Cue privacy policy
Effective October 8, 2026
Cue has no account, no analytics, no crash reporting, no ads, and no tracking. Nothing about what you watch is sent to the developer. The one piece of developer-run infrastructure is the optional Watch Party relay, described below.
Cue is a Plex client for iPhone, iPad, Apple TV, and Mac, made by Off The Clock Labs LLC ("we", "the developer"), a Utah limited liability company. This policy explains what the app stores, who it talks to, and the choices you have. Questions: ben@offtheclocklabs.dev.
Who Cue talks to
Cue connects to the following, and nothing else:
- Your own Plex Media Server, for your library, playback, watch state, subtitles, and downloads.
- Plex's online services (plex.tv), for signing in, finding your servers, and the Plex features Cue surfaces: Discover, watchlist, reviews and ratings, and friends' activity. Your relationship with Plex is governed by Plex's privacy policy, not this one.
- Your own iCloud account, for syncing settings across your devices and, if you turn it on, Onstage face models. See below.
- Apple's Shazam catalog, only when you tap the button to identify a song.
- The Watch Party relay, only if you start or join a Watch Party.
- Other devices of yours on the same local network, only if you use Device Share.
Cue does not use the camera, microphone, photo library, contacts, or location. It requests no advertising identifier and contains no analytics, advertising, or crash-reporting SDKs. Its only third-party code libraries are GRDB (a local database) and Nuke (image loading); neither sends data anywhere.
What is stored on your device
Your Plex sign-in token (in the system Keychain), your preferences, cached artwork and metadata, anything you download for offline viewing, a local diagnostic log, and any face models Onstage learns. All of it stays on the device and is removed when you delete the app.
Settings sync through iCloud
A few preferences (home screen layout, collection sort order, and per-title playback rules) sync between your devices through iCloud's key-value store, so your iPhone and Apple TV behave the same way. This data lives in your own iCloud account. The developer cannot see it. Turning off iCloud for Cue in your device settings stops the sync.
Onstage (recognizing actors on screen)
Onstage is off until you turn it on.
When enabled, it analyzes video frames on your device to recognize faces and builds a small mathematical model of each actor it learns. The frames it examines are never uploaded, and the reference images it keeps stay on your device.
Optional sync. If you leave sync on, those compact models (and only the models, never images) sync through your own iCloud account using CloudKit's end-to-end encryption. The encryption keys live in your iCloud Keychain, which means neither Apple nor the developer can read them. They are stored only in your private iCloud database and are never combined with or compared against any other user's.
Nothing Onstage learns improves the app for anyone but you. You can erase everything it has learned at any time in Settings → Onstage → Reset Learned Faces, which removes it from your other devices too.
Song identification
When you ask Cue to identify a song, it computes an audio fingerprint on your device from the audio already playing (the microphone is never used) and sends that fingerprint to Apple's Shazam catalog through ShazamKit. No account is involved, the developer never sees the request, and Apple's privacy policy covers it.
Watch Party
Watch Party keeps playback in sync between people watching the same thing. To do that, each device connects to a small relay server. The default relay is operated by the developer and runs on Cloudflare at relay.offtheclocklabs.dev; you can point Cue at a relay you run yourself in Settings → Connection, in which case nothing reaches the developer's relay at all.
The relay carries no video. Video always goes from your Plex server directly to each device. What passes through the relay is:
- your playback position, play/pause state, and playback speed
- the Plex rating key of what you're watching (a number identifying the item on your server)
- your Plex profile display name, profile identifier, and avatar image URL, so other people in the party can see who joined
This is held in memory for the length of the session and is visible only to the people in your party. The only thing the relay writes down is what it needs to let a dropped device rejoin: the room code, peer identifiers, hashed reconnect tokens, and timestamps. It holds no names, profile identifiers, avatars, or message contents, and it is deleted when the room ends or five minutes after it empties. If you never start or join a Watch Party, nothing is sent to the relay.
Because the relay is run by the developer, Cue's App Store privacy label declares Name, User ID, and Other Usage Data (the sync payload) as collected for app functionality, linked to you, and not used for tracking.
Device Share
Device Share lets one of your devices that holds downloads serve them to another of your devices nearby over peer-to-peer Wi-Fi, with no router or internet involved. Devices find each other using Bonjour on the local link only and pair by matching a non-reversible fingerprint of the Plex server they both have access to; a device that doesn't match is never contacted. Nothing from Device Share leaves your local network, and the developer is not involved.
Notifications
If you allow notifications, Cue schedules them locally on your device (for example, when a download finishes). There is no push server; the developer cannot send you notifications and receives nothing when they fire.
Diagnostics and feedback
Cue keeps a diagnostic log on your device and records crash and performance diagnostics that iOS provides through MetricKit. None of this is uploaded automatically. If you choose to send feedback from Settings, Cue drafts an email or a GitHub issue for you to review; before anything is shown, it strips email addresses, public IP addresses, server hostnames, and Plex tokens from the text. You see exactly what will be sent and can edit or cancel it.
Links to other sites
Some screens offer to open a web search (for example, a trailer search on YouTube) in your browser. That happens outside the app and is covered by that site's policy.
Purchases
Cue currently has no in-app purchases or subscriptions. If that changes, purchases will be processed by Apple through the App Store and this policy will be updated.
Children
Cue plays media from a server you supply. It has no content of its own, isn't directed at children under 13, and we don't knowingly collect personal information from them.
Your choices and your rights
Because your data lives on your devices and in your own iCloud and Plex accounts, you already control it: delete the app to remove local data, use Reset Learned Faces for Onstage data, manage iCloud data in Settings → your name → iCloud, and manage your Plex data with Plex. If you live somewhere with additional privacy rights (such as California or the EU) and want to exercise them, email us and we'll help.
Changes to this policy
If this policy changes in a meaningful way, the date at the top changes and the change is noted in the app's release notes.
Contact
Off The Clock Labs LLC
Vineyard, Utah, USA
ben@offtheclocklabs.dev