (Art. 6(1)(f))
Client preview link metadataCreating, securing, expiring, revoking, and auditing public preview links, including whether a password is required and when the link was last accessedContract (Art. 6(1)(b))
Notification preferencesLetting you control optional email notificationsContract (Art. 6(1)(b))
Authentication, password reset, and email verification tokensLogin sessions, account security, password reset, and email verificationContract (Art. 6(1)(b))
Billing metadata (via Stripe)Subscription billing, plan provisioning, checkout, and billing portal accessContract (Art. 6(1)(b))
Optional page feedback, the related in-app page path, account email, username, and internal user identifierCollecting, attributing, and triaging product feedback submitted from the authenticated applicationLegitimate interest in improving the Service (Art. 6(1)(f))
IP address, user agent, and request logsServer logs, security, rate limiting, abuse prevention, and troubleshootingLegitimate interest (Art. 6(1)(f))
Sanitized browser error diagnostics, browser and device information, runtime capability status, and technical network metadataDetecting and diagnosing production application failures. Reports may include a stable error type, a normalized safe form of recognized browser error messages, sanitized application and React stack locations, normalized page and API route patterns, API method/status/content-type/timing categories, release, environment, browser user agent and derived browser/operating-system/device details, coarse viewport and connectivity state, browser-storage capability status, a random identifier limited to one page load, trace identifiers, and technical metadata inherent in secure network delivery. They exclude account identity, cookies, authentication headers, query strings, request or response bodies, form or content values, user-supplied filenames, and raw project, track, or public-share identifiers.Legitimate interest in maintaining the reliability and security of the Service (Art. 6(1)(f))
Privacy-minimized website analytics and conversion dataMeasuring aggregate visits, traffic sources, approved campaign labels, successful product actions, first paid Pro subscription purchases, and initial collected payment revenue. Cuepoint sends normalized route templates instead of project, track, share, reset, or verification identifiers; fixed event properties; and approved campaign-level UTM values. Plausible receives technical IP address and browser user agent as part of event delivery. For a purchase, Cuepoint temporarily retains those two values and approved campaign labels from checkout for up to 48 hours so the verified Stripe payment can be reported without identifying the account in Plausible.Legitimate interest in understanding and improving the Service and measuring aggregate campaign performance (Art. 6(1)(f))

We collect only the data needed to provide, secure, operate, and understand the aggregate use of the Service. Payment card details are collected and stored exclusively by Stripe — we never see or store your full card number. We use Plausible for cookieless, aggregate website analytics. We do not use Google Analytics, advertising pixels, remarketing tags, or cross-site tracking.

3. Cookies and Local Storage

We use only essential cookies and browser storage required for the Service to function:

NameTypePurposeDuration
tokenSecure httpOnly cookieShort-lived access session15 minutes
refreshTokenSecure httpOnly cookieSession renewal — keeps you logged in7 days
token, username, emailVerified, userPlanLocal browser storageKeeping the app state and authenticated API requests in your browserUntil logout, account deletion, or browser storage clearing
cuepoint.publicCommentAuthorLocal browser storageRemembering the display name a guest used when commenting on a public preview linkUntil browser storage clearing or replacement by the guest

Plausible analytics does not set cookies or use local storage. We do not use analytics, advertising, or third-party cookies and do not store campaign attribution in browser storage.

4. How We Use Your Data

We do not use your Content or personal data to train artificial intelligence or machine learning models.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

5. Third-Party Processors

ServicePurposeData SharedLocation
Google Cloud PlatformApplication hosting, database, file storage, frontend hosting/CDN, logging, and Vertex AI for optional AI Revision GuidanceAll data listed in §2. For Vertex AI, structured AI guidance context and generated output; raw audio files are not sent to the AI model.EU (europe-west1, Belgium) for primary application and data storage; Vertex AI processing may use Google Cloud locations configured for the AI service
ResendTransactional email deliveryEmail address, email contentUS
StripePayment processing, subscription management, checkout, and billing portalEmail address, subscription status, Stripe customer/subscription identifiers, payment metadataUS/EU
CannyPrivate product-feedback collection and triageSubmitted feedback, related in-app page path, email address, username, and internal user identifierUS
SentryProduction browser error monitoring and source-map-assisted diagnosisSanitized error type and recognized native-browser message form; application and React stack locations; normalized page and API route patterns; API method, status, content type, and duration; release and environment; browser user agent and derived browser, operating-system, and device details; coarse viewport, connectivity, and browser capability status; a random per-page diagnostic identifier; trace identifiers; and technical network metadata inherent in HTTPS delivery. Cuepoint does not send request or response bodies, account identity, cookies, authentication headers, query strings, form or content values, user-supplied filenames, or raw project, track, or public-share identifiers.EU data region
PlausibleCookieless aggregate website, campaign, conversion, and initial-payment revenue analyticsNormalized page locations and internal referrers, external referrer origins, approved campaign-level UTM values, fixed successful-action event properties, initial paid amount and invoice currency, browser user agent, and technical IP address used by Plausible to calculate privacy-preserving aggregate statistics. Cuepoint does not send account identity, customer/subscription/invoice/checkout identifiers, content, filenames, comments, raw dynamic route identifiers, arbitrary query strings, click IDs, cookies, or persistent user identifiers.EU

Resend processes data under Standard Contractual Clauses (SCCs) for EU-US data transfers.

Stripe processes data under their Privacy Policy and EU data transfer mechanisms, including the Data Privacy Framework and SCCs where applicable.

Canny stores its service data in the United States and processes it under its Privacy Policy and applicable transfer safeguards.

Sentry processes sanitized browser error reports and the limited diagnostic context described above in its EU data region under its Privacy Policy and applicable contractual safeguards. Cuepoint does not enable Sentry analytics, tracing, Session Replay, logs, user feedback, or advertising features.

Plausible processes cookieless aggregate analytics under its Privacy Policy and Data Policy. Cuepoint does not enable session replay, advertising profiles, persistent visitor identifiers, or per-user analytics.

6. Data Retention

7. Your Rights (GDPR)

Where GDPR applies, you have the right to:

To exercise any of these rights, contact us at hello@cuepoint.fm. Guests who leave feedback through a public preview link do not have a Cuepoint profile, so they should use this email address for access, correction, or deletion requests.

8. Security

9. Children

The Service is not intended for users under 16 years of age. We do not knowingly collect data from children under 16. If you believe a child under 16 has created an account, contact us at hello@cuepoint.fm and we will delete it.

10. Changes

We may update this Privacy Policy from time to time. Unless a later date is stated, an updated version takes effect when published. The effective date of the current version is shown at the top of this page. We will provide any notice required by applicable law.

11. Contact

For privacy-related questions, contact us at hello@cuepoint.fm.