Skip to content
CueStash

Security

Security by reducing the surface.

How CueStash protects local work, validates licenses, and distributes signed Mac releases.

Last updated July 31, 2026

← Back to CueStash

Plain language first. Release facts and customer policies without buried conditions.

Current release status

CueStash 0.1.6 is distributed as a Developer ID signed, Apple-notarized, stapled disk image. The public download is kept separate from internal ad-hoc QA builds and is verified with Gatekeeper, a SHA-256 checksum, and its Sparkle Ed25519 signature before publication.

Local workspace

Active notes, Done and Archive state, sections, search data, and preferences are stored on the Mac. The core workflow does not need an account or an AI-provider connection. CueStash captures only when the user asks it to; it does not continuously retain clipboard history.

The working library is sealed with AES-GCM using a random key stored as device-only material in the macOS Keychain. A readable JSON file is created only when the customer explicitly exports the library. FileVault and a protected macOS account remain useful device-level controls.

Permissions

The menu-bar item works without Accessibility permission. Accessibility is optional and is used only to read text the user explicitly selected, recognize the global double-Shift gesture, and automate send-back. If permission is absent, CueStash still opens from the menu bar and copies a note for manual paste.

Licensing boundary

Stripe handles payment details. CueStash receives purchase identifiers and the checkout email needed for license delivery. Activation sends a license key, a one-way device identifier, and app-version metadata—not the customer’s notes or local workspace.

Activation receipts are signed and bound to the device and expiration time. Refunds and unresolved payment disputes revoke the associated license. Recovery responses are generic and throttled to avoid revealing whether an email address is a customer.

Release integrity

Customer disk images and Sparkle appcasts are stored in private release storage. The publisher verifies notarization, Gatekeeper, checksums, Sparkle signatures, and uploaded bytes before it promotes the appcast. The appcast is promoted last so a partially uploaded release is never advertised.

Website and API

The storefront and commerce service use HTTPS, restricted cross-origin access, security headers, strict input validation, opaque rate-limit identifiers, and fail-closed readiness checks. Checkout remains unavailable unless fulfillment, email delivery, and the signed release are all configured.

Reporting

Report security issues to security@cuestash.com. Do not include private note content unless it is necessary to reproduce the issue.

CueStash

A private AI work sidecar for Mac.

Product

WorkflowFeaturesQuick AskPricingDownloadUpdatesGuidePurchase policyRecover a licenseEmail support

Trust

PrivacyTermsRefundsSecurityChangelog

© 2026 CueStash. Made for focused work.

macOS 14+ · Apple silicon + Intel