Privacy
Last updated August 7, 2026
CueIQ is sales software operated by Code Consulting LLC. It stores the contacts you work, connects to accounts you already own, and sends text to a language model using a key you supply. This page says what that means for the data involved — in plain words, without the throat-clearing.
Two different sets of people
Almost everything below distinguishes between two groups, because the answers are genuinely different for each.
You — the person with a CueIQ login. You gave us your details directly by signing up.
Your contacts — the prospects and customers whose records live in your workspace. They did not sign up for CueIQ and most will never hear of it. CueIQ holds their data on your behalf: you decide what goes in, who is contacted, and what is said. You are responsible for having a lawful reason to hold and contact them, and for honouring their requests about that data. If one of them asks us directly, we will point them to you and help you act on it.
What CueIQ stores about you
- Your name, work email, and the company name you enter at signup.
- Your password, held by our authentication provider as a hash. Nobody at CueIQ can read it, which is also why a lost password is reset rather than looked up.
- Your workspace: its name, your company's website, and the profile CueIQ learns about your business during onboarding so it can write in your voice.
- Which integrations you have connected, and credentials for them — OAuth tokens for Gmail or Outlook, an Apollo key, a HubSpot connection, a LinkedIn session — stored encrypted.
- Your language-model provider, chosen model, and API key, stored encrypted.
- Ordinary product and operational records: what a run did and when, an activity log of actions taken in the workspace, and per-generation token counts and latency so spend can be shown back to you.
What CueIQ stores about your contacts
For each person in your workspace, whatever you or your sources provide: name, job title, seniority and department, employer, work email and whether it verified, LinkedIn profile URL, phone number, and general location — plus the raw record from wherever it came (an Apollo result, a CSV you uploaded), kept so a field can be traced back to its source.
CueIQ also keeps the outreach itself: emails and LinkedIn messages it drafted, which of them you approved and sent, replies it synced from your connected mailbox for those threads, and aggregate engagement counts such as opens, clicks, and replies per day. If you use the website-visitor feature, it stores the visit records that feature produces.
Why
To run the product you are paying for, and for nothing else. Contact data is there so CueIQ can research an account, draft outreach, and send it from your mailbox. Credentials are there so it can reach the accounts you connected. Logs are there so a run can be debugged and spend can be shown accurately.
We do not sell personal information, we do not share it for advertising, and we do not use your workspace data to train any model of ours. CueIQ has no model of its own — it calls the provider you configured, with your key, and what that provider does with the text is governed by your agreement with them. If that matters to you, read their terms; it is your account and your choice of provider.
Who else sees it
Only the services CueIQ needs to function. Each one gets the data required for its job and no more.
- Supabase
- Hosts the database and handles logins. Everything in your workspace lives here, including the encrypted credentials for your connected accounts. Supabase also sends the account emails — confirmation and password-reset links.
- Vercel
- Runs and serves the application. Requests pass through it, and its logs hold the ordinary things server logs hold: IP address, timestamp, path, user agent.
- Anthropic, OpenAI, or Google
- Whichever one you configure. CueIQ calls it with your own API key, on your own account, so the research and draft text — including contact details that appear in a prompt — goes to that provider under your agreement with them, not ours. You choose the provider and the model in Settings, and you can change or remove the key at any time.
- Apollo.io
- Only if you connect it. CueIQ searches Apollo for people and companies, enriches contacts you ask it to enrich, and — if you use Apollo for sending — pushes contacts and sequence copy into your Apollo account.
- Google (Gmail) or Microsoft (Outlook)
- Only if you connect a mailbox. CueIQ sends approved outreach through your own mailbox and reads replies to the threads it started, using tokens you grant and can revoke.
- Resend
- Sends product email from CueIQ to you — the weekly digest and similar notifications. It receives your email address and the contents of that message.
- Only if you connect it. CueIQ acts inside your own LinkedIn session for connection requests and messages you have approved. LinkedIn sees that activity as yours, because it is.
Beyond that list, we disclose data only if the law requires it, or if CueIQ is ever sold or merged — in which case the buyer is bound by this policy until they tell you otherwise, and we will tell you before that happens.
How long it is kept
Your workspace data stays as long as your account does. It is your working record — a contact from last quarter is exactly the sort of thing you expect to still be there. Nothing expires on a timer.
You can remove individual contacts, lists, and sequences from inside the app whenever you like. When you want it all gone, delete the account.
Deleting your account
Settings → Account → Delete account. You will be asked to retype your email address, because this cannot be undone.
What that removes, immediately:
- Every workspace you own, and everything inside it — contacts, companies, lists, sequences and enrollments, agent runs and their steps, drafted and sent messages, engagement records, activity logs, and the website-visitor records.
- Every credential stored for that workspace: your language-model API key, and the tokens or cookies for Gmail, Outlook, Apollo, HubSpot, and LinkedIn.
- Your login itself, so the email address can no longer sign in.
What it does not, and cannot, reach:
- Workspaces you merely belong to but do not own. You are removed from them; the workspace and its data stay with its owner.
- Mail that has already gone out. A sent email lives in the recipient's inbox and in your own mailbox's Sent folder — CueIQ never had the power to recall it.
- Copies in the accounts you connected. Contacts and sequences pushed to Apollo, or records synced to your CRM, belong to those accounts and are deleted there, by you.
- Prompts already sent to your language-model provider. Their retention is set by their terms, on your account.
- Encrypted backups held by our hosting provider, which are kept on that provider's own rotation and roll off on their schedule rather than the moment you click delete.
If you would rather have it deleted by hand, or want written confirmation once it is done, email privacy@codeconsulting.ai from the address on the account.
Security, honestly stated
Every workspace is isolated at the database level, so one customer’s rows are not reachable from another customer’s session. Third-party credentials and your model API key are encrypted before they are stored. Access to production is limited to the people who operate the product.
CueIQ is a small, new product. No system is guaranteed secure, and we are not going to pretend otherwise or wave a certification we do not hold. If you find a problem, email privacy@codeconsulting.ai and we will take it seriously.
Children
CueIQ is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes
If this policy changes, the date at the top changes with it. If a change materially affects what happens to your data, we will email the account owner rather than quietly editing the page.
Contact
Questions, corrections, deletion requests, or anything you want a straight answer about: privacy@codeconsulting.ai.