Privacy
Last updated 7 August 2026. Cue holds different things depending on how you met it. Find yourself below — only that section applies to you.
If you asked for access
- Your email address.
- Your name, if you typed one — that field is optional.
- A SHA-256 hash of your IP address, salted with a secret held only on the server and not in the source code. The address itself is not stored and the hash cannot be turned back into it. It exists only to rate-limit the form against abuse.
- The user-agent string your browser sends, truncated.
- The date and time you submitted the form.
- Which pricing plan you clicked through from, if any — so that when billing opens, we can write to you about the plan you actually asked about instead of guessing.
That is the entire record. If we invite you, the same row also holds the invitation: the address it was issued to, the plan it starts you on, when it opens and ends, whether it has been used, and whether it was withdrawn.
The marketing and legal pages set no cookies and run no analytics, tracking pixels, or third-party scripts. Fonts are served from this site, not from a third party. Signing in to a studio account sets one cookie — the session — and that is the only cookie Cue ever sets.
If you created a studio account
A studio account is for photographers and videographers who use Cue to prepare and send agreements.
Your account
- Your name and email address.
- Your password, stored only as a one-way hash. We never hold the password itself and cannot recover it.
- For each sign-in session: a session token, its expiry, your browser’s user-agent string, and your IP address, stored in full rather than hashed. That comes from the authentication library Cue uses and is how a session can be recognised and revoked. It is not used for analytics or advertising.
Your studio profile
- Whatever you enter: studio name, legal name, contact email, phone number, business address, and a brand colour.
The agreements you create
- Everything you type into a Cue: its title, your client’s name and email address, the shoot date and location, every answer you give in the builder — fees, deposits, deliverables and the rest — and any private notes you add.
- Once sent: a frozen copy of the finished agreement, a SHA-256 fingerprint of it, and the unguessable link token.
If you signed an agreement someone sent you
You did not create an account and were not asked to. The photographer or videographer who sent you the link chose to use Cue and entered your details; Cue stores them on their behalf. When you sign, Cue records:
- The name and email address the sender entered for you.
- The full legal name you typed.
- An image of the signature, if you drew one. Drawing is optional — your typed name is the signature — and when you do not draw, no image is stored.
- The date and time you confirmed you had read the agreement, and the date and time you signed.
- A salted SHA-256 hash of your IP address — not the address itself — and your browser’s user-agent string, truncated.
- A timestamped list of events on that agreement: when the link was issued, when it was first opened in a visible browser tab, periodic return views, and when it was signed and sealed. Repeated views within five minutes are combined into one event.
This is deliberate: it is the record that makes a signature mean something to both of you. It is described to you before you sign, and shown on the sealed agreement afterwards.
Once an agreement is sealed it cannot be altered — by the sender, or by us. That is the point of it. See below for what that means for deletion.
What we do with all of it
We use it to run the product and nothing else. We do not sell or share it, add anyone to a newsletter, or use it for advertising. The one piece of preference data we hold — the plan you clicked through from — is used to write you the launch email you asked for, and for nothing beyond it. There is no analytics tool, no tracking pixel, and no third-party script on any page.
Being straight about the current state: no email provider is connected to Cue at all. The application cannot send anything automatically — not a signing link, not a copy of a sealed agreement, not a reminder. When you send an agreement, you share the link yourself.
That includes your invitation. When we have room, one person writes to you by hand from hello@krevo.io with your link. Your address is used for that and nothing else — no newsletter, no sequence, no third-party mailing tool holding a copy of it.
Who at Cue can see it
Cue is run by one person. That operator can see studio accounts, their usage, and the agreements they have created — including the client names, email addresses and signing records inside them — through a private, password-protected console. This exists so that accounts can be supported when something goes wrong, and it is the only way anyone at Cue reaches your data.
Two limits on it, enforced by the software rather than by policy: a sealed agreement cannot be altered by the operator either — the record is immutable to us in exactly the way it is to both parties — and administrative actions are written to their own audit log. There is no way for anyone to sign, edit, or impersonate on your behalf.
Where it lives, and who else touches it
Everything is in one PostgreSQL database, behind HTTPS. Signature images sit in that same database as data, not with a file-storage provider. Nothing is copied to a marketing or analytics tool, because there is not one.
Cue runs on rented infrastructure rather than machines Krevo owns, so three companies necessarily hold or pass your data. They are all of them:
- Vercel — runs the application and serves every page, from its northern Virginia region.
- Neon — hosts the PostgreSQL database, in AWS us-east-1, also in northern Virginia. This is where every account, agreement, signature and audit record actually sits.
- Upstash — holds rate-limiting counters only, keyed by the salted IP hash described above. It never sees an email address, an agreement, or a signature, and Cue keeps working if it is unavailable.
All three are in the United States. If you are in the UK or EU, that means your data is processed outside it. Each is used as a supplier running infrastructure, under its own terms — none of them is given your data for their own purposes, and none is paid for it.
Krevo does not run a separate off-site backup. What exists is whatever point-in-time history Neon keeps for the plan Cue is on, which is a supplier feature rather than a promise we are making to you. Cue is run by one person: treat a sealed agreement you rely on as something to download and keep your own copy of.
Getting your data removed
Email hello@krevo.io from the address concerned and we will act on it.
- Access list: we delete the row, and any invitation issued to that address. Nothing is retained.
- Studio account: we delete the account, the studio profile, and every Cue and draft belonging to it.
- If you signed something: write to us and we will tell you what is held and pass the request to the sender, whose agreement it is. We will not quietly alter a sealed record — an agreement both parties relied on is not ours to edit — but we will delete it outright on a legitimate request, and tell you when we have.
What we are not claiming
Cue is in production, but it is built and run by one person. It has not been audited or certified against any privacy or security standard, it has had no penetration test, and there is no data protection officer. Cue is not a law firm and gives no legal advice; the agreements it produces are templates you are expected to have reviewed.
We are telling you exactly what is collected and where it sits so you can judge it on that, rather than on a badge.
Changes
If what we collect changes, this page changes with it and the date at the top moves. Questions go to hello@krevo.io.