Privacy
What Cuelaris processes, what it keeps, and what it does not. This describes the system as built. It is a technical description, not a substitute for a lawyer-reviewed policy.Legal review required
The short version
- · Audio is transcribed in flight. We do not store recordings.
- · Transcripts stay in memory for the session and are discarded when it ends.
- · We keep usage metadata — minutes, tokens, cost — not what was said.
- · You can export everything we hold, or delete your account and its history.
Audio
While a session is running, Cuelaris captures your system audio (what your computer is playing) and, if you enable it, your microphone. Both are streamed to a speech-to-text provider to be turned into text.
We do not store audio. It is not written to disk or to our database at any point. It exists in memory only long enough to be sent for transcription.
Windows displays its standard microphone and audio-capture indicators the entire time a session is running. Cuelaris does not suppress them.
Transcripts
Transcribed text is held in the server’s memory for the duration of your session, because the assistant needs to know what has already been said to be useful. When the session ends, it is discarded.
Transcripts are not written to our database by default. If you explicitly choose to retain a session, that is a deliberate action you take, and you can delete it afterwards.
Context you upload
Documents you attach to a session — a résumé, a job description, product notes — are used to shape answers during that session. They are subject to the same size and count limits as your plan, and are not shared between accounts.
AI providers
Cuelaris sends transcribed text to third-party AI providers to generate answers, and audio to a speech-to-text provider to produce that text. The specific providers depend on configuration; in this beta they are OpenAI and, for transcription, OpenAI or Deepgram.
This means your conversation text leaves our infrastructure to be processed by those providers under their terms.Legal review required — sub-processor disclosure
What we do keep
We keep the metadata needed to run the service and bill you correctly:
- Your account: email address, password hash, workspace, plan and subscription state.
- Session metadata: when a session ran, how long, which purpose, how it ended. Not its content.
- A usage ledger: minutes, token counts, provider, model and estimated cost per session. The question text is hashed, never stored.
- Answer metadata: purpose, answer style, how long the answer took, and your useful / not-useful rating. Never the question or the answer itself.
- Error diagnostics: redacted error messages with an application version and a pseudonymous identifier, so we can fix faults without reading your conversations.
Analytics
We measure the product funnel — signups, activation, first answer, upgrades — and page views on this website. These records contain no conversation content, and identifiers are pseudonymous: a one-way hash, not your email address.
Security
Traffic between the app and our backend is encrypted in transit with TLS. Passwords are stored as scrypt hashes, never in plain text. Each account’s data is scoped to its own workspace, and requests are authorised against that scope.
We do not claim to be “100% secure”, and we hold no compliance certifications (no SOC 2, no ISO 27001, no HIPAA). If you need those, Cuelaris is not ready for you yet.
Screen-share privacy
Cuelaris has a setting that asks Windows to exclude its window from screen captures that honour that flag, which stops you accidentally sharing the panel while presenting.
This does not make Cuelaris undetectable. The application is visible in Task Manager, the operating system shows its audio indicators, some capture methods ignore the flag entirely, and anyone who can see your screen directly can see the window. We will not describe it as invisible, hidden or undetectable, because it is none of those things.
Your control
From your account page you can export everything we hold about you as a JSON file, or delete your account. Deletion removes your user record, workspaces, sessions and stored history. Anonymised billing records with no personal data may be retained for accounting.Legal review required — retention period
Your responsibilities
Recording and consent laws differ by jurisdiction, and your employer or the meeting platform may impose rules of their own. Deciding whether you may use Cuelaris in a given conversation — and telling the other party if that is required — is your responsibility, not ours.
Contact
Questions about any of this go to support.
This page describes the behaviour of the beta as built. Items marked Legal review required need a qualified review before this becomes a binding policy.