01.Our Commitment to Privacy
CueVPN is operated by CueBytes LLC. This policy describes the information used to provide your VPN connection, manage your account and subscription, diagnose problems, and deliver optional CueVPN emails.
Connection and diagnostic records can be associated with your account or device. The information described below includes operational records such as connection times, assigned VPN addresses and bandwidth counts.
02.Information We Collect
The following information is collected to provide and operate CueVPN:
- Account information: Account identifiers, email address, profile information you provide, authentication details and email verification status. Passwords are stored as hashes. Guest access also creates an account identifier.
- Subscriptions and payments: Apple App Store and Google Play handle in-app checkout. CueVPN receives and stores purchase verification data, product and transaction identifiers, subscription status and relevant billing dates to activate, restore and maintain access. Stripe handles web checkout and recurring billing through CueBytes LLC. For web purchases, we share your account email, name and account identifier with Stripe and store your Stripe customer and subscription identifiers, payment status and billing dates. We also retain campaign attribution submitted at checkout. Card details are entered directly with the payment provider; CueVPN does not store full card numbers.
- Connection and usage records: Account and server identifiers, VPN addresses, connection start and end times, duration, bandwidth counts and connection or peer status. These support connection management, usage limits and troubleshooting.
- App, device and access information: Installation and device identifiers, platform, device model, operating system and app version, and network IP information associated with installation or API access. Notification tokens and timezone information may be recorded to deliver app notifications.
- Analytics and diagnostics: App interactions, onboarding and subscription events, connection outcomes, errors, crash reports and performance data. Firebase Analytics, Firebase Crashlytics and Sentry are initialized automatically in the current app; collection is not controlled by the optional marketing email setting. These records can contain app or device identifiers and diagnostic context, so they should not be treated as anonymous.
- Website visits: The website loads Google Analytics, Google Tag Manager, Meta Pixel and Ahrefs Analytics to measure visits, page views and campaign performance. These services can receive browser and network information and use their own identifiers, cookies or pixels. Website tracking is separate from VPN traffic and the app email preference.
- Website enquiries: When you submit the website enquiry form, your name, email, message, campaign parameters (including UTM tags and advertising click identifiers when present), referring page, network and browser information, and timezone are processed in our CueVPN GoHighLevel workspace so we can respond and understand where enquiries came from. An enquiry does not opt you in to marketing emails.
- Support and email preferences: Information you send when requesting help, together with email consent and suppression records used to manage optional communications.
- Optional feedback: The CueBytes-hosted feedback form asks for your CueVPN account email, a reason or response about your experience, and an optional comment. These details are processed in the CueBytes CRM to match and understand your feedback.
- Email journey measurement: Private campaign links connect optional email journeys with an explicit app-opening or store-review-link click, an authenticated return to the app, and a later recorded session where available. These are separate events: a page visit, button click or recorded session does not prove a successful VPN connection or a submitted store review. VPN traffic contents and browsing destinations are not part of this measurement.
03.VPN Traffic and Operational Records
VPN traffic contents, such as the contents of a web page or message, are different from the records used to operate a connection. The connection records described in this policy track session operation and usage; they are not a browsing-history feature.
Operational records can reveal when an account connected, which VPN server it used, its assigned VPN address and how much data was transferred. Error and infrastructure logs can also contain network addresses and diagnostic context. These records must be considered when assessing what information CueVPN holds about you.
04.How We Use Your Information
We use the information described above to:
- Create, secure and manage accounts and guest access
- Verify purchases, restore subscriptions and maintain the correct level of access
- Operate connections, enforce usage limits and investigate errors or misuse
- Send transactional emails (receipts, password resets, service announcements)
- Respond to support requests
- Measure app activation and improve service reliability using analytics and diagnostics
- Deliver optional CueVPN tips, server updates and offers when you have opted in
The optional email integration described below uses account lifecycle information to select relevant CueVPN communications. VPN destinations and traffic contents are not included in that integration.
05.Optional CueVPN Emails
Where available, you can choose to receive CueVPN tips, new server updates and offers using the email preference in the app. This is optional and is separate from account recovery, purchase verification and other necessary service communications. Opt-in requires a verified account email address.
When this feature is enabled and you opt in, CueVPN uses a dedicated CueBytes-operated CRM workspace on GoHighLevel. The lifecycle integration sends your verified email address, CueVPN account identifier, email consent status and broad account states: whether a session has been recorded, recent or inactive use, subscription status and whether a recent payment problem was reported. A recorded session or reported payment problem does not by itself establish a successful VPN connection or a declined charge.
This integration does not send VPN destinations, selected servers, IP addresses, exact connection times, bandwidth counts, purchase receipts, device identifiers or your name to the CRM.
The dedicated app-link, feedback and review pages do not load the website measurement tags described above. Private campaign tokens are supplied in URL fragments, which are not sent with the initial webpage request. An explicit action can send the token to CueVPN’s API or, for feedback, to the intended CueBytes form processor. A token is used for campaign matching; it does not sign you in. Feedback and store reviews are optional and independent: you do not need to give a particular response or rating to receive a review link.
You can withdraw email consent in Settings or use the unsubscribe option in a marketing email. Email delivery may remain suppressed after a bounce or unsubscribe even if you later turn the app preference back on. Withdrawing email consent does not disable app diagnostics or delete your CueVPN account. Suppression records may be retained to prevent further marketing messages; contact us separately for an erasure request.
06.Data Retention and Deletion
Retention depends on the type of record, the systems holding it and the purposes for which it is needed, including operating your account, handling subscription disputes and investigating service problems. Account deletion and email withdrawal do not automatically remove every record held by payment, diagnostic, support or email providers.
Application and error log rotation is configured for 30 days, activity logs for 90 days and security audit logs for 365 days. These rotation settings do not define deletion deadlines for database records, infrastructure logs, backups or records held by other providers.
For the optional email integration, withdrawing consent or deleting an account requests suppression of the associated CRM contact. Suppression prevents further email delivery; it does not erase that contact. Contact us to request information about retained records or to make a deletion request.
07.Third-Party Services
We use a small number of trusted third-party providers to operate CueVPN:
- Stripe: Web checkout, recurring payments, billing management and payment notifications
- Apple and Google Play: In-app checkout, purchase verification and subscription notifications
- Google Analytics and Google Tag Manager: Website measurement and loading configured measurement tags
- Meta Pixel: Website page-view and advertising campaign measurement
- Ahrefs Analytics: Website traffic measurement
- Google Firebase: App analytics, Crashlytics crash reporting and Firebase Cloud Messaging notifications
- Sentry: Error reporting, app session diagnostics and performance monitoring
- GoHighLevel through CueBytes: Website enquiry forms and responses, plus optional CueVPN email contact and lifecycle management, campaign attribution and feedback form processing when enabled
- Hosting and email services: Operating the website and API, storing service records and delivering transactional emails through the configured providers
The information each provider receives depends on its role. For example, payment providers handle store transactions, diagnostic providers receive app telemetry, and the optional CRM receives the limited account fields listed above.
08.Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to access the data we hold about you
- Right to correct inaccurate data
- Right to deletion (right to be forgotten)
- Right to data portability
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority (EU/UK users)
To exercise any of these rights, contact us at support@cuebytes.com. We may need to verify your identity to handle a request.
09.Security
CueVPN uses WireGuard to encrypt the VPN tunnel and HTTPS for the account API. Account passwords are stored as hashes. To report a suspected security issue, contact support@cuebytes.com.
10.Children's Privacy
CueVPN is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
11.Changes to This Policy
Changes to this policy will be reflected on this page with an updated date. Review the current policy to understand how CueVPN handles your information.
12.Contact Us
CueBytes LLC is responsible for operating CueVPN. For privacy questions or requests, contact support@cuebytes.com or write to CueBytes LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States.