Privacy Policy
Effective July 20, 2026
CuePoint ("CuePoint," "we," "us") lets you send short clips of songs through iMessage. This policy explains what happens to your data. For song previews and Apple Music playback, the short version is: almost nothing, because there's almost nothing to collect. Sound bites you record yourself are the one exception — see below.
No account
CuePoint does not require an account, sign-in, or any personal information to use. The app runs primarily on your device and talks directly to Apple's own services (the iTunes Search API for previews, and Apple Music / MusicKit for full-song playback if you have a subscription). Searching, browsing, and previewing songs never leaves a record on any server we control.
Sound bites you record
If you use the "sound bite" feature to record and send your own audio clip, that recording is uploaded to Firebase Cloud Storage (a service we run on Google Cloud infrastructure) so the person you send it to can download and play it, even if they don't have the file locally. This is the one case where CuePoint does have a server-side component:
- What's uploaded: the audio file itself, at a storage path keyed to a random clip ID (not your name, device, or Apple ID).
- How it's protected: the file is reachable only by a long, unguessable URL derived from that random ID — it isn't listed, indexed, or searchable, so only someone who receives the link (i.e., the recipient of your iMessage) can retrieve it.
- Anonymous authentication: uploading requires a Firebase anonymous sign-in. This doesn't create an account or identify you — it's a random, per-install credential that exists solely so our storage rules can reject automated abuse of the upload endpoint. It is not linked to your name, Apple ID, or any personal information.
- Retention: uploaded sound bites are automatically deleted after 30 days.
- Deleting a sound bite yourself: deleting it from your own device also attempts to remove the uploaded copy right away, rather than waiting for the 30-day auto-expiry above. This happens automatically in the background and doesn't require a separate step.
- Sub-processor: this storage is provided by Google Firebase, governed additionally by Google's Firebase privacy policy.
Song previews and Apple Music playback do not go through this pipeline — only sound bites you explicitly record and send.
Anonymous usage statistics
CuePoint records a small set of anonymous feature-usage events — for example, "a cue was sent" or "a sound bite was created" — as an event name and a timestamp, nothing more. These are uploaded in batches under the same anonymous identifier used for sound bites, and are automatically deleted within 30 days. They contain no message content, no song choices, no contact or sender information, and nothing linked to your identity. We use them only to understand which features are used so we can improve the app. They are never used for advertising or tracking, and never shared with anyone.
What we don't collect
- No personal information (name, email, phone number, etc.)
- No behavioral tracking or third-party analytics SDKs — the anonymous feature counters above are the full extent of usage data
- No advertising identifiers or third-party ad SDKs
- No account credentials — CuePoint has none to store
- We never sell or share your information with third parties for advertising or any other purpose
CuePoint's App Store privacy label and the app's on-device Privacy Manifest disclose the exceptions above (sound-bite audio, an anonymous device identifier, and anonymous usage events — used only for app functionality and product improvement, never linked to your identity and never used for tracking).
What stays on your device
A small amount of information is stored locally on your device only, and is never transmitted anywhere:
- Preferences and a trending-songs cache, stored via iOS's standard app storage (shared between the CuePoint app and its iMessage extension so both can read the same cache).
- Song previews are streamed, never cached. Playing a preview clip pulls audio live from Apple's servers each time and never writes it to your device's storage — this matches the terms Apple's preview API requires, and means there's nothing stored locally to worry about even for the free preview tier.
- A local cache of sound bites you've received, so a bite you've already opened plays back instantly without re-downloading. This cache is also limited in size and automatically evicts the oldest files.
Sending clips through iMessage
When you send a song preview or Apple Music clip, CuePoint delivers only the information needed to reconstruct it (which song, and which moment) inside the iMessage message itself — through Apple's Messages infrastructure, subject to Apple's own security and privacy practices (including end-to-end encryption for iMessage-to-iMessage conversations). No audio for these clips passes through any server we control.
Sound bites work differently, because they're your own recording rather than a reference to a song Apple already hosts: the audio is uploaded to our Firebase Storage (see "Sound bites you record" above) and the iMessage payload carries a reference to it. In both cases, we do not keep a server-side log of who you sent a clip to or when. Your device does keep its own local "recently sent" history so you can revisit and replay what you've sent — see "What stays on your device" below — but that history is never transmitted to us and we have no record of it.
Apple Music and the iTunes Search API
Song previews are streamed directly from Apple's content delivery network via the public iTunes Search API. Full-song clips use Apple's MusicKit framework and require you to be signed in with an active Apple Music subscription on your own device. Your interaction with Apple Music (authentication, subscription status, playback) is governed by Apple's Privacy Policy, not this one — CuePoint never receives your Apple ID credentials or Apple Music account details.
Apple Music affiliate link
The "Get Apple Music" link on this site and in the app is an affiliate link. If you subscribe through it, CuePoint may earn a commission at no extra cost to you. This link does not share any personal data about you with CuePoint — the subscription transaction happens entirely on Apple's platform.
Children's privacy
CuePoint does not knowingly collect personal information from anyone, including children. The one exception described above — sound-bite audio, stored briefly to deliver it and auto-deleted after 30 days — is not linked to any identity and applies equally regardless of age. If you believe a child has provided us information beyond this, contact us and we'll look into it.
Canadian privacy law (PIPEDA)
CuePoint is based in Ontario, Canada, and handles personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA). Our privacy contact, reachable at the email below, is accountable for compliance with this policy and can answer questions about how your information is handled.
You have the right to access the personal information we hold about you and to challenge its accuracy. In practice, there is very little to access — as described throughout this policy, almost nothing we handle is linked to an identifiable person. If you have a privacy concern that we haven't resolved to your satisfaction, you may contact the Office of the Privacy Commissioner of Canada.
Changes to this policy
If this policy changes, we'll update the effective date above and post the revised version here.
Contact us
Questions about this policy? Email cuepointapp@gmail.com.