This describes what the current code actually does, not aspirational policy.
Raw audio lives only in your browser's local storage (IndexedDB) until it has been transcribed, at which point it is deleted immediately — it is never uploaded to our servers. The retention window you set (3 days by default) applies only to audio that has not yet been uploaded (for example while offline); that backlog is swept away automatically once it expires.
Transcribed speech (text, not audio) and screen captions — short descriptions and salient text extracted from your screen — are uploaded to Gemini for processing and the resulting text is stored in our Postgres database, tied to your account.
Screen frames you flag as sensitive, or that match your blocklist words, are dropped before they are ever uploaded. This filter applies to screen captures only. Speech has no equivalent filter — everything you or people near you say while capturing is transcribed and uploaded. Do not use ambient capture around conversations you would not want recorded as text.
Gemini (Google) processes audio, screen frames, and text on our behalf to produce transcripts, captions, watch flags, and day reviews. Resend delivers transactional and digest email. Polar processes subscription payments; we do not see or store your card details. Neon hosts our Postgres database.
We use email-only sign-in (magic links). We do not store a password for your account — there is nothing to reset or leak.
From your account page you can export a copy of your traces, day reviews, and profile as JSON, or permanently delete your account and all associated data.
Connected accounts are read-only — earcue never sends or writes anything back to Gmail, Calendar, or Slack. Google access requests gmail.readonly and calendar.readonly; Slack access requests the user-scoped channels:history, groups:history, im:history, and users:read. OAuth tokens are stored AES-256-GCM encrypted, never in plaintext. Synced emails, events, and messages are deleted automatically after 30 days. Disconnecting a provider from Settings → Connections deletes that provider's synced items immediately.
Questions about this policy: reach us via the email address you signed up with, or the address on your billing receipt.