Privacy Policy
Last updated: 2026-08-28
cuemark is built and operated by Mike Bradshaw (sole developer; reachable at hello@cuemarkapp.com). This policy explains what data the app and backend collect, why, where it lives, and what your choices are.
It's written in plain English on purpose. If something isn't covered here, ask — we'll either tell you or update the policy.
1. What we collect
Account
- Your email address. Used for the magic-link sign-in flow (the one-tap email link) and to send transactional messages (welcome, ticket confirmations you forward to log@cuemarkapp.com).
- A device-generated install ID. Random, not tied to your identity. Used to sync your watchlist + history across devices when you sign in.
Activity you save in the app
- Watchlist. TMDb movie IDs you save, plus a timestamp.
- Itinerary. Showtimes you save, including theater name, start time, format, and the ticket link.
- History (logs). Tickets you've forwarded to log@cuemarkapp.com or added via the in-app camera capture. Includes title, theater, date.
- Theater preferences. Your starred theaters and home ZIP.
- Feedback + theater suggestions. Anything you submit via the "tell us" form or the "don't see your theater?" form.
Device + usage
- Approximate location (only when you grant "While Using" permission). We ask your phone for "Balanced" accuracy (about 100 metres), never full-precision GPS — that reading is what's used, live, to find nearby showtimes and estimate travel times between theaters. A separate, coarser copy (rounded to roughly a kilometre) is what's saved to your account, to power on-sale alerts and speed up your next visit's nearby-showtime lookup.
- Notification token if you grant notification permission. Stored so we can ping you about presales / weekend openers / the daily game.
- App version + iOS version in error logs (only when something crashes; see §7).
- Bug-report screenshots. If you submit an in-app bug report, we read the screenshot you just took from your photo library and send it with your report so we can see what you saw. Kept 90 days, then deleted.
Product analytics
- In-app usage events. We use PostHog to record actions like signing in, saving a movie, opening a showtime, playing a game, or completing an outing — so we can see which features people actually use. Each event carries a random anonymous ID until you sign in, at which point it's linked to your account so we can connect your activity before and after sign-in.
- Not used for ad tracking. We turn off PostHog's IP-based location lookup for every event (no city/region derived from your IP). This data is for our own product analytics only.
What we do NOT collect
- We don't track you across other apps or websites.
- We don't collect your contacts list or calendar events. Calendar + camera permissions, when granted, only WRITE (calendar event for an itinerary item) or READ a single image you pick (a ticket receipt for the log, or a bug-report screenshot, per above). The one exception: if you use Outing's named-seat invite to assign specific friends to specific showtimes, the name you pick for each seat (from your contacts, or typed by hand) is sent to our servers so we can show it back on the outing page and track who's responded — never their phone number or any other contact detail. Deleted automatically once the outing's date has passed.
- We don't sell your data. Ever. There is no advertising business model here to sell it to.
2. Where data lives
- Cloudflare D1 (UK + US regions) — authenticated user data (watchlist, itinerary, history, settings).
- Cloudflare KV — short-lived caches (showtimes, trailers, TMDb metadata). No personal data.
- Resend — outbound email delivery (magic links, welcome, receipts). Email addresses pass through Resend per their privacy policy.
- Apple Push Notification Service (APNs) — push tokens + the notifications we send through Apple. Apple's standard service.
- On your device — anything you haven't synced yet, plus preferences (home ZIP, format filters, etc.).
Third-party APIs cuemark calls but never sends your personal data to: TMDb (film metadata + posters), YouTube Data API (trailer playlists), SerpAPI (Google Showtimes results), and cinema chain sites / Fandango (showtime cross-checks). These see no user identifiers — just anonymous backend requests.
For the AI providers we use, see §4.
3. Sharing
We don't sell or rent your data. We share only when:
- Required by law — court order, subpoena, or similar legal process. We'd push back where reasonable and notify you when permitted.
- You ask us to — e.g., emailing your ticket history to yourself via the log forwarding address is, by definition, you sharing it with yourself.
4. AI features & automated processing
Some of cuemark runs on AI. Here's exactly where, and what it means for your data.
Where we use AI:
- Ticket capture (the log). When you pick a ticket photo to log, the image is sent to a third-party AI provider (Anthropic's Claude vision) to read the title, theater, and date off it. We also keep the photo itself (not just the extracted text) so you can tap your itinerary later and see your actual ticket — it's stored roughly until a month after your show (see §6 for the exact window).
- Booth briefs, theater write-ups, and the podcast. These are AI-generated from public film and venue information (synopses, metadata, venue details) — not from your personal data. Your watchlist, location, or identity are never sent to generate them.
What this means:
- The only personal content that ever reaches an AI provider is a ticket photo you choose to log. Nothing else.
- Our AI providers process this data on our behalf and, under their business terms, do not use it to train their models.
- AI output can be wrong. Briefs and summaries are labeled in-app as AI-generated, and you should always confirm showtimes, ratings, and ticket details against the official source before relying on them.
We currently use Anthropic (Claude) for text + image understanding (bug-report triage, in-app support replies, and podcast scripts), and ElevenLabs (primary) with OpenAI (fallback) for podcast voice synthesis.
5. Your choices
- Sign out — clears your login on this device. Your watchlist, itinerary, and history stay right where they are, on the device, so you (or anyone else using it) can keep browsing anonymously. Your account data stays synced on our servers for when you sign back in.
- Delete your account — in-app: Settings → Account → Delete account. It takes effect immediately and wipes your server-synced watchlist, viewings, settings, and email. Data already saved on this device is not touched — reinstalling the app is the way to clear that. (You can also email hello@cuemarkapp.com from the address on file and we'll do it within 7 days.) See §6 for what's kept and for how long.
- Notification opt-out — flip notifications off in iOS Settings → cuemark. We re-check the permission state every launch and stop scheduling pings within minutes.
- Calendar opt-out — same, in iOS Settings. Future itinerary saves skip the calendar event silently.
- Location opt-out — same. Travel-time estimates degrade gracefully to "—".
6. How long we keep your data
We keep data only as long as it's doing a job. Here's the breakdown:
- Email + profile — until you delete your account.
- Watchlist, itinerary, history, theater prefs — until you delete your account.
- Ticket photos — until about 30 days after your show, so you can view it in your itinerary; at least 90 days, capped at roughly 13 months for tickets bought far in advance.
- Feedback + theater suggestions — up to 24 months, then deleted.
- Outing invites (including a named friend's seat) — until 30 days after the outing's planned date, then deleted.
- Crash + error logs — 90 days, then purged.
- Showtime / metadata caches — short-lived; auto-expire (hours to days).
- Notification token — until you turn notifications off or delete your account.
When you delete your account, the data above tied to your identity is removed (immediately for the in-app delete; within 7 days for an email request). Anonymous caches expire on their own.
7. Crash + diagnostic data
When the app crashes or hits an error, we record: the stack trace, iOS version + device model, the cuemark build number, and — if you're signed in — your internal account ID, so we can tell "this keeps happening to the same person" apart from "lots of different people hit this once," which is what actually tells us whether a fix worked. Not your email, and not searchable by it.
We do not record: the contents of your watchlist or itinerary, your email address, or your location at time of crash.
These diagnostics are captured via Sentry (our error-monitoring provider) and the default crash reporting Apple's App Store Connect exposes. They're used only to find and fix bugs, never for advertising or tracking. Logs are retained per §6.
8. Children
cuemark is not directed at children under 13 and we do not knowingly collect personal data from them. We run no advertising, no behavioral tracking, and we never sell or share data — including any child's. Location is off until you explicitly grant it. If you believe a child has signed up, email hello@cuemarkapp.com and we'll wipe the account.
9. International users
The cuemark backend runs on Cloudflare's network, which has data centers globally. By using cuemark from outside the US, you consent to your data being processed in the US and/or the UK.
If you're in the EU/UK and want to exercise GDPR rights (access, deletion, portability), email hello@cuemarkapp.com and reference the email on your account. We'll respond within 30 days.
10. Changes
If we change this policy materially, we'll notify TestFlight + App Store users via in-app banner before the change takes effect.
Questions: hello@cuemarkapp.com. We read every one.