This policy describes the software as it is actually built, not as it is usually described. Where we collect something you might not expect, it is written down here.
The three things worth knowing first. We can see which apps you have chosen to wrap, when you open them, and how many cards you have reviewed. If you connect a tool like Notion, or ask our AI to write cards, that content leaves your device so it can be read. And if you join a project, the other members can see your display name, your streak and your points. Everything else is yours alone.
1. Who we are
Popcue is run by [full legal name of the person or company that runs Popcue], of [full postal address] (“we”). We are the controller of your personal data under the GDPR and the UK GDPR, and the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023: we decide what is collected and why.
You can reach us at hello@popcue.online or through the request form. Our Grievance Officer, and every other contact the law asks us to publish, are on the legal notice.
2. What we collect
Account
You sign in with Google. We receive your email address, your display name, and Google’s stable account identifier for you. We store those against your account so your streak, your mastery and your stats follow you between devices. We do not receive your Google password, and we never ask for it.
Your age, but not your date of birth
When you create an account we ask for the month and year you were born. We use them once, for the age check in section 11, and then keep only the result: whether the account is an adult’s or a minor’s, and when the check ran. We never store the date itself. If you are under 18, we also record that you confirmed a parent or guardian agrees to you using Popcue.
On Android, where the law makes Google Play share an age range for your Google account (at the moment, in Texas and Brazil), the app reads that range at the same moment and applies whichever of the two answers is more protective. It is used for nothing else, and not stored.
Goals, cards and reviews
The learning material you make. Goal titles, the notes you write about why you are learning something, the text you paste in as source material, the cards themselves (in any of eight formats), the images you attach, and every rating you give with its timestamp. Ratings feed a spaced-repetition scheduler, so we keep a per-card record of how many times you have seen it, when you last saw it, and when we should show it again. Cards our AI wrote are marked as AI-written.
Which apps you wrapped, and when you open them
This is the part the product exists for, so we are precise about it. The app watches for the apps you specifically chose to wrap. When one of them comes to the foreground, we record that it opened, and whether an interrupt was shown. We never receive the full list of what is installed on your phone, and we never see anything about what happens inside an app once it is running.
We keep per-app daily counts: how many times you opened it, and how many times a card interrupted you.
Device and technical data
A random identifier generated by the app, used to tie a request to your session. Your IANA time zone, sent so your streak rolls over on your midnight rather than ours. Your email’s domain, if you use an assistant connection.
Our server records each request it receives in its logs: the time, your IP address, the address requested (with any credential in it removed) and the result. We use the logs to keep the service secure and working, and delete them after 180 days.
On your phone, the app keeps what it needs to work offline: your session, cached cards and images, ratings waiting to be sent, and your reminder settings. On the web, the app keeps your session in your browser’s storage, because you could not stay signed in without it. It is not used to track you.
If you subscribe to Pro
Before you subscribe, the app asks you to tick a box agreeing to the renewal terms. We keep a record of that: the exact sentence you agreed to, the price and trial it showed, and when. California law requires us to be able to prove that consent. Google Play or PayPal takes the payment; we receive the product you bought and a purchase token, never your card details. We email you the terms after you subscribe and a reminder of them once a year.
If you join the waitlist
This is the one place we hold an address that is not attached to an account, and it is worth being exact about. The waitlist form on this site posts to a Google Form, and Google LLC is the processor of what you send. What is sent is: your email address, which of the five options you chose from the dropdown, the year you were born, the wording of the consent you ticked, and a short label for where you came from (a campaign name, the website that referred you, or “direct”).
We email you a link to confirm your address first. If you never click it, we do not email you again, and we delete the signup 30 days after we sent the link.
We do not store your IP address against it, we set no cookie for it, and we build no profile from it. Your address does not go to a mailing-list service. It goes to the Google Form described above, which is where the response is held.
Every email we send you has a one-click unsubscribe link. Using it deletes your waitlist entry. So does emailing hello@popcue.online from that address.
If you unsubscribe
We keep a one-way hash of your address on a list of people not to email. It is not your address, and it cannot be read back into one, but it lets us recognise it, which is how we make sure a stray copy of an old list can never reach you again.
If you send us a request, a notice or a report
Through the request form, or by reporting a project member or an AI-written card in the app, you send us what the form asks for: usually your name, your email address, where you live if you choose to say, what the request is about and where any content is. For a report made in the app, we also record which account made it and, for an AI-written card, what the card said at that moment. We use this only to handle the request.
If you ask us to delete your account from this website
The deletion page takes an email address and nothing else. We store that address, anything you typed into the box marked optional, and the date, until the request has been dealt with. We then delete the request row along with the account.
The address is not enough on its own, so nothing is erased when you submit. The request waits for a reply from you, which is the only thing that proves the address is yours. This is not a queue we get around to: it is the whole reason the reply is required.
What we do not collect
- The contents of your messages, browsing, files, or any app you wrap.
- Your location. We never call a location API.
- Your contacts, calendar, call log, camera or microphone.
- Your photo library. You can pick one image at a time to attach to a card, and only that image is sent.
- Your clipboard, on our servers.
- Your device model or manufacturer, on our servers.
- Your date of birth. See above.
What we do not do
- On the Android app: No analytics SDK, no tracking pixel, no session recording, no advertising profile built about you.
- On this website: We use Google Analytics (GA4) to understand how you use the site, but only with your consent. Google’s analytics code is not requested at all until you accept, and no cookies are set before you accept. No selling or renting your data.
- No session recording, no advertising profiles, no dark patterns, no pre-ticked boxes, no consent by continued use.
Analytics on this website
If you accept analytics in the consent banner when you visit popcue.online, we collect anonymized data about your interactions: which pages you visit, how long you stay, whether you scroll through the content, and whether you attempt to join the waitlist. This data is collected by Google Analytics and used only to improve the site and understand demand for Popcue. No personally identifiable information is sent to Google Analytics.
The events we send are: which waitlist button you clicked, that you started filling in the form, that you submitted it (with the same short label of where you came from described above), and that sending failed, if it did. What you typed into the form is never sent to Google Analytics.
Until you accept, Google Analytics is not loaded and nothing about your visit
is sent to Google. If you decline, or never answer the banner, that stays
true. Your choice is remembered on your device, in your browser’s local
storage rather than in a cookie. You can change it at any time with the
“Analytics choices” link in the footer of every page. Choosing
Decline there stops analytics at once and deletes the Google Analytics
cookies this site set (named _ga and _ga_ followed by
an identifier). The waitlist form works whether or not you accept analytics.
3. The Android permissions we ask for
Two make Popcue work, and both are explained in plain English before the system dialog appears.
| Permission | What it does |
|---|---|
| Usage access | Lets Popcue notice that an app you wrapped has opened. It does not give us access to your messages, browsing, or what you type. |
| Display over other apps | Lets the card be the thing on screen instead of the app. This is the permission that makes an actual interruption possible rather than a notification you can swipe away. |
The rest are asked for only when you use the feature that needs them, and you can say no:
| Permission | When it is asked for |
|---|---|
| Notifications | If you turn on streak reminders, and for the quiet notification Android requires while Popcue watches your wrapped apps (Android 13 and later). |
| Photos | On Android 12 and older, when you attach an image to a card. Newer Android versions use the system photo picker, which needs no permission and gives Popcue only the image you pick. |
| AnkiDroid | Only if you connect AnkiDroid, so Popcue can read your due cards and answer them back. Those cards never leave your phone. |
Android also grants some permissions without asking: internet access, and the advertising ID the ads SDK uses (section 4). You can check every permission yourself in Settings, then Apps, then Popcue, then Permissions. We do not request Android’s Accessibility Service, which some other blockers rely on.
4. Who else sees your data
These are the only parties that receive anything identifying you or drawn from your account. Each one is listed with the reason, because a subprocessor list that does not say what was sent is not a subprocessor list.
| Party | What they receive | Why |
|---|---|---|
| Google (Sign-In, Play Billing) | Your email and name at sign-in. At purchase, the product ID and a purchase token, plus a random account reference so a purchase cannot be replayed onto another account. | To authenticate you and to take payment. |
| Google (Forms for the waitlist; Analytics only if you accept) | Waitlist form: the email address, dropdown choice, year of birth, consent wording and referral label you submit. Analytics, only after you accept the banner: the pages you view and the events listed under “Analytics on this website”, with the technical details any web request carries, and a random identifier stored in a cookie on this site. | To hold the waitlist, and to count visits and sign-ups. |
| Google AdMob | Only if you choose to watch a short video: your device’s advertising ID, your IP address, basic device and app information, and a random Popcue account reference so the reward reaches your account. The ads are non-personalised: Google uses this to show, count and cap them and to prevent fraud, not to build a profile of you. In the EEA, the UK and Switzerland you are asked first, and you can change your answer under You, then Ad privacy choices. A minor’s requests carry Google’s teen treatment. | To serve the video you can optionally watch to unlock something. Your goals and cards are never sent. |
| OpenRouter and the model provider it routes to | When you ask AI to write cards: your goal title, your goal type, the notes you wrote about why you are learning it, any focus text, up to 20,000 characters of your own pasted material or connected page text, and the questions on the cards you already have, so the new ones are not repeats. | To generate the cards. Every request tells OpenRouter to use only providers that do not train on it, and by default only ones that keep nothing once they have answered. This is the single largest transfer of your content in the product, and it happens only when you ask, for the goal you ask about. |
| Notion (and any MCP endpoint you choose) | Your OAuth access and refresh tokens, encrypted. We use them to search your pages and read their text, to build cards from them. | To read the material you asked us to read. Disconnecting removes the stored tokens. |
| PayPal | Your email, on web purchases only. | To take payment. Android purchases go through Google Play instead. |
| Our email provider | Your email address and the message, when we email you. | To deliver email you asked for or that we must send: a waitlist confirmation, the terms of a subscription, a yearly subscription reminder, an acknowledgment of a request. |
| Our hosting providers | Everything above, stored on their servers on our behalf, and your IP address when you use the app or this site. | To run the service. They act only on our instructions. |
About AI generation. If you ask us to write cards from a tool you connected or from text you paste, that material is sent to our AI provider so a model can read it. If that is not acceptable for what you are working with, write the cards yourself or use a bring-your-own-model endpoint, which we never route anywhere.
When you use an assistant connection
You can optionally give an AI assistant (Claude, ChatGPT, or anything else that speaks the Model Context Protocol) a key that lets it read your goals and cards, and write new ones. The key is stored only as a salted hash and encrypted ciphertext, so we cannot show it to you or anyone else. Whoever holds it can read your learning material through the tools you enabled. You can revoke it at any time in Settings, and doing so removes it.
When you join a project
Projects are small, closed groups, not a public feed. Other members can see your display name, an avatar colour you picked, your current streak, your points and your rank. They cannot see your email address, your card content, or your goals. You can see the same of them. You can leave a project at any time, except if you created it, in which case remove a member instead.
When the law requires it
We disclose data to a court, a regulator or the police only when the law requires us to, and we tell you unless the law forbids it. Content that sexually exploits a child is reported to the authorities, as the law requires everywhere we operate.
5. Why we are allowed to
Under the GDPR and UK GDPR we rely on:
- Contract, to do what you use Popcue for: run your account, your goals, cards, reviews and streaks, show a card at the right moment, write cards with AI when you ask, and read a tool you connected. Nothing goes to an AI provider or is read from a tool unless you asked for it; you stop it by not asking, or by disconnecting the tool.
- Consent, for the waitlist and the emails it sends. The tickbox is not decoration: the server rejects a submission without it, and the confirmation link shows it was you. The one-click unsubscribe in every email withdraws it.
- Consent, where the law requires it for the advertising ID the ads SDK uses (in the EEA, the UK and Switzerland), given in Google’s consent form and changeable under You, then Ad privacy choices.
- Legal obligation, for the age check; the billing records and subscription consent records we are required to keep; handling the requests, complaints and notices the law says you may send us; completing a deletion request; and remembering an unsubscribe.
- Legitimate interests, for keeping the service secure, preventing abuse, and understanding it in aggregate. We do not use this to profile you.
You may object to processing based on legitimate interests, and you may withdraw consent at any time, without affecting processing that already happened.
Under India’s Digital Personal Data Protection Act we process your data with the consent you give when you create an account after reading this notice, or for a legitimate use the Act allows, such as complying with a law. You can withdraw consent as easily as you gave it: by deleting your account, by unsubscribing, or by disconnecting a tool.
6. AI, and decisions made by software
- AI writes cards only when you ask it to. Every card it wrote is marked as AI-written in the app and in your data export.
- AI can be wrong. You can edit or delete any card, and report one that is offensive or wrong from the card itself.
- No decision with a legal or similarly significant effect on you is made by software alone. The age check applies a fixed rule to the answer you give, and anyone who thinks it went wrong can ask a person to look at it through the request form.
7. How long we keep it
| What | For how long |
|---|---|
| Your account, goals, cards, reviews, streak, settings, and wrapped-app history | Until you delete your account, then erased straight away. |
| Your age band, when it was checked, and a guardian’s agreement | With the account. Your date of birth is never kept at all. |
| Connected-service tokens (Notion, MCP endpoints) | Until you disconnect, or delete your account. Erased with the account. |
| Images you attach to cards | Until you delete the card, or your account. |
| Idempotency receipts for offline reviews | 30 days. |
| Server logs | 180 days. |
| Your waitlist entry | Until you unsubscribe or ask us to remove it. We do not need it once the build has shipped and you have had it. An entry that is never confirmed is deleted 30 days after we send the confirmation link. |
| An unsubscribe (a one-way hash of your address) | Kept indefinitely, because forgetting it is how an unsubscribed person starts getting email again. |
| An outstanding web deletion request (address, optional note) | Until the account it refers to is erased, which is when the request row is deleted with it. It cannot be erased by the deletion it asks for, because it is the record of that request. |
| Requests, notices and reports | Until handled, then three years, so how they were handled can be shown if it is questioned. If you delete your account, your account’s identifier is removed from them. |
| Billing records (purchase tokens, subscription IDs, ad reward records) | Retained after you delete your account. We are required to keep transaction records for accounting and to handle refunds and disputes. These contain an account reference, not your content. |
| Subscription consent records | Retained after you delete your account, for three years or one year after the subscription ends, whichever is longer, as California law requires. |
| Records that a shared project needs (the project itself, and the fact that you joined a referral) | Retained after you delete your account so that other members’ earned points and an earned referral credit stay intact. Your membership record and display name on other boards are removed. |
| Invite codes | Retained while the account exists, so a reward already claimed stays claimed. |
Deleting your account does not cancel a Google Play subscription. Cancel in the Play Store first, or you will keep being charged for something you have deleted.
8. Your rights
Wherever you live, you can ask us for these, and we answer everyone the same way. The GDPR, the UK GDPR, India’s DPDP Act and the US state privacy laws (California’s CCPA/CPRA and the laws of Colorado, Connecticut, Virginia, Texas, Oregon and the other states that have one) each give some or all of them the force of law:
Get a copy
Everything we hold, as a single JSON file. In the app: You, then Download my data. Or ask us, and we will send it, with a summary of what we do with it and who we shared it with.
Correct it
Your display name, goals and notes are editable in the app. For anything else, including something missing or out of date, ask us.
Delete it
In the app: You, then Delete account. Or use the deletion page. We do the same thing either way.
Stop us using it
Disconnect a tool, stop asking for AI, unsubscribe, change your ad privacy choices, or object to processing based on legitimate interests.
Take it elsewhere
The export is JSON, in a documented shape, so it is readable by something that is not us.
Name someone
Under India’s DPDP Act, you can nominate a person to use these rights for you if you die or can no longer act yourself. Tell us who.
Complain
To us first if you like, through the request form. Then to a regulator: see below.
How to ask. Use the request form or email hello@popcue.online. You can ask through someone you have authorised, and we may need to check it is really you, or really them. We answer within 30 days (45 for a US state request); if a request is unusually complex we may take longer, and we will tell you why within that time. We do not charge, and we do not treat you differently for asking.
Complaints. Through the form, a complaint is acknowledged at once and in any case within 30 days, and we tell you what we did about it. You can also complain to a regulator: in the EU, the data protection authority where you live; in the UK, the ICO; in India, the Data Protection Board of India, after first raising it with our Grievance Officer; in the US, your state attorney general; in Canada, the Office of the Privacy Commissioner; in Brazil, the ANPD; in Australia, the OAIC.
If you live in the United States. We do not sell your personal information, share it for cross-context behavioural advertising, use it for targeted advertising, or profile you in a way that produces legal or similarly significant effects, so there is nothing to opt out of. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out anyway. We do not use or disclose sensitive personal information as California law defines it. If we decline a request, you can appeal by replying to our answer; we answer an appeal within 45 days, and if we still decline you can contact your state attorney general.
9. International transfers
We are based outside the European Economic Area and the United Kingdom, and the services listed in section 4 are largely American. Your data is therefore transferred outside the UK and EEA to count as a transfer under Chapter V of the GDPR.
Where a transfer is subject to the UK IDTA or the EU Standard Contractual Clauses, we rely on those. Where a service is covered by an adequacy decision, including the EU-US Data Privacy Framework where a recipient has certified, we rely on that instead. Where neither applies, we use the safeguards in the preceding sentence and, where the transfer is to a country without an adequacy decision, supplementary measures where they are available.
10. How it is kept safe
- Passwords, where they exist, are stored as bcrypt hashes and are never recoverable.
- Connected-service tokens are encrypted at rest with AES-GCM. The encryption key is separate from anything else.
- Assistant access keys are stored only as a salted hash and encrypted ciphertext.
- Data in transit is TLS. Our API rejects unencrypted requests in production, and refuses to start at all with an unsafe configuration.
- Credentials are removed from our logs before they are written.
- Deleting your account erases your data, not just hides it.
- Images you attach are served only to you, and only if you know the identifier.
No system is perfectly secure. If a breach affects your data we will tell you without undue delay, and tell the regulators the law names in the time it sets: within 72 hours for the GDPR and India’s Data Protection Board, and within 6 hours for a cyber incident India’s CERT-In must be told about.
11. Children and teenagers
Popcue is not directed at children, and you must be at least 13 to use it. When you create an account we ask for the month and year you were born.
- Under 13: we do not create the account, and we keep nothing from the attempt. The app will not ask again on that device for a day.
- 13 to 17: you confirm that a parent or guardian knows you are using Popcue and agrees. Ads are requested with Google’s teen treatment and a teen content rating. Nothing about you is used for advertising, which is true for everyone.
- On Android, where Google Play shares an age range for your Google account, the stricter of that and your answer applies, and a parent who manages your account in Google Play can decline Popcue there.
If we learn that an account belongs to someone under 13, we delete it. If you are a parent and believe your child under 13 has an account, tell us through the request form and we will delete it.
India’s Digital Personal Data Protection Rules will require the verifiable consent of a parent for users under 18 from 14 May 2027. We will change how accounts for under-18s in India work before then, and update this policy when we do.
12. Changes to this policy
If we change what we collect or why, we will update this page and change the date at the top. If a change materially affects how your data is used, we will tell you in the app before it takes effect. The version history is available on request.
13. Contact
hello@popcue.online reaches a person, and the request form gives you a reference number. Please include enough to identify the account, such as the email address you signed up with, but never send us a password or an access key.
See also the Terms of Service, the legal notice and the account deletion page.