Privacy Policy
Effective Date: June 14, 2026
Cuebird ("we," "our," or "us") provides a real-time AI copilot service for interviews, sales calls, and conversations. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address — used for login, account recovery, and service communications.
- Display name — optional; you can set or change this at any time.
- Authentication provider data — if you sign in with Google, we receive your email address and name from Google. We do not access your Google contacts, Drive, or other Google services.
1.2 Content You Provide
- Resumes (PDF, DOCX, TXT) — uploaded by you for AI context during sessions. Stored in Supabase Storage and accessible only to your account.
- Job descriptions and notes — entered by you to tailor AI suggestions.
- Knowledge Base (STAR stories) — personal accomplishments you write and save for the AI to reference.
- Session context — role, company, interview mode, and other settings you configure per session.
1.3 Audio & Transcripts
- Live audio is streamed directly from your browser to our speech-to-text provider (AssemblyAI or Google Cloud Speech). Audio is never stored on our servers. It passes through our backend in transit only and is discarded immediately after transcription.
- Transcripts exist only in your browser's active session memory and are discarded when you close the tab. We do not persist transcripts to disk or database unless you explicitly save a session.
- If you choose to save a session, the transcript turns and AI suggestions are stored in your account for later review.
1.4 Usage Data
- Session metadata — agent type, session duration, STT seconds, and OpenAI token counts. Used for usage tracking and plan limits.
- Plan and subscription data — managed through Stripe. We store your Stripe customer ID and subscription status. Full payment details are handled by Stripe and never touch our servers.
1.5 Cookies & Local Storage
- Theme preference — stored in a cookie and localStorage to remember your light/dark mode choice. This cookie contains no personal data.
- Supabase auth token — stored in the browser's localStorage by the Supabase client library. This is required for authentication and contains a signed JWT.
- We do not use third-party analytics cookies, advertising cookies, or tracking pixels.
2. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Provide real-time AI suggestions during sessions | Live transcript text, session context (role, company, resume, stories) |
| Authenticate your account | Email, JWT token |
| Manage your subscription and process payments | Email, Stripe customer ID, subscription status |
| Track usage against plan limits | Session count, STT seconds, token usage |
| Improve AI suggestion quality | Your uploaded content (resumes, stories, job descriptions) is used only to ground AI responses in your specific context. It is not used to train AI models. |
| Send service-related communications | Email (only for account-related messages; we do not send marketing emails without consent) |
3. Third-Party Services
We use the following third-party services to operate Cuebird. Each processes data according to its own privacy policy:
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| OpenAI | AI suggestion generation, TTS, translation | Transcript text, session context | OpenAI Privacy Policy |
| AssemblyAI | Speech-to-text transcription | Live audio stream | AssemblyAI Privacy Policy |
| Google Cloud Speech | Speech-to-text (CJK/Portuguese languages) | Live audio stream | Google Cloud Privacy Notice |
| Supabase | Authentication, database, file storage | Email, profile, resumes, stories, jobs, sessions | Supabase Privacy Policy |
| Stripe | Payment processing | Email, payment method (via Stripe.js) | Stripe Privacy Policy |
| ElevenLabs | Text-to-speech (optional) | AI-generated text | ElevenLabs Privacy Policy |
| Fly.io | Application hosting | All application data in transit | Fly.io Privacy Policy |
4. Data Retention
- Account data (email, profile) — retained until you delete your account.
- Uploaded content (resumes, stories, jobs) — retained until you delete them or your account.
- Session history — retained until you delete the session or your account.
- Live audio — never stored. Streamed, transcribed, and discarded in real time.
- Live transcripts — exist only in browser memory during the session. Not persisted to disk unless you explicitly save the session.
- Payment records — retained as required by tax and accounting regulations (typically 7 years).
5. Data Security
We implement the following security measures:
- Encryption in transit: All traffic is served over HTTPS (TLS 1.3). WebSocket connections use WSS.
- Encryption at rest: Supabase encrypts all stored data at rest using AES-256. Resumes uploaded to Supabase Storage are encrypted at rest.
- Row-Level Security (RLS): All database tables are protected by Supabase RLS policies ensuring you can only access your own data.
- JWT authentication: All API requests are authenticated using signed JWTs with expiration.
- Content Security Policy: Strict CSP headers prevent XSS attacks.
- API rate limiting: Prevents abuse of authentication and AI endpoints.
6. Your Rights
Depending on your location, you may have the following rights:
- Access: You can export your data by contacting us.
- Correction: You can update your display name and profile at any time in Account Settings.
- Deletion: You can delete individual items (resumes, jobs, stories) from within the app, or delete your entire account and all associated data. See Section 7 below.
- Portability: You can request a copy of your data in a machine-readable format.
- Objection: You can object to certain processing by discontinuing use of the service.
To exercise any of these rights, email privacy@cuebirdai.com. We will respond within 30 days.
7. Deleting Your Account & Data
You can delete your account and all associated data in two ways:
- In-app: Go to Account Settings → Delete Account. This permanently deletes your profile, all uploaded resumes, all stories, all jobs, all session history, and your subscription record. This action cannot be undone.
- By email: Send a request to privacy@cuebirdai.com from the email address associated with your account. We will process your deletion within 14 days and confirm via email.
Upon account deletion, all your personal data is permanently removed from Supabase (database and storage). Stripe customer records are deleted from Stripe. Anonymized usage counts may be retained for aggregate statistics.
8. Children's Privacy
Cuebird is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
9. International Data Transfers
Cuebird is hosted on Fly.io in the United States (iad region). Our third-party providers (OpenAI, AssemblyAI, Supabase, Stripe) operate globally. By using Cuebird, your data may be processed in the United States and other jurisdictions. We rely on standard contractual clauses and provider Data Processing Agreements where required.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the app. Continued use of Cuebird after changes constitutes acceptance of the updated policy.
11. Contact
For privacy-related inquiries, contact us at:
Email: privacy@cuebirdai.com
Website: https://cuebirdai.com