Privacy
A clear view of your data.
Last updated July 28, 2026
What we collect
When you sign in, Google provides your name, email address, and profile image. A beta application also includes the use case, apps, and device types you choose to share. Cueboard stores the decks and pairing records needed to provide the service. If you send product feedback, we store the message, its category, and the account identity needed to reply.
To protect Cueboard from abuse, we keep short-lived security event records for rejected inputs, failed authentication or authorization, invalid device credentials, and rate-limit activity. These records use a keyed, pseudonymous source fingerprint instead of storing your raw IP address, and never include submitted attack strings, pairing tokens, OAuth codes, or full browser user-agent data. Security events are retained for up to 30 days.
Google sign-in and Google user data
Cueboard uses Google sign-in only for basic account identity. We receive your name, email address, and profile image so we can create your Cueboard account, display your identity, manage beta access, and associate cloud decks with you. Cueboard does not request access to Gmail, Google Drive, Google Calendar, Google Contacts, Google Docs, or other Google service content.
Google profile data is not sold, used for advertising, or used to train artificial intelligence models. We do not transfer Google user data except to service providers acting on our behalf as necessary to operate Cueboard, or where required by law.
How we use it
We use this information to operate Cueboard, review beta access, keep your decks in sync, secure paired devices, and diagnose reliability issues. We do not sell personal information or use marketing cookies.
AI workflow builder
When you choose to build a workflow with AI, Cueboard sends the description you enter and a list of app names reported by your companion to the configured AI provider. This information is used to draft supported workflow steps. Your Google profile data, deck credentials, pairing secrets, and document contents are not included in that request. You can review and edit the result before using it.
Service providers
Railway hosts the application, Supabase provides authentication and production data services, Google provides sign-in, Cloudflare provides privacy-conscious aggregate web analytics, and the configured AI provider processes workflow descriptions only when you use the AI builder. Each provider processes data under its own terms.
Controls and retention
You can delete cloud decks from Cueboard. To request access to, correction of, or deletion of account information, email hello@pointillist.org. Security records and backups may remain for a limited period where required for service integrity.
Contact
Questions about privacy can be sent to hello@pointillist.org.