Privacy Policy

Last updated: 20 September 2026

cueFlow Pty Ltd ("we," "us," or "our") respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains what information we collect, how we use and store it, the steps we take to keep it secure, and the limits of what we can promise or be held responsible for.

This Policy should be read together with our Terms and Conditions and our End User License Agreement. By using cueFlow, you agree to the collection and use of information as described here.

1. Information We Collect

We collect information in the following ways:

  • Account information: name, email address, and password (stored in hashed form) when your account is created.
  • Production content: cue sheets, markers, audio files, project data, and other content you upload or create using the Service.
  • Billing information: subscription and payment details, processed on our behalf by third-party payment processors such as Stripe. We do not store full payment card numbers on our own servers.
  • Usage information: log data, device and browser information, and how you interact with the Service, collected automatically to help us maintain and improve it.
  • Communications: information you provide when you contact us for support or other enquiries.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including account authentication and two-factor authentication
  • Process subscriptions, payments, and billing
  • Communicate with you about your account, updates, and support requests
  • Monitor, investigate, and prevent fraud, abuse, and security incidents
  • Analyse usage to improve the Service, diagnose problems, and develop new features
  • Comply with our legal obligations

We do not sell your personal information, and we do not use your production content to train third-party models without your consent.

3. Data Security

Precautions we take: We take the security of your data seriously and implement reasonable administrative, technical, and physical safeguards designed to protect it, including encryption of data in transit and, where supported by our infrastructure providers, at rest; access controls and role-based permissions; optional two-factor authentication; regular review of access to production systems; and reliance on reputable third-party infrastructure providers (including Supabase and Stripe) who maintain their own independent security programs.

No security is absolute: Despite these precautions, no method of transmission over the internet, and no method of electronic storage, is 100% secure. We cannot and do not guarantee the absolute security of your information, and we cannot guarantee that unauthorised access, hacking, data loss, or other breaches will never occur, including breaches resulting from circumstances beyond our reasonable control (such as attacks on third-party infrastructure, compromised credentials, or vulnerabilities in software we did not create).

Limitation of liability for security incidents: To the maximum extent permitted by applicable law, cueFlow Pty Ltd, its directors, officers, employees, and agents will not be liable for any unauthorised access to, alteration of, disclosure of, or destruction of your data, or for any other security incident or data breach, except to the extent such liability arises directly from our gross negligence or wilful misconduct. Nothing in this Policy limits any right you have under the Australian Consumer Law or the Privacy Act 1988 (Cth) that cannot lawfully be excluded or limited.

If a breach occurs: Where we become aware of a data breach that is likely to result in serious harm, we will take reasonable steps to contain and investigate the incident and will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where required under the Notifiable Data Breaches scheme.

Your responsibilities: You are responsible for keeping your account credentials confidential, using a strong password, enabling two-factor authentication where available, and promptly notifying us of any suspected unauthorised use of your account. We are not responsible for losses arising from your failure to safeguard your own credentials.

4. Data Storage, Retention and Backups

We retain your information for as long as your account is active or as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account and associated data at any time, subject to any information we are required to retain by law.

While we take reasonable steps to back up data, we are not a substitute for your own backup practices. As set out in our Terms and Conditions, you remain responsible for maintaining independent copies of any content that is critical to you.

5. Sharing Your Information

We do not sell your personal information. We may share information with:

  • Service providers: infrastructure, hosting, database, and payment providers (including Supabase and Stripe) who process data on our behalf under appropriate confidentiality and security obligations.
  • Legal requirements: where required to comply with a legal obligation, protect our rights, or respond to a valid request from a public authority.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to equivalent protections for your information.
  • With your consent: for any other purpose disclosed to you at the time we collect the information.

6. International Data Transfers

Your information may be stored and processed in Australia or in other countries where we or our service providers operate infrastructure. Where information is transferred overseas, we take reasonable steps to ensure it continues to be protected consistently with this Policy and the Australian Privacy Principles.

7. Your Rights

Subject to applicable law, you may:

  • Request access to the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of your account and associated personal information
  • Export your project data from the Service
  • Withdraw consent for optional processing, where consent is the basis for that processing
  • Lodge a complaint with us, or with the OAIC, if you believe your privacy has been breached

To exercise any of these rights, contact us using the details below.

8. Cookies and Similar Technologies

We use cookies and similar technologies that are strictly necessary to keep you signed in, remember your preferences (such as light/dark theme), and keep the Service secure. You can control cookies through your browser settings, though disabling them may affect the functionality of the Service.

9. Children's Privacy

cueFlow is intended for business and professional use and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can remove it.

10. Changes to this Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on this page and updating the "Last updated" date, and where appropriate, via email or through the Service. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:

cueFlow Pty Ltd

Email: legal@cueflow.com

Website: Contact Us