PrivateCue
How it worksPricingTaxonomyFAQAlready sent money?
How it worksPricingTaxonomyFAQAlready sent money?
Sign in Get started
Legal

Privacy policy

Last updated 28 September 2026

Written to be read, not to be survived. The most important fact about PrivateCue is structural: conversations and screenshots stay on your device.

Conversation stays localScreenshot OCR stays localStored data is named below
Your deviceText · screenshots · findings
only limited metadata
PrivateCueAccount · usage · billing
Blocked by designConversation textScreenshot filesMatched phrases
The short versionWho we areWhat we collectWhat we never collectWhere analysis happensWhy we process what we processHow long we keep itWho we share it withCookiesSecurityYour rightsCalifornia residentsChildrenInternational transfersChanges to this policyA note on what this policy cannot cover

The short version

If you take nothing else from this page: the conversation you paste into PrivateCue is analysed inside your own web browser and is never sent to us. We cannot read it, we do not receive it, and we have deliberately built our system so that there is nowhere to put it.

We do not have a database column, a log field, a cache entry or an analytics event that can contain your conversation text. This is not a promise we are trying to keep — it is a structure we chose so that we could not break it accidentally. Our automated test suite fails the build if such a field is ever added.

Who we are

PrivateCue ("PrivateCue", "we", "us") operates the website and application at the address you are currently using. We are the data controller for the account information described below.

Email privacy@privatecue.com for privacy matters, or support@privatecue.com for everything else.

What we collect

We collect the minimum needed to run an account, enforce plan limits, and take payment. Specifically:

  • Account data. Your email address, your password in salted-hashed form (scrypt, never reversible), and optionally a display name you choose.
  • Session data. A random session identifier. Only its cryptographic hash is stored, so a database leak cannot be replayed as a signed-in session. We record the IP address and user-agent string present at sign-in, for security investigation.
  • Usage metadata. For each analysis you run, signed in or not: the timestamp, the resulting risk band, the numeric score, the word count of the text you analysed, and the country you selected for reporting links. If you are not signed in, the row is attached to your anonymous visitor id rather than to an account — that is how the free allowance is counted.
  • Site analytics. Our own, first-party, and described here because the honest answer to "do you run analytics" is that we count pages. For each page load we record an anonymous visitor id (a random string in a first-party cookie, not tied to your identity or your account), the page path, a coarse device type — desktop, mobile or tablet — and the referring hostname only, never the full referring URL, which can carry a path and query belonging to the previous site. We do not record IP addresses, user-agent strings, query parameters or any third-party advertising identifier. We use it to know which pages are read and where visitors come from, and for nothing else. We do not sell it and we do not use it to target advertising.
  • Billing data. Your payment processor's customer identifier, the plan purchased, the amount, the currency, and the payment status.
  • Family workspace data. If you use Family: the household membership, member email addresses visible to the organiser and other members, pending invitation address and expiry, and any metadata-only risk alert a member explicitly shares. A shared alert contains the checker type, score, band and time only. It never contains conversation text, matched phrases or a full report.
  • Email deliverability data. Whether a verification or reset email was sent, and whether the link was used.
  • Support, partner and demo enquiries. If you submit a contact form, we receive the contact details, category and message you enter. The partner form additionally asks for organisation, role, organisation type and approximate audience. These forms are separate from the analyzers and are sent only because you explicitly ask us to respond.

What that usage metadata is not: it is not your conversation. Word count and score band tell us the product is being used and how it is performing. They cannot be reversed into what anyone said to you.

What we never collect

  • The text of any conversation you analyse. Not transmitted, not stored, not logged, not cached.
  • Photos, screenshots, audio or video. When you select screenshots for conversation or phishing OCR, the image files are read on your device and are never uploaded to PrivateCue or an external OCR provider. The extracted text remains in the browser for you to review before analysis. We do not receive either the image or that text.
  • Names, phone numbers, email addresses, wallet addresses or other identifiers appearing inside a conversation. These are extracted and scored in your browser and discarded when the tab is closed or the report is cleared.
  • Your contacts, location, camera, microphone or clipboard. We request no browser permissions. Our pages send a Permissions-Policy header explicitly disabling camera, microphone, geolocation and payment APIs.
  • Third-party advertising or analytics identifiers. We run no analytics SDK, no advertising pixel, no cross-site tracking and no third-party cookies on any page of this product, including the pages where analysis happens. The first-party page counting described above is ours, stays on this server, and counts pages rather than profiling people.
If we ever add a marketing pixel — for example to measure advertising — it will be placed on public marketing pages only, never on the analyzer or any authenticated page, and this section will be updated first rather than afterwards.

Where analysis happens

The scoring engine is JavaScript delivered to your browser and executed locally. The taxonomy of fraud scripts — the patterns, weights and reasoning — is downloaded once with the page. Matching, scoring, timeline reconstruction and report rendering all happen on your device.

Screenshot text extraction works the same way. The OCR runtime, WebAssembly core and English language model are served by PrivateCue, then execute in a worker on your device. The selected image is not posted to our server, and OCR does not automatically analyse anything: you see and can correct the extracted text first.

When you run an analysis while signed in, your browser sends us a short metadata record so we can apply your plan limit and, on paid plans, show your history. That record contains: a request to increment your usage counter, the risk band, the numeric score, the word count, the checker used, and your selected country. It does not contain the conversation, any fragment of it, or any identifier extracted from it.

You can verify this yourself with your browser's developer tools. Open the Network tab before analysing a conversation and inspect every request — you will see the metadata fields listed above and nothing else. We would rather you checked than trusted us.

Why we process what we process

Where the GDPR or UK GDPR applies, our lawful bases are:

  • Contract (Article 6(1)(b)) — account data, session data and usage metadata, to provide the service you signed up for and to apply the plan limits you agreed to.
  • Legitimate interests (Article 6(1)(f)) — security logging, fraud prevention against our own service, and abuse rate-limiting. Our interest is preventing credential stuffing and account takeover; the impact on you is limited because we store hashed values and short retention windows.
  • Legal obligation (Article 6(1)(c)) — retaining billing records for the period required by applicable tax law.
  • Consent (Article 6(1)(a)) — support, privacy, partner and demo enquiries, and any future product emails beyond transactional ones. You can withdraw consent at any time without affecting the service.

How long we keep it

  • Sessions: 30 days from creation, or until you sign out. Expired sessions are pruned automatically.
  • Email verification and password-reset tokens: 24 hours and 1 hour respectively, and single-use. Revoked tokens are marked used rather than retained as valid.
  • Usage metadata attached to an account: for the life of the account. It is the smallest data we hold and it is what powers your history.
  • Family invitations: until accepted, cancelled or expired after seven days. Membership lasts until the member leaves, the organiser removes them, the organiser deletes the household, or the subscription ends. Revoked shared alerts stop appearing in the workspace.
  • Usage metadata with no account: 90 days, then deleted automatically. It exists only to count the free allowance.
  • Site analytics: pageview rows 90 days, security event rows 30 days, both pruned automatically.
  • Billing records: for the period required by applicable tax and accounting law — typically six to seven years — after which they are deleted.
  • Support, privacy, partner and demo enquiries: in the relevant support or privacy inbox for up to 12 months after the last contact, then deleted unless a continuing business or legal reason requires the correspondence. You can ask us to delete it sooner.
  • Account data: until you delete your account, which is immediate and permanent.

Because we never hold conversation text or screenshots, there is no analyzer-content category whose retention you need to manage. The identifiable information we hold is limited to account, billing, Family and any support or partner-enquiry details you deliberately provide.

Who we share it with

We do not sell, rent or trade personal data. We share only with processors who need it to operate the service, under written terms:

  • Payment processing — Stripe, if and when you purchase a plan. Card details go directly to Stripe and never touch our servers; we receive only a customer identifier and payment status.
  • Email delivery — our email provider, for verification, password reset, Family invitations, receipts, support messages and partner/demo enquiries. Form enquiries are delivered to our support or privacy address with your email as the reply-to address. If no provider is configured, development messages are written to the server log instead of being sent.
  • Hosting infrastructure — the provider hosting this application.
  • Law enforcement — only in response to a valid, lawful order, and only for the data we actually hold. We will notify you unless legally prohibited, and we publish the number of requests received.

We use no advertising networks, no data brokers, no behavioural-analytics providers and no AI model providers. Your conversation text is never sent to a third-party model API — the analysis is pattern-matching that runs on your own device.

Cookies

We use three first-party cookies and no third-party cookies:

  • tt_session — HttpOnly, SameSite=Lax, Secure in production. Keeps you signed in. 30 days.
  • tt_csrf — readable by the page's own scripts by design. This is the double-submit token that prevents another site from making requests on your behalf. 30 days.
  • tt_vid — an anonymous visitor id, readable by the page's own scripts, set for everyone whether or not they have an account. It counts the pages you visit and, if you are not signed in, how many of your free analyses you have used. It is a random string that identifies a browser and nobody. One year, or until you clear it — clearing it resets the free-analysis count, and we would rather you knew that than found it out.

We also use browser localStorage for one value: your light or dark theme preference. That is not transmitted to us.

tt_session and tt_csrf are strictly necessary for the service you requested. tt_vid is not strictly necessary in that narrow sense: it counts pages and keeps the free-analysis allowance honest. It carries no advertising, no third parties and no profiling, so no consent banner is shown — but it is disclosed here rather than left for you to find in your browser. If we ever add a cookie that is genuinely non-essential, we will ask first.

Security

  • Passwords are hashed with scrypt (N=16384, r=8, p=1) using a unique 16-byte random salt per account, and compared in constant time.
  • Session and reset tokens are 256-bit cryptographically random values. Only SHA-256 hashes are stored.
  • All state-changing requests require a valid CSRF token.
  • Session cookies are HttpOnly, SameSite=Lax, and Secure in production.
  • Rate limiting is applied per IP address and, where relevant, per account across signup, sign-in, password reset, contact forms and analysis.
  • New passwords are screened against known breach corpora and weak-pattern rules.
  • Security headers are set on every response, including X-Content-Type-Options, X-Frame-Options DENY, Referrer-Policy and Permissions-Policy.
  • Data at rest is written with restrictive file permissions and atomic replacement so a crash cannot leave a half-written database.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority within the timeframes required by applicable law, and we will say plainly what was and was not exposed.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, port, or object to the processing of your personal data, and to withdraw consent.

  • Access and portability: email us and we will send you everything we hold about you in a machine-readable format. Given how little that is, we aim to do this within 7 days rather than the 30 we are entitled to take.
  • Deletion: delete your account from your dashboard. It is immediate, permanent, and does not require emailing anyone or explaining yourself.
  • Correction: change your display name and password from your dashboard at any time.
  • Objection and restriction: email us. Because we process so little and hold no conversation content, we can usually simply stop.

Email privacy@privatecue.com for privacy matters, or support@privatecue.com for everything else.

European Union and EEA: you may complain to the supervisory authority in your member state. United Kingdom: the Information Commissioner's Office, ico.org.uk. California: the California Privacy Protection Agency, cppa.ca.gov. We will not treat you differently for exercising a right, and we do not require you to create an account with a third party to make a request.

California residents

Under the CCPA and CPRA: we do not "sell" or "share" personal information as those terms are defined. We collect the categories listed under "What we collect" for the purposes listed there. You have the right to know, delete, correct, and limit use of sensitive personal information — though note that we do not collect any of the CCPA's defined categories of sensitive personal information, because we never receive your conversation content. You may designate an authorised agent to make a request on your behalf; we will ask for proof of that authorisation and will not require you to give the agent your password.

Children

PrivateCue is not directed at children under 16 and we do not knowingly collect their data. We recognise that sextortion disproportionately targets teenagers, and that a teenager may be the person who needs this tool. If you are under 16 and worried about a conversation, you do not need an account to get help: the free reporting contacts and verification steps published on this site are complete and require nothing from you. If you are a parent or guardian who believes a child has provided us data, contact us and we will delete it promptly.

International transfers

Our infrastructure is hosted in the region we operate from. If personal data is transferred across borders, we rely on the applicable lawful transfer mechanism — the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision — and we will tell you which on request.

Changes to this policy

If we change this policy in a way that materially reduces your privacy, we will say so prominently on the site and by email before the change takes effect, not after. We will never quietly expand what we collect. The date at the top of this page is the date the current version took effect; previous versions remain available on request.

A note on what this policy cannot cover

This policy describes what we do with your data. It cannot protect you from what the person you are analysing has already done with it. If you are in a conversation where your messages, photos or identity may already have been captured by someone acting in bad faith, treat that as a separate and more urgent problem, and read the guidance in your report — including the warning about recovery scams, which specifically target people who have just been defrauded.

PrivateCue

Patterns made visible.
Decisions left with you.

Private fraud checks against an inspectable rulebook. Conversation and screenshot text stays on this device.

Privacy boundary
Your deviceMessage or screenshot
→
Local rulesPattern analysis here
× Text upload× Transcript storage× Person verdict

Understand

How it works Open rulebook Limits and honesty Case files Questions answered

Check

Phishing message Link and claim Job offer Buyer or seller Investment approach Recovery agent

Act

How to report Report portal Plans and pricing Your account Contact and support

PrivateCue

About Partner with us Field notes Privacy policy Terms of use
!
Already sent money?

Call your bank or payment provider now using the number on your card, statement or official app. Recovery windows can close within hours.

Contact support →
Questions and account helpsupport@privatecue.com Privacy and data rightsprivacy@privatecue.com
Sources behind the rule library +

FBI IC3 Internet Crime Report 2025 · FTC Consumer Sentinel and the April 2026 romance-fraud release · City of London Police (May 2026) · AARP Fraud Watch Network (Feb 2026) · McAfee Labs 2026 · CFPB elder-fraud guidance · FINRA Rule 2165 and Trusted Contact guidance.

© 2026 PrivateCue. Not legal, financial or law-enforcement advice. PrivateCue reports resemblance to documented fraud scripts; it never makes a finding that a specific person committed a crime. In immediate danger, contact local emergency services.