Cue

Privacy Policy

Last updated July 6, 2026

Karan Joshi (“Cue”, “we”, “us”)operates Cue, a social media scheduling tool that lets agencies plan, schedule, and publish posts to their clients' LinkedIn, Instagram, and YouTube accounts. This policy explains what we collect, why, and the choices you have.

Information we collect

  • Account data. The email address you sign in with (via a passwordless one-time code we email you) and a display name you choose.
  • Connected social accounts. When you connect a LinkedIn, Instagram, or YouTube account, we receive and store an access token (and, where provided, a refresh token) plus that account's platform id, username, and display name. Tokens are encrypted at rest and used only to publish on your behalf.
  • Content you create. Post captions, scheduling times, and any images, videos, or documents you upload for publishing. Media is stored in Cloudflare R2.

How we use your information

We use the data solely to provide the service:

  • Authenticate you and keep your workspace isolated.
  • Schedule and publish your posts to the LinkedIn, Instagram, and YouTube accounts you connect, at the times you set.
  • Show publishing status, history, and account health.

We do not sell your data or use it for advertising.

Platforms and third parties

Cue integrates with the official APIs of LinkedIn, Meta (Instagram), and YouTube. When you publish, your content and the relevant access token are sent to those platforms to create the post. Our use of the Instagram Platform complies with the Meta Platform Terms and Developer Policies. We also rely on these processors:

  • Supabase — authentication and database.
  • Cloudflare R2 — storage for the media you upload.
  • Vercel — application hosting.

YouTube API Services

Cue uses YouTube API Services to upload videos to the channel you connect. By connecting a YouTube channel you agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.

  • What we access. Your Google account id, email address, and name — used only to label the connected channel — plus permission to upload videos on your behalf. We do not read your existing videos, comments, subscribers, or analytics.
  • Limited Use. Cue's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell this data, use it for advertising, or let humans read it except where required for security or by law.
  • Revoking access. Disconnect the channel from the Clientspage, which deletes its stored tokens, or revoke Cue's access at any time through your Google security settings.

Data retention

  • Access tokens are kept until you disconnect the account or delete the client, then removed.
  • Published posts and their uploaded media are automatically purged about 7 days after they finish publishing; a lightweight record (platform, link, date) is retained for your history.
  • Deleting a client or workspace removes its accounts, posts, and media.

Your choices and data deletion

You can disconnect any social account at any time from the Clients page, which immediately deletes its stored tokens. To request deletion of your account and all associated data, see our Data Deletion instructions or email us at joshikaran0008@gmail.com.

Security

Traffic is served over HTTPS and social access tokens are encrypted at rest. No system is perfectly secure, but we work to protect your data using industry-standard measures.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.

Contact

Questions? Email joshikaran0008@gmail.com.