
legal
Privacy notice
Privacy notice
Last updated: July 2026
This notice explains how CueCrux Limited ("CueCrux", "we"), a company registered in England and Wales, handles personal data across the cuecrux.com website, our hosted services (including hosted sync, Governance features, and WikiCrux at wiki.cuecrux.com), and the Crux Daemon software. Contact: privacy@cuecrux.com.
1. Local-first by design
The free Crux Daemon runs on your machine. Content, memory, receipts, and passports created by a local installation are stored locally and are not transmitted to us. The daemon requires no account. If you use only the local daemon, we hold no personal data about your use of it.
Data reaches our systems only where you choose a hosted feature: creating an account, enabling hosted sync, using hosted retrieval lanes or metered services, or querying WikiCrux.
2. What we collect and why
- Account data (email address, hashed credentials, organisation membership): to provide Pro and Governance subscriptions. Lawful basis: contract.
- Synced content (data you explicitly enable hosted sync for): to provide the sync service. Lawful basis: contract. You control scope; local-only data never syncs implicitly.
- Billing metadata (plan, payment status, renewal dates): payments are processed by Paddle as merchant of record; we do not receive your card details. Lawful basis: contract and legal obligation.
- Service logs and metering records (request metadata, credit spends): to operate, secure, and bill the hosted services. Each credit spend also mints a signed receipt visible to you. Lawful basis: contract and legitimate interests (security, abuse prevention).
- Support correspondence: to resolve your requests. Lawful basis: legitimate interests.
- Cookies: essential cookies only, for session continuity and security on the website and hosted apps. No advertising trackers, no third-party analytics profiling.
We do not sell personal data, and we do not use your content to train models.
3. Retention
- Account data: for the life of the account, then deleted or anonymised.
- Synced content: until you delete it or close the account.
- Service logs: up to 12 months.
- Support correspondence: up to 18 months after resolution.
- Backups: 30-90 days on a rolling basis.
- Billing records: as required by tax and accounting law.
4. Receipts and erasure
Receipts are append-only and commit to content hashes, not content. Erasure is implemented as scoped forget with a dry-run: you (or we, on a valid request) preview exactly what will be removed, then commit. Erased content is removed while the receipt chain retains its integrity, and the erasure operation itself is receipted, so completion is demonstrable. Where a record must be retained for legal reasons, we restrict access instead and tell you why.
5. Your rights
Under UK GDPR (and EU GDPR where it applies) you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. Write to privacy@cuecrux.com; we acknowledge within 5 working days and respond within 30 calendar days. If you are unsatisfied, you may complain to the Information Commissioner's Office (ICO) or your local supervisory authority.
6. International transfers
Hosted services are operated from the UK and EEA. Where a transfer outside the UK/EEA occurs, we use standard contractual clauses with the UK Addendum, and encryption in transit and at rest throughout.
7. Security
TLS in transit, encryption at rest, least-privilege access, and signing keys held in managed key infrastructure. The integrity of receipt data is additionally protected by the hash chain itself: tampering is detectable by any holder of the trail, including you.
8. Changes
Material changes to this notice are announced at least 14 days in advance on this page, with a version history retained.