Privacy & security

Your privacy.
Your questions, answered.

This overview explains Cue’s security architecture, the scope of cloud processing, and the controls specified for your memory. It describes the product design; availability depends on the release.

Comfort around others

Everyday eyewear

Does Cue take photos or put a screen in front of me?

Cue has no camera and no display. Lightweight titanium frames are designed to feel like everyday eyewear, without photographing people or putting a screen in your line of sight.

Cue can still capture conversations. Let people know when it is in use and respect requests to pause. Its familiar appearance does not replace that conversation.

Your audio & personal details

Local processing

Do you keep my original audio?

Raw audio is not uploaded to the cloud. Your phone decrypts it, converts speech to text, and processes it locally. By default, the original audio is deleted immediately after processing, with no raw audio file retained.

If you explicitly enable optional local audio retention, a copy can remain on your phone for no more than seven days. Raw audio is not uploaded in either mode. Processed memory data has a separate cloud-processing path, described below.

Sensitive information

What happens to personal numbers?

The privacy requirements specify replacing phone numbers, payment card numbers, and government identity numbers with codes before synchronization. Their original values stay local.

Automated redaction may miss information. Saved text can still contain private context, which is why encryption, access controls, and user review remain important.

Your choices & access

Memory controls

Can I pause, change, or delete a memory?

The product requirements include pausing capture, correcting or deleting saved memories, and choosing what to share. Removing a device does not itself delete memories already processed from it.

Let people know when you are using Cue to capture a conversation. Respect requests to pause. Having no camera does not remove the need to respect other people’s privacy.

Recovery & key management

How can I recover access?

The design separates your password from the keys that protect your data. Changing a password can re-protect the keys without re-encrypting every saved memory.

A 24-word recovery phrase and 90-day cloud-key rotation are specified for a later development stage. They should not be assumed available in every build. Losing a phone and recovery credentials can affect access to unprocessed device audio.

Encryption & cloud access

Lost-device protection

If I lose Cue, can someone read my audio?

Finding your glasses does not grant access to your conversations. Cue encrypts stored audio blocks with AES-256-GCM and uses separate session keys. Copying an encrypted file does not make its contents readable without the required keys.

The user private key for device audio is protected in your phone’s secure key storage and is never stored on Cue. Neither Sutyo nor its cloud service providers hold this user private key in readable form. This protection concerns device audio; processed cloud memories use a separate cloud data key.

Your private key

Who holds the key to my device audio?

Your phone protects the usable private key. Your user ID links that key to your account; the ID itself is not a secret key and cannot unlock audio.

The design also allows servers to store an encrypted backup of the private key. It is wrapped with a key derived from your password; the server does not hold that wrapping key. Where recovery is supported, a separately encrypted copy can be unlocked using your recovery phrase. An encrypted backup does not give Sutyo or a provider the readable private key.

These protections depend on the integrity of the device and your phone, and on keeping your password and recovery credentials private. They do not claim protection after an attacker compromises an unlocked phone or the device’s secure firmware.

Encrypted transport

Is my audio protected on the way to my phone?

Encrypted audio travels over a separately encrypted Bluetooth connection. Pairing establishes the device relationship used to derive the audio keys.

The specified key agreement uses X25519 with HKDF. Phone-side keys are protected by the operating system’s secure key storage.

Cloud processing

What can cloud services access?

Processed data is encrypted for transfer to cloud services. Authorized services can use a separate cloud data key to decrypt it, generate memory results, and re-encrypt the results for storage.

This is not a claim that all cloud content is inaccessible to Sutyo. The design uses managed cloud keys, limited permissions, access logging, and auditing. Those protections have a different scope from the keys that protect device audio.

Availability & website privacy

Release status

Which protections are available at launch?

The encryption design includes staged implementation, integration tests, and planned independent security review. Recovery, rotation, and audit features have separate development milestones.

This page does not claim that a particular certification or third-party audit has been completed. Release-specific data handling, supported controls, and retention behavior must match the version you receive.

Website & email

What happens to my signup email?

The website privacy policy covers your email, website usage, and contact requests. It states that Sutyo does not sell or rent this information and does not use advertising or cross-site tracking cookies.

It also explains service providers, international processing, retention, and rights to access, correct, or delete information. These website terms should not be read as the full policy for every Cue or Sutyo AI feature.