Privacy policy
CueWeek runs on your Mac. The text of your posts and your Buffer tokens never reach our server; only media files pass through our storage, because Buffer fetches them from a web address. During the beta the app sends us counts about how you use it. Below we go through everything: what, where, why, for how long and how to delete it.
Who is the controller
The controller is Michał Liszcz, a sole trader operating as Motion Pikczer Michał Liszcz, tax ID (NIP) 5170271864, ul. gen. Romualda Traugutta 23, 95-039 Sokolniki-Las, Poland. For anything about personal data write to [email protected] or [email protected].
CueWeek is an independent app. It integrates with the Buffer API but is not a Buffer product and is not endorsed by Buffer. Buffer, Inc. (USA) is a separate controller of your Buffer account and has its own privacy policy.
Data on your Mac
| Data | Where | Who can access it |
|---|---|---|
| Buffer access and refresh token, or Buffer API key | macOS Keychain, item app.cueweek.macos.buffer | only the app on your Mac |
| Copy of channels, organizations and posts fetched from Buffer | ~/Library/Application Support/app.cueweek.macos | only you and the app |
| Local drafts, view settings, license file, random installation ID, usage counters | same as above | you and the app; the ID and counters go into the beta report (below) |
| Brand voice, a description of an account’s style, if you save one | same as above, folder glos | you and the app; the AI assistant when you use it (below) |
| Media files you add to a post | your disk; a copy in our storage (below) | Buffer at the time of publishing |
The app has no advertising analytics or tracking. It connects to Buffer, to our media storage, to the license server cueweek.app/api and to the update server on GitHub. It starts the AI assistant only when you use it yourself. Once sales start, a payment provider will be added.
Beta sign-up, license and beta report
You join the beta through the form on cueweek.app or get an invite from me. The form collects your full name and email; we also store the page the sign-up came from and its language. For one day we keep a hash of your IP address to limit sign-ups from a single network. For every new sign-up I get an email with the name, email address and page, and with the city, country and provider derived from the IP address.
An invite contains a name and, where we know it, an email. The license server records when you first opened the invite page and when you downloaded the app. At activation it stores a random ID of your installation, your IP address and the city, country and provider derived from it, and sends me an activation email. At launch and after syncing with Buffer, at most every 10 minutes, the app sends:
- Mac model, processor, memory, and macOS and CueWeek version (since version 2.5.2 without the computer name);
- the names of your Buffer accounts and channels with their service (e.g. Instagram);
- post counts: sent in the last 28 days, scheduled, drafts and errors;
- usage counters: how many posts were added, scheduled and deleted in CueWeek, how many times a post caption was changed in it, how many times and on how many days the app was opened, the date of the first launch and the time of the last sync.
We never send post text, photos, videos, links, tokens or passwords. The data is stored in a Cloudflare D1 database. Only the app’s author sees it, in the beta panel, and notifications go to his mailbox.
Legal bases: the sign-up, invite and license serve the performance of the beta participation agreement (Art. 6(1)(b) GDPR). The beta report, the IP address from activation and the invite-opening data serve our legitimate interest in testing, improving and supporting the beta, and the IP hash from the form serves protecting the form against abuse (Art. 6(1)(f) GDPR). Giving your name and email is voluntary, but without them we cannot give you beta access. The beta report also refreshes the license, so the beta does not work without it.
We delete beta data, including the notification emails, when the beta ends or earlier at your request sent to [email protected]. You can also object to the beta report at any time; we then switch off your invite and delete the data, and the app returns to the activation screen.
Buffer: what we pass on and why
When you click “Connect Buffer” you log in to your own account in the browser and grant the scopes:
account:read, the list of your organizations and channels;posts:read, your posts, to show the week and the month;posts:write, creating, editing and deleting the posts you order in the app;offline_access, refreshing access without logging in every hour.
Data travels directly between your Mac and api.buffer.com. It does not pass through our servers. The page cueweek.app/oauth/callback only hands the one-time code from the browser to the app and stores nothing. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
You can revoke access in two places: in CueWeek’s settings (“disconnect” next to the account) and in your Buffer account settings, which invalidates all CueWeek tokens.
Media: storage for the time of publishing
Buffer does not accept files directly; it fetches them from a web address when it publishes. So a file you add to a post goes from your Mac to our Cloudflare R2 storage under a random name, without the file name or the path on your computer. The file is available at that random address to anyone who knows it; we pass the address to Buffer. Together with the file we store a small JPEG thumbnail (480 pixels) that the app shows on the post tile.
The app deletes the original at the first sync after one hour has passed since the post was published. An original the app has not deleted earlier (e.g. the post stayed in drafts or the upload was interrupted) is deleted automatically by the storage 45 days after upload. Thumbnails are deleted automatically after 400 days. We do not look at your media. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
AI assistant
CueWeek can draft a post caption or walk you through setup with Claude Code or the Claude app (Anthropic) or Codex (OpenAI), if you have them installed and signed in on your Mac. The app then hands that tool, on your Mac, the data the task needs: the channel name and service, the publishing day, your guidelines, the current caption draft, frame descriptions or file names, up to five recent published posts from the channel and the brand voice. An assistant connected to CueWeek can also read the posts from a chosen week and read and save a brand voice.
The tool sends that data to Anthropic or OpenAI under your own agreement with that company and its privacy terms. We do not receive this data. Without such a tool installed, the feature is off.
The cueweek.app website
The website runs on Cloudflare Pages. We count visits with Pirsch (Emvi Software GmbH, Germany), which uses no cookies and does not store IP addresses: it builds a hash from the IP address, browser data, the date and a random salt, which cannot recognize a visitor after one day. We also count clicks on buttons leading to the beta. Pirsch does not run on the beta page, on the Buffer return page or in the author’s panel. Legal basis: our legitimate interest in measuring which content works (Art. 6(1)(f) GDPR).
The home page stores one cookie, cueweek_lang, with the site language (pl or en) for one year, so the next visit shows the same language. It is not used for tracking.
Buying a license
The payment provider will be named here before sales start; until then the app is not sold. Once sales start, a purchase gives us your email address, full name or company name, tax ID (for a company invoice), the amount and the date. We will issue the invoice in Fakturownia. Legal bases: performance of the contract and tax obligations (Art. 6(1)(b) and (c) GDPR). We keep sales documents for the period required by tax law, as a rule 5 years from the end of the calendar year in which the tax payment deadline passed. The license file contains none of your Buffer data.
Messages and reports
The “Send Feedback…” command in CueWeek’s menu opens your mail app with a message to [email protected], to which the app adds the CueWeek version, macOS version, Mac model and the name from the license. You see the whole message and send it yourself. Mail to [email protected] lands in the author’s Microsoft 365 mailbox. We keep correspondence for up to 12 months after the matter is closed. Legal basis: our legitimate interest in answering messages and handling reports (Art. 6(1)(f) GDPR).
Who we share data with
| Entity | Role | What it receives |
|---|---|---|
| Buffer, Inc. (USA) | separate controller | your publishing instructions, post text, media addresses (directly from your Mac) |
| Cloudflare, Inc. (USA) | processor: website hosting, license server and beta database, media storage, forwarding mail to [email protected] | beta data, media files, emails, technical connection data |
| Emvi Software GmbH (Pirsch, Germany) | processor: website visit statistics | a hash of the IP address and browser data, pages visited |
| Microsoft (Microsoft 365) | processor: email | messages and sign-up and activation notifications |
| GitHub, Inc. (USA) | hosting of app and update files | IP address and technical request data when you download the app and when it checks for updates |
| Fakturownia sp. z o.o. | processor, once sales start | invoice data |
Buffer, Cloudflare, Microsoft and GitHub may process data outside the European Economic Area, in particular in the USA. Transfers rely on the European Commission’s adequacy decision (EU-US Data Privacy Framework) or on standard contractual clauses, depending on the entity.
Your rights
You have the right to access your data, to have it corrected, deleted, restricted and ported, and, where processing is based on our legitimate interest, the right to object. You can lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) or with the data protection authority in your country. For beta, purchase and correspondence data, write to the address at the top of this page.
You delete the app’s data yourself: “disconnect” next to an account in CueWeek’s settings removes the token from Keychain, and deleting the folder Application Support/app.cueweek.macos removes the copy of Buffer data, drafts and brand voices.
We do not make decisions about you based solely on automated processing, including profiling.
Changes
We publish changes on this page with a new version date. We also announce significant changes in the app’s release notes.