Privacy Policy
The short version
CueStep stores everything you create — cue tracks, cue points, labels, and favorites — locally on your device. We don't sell your data and we never upload your audio. The exceptions to the local-only rule are described below, and the big one is sharing: when you tap Share on a cue track, that track's details are uploaded so the link you send can be opened by someone else.
What CueStep stores on your device
- Apple Music library — only when you choose to add an Apple Music track. CueStep stores the song identifier so it can play the track again later.
- Local audio files — when you import a file, CueStep stores a security-scoped bookmark so it can re-open the file in future sessions. The file itself stays where you put it.
- YouTube links — when you paste a YouTube URL, CueStep stores the video ID locally so it can play the video again later.
Data sent off your device
- YouTube oEmbed — when you add a YouTube link, CueStep makes a one-time request to YouTube's public oEmbed API (no API key required) to fetch the video's title and thumbnail. Playback of the video uses YouTube's embedded player and is subject to YouTube's own privacy practices.
- Firebase Analytics — CueStep uses Firebase Analytics to understand which features are used and how the app performs in aggregate. The data collected is anonymous and aggregate (such as screen views, feature interactions, app version, device model, OS version, and a random app-instance identifier). We never send the content of your cue tracks, cue point labels, imported audio, song titles, or YouTube URLs to Analytics.
- Firebase Crashlytics — when CueStep crashes, Crashlytics sends Google a crash report so we can fix the bug. Reports include the stack trace, device model, OS version, app version, and a random installation identifier. They do not include the content of your cue tracks, labels, or imported audio.
- Sharing a cue track — only when you tap Share. This is the one case where something you created leaves your device. See Sharing a cue track below.
Sharing a cue track
Nothing is uploaded until you tap Share on a specific cue track. When you do, CueStep creates a share link and uploads that one cue track to our server so whoever you send the link to can open it.
What gets uploaded
- The track's title, artist name, and how long it is.
- Which source it came from (Apple Music, YouTube) and that source's identifier — the song ID or video ID.
- Every cue point on that track: its label and its timestamp.
Your audio is never uploaded. A shared cue track is only a set of references and timestamps. When someone opens your link, their own copy of the song plays from their Apple Music or from YouTube. If they don't have access to the source, they won't hear anything.
Local files can't be shared at all. Tracks you imported from your own audio files have no identifier that means anything on another device, so the Share button is turned off for them and nothing about them is ever uploaded.
Who can see a shared cue track
Anyone who has the link. A share link works without an account and without the app — opening it in a browser shows a page with the track's title, artist, and its first few cue point labels. Link previews work the same way: when you paste a share link into Messages, WhatsApp, Slack, or similar, that service fetches the page to build its preview card, which shows the track title.
Share links contain a random 20-character code, so they can't be guessed or found by browsing our site, and they can't be listed or searched. But treat a share link like a key: whoever you send it to can open it, and so can anyone they forward it to. Don't put anything private in a cue point label on a track you intend to share.
How long it's kept
Share links expire 30 days after you create them. Once expired, the link stops working immediately and the uploaded copy is deleted automatically. There's currently no way to cancel a link early — if you shared something by mistake, the link stops working after 30 days, or you can email us and we'll delete it.
Accounts
Sharing signs you in to Firebase anonymously. This is not a user account in any normal sense: there's no email, no password, no name, and nothing for you to create or manage. It's a random identifier that records which device created a share, so that only that device can delete it. It isn't connected to your Apple ID or to anything else about you.
What CueStep does not do
- No sign-up, no password, no email address — there's nothing to create and nothing to log in to.
- No advertising SDKs, ever.
- We never upload your audio files, and we never upload a cue track you haven't chosen to share.
- We don't store your library on our servers. Only the individual cue tracks you tap Share on are uploaded, and only for 30 days.
- No cloud sync (yet — if we add iCloud sync in the future, your data stays in your own iCloud account, not ours).
In-app purchases
Premium ($4.99, one-time) is processed by Apple via StoreKit. We never see your payment details. Apple's privacy policy applies to the transaction itself.
Children
CueStep is rated for general audiences. We never ask any user — child or adult — for personal information: no name, no email address, no account, no profile.
The one thing worth knowing is that cue point labels are free text, and the labels on a shared cue track appear on a public link page. If you're an instructor sharing routines with younger students, keep labels to the music itself — “Intro”, “Chorus”, “the turn we keep missing” — rather than anything about a specific person. Nothing is shared unless someone taps Share, and links expire after 30 days.
Changes to this policy
If we ever change how CueStep handles data, this page will be updated and the “Last updated” date above will change.
Contact
Questions? Email hello@cuestep.app.