Selected text and prompts
CueDraft sends selected text, editable working text, and your instruction only to the provider you choose for the action. CueDraft does not send that content to a CueDraft account service.
Ollama
Ollama can run on your Mac or at another server URL. If you configure a remote server, the text is sent to that server. Its operator and policies determine how it is handled.
Claude CLI, Codex CLI, Cursor Agent, and Gemini CLI
CueDraft invokes the installed command-line tool using its existing provider-managed sign-in. Provider services may receive and process the request under their own terms and privacy policies. CueDraft does not read or store provider API keys. For Gemini, CueDraft supports the cached Sign in with Google flow and removes Gemini and Google API-key variables from the process it starts.
Local data
Preferences, shortcuts, provider choices, and custom presets are stored locally on your Mac. Temporary source edits and review results are cleared when the Quick HUD session is dismissed or delivered.
Anonymous product analytics
Share anonymous usage analytics is enabled by default and can be turned off at any time in CueDraft’s General Settings. Turning it off immediately stops collection, removes queued events, and clears the random analytics identifier stored on that Mac. Analytics never blocks writing, generation, or downloads.
CueDraft can report first launch, intentional daily activity, Quick Command, Quick Fix, workspace use, generation, delivery, preset creation, cancellation, and coarse failure outcomes. Allowed context is limited to provider family, action, trigger, HUD or workspace surface, delivery method, outcome, duration bucket, app version and build, macOS major version, and processor architecture. Each installation uses a random UUID; the server replaces it with a keyed one-way hash before storage. CueDraft does not use a hardware identifier or connect analytics to an email address.
CueDraft explicitly does not send selected or editable text, prompts, generated results, preset names or instructions, source-app names, URLs, file paths, window titles, clipboard data, CLI output, model names, provider output, or raw error messages. The ingestion service rejects fields and values outside its coarse allowlist.
Download measurement
Release downloads remain direct file links. A dedicated download log records only time, a temporary request identifier, release path, response status, byte range, and bytes transferred—never IP address, user agent, or referrer. Hourly processing turns those records into version and artifact totals, then estimates completed-download equivalents by dividing bytes served by the signed artifact size. Sparkle update traffic is reported separately from new downloads. Request identifiers are not stored in the analytics database.
Retention and access
Raw coarse product events are retained for 90 days. Anonymous per-install daily usage is retained for up to 13 months. Identifier-free daily aggregates and download trends may be kept for historical comparison. The private analytics dashboard exposes aggregate reports only and does not provide installation-level browsing or device timelines.
Website and security logs
The website uses no advertising, tracking cookies, or third-party analytics. The hosting infrastructure keeps ordinary security access logs for availability, abuse prevention, and incident response. Those logs may include request time, IP address, requested path, user agent, response status, and a diagnostic request identifier; they are bounded and rotated after 14 days and are not exposed in the analytics dashboard.
Accessibility and clipboard
Accessibility permission lets CueDraft read the focused selection and replace text you explicitly approve. Passive monitoring does not use the clipboard. A guarded paste fallback may temporarily use it for a requested replacement; CueDraft restores the previous clipboard content and verifies the result.
Contact
Privacy questions can be sent to support@cuedraft.com.