Privacy
Last updated 21 September 2026. Cue holds different things depending on how you met it. Find yourself below — only that section applies to you.
If you asked for access
- Your email address.
- Your name, if you typed one — that field is optional.
- A salted SHA-256 of your IP address, stored truncated to 32 hex characters. The address itself is not stored and the hash cannot be turned back into it. It exists only to rate-limit the form against abuse. The salt is a secret held only on the server, not in the source code.
- The user-agent string your browser sends, truncated.
- The date and time you submitted the form.
- Which pricing plan you clicked through from, if any — so that when we write, we can talk about the plan you actually asked about instead of guessing.
- An operator moderation status on the row: pending, screening, approved, suspended, or blacklisted. You do not set this; it defaults to pending.
That is the entire waitlist record. If we invite you, that lives in a separate invite table: the address it was issued to, the plan it starts you on, when it opens and ends, whether it has been used, and whether it was withdrawn.
The marketing, legal, and feedback pages set no cookies and run no analytics, tracking pixels, or third-party scripts. Fonts are served from this site, not from a third party. Signing in to a studio account sets one cookie — the session — and that is the only cookie Cue ever sets.
If you sent feedback
The public page at /feedback stores a note so it can be reviewed. It does not ask for an email address.
- The text you typed.
- One or two categories you picked: General, Feature request, Bug, or Other.
- A SHA-256 of the text, shown as a short hash on the receipt, so the printed slip can name the note without reprinting it.
- A salted SHA-256 of your IP address, truncated, and your browser’s user-agent string, truncated — the same pair the access form keeps, used only to rate-limit the page.
- If you were signed in to a studio when you sent it, the ids of that user and studio, so a note from inside Cue can be tied back. Guests leave those empty.
- The date and time you sent it, and an unguessable public id.
After the note is stored, Cue files it for internal review. The receipt does not wait on that. Save your tracking link to check the initial review status. Anyone with that link can see receipt details and status, but not your note. Do not put secrets in the box.
If you created a studio account
A studio account is for photographers and videographers who use Cue to prepare and send agreements.
Your account
- Your name and email address.
- Your password, stored only as a one-way hash. We never hold the password itself and cannot recover it.
- For each sign-in session: a session token, its expiry, your browser’s user-agent string, and your IP address, stored in full rather than hashed. That comes from the authentication library Cue uses and is how a session can be recognised and revoked. It is not used for analytics or advertising.
- If you ask for a password reset: the email address you typed, the same salted IP hash and truncated user-agent the access form keeps, and when you asked. Nothing is emailed automatically — a person reviews the request and replies from hello@krevo.io. The request is kept after it is handled, marked as resolved.
Your studio profile
- Whatever you enter: studio name, legal name, contact email, phone number, business address, and a brand colour.
The agreements you create
- Everything you type into a Cue: its title, your client’s name and email address, the shoot date and location, every answer you give in the builder — fees, deposits, deliverables and the rest — and any private notes you add.
- Once sent: a frozen copy of the finished agreement, a SHA-256 fingerprint of it, and the unguessable link token.
If you signed an agreement someone sent you
You did not create an account and were not asked to. The photographer or videographer who sent you the link chose to use Cue and entered your details; Cue stores them on their behalf. When you sign, Cue records:
- The name and email address the sender entered for you.
- The full legal name you typed.
- An image of the signature, if you drew one. Drawing is optional — your typed name is the signature — and when you do not draw, no image is stored.
- The date and time you confirmed you had read the agreement, and the date and time you signed.
- A salted SHA-256 hash of your IP address — not the address itself — and your browser’s user-agent string, truncated.
- A timestamped list of events on that agreement: when the link was issued, when it was first opened in a visible browser tab, periodic return views, and when it was signed and sealed. Repeated views within five minutes are combined into one event.
This is deliberate: it is the record that makes a signature mean something to both of you. It is described to you before you sign, and shown on the sealed agreement afterwards.
Once an agreement is sealed it cannot be altered — by the sender, or by us. That is the point of it. See below for what that means for deletion.
What we do with all of it
We use it to run the product and nothing else. We do not sell or share it, or use it for advertising. If you joined the waitlist, that list is how we tell you about access and product news by hand from hello@krevo.io. The plan you clicked through from is so that note can mention the plan you actually asked about. There is no analytics tool, no tracking pixel, and no third-party script on any page.
Cue itself still cannot send mail. There is no waitlist confirmation, signing link, sealed copy, or reminder email from the application. When a person writes from hello@krevo.io, that is someone typing. When you send an agreement, you share the link yourself.
Who at Cue can see it
Cue is run by one person. That operator can see studio accounts, their usage, and the agreements they have created — including the client names, email addresses and signing records inside them — through a private, password-protected console. This exists so that accounts can be supported when something goes wrong, and it is the only way anyone at Cue reaches your data.
Two limits on it, enforced by the software rather than by policy: a sealed agreement cannot be altered by the operator either — the record is immutable to us in exactly the way it is to both parties — and administrative changes to customer or access data are written to their own audit log. There is no way for anyone to sign, edit, or impersonate on your behalf.
Where it lives, and who else touches it
Accounts, agreements, signatures, the waitlist, and feedback notes live in one PostgreSQL database, behind HTTPS. Signature images sit in that same database as data, not with a file-storage provider. Files attached to a Cue (the gallery next to the agreement) are stored with the object-storage provider Cue is configured to use, when that configuration is present. Nothing is copied to a marketing or analytics tool, because there is not one. Feedback text is also filed for internal review when that follow-up is configured, as described above.
Cue runs on rented infrastructure rather than machines Krevo owns, so five companies necessarily hold or pass your data. They are all of them:
- Vercel — runs the application and serves every page, from its northern Virginia region.
- Neon — hosts the PostgreSQL database, in AWS us-east-1, also in northern Virginia. This is where every account, agreement, signature, waitlist row, feedback note, and audit record actually sits.
- Upstash — holds rate-limiting counters only, keyed by the salted IP hash described above. It never sees an email address, an agreement, or a signature, and Cue keeps working if it is unavailable.
- GitHub — receives a /feedback note (categories and text) as a private issue in Cue's repository, when that follow-up succeeds.
- OpenAI — receives feedback text and repository code for an AI-assisted initial review through a Codex scheduled task. Customer database records are not part of the review.
All five are in the United States. If you are in the UK or EU, that means your data is processed outside it. GitHub hosts the private review issue. OpenAI provides the review model. None of these suppliers is sold your data.
Krevo does not run a separate off-site backup. What exists is whatever point-in-time history Neon keeps for the plan Cue is on, which is a supplier feature rather than a promise we are making to you. Cue is run by one person: treat a sealed agreement you rely on as something to download and keep your own copy of.
Getting your data removed
Email hello@krevo.io from the address concerned. We will verify the request, explain what is held, and act within the limits below rather than promising to erase a record the product is designed to keep immutable.
- Access list: the waitlist row can be deleted. An unused invitation can also be removed. If an account already relies on the invitation, it can be revoked to stop access but remains as the record of that access decision.
- Feedback: the Cue row can be deleted. An issue opened from it in Cue's private GitHub repository may remain after the row is gone.
- Studio account: Cue does not currently offer a safe hard-delete for an account that has sent agreements. Access can be withdrawn, and drafts can be deleted, but sent and sealed Cues stay with their audit trail so neither party’s record is silently rewritten.
- If you signed something: write to us and we will tell you what is held and pass the request to the sender, whose agreement it is. Cue cannot alter or delete a sealed record through the product; that constraint applies to the sender and operator too.
What we are not claiming
Cue is in production, but it is built and run by one person. It has not been audited or certified against any privacy or security standard, it has had no penetration test, and there is no data protection officer. Cue is not a law firm and gives no legal advice; the agreements it produces are templates you are expected to have reviewed.
We are telling you exactly what is collected and where it sits so you can judge it on that, rather than on a badge.
Changes
If what we collect changes, this page changes with it and the date at the top moves. Questions go to hello@krevo.io.