DeskCue
Privacy
Last updated: August 14, 2026
What we collect
If you submit a Cloud Preview or future-plan update request, we collect the email address, selected plan, optional workflow note, consent choice, and the time of submission.
Anonymous website analytics
We use a self-hosted Umami instance to understand aggregate website usage and performance. It records page views, referrers, browser, operating system, device type, approximate location, and Core Web Vitals. The tracker uses no cookies, does not store IP addresses, excludes URL queries and fragments, respects your browser's Do Not Track setting, and does not identify you across websites.
Why we use it
We use request data to respond about Cloud Preview and future plans, and send product updates only when you opt in. DeskCue does not sell this data.
Cloud accounts
Cloud registration and login take place in the separate DeskCue Cloud application, not on this static website. Cloud stores account, device, and machine identities together with a bounded session projection: opaque session ID, runtime family, lifecycle status, reply state, and update time. Passwords, verification codes, and session credentials must not be included in a Preview request.
Remote DeskCue data
Remote reads, Files, Diff, control, realtime, and Preview require capabilities enabled from the local daemon. Their payloads pass transiently through DeskCue Cloud while the daemon is online and are not stored as Cloud content or payload logs. The current relay uses TLS, but is not end-to-end encrypted: the Cloud service can process plaintext payloads in memory while relaying them.
Where it goes
Cloud request data is processed by the DeskCue Cloud service. Transactional messages may be delivered through our email delivery provider, currently Resend. Messages you send to our published contact addresses may be handled through our business email provider, currently Proton Mail. The local, self-hosted DeskCue application does not require DeskCue Cloud to work.
Product updates
Product updates are optional and require the separate checkbox in the request form. Operational messages about a request or account are transactional and are not treated as marketing consent. You can withdraw product-update consent at any time.
Your choices
You can ask to access, correct, or delete your request or Cloud account data, or unsubscribe from product updates, by emailing hello@deskcue.io.
Retention and security
Browser sessions expire after 30 days. Verification and reset challenges, together with encrypted pending email payloads, become eligible for bounded cleanup seven days after expiry or one day after use or invalidation. Preview requests and account records remain while the request or account is active and can be deleted on request, subject to limited security and legal records. Do not put source code, credentials, or other secrets in the optional workflow field.