CUE Privacy Policy
Effective date: October 4, 2026
This policy explains what data the CUE app, cuealerts.com, and our online services handle. CUE is run by Square One Media LLC ("we"). Contact us at [email protected].
Short version: most of CUE runs on your own PC and keeps its data there. A few things go online so CUE can work: your overlay alerts (through our relay), your LIVE events (from ONEhub), problem reports (scrubbed, and you can turn them off), and your CUE account and payment status (Supabase and Stripe). We do not sell your data and we do not run ads.
1. Data that stays on your PC
CUE stores these in its data folder on your computer. We do not receive them.
- Settings, screens, packages, automations, and widgets you set up.
- LIVE recaps: for each LIVE or Practice session, counts (gifts, likes, comments, viewers) and up to the last 5,000 events, including viewer names and usernames. Kept until you delete them.
- Viewer points and levels: viewer usernames, display names, and point totals for the Points feature.
- Sounds and images you add (My sounds, including ones you download from Myinstants), stored in the app's local browser storage (IndexedDB).
- Text-to-speech: voices are generated on your PC. The text (including viewer chat for chat TTS) is not sent to any voice service.
- Spotify: the Client ID you enter and the sign-in tokens Spotify gives CUE. CUE talks directly to Spotify from your PC.
- OBS Studio and Streamer.bot: addresses and passwords you enter. They are only used to connect on your PC or home network and never shown back in the window.
- ONEhub sign-in: a device token, encrypted with Windows' protection for your user account.
- Error log: a local log of problems (
logs/cue-errors.log). - Computer stats: CUE reads CPU, memory, and GPU use to show them to you. They are not sent anywhere.
2. Data that goes online, and why
LIVE events (ONEhub)
- CUE gets your LIVE events (gifts, likes, follows, shares, joins, chat, viewer counts, viewer usernames, display names, and profile pictures) from ONEhub, a Square One service that connects to TikTok LIVE through a third-party provider (Euler Stream).
- Chat text is delivered only to your own CUE and is not stored by ONEhub. The CUE + Tracking plan, which would store LIVE history, is not available yet; we will update this policy before it is.
- To connect, you sign in to ONEhub, which knows your TikTok @handle.
Overlay relay
- To show alerts in TikTok LIVE Studio, CUE sends overlay data to our relay server (hosted on Railway in the US). This includes alert text (often a viewer's name and message), widget content (timer, roulette, chat messages for the chat widget), Spotify now playing (song, artist, album cover), screen positions, and images or videos you choose for alerts.
- Alerts and widgets are passed straight through and kept only in the server's memory (the latest state of each widget and screen). They are lost when the server restarts.
- Images and videos you upload for alerts are stored on the relay (up to 250 MB per channel) until you delete them or ask us to delete your data.
- Your overlay link is private. Anyone who has it can see your overlays, so do not share it.
- The relay sees your IP address when CUE connects. It is used briefly to limit abuse and is not stored in our records. Our hosting providers keep their own short-term server logs, which may include IP addresses.
Problem reports
- When CUE hits an error, it sends a report to our relay so we can fix bugs. This is on by default and you can turn it off in CUE (Settings → Problem reports).
- A report includes: an error message and technical details, CUE version, Windows version, a random install ID, your overlay channel ID, and sometimes your TikTok @handle.
- Before sending, CUE removes tokens, private links, email addresses, long secret-looking codes, and your Windows user name. We check again on the server.
- Reports are kept on the relay (about the newest 2,000, capped at about 10 MB) and only the owner can view them.
Updates
- CUE checks GitHub (github.com) for new versions and downloads them automatically. GitHub sees your IP address. See GitHub's privacy statement.
Myinstants
- If you open Myinstants in CUE, you are visiting their website. They may use cookies and see your IP address under their own policy. CUE only saves the sounds you choose to download.
Spotify, OBS, Streamer.bot, and webhooks
- Spotify: CUE reads and controls your playback with Spotify using your own Spotify developer app. Spotify's privacy policy applies.
- OBS and Streamer.bot: connections stay on your PC or home network.
- Webhooks you set up send the event data you choose (up to 20 fields, for example a viewer name or gift) to the web address you enter. You choose that site; its policy applies. Webhooks only run during real LIVEs.
3. Accounts, payments and the website
- Your CUE account: your email, your password (stored only as a secure hash by our sign-in provider, Supabase) or your Google sign-in, your plan and its status, and the PCs you linked to CUE (a name for each PC and when it last checked your plan).
- Payments: handled by Stripe. Stripe collects your card and billing details. We receive your plan, payment status, country or postal code for tax, and the last 4 digits and expiry of your card. We never see your full card number.
- Square pricing: if you link ONEhub, ONEhub tells us only whether you are an active Square. We keep your ONEhub email to show the link, never your ONEhub password.
- Affiliates: if you sign up through a Square's link, our affiliate provider (Rewardful, once the affiliate program opens) records that referral with a cookie and links it to your payments so the Square can be paid a commission. The Square sees your sign-up date and payment amounts, not your name or email.
- Website: cuealerts.com uses Cloudflare Web Analytics to count visits. It does not use cookies or track you across sites. The account page keeps you signed in using your browser's storage. If you click an Amazon link on our gear page, Amazon may set its own cookies, and we may earn a commission.
- Waitlist and applications: if you leave your email for a plan that is not open yet, or apply to join Square One, we store what you send (for an application: name, TikTok username, email, optional phone and country, and your answers) and use it only to contact you about that. Only the owner of Square One can read applications.
- Emails: account emails (like password resets) are sent through Resend. Mail to [email protected] is forwarded by Cloudflare.
4. Viewers' data
CUE handles data about your TikTok viewers (usernames, display names, profile pictures, chat, gifts) to show alerts and run your stream. You are responsible for using it fairly on your stream. Most of it stays on your PC (see section 1). Viewers who want something removed from a recap or the points list can ask you, and you can delete it in CUE.
5. Who we share data with
Only service providers who help run CUE: Railway and Cloudflare (hosting, website and email forwarding), Supabase (accounts and data), Stripe (payments), Resend (account emails), GitHub (updates), Euler Stream (LIVE connection, through ONEhub), and Rewardful (affiliates, once that program opens). We may also share data if the law requires it or to protect users and our services. We do not sell or rent personal data and do not share it for advertising.
6. How long we keep data
- Data on your PC: until you delete it or uninstall CUE (uninstalling may leave the data folder; delete it to remove everything).
- Problem reports: until replaced by newer ones (about the newest 2,000).
- Uploaded alert media: until you delete it or ask us to delete your data.
- Account and billing records: while your account is open, and then as long as tax and accounting laws require (usually 7 years).
7. Your choices and rights
- Turn off problem reports in CUE at any time.
- Delete recaps, points, sounds, and settings in CUE.
- Ask us to access, correct, export, or delete your data: [email protected]. We reply within 30 days.
- Depending on where you live (for example California, the EU or the UK), you may have more rights. Contact us and we will help.
8. Children
CUE is not for children under 13, and paid plans are for people 18 or older. We do not knowingly collect data from children. If you think a child gave us data, contact us.
9. Security
We use HTTPS, private tokens, encrypted sign-in storage, scrubbing of problem reports, and access limits on our servers. No system is perfectly secure.
10. Changes
We will post changes here and update the effective date. For important changes we will tell you in CUE or by email.
11. Contact
Square One Media LLC. Email: [email protected].