Legal
Privacy Policy: how CueScout handles your data
Last updated: October 3, 2026. This policy explains how CueScout handles data for its AI visibility tracking, search performance, analytics, and content-planning workflows, and for its free tools, MCP server, and ChatGPT app.
What CueScout does
CueScout helps teams monitor configured public sources, review the buyer questions found there, review evidence-backed recommendations and track completed work, copy tracked links, and record outcomes.
CueScout is read-only on third-party platforms. It does not post, vote, comment, send direct messages, or operate your community accounts, and it does not ask you to connect one.
Information we collect
Account data such as your name, email address, authentication state, and password reset metadata.
Product setup data such as product names, descriptions, positioning notes, keywords, competitor keywords, target communities, excluded terms, brand voice samples, preferred call-to-action style, and forbidden claims.
Source and scan data such as configured platforms, connection state, scan requests, source health events, matched public posts, match reasons, lead feedback, writing-plan items, published page addresses you enter, copied tracked links, and revenue events you log or receive through connected billing webhooks.
Integration data needed to operate connected sources or providers, including encrypted OAuth access and refresh tokens, granted scopes, connected account email addresses, selected property identifiers, API-key configuration state, webhook delivery metadata, and provider identifiers from billing or revenue systems.
Usage and diagnostics data such as page views, product events, error logs, IP-derived request metadata, browser/device information, and support messages.
Google Search Console and Google Analytics data
If you choose to connect Google Search Console, CueScout uses read-only access to list sites available to your Google account and retrieve search-performance data for the site you select. This can include page and query dimensions, clicks, impressions, click-through rate, average position, access level, and the selected site address.
If you choose to connect Google Analytics, CueScout uses read-only access to list the accounts and GA4 properties available to you and retrieve aggregate reporting data for the property you select. This can include property name and identifier, time zone, currency, key-event names, users, sessions, key events, landing-page performance, referral sources, and daily totals.
CueScout uses this Google data to show reports for your own properties, measure outcomes, and support the recommendations you review. The scopes are read-only: CueScout cannot modify your Search Console sites, Analytics properties, events, settings, or reporting data.
CueScout does not sell Google user data, use it for advertising, determine creditworthiness, or use it to train generalized AI or machine-learning models. When you explicitly request AI-generated output, relevant writing-plan context, which may include Google-derived query or page context, may be sent to an AI service provider only to produce that requested output.
CueScout's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use information
To create and secure your account, operate the app, run configured scans, build and display supported recommendations, maintain tracked-link redirects, attribute outcomes, and show reports.
To improve lead matching, tune product setup quality, diagnose failed scans or billing webhooks, prevent abuse, respond to support requests, and understand product usage.
To send service messages such as account, billing, security, support, and operational notices.
Public and connected sources
CueScout may scan public conversations from configured sources such as Reddit, Hacker News, and Quora. Public scan mode does not require us to control your account.
Optional OAuth readiness may be used for source connection flows where available, but OAuth access is not a promise that a platform approves a specific use, prevents rate limits, or guarantees account safety.
You are responsible for using recommendations and public-source information in a way that respects each platform, community, and applicable law.
AI-generated drafts
Writing-plan guidance is generated from product context and matched conversation context. What you publish, and where, is entirely your decision. CueScout does not connect to or act on any Reddit, Hacker News, or Quora account.
CueScout does not guarantee that a draft is accurate, compliant with a community rule, accepted by a platform, or suitable for every audience.
Analytics, tracked links, and billing webhooks
We may use product analytics tools such as DataFast and PostHog to understand product usage and improve the workflow. When you are signed in, these tools may associate activity and session replays with your account. See the cookie policy for what each one records.
Tracked links may record redirect events and related campaign parameters so you can measure whether a published page led to visits or outcomes.
Billing webhooks are processed from our payment provider, Polar, to update subscription state, record revenue attribution, and prevent duplicate processing.
Free tools, the MCP server, and the ChatGPT app
The free tools on cuescout.com/tools, the CueScout MCP server, and the CueScout app in ChatGPT can be used without an account. When you run one, we store what you entered (a site address, or a brand name, a question, and competitor names), a summary of the result, the time, your IP address, and your browser's user agent. When the request comes through the hosted MCP server or ChatGPT, we store an anonymous user ID that ChatGPT sends instead of your IP address where one is sent. ChatGPT does not share your name, email address, or chat history with us.
We use these records to run the check you asked for, enforce the per-minute and daily limits, stop abuse, and see which checks people use. To answer a visibility check, we send the question and brand name to an AI provider that runs the search-grounded model you picked. Site checks fetch public pages from the site you named.
If you connect your CueScout account to ChatGPT, ChatGPT can read your brands, AI visibility results, tracked prompts and their answers, cited pages, To-dos, and site audit, and nothing else. It cannot see billing or your password and cannot change anything. We store the connection (which app, when you connected, and when it was last used) and the access tokens, which we keep only as one-way hashes. Access tokens expire after an hour and are renewed while you stay connected.
Sharing and processors
We do not sell your personal information.
We may share information with service providers that help run the product, including hosting, database, authentication, analytics, AI, email, billing, logging, and support providers.
Google API data is shared only with processors needed to operate the user-facing features you request. Relevant Google-derived writing-plan context is shared with an AI provider only when you request an AI-generated output. Authorized personnel may access data only when needed for support, security, legal compliance, or with your permission.
We may disclose information if required by law, to protect rights and safety, or in connection with a business transfer such as a merger, acquisition, financing, or sale of assets.
Retention and security
We keep information for as long as needed to provide the service, comply with legal obligations, resolve disputes, prevent abuse, and maintain business records.
Google connections and their imported reporting data are retained while the connection is active. Disconnecting a Google service deletes its stored connection, tokens, and imported data from the live service. Deleting the related product also deletes that data, and CueScout asks Google to revoke the access unless another of your products still uses the same Google connection. Deleted information may remain temporarily in encrypted backups until those backups rotate.
When you ask a publisher to add you to a list, CueScout stores the author name and contact address that publisher prints on their own site, or one you type in. It does not guess addresses and does not send the email; you do, from your own inbox. The name and address are deleted 90 days after the request is closed.
Free-tool and MCP records are deleted about 90 days after the check ran. A ChatGPT connection is kept until you disconnect it; tokens are deleted about 90 days after expiry, revocation, or rotation.
OAuth tokens are encrypted at rest, and data is protected in transit using HTTPS. Access is limited to systems and personnel that need it to operate, secure, or support the service.
We use reasonable technical and organizational safeguards, but no internet service can guarantee absolute security.
Your choices
You can update product setup, disconnect supported integrations, delete a product, or request support. There is no self-serve account deletion yet. To delete your account, email hello@cuescout.com from the address you sign in with. We then delete the account, its products, and its connections by hand, subject to legal, security, billing, and backup retention limits.
You can revoke CueScout's Google access at any time from your Google Account permissions. Disconnecting in CueScout removes the local connection and imported data; CueScout also requests revocation from Google when doing so will not disrupt another CueScout Google connection that uses the same grant.
You can disconnect the CueScout app in ChatGPT at any time under Settings → Connections. It stops working on its next request. To have free-tool records deleted before the 90 days are up, email hello@cuescout.com with the site or brand you checked and roughly when.
You can control browser-level cookies and tracking settings. Some choices may affect product functionality.
Contact
Questions about this Privacy Policy can be sent to hello@cuescout.com.