Trust centre

Where your data goes.

CueCrux is local-first: the daemon runs on your machine and, by default, none of your data leaves it. (This marketing website itself loads web fonts from Google, listed below, but that is separate from where your product data goes.) This page is the honest account of what changes when you opt into a hosted capability: who processes what, for how long, and how to report a problem.

Data flow

Your machineLocal daemon · free forever· Memory & retrieval· CROWN receipts· Passports & custody· ExportDefault: nothing leavesCueCrux-hostedOpt-in · metered compute· Managed embeddings, rerank· Sync, hosted RCX, alertingPaddlePayments · merchant of recordonly opted-in databilling detailscannot readyour local store

The dashed arrows are the only paths off your machine, and each one carries only the data for the capability you opted into. Neither hosted compute nor Paddle can read your local store.

Subprocessors

Product subprocessors process your data on our behalf when you use a hosted capability. If you only run the local daemon, none of these are involved. This site loads no third-party analytics or tracking.

ProcessorPurposeDataRegion
Paddle.com Market LtdPayments and merchant of record for subscriptions and credit purchases.Billing details, transaction records. Card data is handled by Paddle; CueCrux never receives it.UK / EU
Hetzner Online GmbHCloud hosting and compute for CueCrux-hosted (opt-in) services.Only data you sync to a hosted capability, or send to a metered operation.EU (Germany)

Website-delivery vendors

Serve this marketing website only. They never touch product data, the local daemon, or hosted capabilities.

VendorPurposeDataRegion
Google FontsDelivery of web fonts for this marketing website.Standard request metadata (IP, user-agent) at font fetch time. No account, product, or content data.Global CDN

Retention & deletion

Local data lives only on your machine and is deleted when you delete it; there is nothing for us to purge.

For hosted capabilities: receipts and operational logs are retained 90 days by default; hosted stores follow the retention you configure (Governance retention SLA where applicable).

Deletion of an imported or synced store is a batched tenant-scoped erasure that leaves an attestable deletion record: we record that data was deleted without retaining what was deleted.

To request deletion of hosted data, email security@cuecrux.com.

No training on your data

We do not train models on your content, memory, or receipts, and we do not sell or share them for advertising.

Managed embedding and extraction operations process your input to return a result to you; the input is not retained to train anything.

Where a hosted capability uses a third-party model provider, it is named in the subprocessor list above and inherits this commitment.

Reporting a vulnerability

If you believe you have found a security issue, email security@cuecrux.com. Please include enough detail to reproduce it. We aim to acknowledge within three working days.

Please give us reasonable time to remediate before public disclosure, and avoid privacy violations, data destruction, or service degradation while testing. Good-faith research under these terms is welcome and we will not pursue action against it.

Machine-readable policy: /.well-known/security.txt

Status & incident history

Where service status and past incidents are reported.

View status

Informational, not legal advice. This page describes current practice and is reviewed as our hosted services evolve.