Skip to content
CueStash

Privacy policy

Privacy, without the fog.

CueStash is designed so the material you capture can stay on your Mac. This policy explains the narrow cases where data does cross the network.

Last updated August 21, 2026

← Back to CueStash

Plain language first. Release facts and customer policies without buried conditions.

The short version

CueStash is operated by Remodeled AI, LLC. CueStash does not need to upload your active notes, Done items, sections, or Archive to operate. The Mac app stores its core content locally. We do not sell personal information, use your captures to train models, or require an account inside the app.

What stays on your Mac

Captured text, prompts, links, notes, item status, search data, and app preferences are stored locally by the CueStash Mac app. The working library is encrypted with a device-only key held in the macOS Keychain; a JSON export is readable only when you explicitly create one. Content leaves your device only when you deliberately copy or send it to another application, or explicitly enable a network integration that explains its behavior before use.

What the website processes

Basic delivery data

Our hosting and security providers may process standard request data such as IP address, browser type, requested URL, timestamps, and security signals to deliver the site, prevent abuse, and troubleshoot reliability. We do not add behavioral advertising trackers to the CueStash website.

Purchases and licenses

Checkout is handled by Stripe. Stripe receives the payment and billing information needed to complete your purchase, calculate tax, prevent fraud, and issue receipts. CueStash receives purchase identifiers, your checkout email, payment status, and enough information to create and support your license. If a campaign or affiliate link brought you to the site, we also retain limited first-touch campaign or referring-domain labels with the license so we can measure acquisition without cross-site tracking. We do not receive or store your full card number. Payment and license-delivery work may be placed in a private operational queue. If repeated delivery attempts fail, the job and the minimum purchase or recovery data needed to resolve it may be retained in a restricted failure record for support and reliability work.

Launch list

If you join the launch list, we store the email address you submit, the page where you joined, and limited campaign or referring-domain labels. We use that information to send release announcements and understand which launch work is useful. We do not add cross-site behavioral advertising trackers. You can unsubscribe from any message.

License activation

When you activate CueStash, the licensing service receives your license key, a one-way device identifier, the app version, and activation timestamps. This lets us enforce the three-Mac license limit, restore access, and revoke licenses associated with refunded or fraudulent purchases. The device identifier is not intended to reveal your files, captures, Apple ID, or hardware serial number.

Quick Ask

Quick Ask sends only the text you explicitly submit with Option–Return to the model source you selected. Ollama and compatible local endpoints can keep the request on your Mac. For BYOK, the Mac app sends it directly to OpenAI, OpenRouter, xAI, Anthropic, Kimi, or the compatible endpoint you configure, using any key stored in your Keychain. The OpenAI-subscription option runs Codex locally after you sign in; CueStash does not read or store that credential. For CueStash Hosted, our Cloudflare service verifies your license and subscription, forwards the prompt to OpenAI, and returns the answer. CueStash does not store hosted prompt or answer text on its server. We retain aggregate monthly request and token counts for limits, abuse prevention, cost control, and support. Each selected model provider processes submitted text under the terms that apply to its service.

Support

If you email support, we process your email address and the message or files you choose to send so we can answer. Do not send private captures unless they are necessary to diagnose the issue and you intend for us to inspect them.

Service providers

We use a small number of providers for defined purposes:

  • Cloudflare for website delivery, security, commerce APIs, and license records.
  • Stripe for checkout, payments, tax calculation, fraud prevention, and receipts.
  • OpenAI for model inference when you select OpenAI BYOK, OpenAI subscription through Codex, or CueStash Hosted.
  • OpenRouter for model routing when you select OpenRouter BYOK.
  • xAI for model inference when you select xAI/Grok BYOK.
  • Anthropic for model inference when you select Anthropic BYOK.
  • Moonshot AI for model inference when you select Kimi BYOK.
  • Apple for code signing, notarization, and macOS platform services.

Their processing is governed by their own terms and privacy policies. We do not authorize these providers to use your saved CueStash library. Quick Ask sends only the prompt text you explicitly submit to the provider selected in Settings.

Retention

Local stash content remains until you delete it or remove the app's data. Quick Answer history is removed after the retention period you select, which defaults to 24 hours. Purchase, tax, refund, and license records are retained as needed to deliver your license, meet accounting and legal obligations, resolve disputes, prevent fraud, and repair failed license delivery. Operational failure records are resolved or deleted when they are no longer needed for those purposes. Launch-list records remain until you unsubscribe or request deletion. Support correspondence is retained only as long as it remains useful for those purposes.

Your choices

You may:

  • delete content from the Mac app and create an explicit readable JSON export;
  • uninstall CueStash and remove its local data;
  • decline optional network integrations;
  • request access to or deletion of support and license data, subject to records we must retain;
  • request a qualifying refund under our refund policy.

Security

Customer downloads are signed and notarized for macOS. Website and commerce traffic use HTTPS. We restrict service access and avoid collecting content the service does not need. We will investigate and communicate material incidents affecting customer data.

Children

CueStash is a professional productivity tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13.

Changes

If this policy changes materially, we will update the date above and publish the revised policy here. Any new feature that sends saved library content off-device will require prominent notice and an explicit user choice.

Contact

Send privacy requests to privacy@cuestash.com. Send product or license questions to support@cuestash.com.

CueStash

A private AI work sidecar for Mac.

Product

WorkflowFeaturesQuick AskPricingDownloadUpdatesGuidePurchase policyRecover a licenseEmail support

Trust

PrivacyTermsRefundsSecurityChangelog

© 2026 CueStash. Made for focused work.

macOS 14+ · Apple silicon + Intel