The short version: CamCue transcribes Listen audio on your device and stores session history locally. Recognized speech, text extracted from your screen, and relevant context are sent through our service to AI providers when you use AI features. Account, billing, usage, and technical information help us operate the service.
1. Who this policy covers
This Privacy Policy applies to the CamCue website, checkout experience, desktop application, and support communications. In this policy, “CamCue,” “we,” and “us” refer to lirik, the operator of the CamCue product. For privacy requests, contact support@camcue.app.
2. Information we collect
Account information
When you sign in by email, Google, or Apple, we process your account identifier, email address, profile information you provide, and authentication records. Your account links your plan, allowances, and purchases. Sign-in providers process information under their own privacy policies.
Audio, screen content, and AI context
Listen captures system audio and microphone audio while running, subject to the permissions you grant. It transcribes both locally after downloading a speech model. Microphone speech supplies your side of the conversation as context. Raw Listen audio stays in memory and is not saved or uploaded by CamCue. Recognized text is sent through CamCue’s service to AI providers to detect questions and generate answers. Relevant conversation history and your selected context may be included.
Capture and Select take a screenshot of the whole screen or the area you choose and recognize its text on your device. The current cloud workflow sends that extracted text and its layout information, rather than the screenshot image, for AI analysis. Requests can also include previous answers, your context mode, custom instructions, response-language preference, and selected excerpts and document names from your CV, documents, or job description.
Session notes, transcripts, and completed AI answers are stored locally on your device. The current service processes this content in memory for inference rather than retaining transcript text or answer bodies in its session database. This is not an offline AI service. AI providers may retain request data under their own policies and the configuration of the service account used for processing.
Documents, presets, and practice demos
Documents you add are copied to local app storage. CamCue extracts document text locally and selects excerpts for AI requests; adding a document does not upload the original file to a cloud document library. Presets can reuse context across sessions on the same device. Document extraction may omit formatting, embedded images, or content that cannot be read as text.
Pasting a public job link can automatically contact that website to retrieve the job description. The destination receives an ordinary network request, including your IP address. CamCue does not send your browser cookies or sign-in credentials to import it. You can enter a description manually instead.
The in-app Listen demo sends your selected context to generate practice questions and answers. It uses a fictional example profile when you have not added your own context. Generated practice speech is delivered for playback. The website demos use fixed examples and do not upload a CV or send your interactions to an AI model.
Usage and diagnostics
We process account-linked usage, timing, credit accounting, operation status, and technical records to run the service, apply allowances, diagnose errors, and prevent abuse. Production versions use PostHog for product interaction events and Sentry for crash and error diagnostics. These records can include an account or installation identifier, app and operating-system version, selected feature, event timing, and error category.
Desktop analytics uses a locally stored anonymous identifier before sign-in and an opaque account identifier after sign-in; signing out resets that association. Product analytics is configured to exclude note content, transcripts, screenshots, audio, documents, credentials, and email addresses, and does not use session replay. Crash reports can include technical logs and native memory dumps; memory dumps may contain fragments of data that were in the app’s memory when it crashed.
Operational notifications
A release installation reports its first authenticated connection, including a persistent device identifier, account identifier, app version, and platform. We use private Telegram notifications for these operational events. Where enabled for the relevant billing environment, notifications also cover purchases, renewals, payment problems, cancellations, refunds, and disputes. Billing notifications can include the email address and country supplied by Stripe, plan, amount, currency, and transaction identifiers. They do not include full card details, audio, transcripts, documents, or AI answers.
Purchase information
Purchases are processed by Stripe. Stripe may collect your name, email address, billing information, payment method details, country, tax information, and transaction data. We may receive limited purchase information from Stripe, such as your email address, purchase status, amount, currency, and transaction identifier. We do not receive your full payment card number.
Website and technical information
Our hosting provider may process standard request information needed to deliver and protect the website, including your IP address, browser and device type, requested pages, timestamps, and diagnostic or security logs. We use PostHog to measure website visits, referral sources and campaign tags, download-button clicks, pricing views, and interactions with the demo, FAQ, and links. The website stores a random analytics identifier and the first referral source in your browser’s local storage. We do not identify website visitors by name or email, record website sessions, or collect form contents. Website analytics respects the browser’s Do Not Track setting. Download links and app update checks contact GitHub; speech-model downloads contact Hugging Face, the model host. Those providers receive the network information needed to serve the request, such as your IP address and the requested resource.
Support communications
If you contact us, we receive the information you choose to provide, including your email address, message, and any files or diagnostic details you attach.
3. Why we use information
We use personal information only as needed to:
- authenticate accounts, process subscriptions, and provide Free or PRO access;
- deliver AI answers, maintain, secure, and troubleshoot the website and app;
- understand referral sources, downloads, and how people use CamCue;
- respond to support, refund, and legal requests;
- keep transaction, tax, and accounting records; and
- prevent fraud, abuse, and unauthorized distribution.
Depending on where you live, our legal bases may include performing a contract with you, complying with law, our legitimate interests in operating and securing CamCue, and consent where it is required.
4. When information is shared
We share information only with service providers that help us run CamCue, including Supabase for account and backend services, AI providers for question detection and answer generation, Stripe for payments, PostHog for product analytics, Sentry for diagnostics, Telegram for private operational notifications, GitHub for downloads and updates, speech-model hosting and email providers, and professional advisers when necessary. The AI provider used can vary by feature and service configuration. These providers process information under their own terms or on our instructions. You can read Stripe’s Privacy Policy for details about its practices.
We may also disclose information when required by law, to protect the rights and safety of users or others, or in connection with a merger, financing, acquisition, or sale of the business. We do not sell personal information.
5. Retention
We keep purchase and accounting records for as long as required by applicable tax, accounting, and consumer-protection laws. Support messages are retained only as long as reasonably needed to resolve the request, maintain service history, or meet legal obligations. Local app content remains on your device until it is removed; uninstalling the application may leave its data directory behind. Server-side account, usage, and diagnostic records have separate operational and legal retention needs. Technical session records can include timestamps, character counts, content hashes, model identifiers, and credit usage even though transcript and answer bodies are not retained in the session database. These records are not anonymous. Delivered Telegram notification payloads are removed from our delivery queue after seven days; delivery identifiers remain, failed deliveries may remain for investigation, and messages already delivered to Telegram have a separate lifecycle. Device-installation records can remain with their account link removed after account deletion. Backups and third-party provider records follow their respective retention schedules.
6. International transfers
Our service providers may process information in countries other than your own. Where required, appropriate safeguards are used for international transfers of personal information.
7. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of your personal information, or to receive a portable copy. You may also have the right to withdraw consent and complain to your local data-protection authority.
To make a request, email support@camcue.app. We may need to verify your identity before completing it. You can request account deletion in the app after email verification. The deletion process cancels subscriptions and removes the account; after server completion, the app clears that account’s local sessions, transcripts, and cached answers on the current device. Shared context presets, documents, legacy local content, and copies on other devices are not all removed by this process and may require separate deletion. Self-service account-data export is not currently available; contact us to request a copy of your account information. Records that must be retained for legal obligations may be kept as required.
You can stop Listen, remove local sessions and context, and change CamCue’s microphone, system-audio, and screen-recording permissions in macOS System Settings. Revoking a permission can prevent the corresponding feature from working. Stealth controls visibility in supported screen-sharing tools; it does not prevent the AI processing described above.
8. Children
CamCue is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided personal information to us, please contact us.
9. Security
We use reasonable technical and organizational safeguards to protect information. No system is completely secure, so we cannot guarantee absolute security.
10. Changes to this policy
We may update this policy as CamCue or applicable law changes. The effective date at the top shows when the latest version took effect. Material changes will be communicated where required.
11. Contact
Questions about privacy can be sent to support@camcue.app.