Your Privacy Matters

Privacy Policy

Your data is yours. This page explains, in plain terms, exactly what Cuewise does — and doesn't do — with it.

Last Updated: August 8, 2026

Our Commitment

Cuewise is built privacy-first. Your productivity is personal, and your data should stay yours alone — so we designed the extension to keep it that way.

By default, we do not collect, store, or share any of your personal information on our servers. If you choose to turn on the optional Cloud Sync, your data is end-to-end encrypted on your device before it is sent — our servers store only ciphertext they cannot read (see the Cloud Sync section below).

What Data We Collect

Extension Usage Data:

  • Your daily goals and tasks (stored locally on your device)
  • Your preferences and settings (stored locally on your device)
  • Your progress and completion history (stored locally on your device)

Newsletter Subscription (Optional):

  • Email address (only if you choose to subscribe to our newsletter)
  • Subscription timestamp

Newsletter subscriptions are completely optional and separate from extension usage.

Uninstall Feedback (Optional):

If you fill in the optional feedback form after uninstalling, we receive exactly what you submit — the reason you picked, anything you typed, and the extension version — as a one-off email. Nothing else is attached, and we have no way to link it to you.

How We Store Your Data

Local-First Storage:

By default, all your goals, tasks, and productivity data are stored exclusively on your device using your browser's local storage. This means:

  • We never see your personal data
  • Your data doesn't leave your device unless you turn on an optional feature that needs it: the end-to-end encrypted Cloud Sync, the Google Calendar agenda, or the Weather widget. Each is off until you switch it on, and each is described in its own section below. Background photos are the one thing fetched without asking — see "Third-Party Services" for what Unsplash can see
  • No servers store your productivity information in readable form — with sync off, they store nothing at all
  • You have complete control over your data

Newsletter Data:

If you subscribe to our newsletter, your email is stored securely and used only to send you:

  • Product updates and announcements
  • Tips for mindful productivity
  • Feature releases and improvements

Google Calendar Integration (Optional)

Cuewise offers an optional, opt-in Google Calendar connection so you can see today's schedule beside your timer. It is off by default and only activates when you click "Connect Google Calendar" and grant access through Google's own consent screen.

Google user data we access:

  • Read-only access to your primary Google Calendar, and nothing else, via the single https://www.googleapis.com/auth/calendar.readonly scope.
  • Only events for the current day are requested. For each event we read its title, start and end time, color, status, your own attendance response, and a link back to the event in Google Calendar.
  • We do not access your Google profile, email address, contacts, other calendars, or any past or future days beyond today.

How we use this data (Data Usage):

  • Sole purpose: to display your remaining events for today as an "Up next" agenda alongside your focus timer. The data is used for no other purpose.
  • Processed in your browser: events are fetched, filtered (cancelled and declined events are hidden), and rendered entirely on your device. No human at Cuewise ever sees your calendar data.
  • No secondary use: your Google Calendar data is never used for advertising, profiling, training models, analytics, or any feature other than the agenda display described above.

How we store and protect this data (Data Storage & Protection):

  • No Cuewise servers: the extension requests calendar data directly from Google's API in your browser. It never passes through, and is never stored on, any Cuewise or third-party server.
  • Encrypted transport: all requests to Google are made over HTTPS (TLS), so the data is encrypted in transit.
  • Secure token handling: the OAuth access token is issued and stored by your browser's built-in Chrome Identity service, not by Cuewise. Cuewise never receives, stores, or has access to your Google password.
  • Sandboxed local storage: the fetched events are cached only in your browser's extension storage, which is sandboxed to your device and isolated from other sites and extensions.
  • Minimal retention: only the current day's events are kept; they are refreshed each day and are deleted immediately when you disconnect the calendar or uninstall the extension.
  • Read-only and revocable: Cuewise never creates, edits, or deletes calendar events. Disconnecting revokes the access token and removes the permission, and you can revoke access at any time at myaccount.google.com/permissions.

Limited Use:

Cuewise's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is never sold, never used for advertising, and never transferred to others — because access is entirely client-side, it is not transferred to us at all.

Cloud Sync (Optional)

Cuewise offers an optional, opt-in Cloud Sync so your goals, quotes, and reminders follow you across devices. It is off by default and only activates when you sign in from the Cloud Sync settings. With sync off, nothing in this section applies — Cuewise works fully offline.

End-to-end encrypted — we cannot read your data:

  • Your synced data (goals, quotes, collections, reminders, and settings) is encrypted on your device with AES-256-GCM before it is sent. Our servers store and relay only that ciphertext — they never see, parse, index, or log its contents.
  • The encryption key is created on your device and never sent to us in a readable form. It is protected by a recovery code that only you hold — which also means we cannot recover your synced data for you if you lose the recovery code and all of your devices.

What our servers do store:

  • Account: the email address from your sign-in provider (e.g. Google), used only to identify your account.
  • Devices: a name for each signed-in device and its session, so you can recognize them.
  • Sync metadata: timestamps and sequence counters needed to order changes. None of this reveals the content of your data.

Your controls:

  • Turn it off any time: disabling sync stops all syncing immediately; your local data is unaffected.
  • Export: you can export everything your account has stored.
  • Delete: deleting your account removes your user record, sessions, key material, and every synced record from our servers.

Weather (Optional)

Cuewise offers an optional, opt-in Weather widget. It is off by default and only activates when you turn it on and search for a city. It is the one feature that sends anything about where you are to a Cuewise server, so here is exactly what happens.

We never read your device's location:

  • Cuewise does not use your browser's location permission, GPS, or your IP address to work out where you are. It never asks, because it never uses it.
  • You choose a city yourself by typing its name. The forecast is for the city you picked — nothing more precise, and nothing we inferred about you.

What is sent, and how little of it:

  • For the forecast: the coordinates of the city you chose, rounded on your device to about 1 km before they are sent, plus whether you prefer °C or °F. The rounding happens on your device deliberately — precise coordinates never leave it in the first place.
  • For city search: the text you type into the search box, so we can look up matching places.
  • Nothing is attached that identifies you — no account, no device id, no name. The Weather widget works whether or not you have ever signed in.

Why it goes through our server at all:

  • Forecasts come from Open-Meteo. Your browser never contacts them directly — our server asks on your behalf, so the weather provider never sees your IP address, your browser, or that you exist as a distinct person.
  • Nearby users share a single cached request upstream, so the provider sees a place being asked about, not a stream of individual lookups.

We do not keep it:

  • Nothing is stored. The weather requests touch no database and create no record. They are answered and forgotten.
  • Nothing is logged. Coordinates and city searches are never written to our logs. The requests are deliberately built so that this data cannot appear in server logs even by accident, and an automated test fails the build if that protection is ever removed.
  • Turn the widget off, and Cuewise stops contacting the weather service entirely.

What We Don't Do

  • No Tracking: We don't track your browsing activity or behavior
  • No Analytics: We don't use third-party analytics services
  • No Selling: We never sell, rent, or share your data with third parties
  • No Advertising: We don't use your data for advertising purposes
  • No Profiling: We don't create profiles or analyze your habits

Your Rights

You have complete control over your data:

  • Access: All your data is stored locally and accessible to you at any time
  • Delete: You can delete your local data by clearing your browser's local storage or uninstalling the extension; if you used Cloud Sync, deleting your account removes everything from our servers too
  • Export: Your data is stored in standard browser storage format, and synced data can be exported from your account
  • Unsubscribe: You can unsubscribe from our newsletter at any time using the link in any email

Third-Party Services

Cuewise uses minimal third-party services:

  • Email Delivery: We use Resend to send newsletter emails. They only have access to your email address if you subscribe.
  • Chrome Web Store: Extension downloads are managed by Google according to their privacy policy.
  • Google Calendar (optional): if you connect it, the extension reads your calendar directly from Google's API; the data stays client-side and never reaches our servers. See "Google Calendar Integration" above.
  • Open-Meteo (optional): if you turn on the Weather widget, forecasts come from Open-Meteo — but only ever via our server, so they never see you. See "Weather" above.
  • Unsplash: the background photos behind the glass theme and Focus mode are loaded straight from Unsplash's image CDN, so Unsplash sees the request — your IP address and browser, nothing more. No account, no identifier, and nothing about your goals or quotes. These photos load only when you use the glass theme, start Focus mode, or open the Pomodoro page; on the other themes nothing is fetched.
  • YouTube (optional): if you play a focus playlist, the player is YouTube's and they see it as an ordinary YouTube view, subject to their privacy policy. Nothing plays until you choose a playlist.

Fonts are bundled with the extension rather than fetched from a font service, so opening a new tab reaches no third party at all.

When This Policy Changes

If this policy ever changes, we'll:

  • Update the "Last Updated" date at the top of this page
  • Notify users through our newsletter (if subscribed)
  • Continue to respect your privacy as our top priority

Questions?

If anything here is unclear, or you just want to ask about your data, we're happy to help:

Your Data, Your Device

That's the whole story. Head back and turn your next tab into a moment of intention.