Privacy Policy
Last updated 5 September 2026
1. Overview
Cueora is an AI meeting notes app. This policy explains what personal data we collect, why, how long we keep it, and the controls you have. We are the data controller for your account data, and a processor for the meeting content you capture.
2. What we collect
- Account data — name, email, authentication identifiers, plan and subscription status.
- Calendar data — if you connect Google Calendar or Outlook, the events on the calendars you select: title, time, attendees, description, and conferencing links, used to detect meetings and generate briefs.
- Meeting content — audio you explicitly choose to share, transcripts, notes, action items, decisions, and any flagged audio clips.
- Settings and diagnostics — capture preferences, shortcuts, and technical logs such as connection state and latency.
2a. Google user data
If you connect Google Calendar, Cueora requests the read-only scopes calendar.readonly, userinfo.email and userinfo.profile. Here is exactly what happens with that data:
- What we access — events on the calendars you select, limited to the next 14 days: title, start and end time, attendee names and email addresses, description, location and conferencing link. Your Google account email, to label the connection.
- How we use it — to list your upcoming meetings in live notes, start a capture at the right time, attach the right invite to a session, name the people who spoke, and write a short pre-meeting brief. Nothing else.
- How we store it — imported events are stored in your account, encrypted at rest, and replaced on every sync. The OAuth token is stored encrypted (AES-256-GCM) and is never exposed to your browser.
- Who we share it with — nobody. Calendar data is not sold, not used for advertising, not used to train AI models, and not shared with any third party. Attendee names and event titles are sent to our speech-to-text and language-model providers only as context to produce your own notes, under contracts that forbid retention and secondary use.
- How to revoke — Settings → Calendar → Disconnect deletes the stored token and every imported event immediately. You can also revoke Cueora at myaccount.google.com/permissions.
Cueora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Audio handling and retention
Capture only runs when you start it or when you have explicitly enabled auto-capture, and an indicator is shown throughout. By default we process audio in-flight for transcription and do not retain the full recording. Flagged clips you save are stored encrypted at rest. You control the retention window for audio in Settings → Privacy, and can set it to delete immediately after transcription.
4. Why we process it
To provide the Service you ask for (contract), to keep it secure and prevent abuse (legitimate interests), to meet legal and tax obligations, and — only where you opt in — to send product updates (consent).
5. Who processes data for us
- Speech-to-text and language model providers, to transcribe and shape notes.
- Cloud hosting and database providers, to run the Service and store your data.
- Dodo Payments, our Merchant of Record, to take payments and handle applicable sales taxes.
- Destinations you connect yourself, such as Slack and Notion, when you share notes to them.
We do not sell personal data or share it with advertisers.
6. Private vs shareable layers
Notes marked private stay in your account and are excluded from anything shared to a team, Slack, or Notion. Only the shareable layer is included when you export or send notes.
7. Your rights and controls
You can access, correct, export, and delete your data. Settings → Privacy provides one-click export of all your meetings, transcripts, and notes, and permanent deletion of your account and its content. Depending on where you live you may also have rights to object to or restrict processing, and to complain to your data protection authority.
8. Security
Data is encrypted in transit and at rest, access is scoped per user through row-level security, and third-party credentials such as calendar tokens are stored encrypted with AES-256-GCM.
9. International transfers and retention
Data may be processed in countries other than yours, protected by appropriate safeguards such as standard contractual clauses. We keep account data while your account is active and delete meeting content according to your retention setting or within 30 days of account deletion, except where law requires longer.
10. Browser extension
The Cueora Chrome extension reads the URL and title of tabs on supported meeting hosts — Google Meet, Zoom, Microsoft Teams, and Whereby — solely to detect whether a tab is an active call and to badge it. When a meeting is detected, that tab's title is sent once to your Cueora live notes so the note can be named. The extension does not collect, store, or transmit your browsing history, and requests no access to any other site. What it stores locally in Chrome is limited to your capture preferences, your keyboard shortcuts, and a device-local timestamp recording when you last granted microphone access; that timestamp is never synced between machines. The extension does not itself capture audio — capture runs in your Cueora live notes tab, under the audio handling described in section 3.
11. Contact
Privacy questions or requests: support@cueora.app.
Questions about this policy? Email support@cueora.app.