This page covers two things: this website, and the CuePoint desktop app. For each it says what is collected, who receives it, and what you can do about it.
The short version
- This website sets no cookies. It counts visits with Umami Cloud, which says it uses no cookies and stores no personally identifiable information.
- The forms on this site send what you type, and only that, to the publisher's email through Web3Forms.
- The app has no analytics and no usage tracking. Your Rekordbox collection stays on your computer.
- The app sends an error report to Sentry (EU region) when it hits an unexpected error, unless you turn that off in Settings → Privacy → Send error reports. Reports are cleaned on your computer first, and are built not to carry file, folder, track, artist, label or playlist names.
- The app asks GitHub for new versions, about 10 seconds after it starts and then every 4 hours. That check sends only what any request to GitHub sends: your IP address and the name of the software asking. Nothing from your library goes with it.
- Nothing is sold or rented to anyone.
Who publishes CuePoint
CuePoint is published by Stelios Vasileiou, as an individual, who is also the person to write to about privacy. The app is open-source software, and its code is public at github.com/stuchain/CuePoint.
Contact: write to the publisher through the contact form. You can also open an issue in the repository.
This website
Hosting
The site's pages are served by GitHub Pages. Like any web server, GitHub receives each request, which includes your IP address and the page you asked for, and keeps logs of it. The publisher does not receive those logs. See GitHub's privacy statement.
Visit counts
To learn how many people visit, where they come from and whether the download is used, the site uses Umami Cloud (umami.is). The site sets no cookies and stores nothing on your device for it. It counts:
- page views, and which page;
- the site you came from (the referrer);
- a few actions, as events: a click on a download and a form being sent. If a sound button is added, a press of it will be counted the same way.
Umami's own FAQ (docs.umami.is/docs/faq) says it uses no cookies, does not store personally identifiable information, and identifies a visit by an anonymous session id. These counts are not tied to your name or email, and the publisher uses them only to see how the site is doing.
The forms
The contact form and the bug-report form send through Web3Forms (web3forms.com), a form service, because this site is static and has no server of its own. When you press Send, your browser sends the fields you filled in to Web3Forms, which passes them to the publisher as an email:
- Contact and feedback: your name (optional), your email address, the subject you chose and your message.
- Bug report: your email address, the version of the app, your system and chip, and what happened, what you expected and the steps.
The forms use a hidden field and a fill-time check to stop spam, and no puzzle: a form filled in faster than a person could type it is not sent. Web3Forms also filters spam itself. The publisher uses what you send only to reply to you and to fix a problem. Web3Forms acts as a processor for the publisher, who decides what is done with the messages. Its privacy page (web3forms.com/privacy) says it stores submissions, on Amazon Web Services, for up to 3 years, and that it may pass your IP address and email address to spam-filtering services (CleanTalk and Akismet). If you want a message you sent deleted, write to the publisher through the contact form and ask.
Cookies and your browser's storage
The site sets no cookies. If it ever finds a cookie it did not set itself, it asks whether it may count visits, and remembers your answer in your browser's local storage, on your device, under the name cuepoint-site-consent. That answer is not sent anywhere. Clear your browser's site data to remove it.
The site's fonts and its own scripts come from the site itself, with one exception: Umami's counting script, from cloud.umami.is. It loads nothing from Google, and no advertising or social network code. Links to other sites, such as GitHub, lead to places with their own policies.
The CuePoint app
Your library stays on your computer
CuePoint reads your Rekordbox collection and does its work on your computer. The app has no analytics and no usage tracking. It makes network requests only for the things listed below.
Error reports (on by default; you can turn them off)
When a released build of CuePoint hits an unexpected error, it sends one error report so the bug can be found and fixed. Builds run from source do not send them, and neither does the command-line tool.
A report carries:
- the kind of error and its message, with file and folder names, your user, home and computer names, and track, artist, label and playlist names removed on your computer before it is sent;
- where in CuePoint's code it happened (the stack trace);
- a short description of each of the last steps before it, for example a screen was opened or a lookup failed, cleaned the same way;
- CuePoint's version and build, and basic details about your computer: operating system and version, processor and graphics hardware, memory, screen size, when the app was last started, language and time zone;
- when the part of CuePoint that does the work, or the audio player, stops unexpectedly, the last lines of what it wrote, with the same removals applied;
- if you use Help → Report a problem, the note you write there, the app's version and the id of the last report. That is sent only when you press Send, and the note is sent exactly as you write it, so leave out anything you do not want read.
A report is built not to carry (the note you choose to send with Report a problem is the one exception): file or folder names (a path is reduced to its depth and file extension), your user, home or computer name, track, artist, label or playlist names, the notes and tags you keep in CuePoint, tokens or passwords, the values of variables in the code, your library or Rekordbox collection, screenshots, recordings or memory dumps. The app sends no user id, name or email and does not put your IP address in a report. As with any server you connect to, Sentry receives the network address a request comes from, and works out from it the country a report came from.
Where it goes: to Sentry (sentry.io), in Sentry's EU region. Sentry is the only service that receives error reports.
How long it is kept: for as long as Sentry keeps error events on the project's plan: 30 days on the free plan, 90 days on a paid one, after which Sentry deletes them. Reports are read only to fix bugs.
How to turn it off: Settings → Privacy → Send error reports, or Help → Privacy, then Change these in Settings → Privacy. It takes effect at once, with no restart: nothing is sent after that, and nothing is saved to send later. A report that has already reached Sentry stays there until Sentry deletes it.
Updates
The installed app asks GitHub, where its versions are published, whether a newer version exists: about 10 seconds after it starts, then every 4 hours while it is open, and whenever you choose Check for updates in Settings → About & updates. It does not do this when run from source. On Windows and Mac it then downloads the new version from GitHub and installs it when you choose Restart now, or the next time you quit. On Linux it shows a link to the download instead.
A check sends only what any request to GitHub sends: your IP address and a user agent, the line that names the software asking. The list of versions is asked for with a user agent that names CuePoint and the version you have; on Mac the download goes through the app's built-in browser, whose user agent also names its own version and your operating system, and on Windows through the update library, whose user agent is electron-builder. No id, no account and nothing from your library goes with it. If you are offline or GitHub cannot be reached, the check fails quietly and is not sent as an error report. There is no setting to turn the check off. The user guide's Updates page says what you see in the app.
Beatport and DuckDuckGo
When you run a match, CuePoint searches Beatport, directly and through DuckDuckGo, with text built from the tracks' title and artist. Features that use your Beatport account send your Beatport token to api.beatport.com. These requests go straight from your computer to Beatport or DuckDuckGo, only when you start them, and each service handles them under its own privacy policy.
The command-line tool
CuePoint's command-line tool has its own usage telemetry. It is separate from the app, opt-in, and off unless you turn it on.
What the app keeps on your computer
- Settings and preferences, in
~/.cuepoint/config.yaml. If you set up a Beatport token, it is kept there too. - Your library database: the Rekordbox library you imported, with the tags, ratings, notes, match decisions and change history CuePoint records about it. It is stored at
~/.cuepoint/cuepoint.db, with its backups in~/.cuepoint/backups/. - A cache of lookups, to make repeated ones faster:
~/Library/Caches/CuePointon macOS,%LOCALAPPDATA%\CuePointon Windows,~/.cache/CuePointon Linux. - Logs, rotated and cleaned of secrets and tokens, to help diagnose problems: a
Logsfolder in~/Library/Application Support/CuePointon macOS,%LOCALAPPDATA%\CuePointon Windows,~/.local/share/CuePointon Linux. - Exports you make (CSV, Excel or JSON), in the place you choose.
Help → Privacy clears the cache and the logs now. Whether CuePoint clears them each time it quits is chosen inSettings → Privacy → When CuePoint quits. Neither touches the library database: to remove your library and everything else CuePoint keeps in your home folder, delete the ~/.cuepoint folder yourself.
Help → Export support bundle makes a file with diagnostics, cleaned logs and your settings with secrets removed. You decide whether to share it. It does not contain your library, only the shape of it, such as the number of rows, and never track titles, artists, file paths, tags, ratings or notes.
Your choices
- Turn error reports off any time in Settings → Privacy → Send error reports.
- Clear the app's cache and logs in Help → Privacy, or have it do so each time it quits in Settings → Privacy → When CuePoint quits.
- Delete everything the app keeps, library included, by deleting the
~/.cuepointfolder. - If you wrote to the publisher through a form and want your message deleted, write to the publisher through the contact form.
Nothing you send, and nothing the app or the site collects, is sold or rented.
Changes to this policy
If what the site or the app does with information changes, this page is updated and its date changes. The app's own notice is in the repository as PRIVACY_NOTICE.md, and this page says the same about the app. The terms of use cover the rest.
Contact
Questions about privacy: write to the publisher through the contact form, or open an issue at github.com/stuchain/CuePoint/issues.