Privacy
Last updated 26 July 2026. Cue holds different things depending on how you met it. Find yourself below — only that section applies to you.
If you joined the waitlist
- Your email address.
- Your name, if you typed one — that field is optional.
- A SHA-256 hash of your IP address, salted with a secret held only on the server and not in the source code. The address itself is not stored and the hash cannot be turned back into it. It exists only to rate-limit the form against abuse.
- The user-agent string your browser sends, truncated.
- The date and time you submitted the form.
That is the entire waitlist record. The marketing pages set no cookies and run no analytics, tracking pixels, or third-party scripts. Fonts are served from this site, not from a third party.
If you created a studio account
A studio account is for photographers and videographers who use Cue to prepare and send agreements.
Your account
- Your name and email address.
- Your password, stored only as a one-way hash. We never hold the password itself and cannot recover it.
- For each sign-in session: a session token, its expiry, your browser’s user-agent string, and your IP address, stored in full rather than hashed. That comes from the authentication library Cue uses and is how a session can be recognised and revoked. It is not used for analytics or advertising.
Your studio profile
- Whatever you enter: studio name, legal name, contact email, phone number, business address, and a brand colour.
The agreements you create
- Everything you type into a Cue: its title, your client’s name and email address, the shoot date and location, every answer you give in the builder — fees, deposits, deliverables and the rest — and any private notes you add.
- Once sent: a frozen copy of the finished agreement, a SHA-256 fingerprint of it, and the unguessable link token.
If you signed an agreement someone sent you
You did not create an account and were not asked to. The photographer or videographer who sent you the link chose to use Cue and entered your details; Cue stores them on their behalf. When you sign, Cue records:
- The name and email address the sender entered for you.
- The full legal name you typed.
- An image of the signature, if you drew one. Drawing is optional — your typed name is the signature — and when you do not draw, no image is stored.
- The date and time you confirmed you had read the agreement, and the date and time you signed.
- A salted SHA-256 hash of your IP address — not the address itself — and your browser’s user-agent string, truncated.
- A timestamped list of events on that agreement: when the link was issued, when it was first opened, each time it was viewed, and when it was signed and sealed.
This is deliberate: it is the record that makes a signature mean something to both of you. It is described to you before you sign, and shown on the sealed agreement afterwards.
Once an agreement is sealed it cannot be altered — by the sender, or by us. That is the point of it. See below for what that means for deletion.
What we do with all of it
We use it to run the product and nothing else. We do not sell or share it, add anyone to a newsletter, or use it for advertising or profiling. There is no analytics tool, no tracking pixel, and no third-party script on any page.
Being straight about the current state: no email provider is connected to Cue at all. As of 26 July 2026 nothing has ever been emailed to anyone and nothing can be sent automatically. When you send an agreement, you share the link yourself. We intend to email waitlist members once, when Cue opens.
Who at Cue can see it
Cue is run by one person. That operator can see studio accounts, their usage, and the agreements they have created — including the client names, email addresses and signing records inside them — through a private, password-protected console. This exists so that accounts can be supported when something goes wrong, and it is the only way anyone at Cue reaches your data.
Two limits on it, enforced by the software rather than by policy: a sealed agreement cannot be altered by the operator either — the record is immutable to us in exactly the way it is to both parties — and administrative actions are written to their own audit log. There is no way for anyone to sign, edit, or impersonate on your behalf.
Where it lives
In one PostgreSQL database on a single rented virtual server, reachable only from the application over a private network, behind HTTPS. Nothing is copied to a third-party marketing or analytics tool. Signature images sit in that same database, not with an outside provider.
There are currently no off-site backups. That is a deliberate choice while Cue is pre-launch, and it means data loss is possible. This page changes when that does.
Getting your data removed
Email hello@krevo.io from the address concerned and we will act on it.
- Waitlist: we delete the row. Nothing is retained.
- Studio account: we delete the account, the studio profile, and every Cue and draft belonging to it.
- If you signed something: write to us and we will tell you what is held and pass the request to the sender, whose agreement it is. We will not quietly alter a sealed record — an agreement both parties relied on is not ours to edit — but we will delete it outright on a legitimate request, and tell you when we have.
What we are not claiming
Cue is a pre-launch product built by one person. It has not been audited or certified against any privacy or security standard, it has had no penetration test, and there is no data protection officer. Cue is not a law firm and gives no legal advice; the agreements it produces are templates you are expected to have reviewed.
We are telling you exactly what is collected and where it sits so you can judge it on that, rather than on a badge.
Changes
If what we collect changes, this page changes with it and the date at the top moves. Questions go to hello@krevo.io.