cue.
English by Dialogue
Privacy Policy
Last updated 30 August 2026 · 303plus Inc.
The short version. There is no account and no sign-in. Cue never asks for your name or email, and has no text field anywhere that you could type personal information into. Your learning progress lives on your device, and in your own iCloud if you use it — we cannot see it. We collect a small stream of anonymous usage events that are not linked to your identity, and we do not track you across apps or websites. Ads are non-personalized and only ever shown if you choose to watch one.
1. What we never collect
- No account, sign-up, login, email address, phone number, or profile.
- No free-text input. The bug report screen is a fixed set of checkboxes with no text field, so there is nowhere for personal information to be entered.
- No name, contacts, photos, calendar, health data, or precise location.
- No tracking across other companies' apps or websites. Cue never shows the App Tracking Transparency prompt because it has nothing to ask for.
- Your IP address is never stored.
Cue's app listing declares Bluetooth and camera usage descriptions. That is because the open-source media library Cue is built on references those system APIs; Cue itself does not use them and never requests those permissions. The microphone is different: Cue does use it, but only for speaking practice, only with your permission, and never in a way that sends your voice anywhere — see section 2.
2. What stays on your device
Stored locally and never sent to us:
- Your progress log — which phrases you have learned, whether each quiz answer was right or wrong, and when.
- Your settings — chosen voices, speech rate, typeface, interface language, practice preferences, and window state.
- A random installation identifier used only to name your own file inside your own iCloud container.
Speech is generated on-device by Apple's built-in speech synthesizer. Nothing you hear is produced by or sent to a server.
Speaking practice and the microphone. A lesson may ask you to read a line out loud. You can also choose to practice a whole dialogue as a read-aloud roleplay once you have finished listening to it, taking one of the two parts; that is optional, you start it yourself, and it pauses for you to speak on each of your turns. In both cases the microphone is turned on only at that moment, and only after you have granted microphone and speech recognition permission — it is off at every other time, and the app never listens in the background. What you say is transcribed by Apple's built-in speech recognition, which Cue configures to run strictly on-device: your voice is not sent to Apple's servers, and not to ours. The audio is never written to a file and is discarded the moment the prompt ends; the transcript is shown to you so you can see how you were heard, and then discarded too. Neither the audio nor any text derived from it ever leaves your device, and neither is ever part of the analytics described in section 4. Speaking practice is never required — there is always a Skip button, skipping affects your progress in no way, and you can turn the feature off entirely in Cue's Settings or simply decline the permission.
3. iCloud sync (optional)
If you are signed in to iCloud, Cue mirrors your progress log into your own private iCloud container so your progress follows you between your devices. That data belongs to your Apple account. We have no access to it, it never reaches our servers, and it is covered by Apple's Privacy Policy. Disabling Cue under Settings › Apple Account › iCloud stops the mirroring; the app keeps working from local storage.
4. Anonymous usage analytics
Cue uses no third-party analytics SDK. We run a small pipeline of our own so we can see which lessons confuse people, whether learners come back, and whether reported problems cluster on particular content. Each event carries:
- An anonymous installation ID — a random value generated on first launch and stored on your device. It is not your Apple ID, not your device's advertising identifier, and not linked to any identity. Reinstalling the app produces a brand-new one, which we cannot connect to the old one.
- A session ID — random, regenerated each time you open the app.
- The event name and a few properties (listed below).
- App version, platform, timestamps, and a random de-duplication value.
- Country — derived at our server edge from the incoming network connection. The IP address itself is discarded and never written to storage.
The complete list of events is:
app_open,screen_view— the app was opened; which screen was shown.learn_start,learn_done,review_start,cap_reached— lesson and review milestones.learn_startalso carries whether speaking practice is usable on your device, as one of a fixed set of labels (for example on, off, or unavailable), so that we can tell how many devices can support the feature at all.review_startalso records which of the two kinds of practice — dialogue or picture — the round drew.lesson_playback— that a dialogue started playing, which screen it played on, and whether the sound came from a pre-recorded file, from your device's own voices, or could not start at all. It names no phrase. We collect it to tell a lesson that never started apart from one you started and left.voice_gate— that the notice about the English voices installed on your device appeared before a lesson, which of a fixed set of concerns raised it (no voice, low quality, or same voice for both speakers), and what you did with it, also as one of a fixed set of labels (continue, not now, hide for today, or dismiss).quiz_answer— whether an answer was correct, and which phrase it was for.pic_learn_start,pic_learn_done,pic_quiz_answer,pic_cap_reached— the same milestones and quiz result for the picture lessons, and which picture item they were for.pic_cap_reachedcarries no item — it records only that you reached the daily limit for picture lessons on that day. They are recorded under their own names rather than merged into the events above, because a picture lesson is a different kind of session.speak_prompt— that Cue's own notice explaining speaking practice appeared before any system permission prompt, and what became of it, as one of a fixed set of labels (shown, accept, decline, or timeout — the last meaning the system prompt was left unanswered long enough that Cue stopped waiting for it). Declining never opens the system prompt.speak_attempt— that a speaking prompt finished, which phrase it was for, how it ended as one of a fixed set of labels (heard, silent, no input, skipped), how many times you retried, and whether it came from a lesson prompt or from a roleplay turn. No audio and no transcript — nothing that records what you actually said.roleplay_start— that you started a read-aloud roleplay, which lesson it was for, which of the two parts you took, and whether you chose to hide the lines while practicing.ad_accepted,ad_declined,ad_watched— your response when an optional ad was offered.tip_purchased— that a coffee tip happened. No amount, no payment details.report— which lesson and dialogue you reported, where playback had reached, which of the fixed reason checkboxes you ticked, whether you were in a new lesson or a review, and the quality tier of the voices that were speaking (so that complaints about audio can be told apart from complaints about the wording).font_selected,language_selected— which typeface, and which interface language, you picked in Settings.font_fallback— which font file on your device Cue ended up using to draw each non-Latin script it supports (Cyrillic, Korean, Japanese, Chinese), or that it found none, plus how many directories and files the search looked at. This describes your device's font configuration and nothing about you; we collect it because these fonts differ between iOS versions and we cannot see the result any other way.crash— that the app crashed, plus the technical failure message or system signal name produced by the crash itself, so we can find and fix it. This is our own diagnostic text, not anything you entered or said.
That is the entire list. This data is not used for advertising, profiling, or building a picture of you as a person, and it is never sold or shared with data brokers.
Where it goes. Events are processed and stored on Cloudflare infrastructure (Workers, D1, and R2) in the Asia-Pacific region, acting as our processor. Rows in the queryable database are deleted after 24 months, and the compacted archive kept behind them in object storage is deleted after 36 months. No analytics event is retained beyond that.
5. Advertising
Cue shows exactly one kind of ad: an optional rewarded video, offered at most once a day, only after you have finished the day's learning goal, and only if you tap to watch it. There are no banners, no interstitials, and no ads inside a lesson.
- Ads are requested from Google AdMob as non-personalized at all times. Cue never accesses the device advertising identifier (IDFA) for tracking and never shows the tracking prompt.
- To serve and measure even non-personalized ads, Google may process device information such as a device identifier, coarse location derived from the network connection, and diagnostic data. This is described in how Google uses information from sites or apps that use its services and in the Google Privacy Policy.
- An ad is fetched in advance only when you are one lesson away from finishing the day's goal. If you decline the offer, the fetched ad is discarded.
- If you are in the EEA, the UK, or Switzerland, Cue shows Google's certified consent form before it ever requests an ad, and asks whether you consent to that processing. Choosing "Do not consent" means no ad is requested and none is ever shown — the rest of the app is unaffected. You can change that choice at any time from Settings › Ad privacy options inside the app.
6. Purchases
"Buy me a coffee" is an optional one-off tip. It unlocks no content and no features. The transaction is handled entirely by Apple; we never receive your payment method, billing address, or Apple ID. Cue records only the anonymous event noted above, saying that a tip occurred.
7. Children
Cue is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has provided us information, contact us and we will look into it — though note that, by design, nothing collected identifies an individual.
8. Your choices
- Deletion. Your anonymous installation ID is shown at the bottom of Cue's Settings screen — tap it to copy. Email it to cs@303.plus and we will delete every event carrying that ID within 30 days — from the queryable database and from the monthly archive files alike. (Those archives hold many installations merged together, so we rewrite each affected file without your entries; a file left holding nothing else is deleted outright.) We keep a record that the request was made and completed, so that we can show the deletion happened. The ID is a random value known only to your installation, so holding it is proof enough to make the request — we ask for nothing else.
- What happens after a deletion. If you keep using Cue, new events are recorded under that same ID from then on, so a deletion clears your history rather than stopping collection. Deleting the app removes the ID entirely; a fresh install generates a new one that we have no way to link to the old.
- Access. Section 4 lists everything we hold, and we will send you the rows carrying your ID if you ask.
- Progress and settings. Everything that actually describes your learning lives on your device and in your own iCloud, entirely under your control — we never receive it.
- iCloud. Turn it off for Cue under Settings › Apple Account › iCloud.
- Ads. Decline the offer, and no ad is shown.
9. Changes to this policy
If what we collect changes, this page and the date at the top change with it. Material changes will also be noted in the app's release notes.
10. Contact
303plus Inc. — cs@303.plus