This policy explains what data Sidecue collects, why, and the choices you have. It covers the Sidecue browser extension and web dashboard (together, the “Service”).
1Who we are
Sidecue is operated by Michał Włosik EFC, ul. Północna 16/5, 54-105 Wrocław, Poland (NIP: 8942747708). “We”, “us”, and “our” refer to the operator. “You” refers to you, the user of the Service.
2What Sidecue does
Sidecue is a Chrome extension and companion web dashboard that provides real-time answer cues during conversations. When you start a session, the extension captures audio from a browser tab, transcribes it in real time, detects questions or talking points, and generates suggested responses in a side panel or floating overlay. Sidecue does not access your microphone.
The dashboard lets you manage your knowledge base (context text and uploaded files), review past session history, and manage your account. Knowledge base content syncs automatically between the dashboard and the extension. Audio is never recorded or stored on any server, tab audio is streamed to a speech-to-text provider for live transcription and discarded immediately after processing.
3Eligibility
Sidecue is intended for users aged 16 and older. By using the Service, you confirm you are at least 16. We do not knowingly collect data from anyone under 16; if we learn that a user is under 16, we will promptly delete their account and associated data.
4Data we collect
4.1 Account data
- Email address: for authentication and account management.
- Display name and profile photo: provided by Google if you sign in with Google OAuth; used only for display within the Service.
- Authentication tokens: stored locally on your device and managed server-side via Supabase Auth to keep you signed in.
4.2 Knowledge base content
- Context text: free-text notes about your experience and the role, stored in our database and synced between extension and dashboard.
- Uploaded files: resumes, job descriptions, or notes (.txt, .md, .pdf, .docx) stored in Supabase Storage under your account. At session start, files are temporarily transferred to Google’s Gemini File API so the AI can read them; those copies expire automatically after 48 hours.
You control your knowledge base entirely and can edit, delete, or clear it at any time. Deleting a file removes it from our storage immediately.
4.3 Session usage data
- Session start and end timestamps, to calculate duration.
- Session duration, to meter usage against your monthly quota.
- Account tier (Free or Paid), to enforce usage limits.
4.4 Session history
- Session title and platform, e.g. “Google Meet”, from the captured tab title.
- Conversation transcript, attributed to “You” and the other speaker.
- Generated cues, the questions detected and answers produced during the session.
You can delete individual sessions or your entire account at any time.
4.5 Settings and preferences
Your configuration choices (theme, language, response style, and so on) are stored locally in the extension’s browser storage and are not transmitted to our servers.
4.6 Analytics
We use Google Analytics to collect anonymous, aggregated usage statistics such as page views and feature usage. You can opt out with the Google Analytics Opt-out Browser Add-on.
5How we use your data
- Provide the service: authenticate your account, manage sessions, enforce quotas, and sync your knowledge base across devices.
- Generate real-time cues: relay transcribed speech and your knowledge base to a large language model. Prompts and responses are processed in real time and are not stored by us.
- Transcribe audio: stream tab audio to a speech-to-text provider. Audio is processed in real time and not retained.
- Session history: save transcripts and cues so you can review them later.
- Improve the product: analyse anonymous, aggregated usage patterns.
- Customer support: respond to enquiries you send us.
6Third-party services
Deepgram, speech-to-text
- Tab audio is streamed via encrypted WebSocket for real-time transcription.
- Audio is processed on the fly and not stored under our configuration.
- deepgram.com/privacy
Google Gemini, cue generation
- Recent transcribed speech and your context text are sent via our server-side proxy to generate cues.
- Uploaded files are temporarily sent to the Gemini File API and expire after 48 hours.
- Prompts and responses are processed in real time; we don’t log or store them.
Supabase, backend infrastructure
- Handles authentication (email/password and Google OAuth).
- Stores account data, usage records, knowledge base content, uploaded files, and session history.
- Hosted in the EU West region.
Google Analytics, usage analytics
- Collects anonymous, aggregated usage statistics.
Polar.sh, payment processing
- If you subscribe to a paid plan, payment is handled by Polar.sh. We never receive or store your card details.
7Data sharing
We do not sell, rent, or trade your personal data. We share data only with the third-party providers above to operate the Service, when required by law, or in the event of a business transfer.
8Data retention
- Account data: retained while your account exists; removed within 30 days of deletion.
- Knowledge base and files: retained until you delete them or your account.
- Session history: retained until you delete the session or your account.
- Temporary Gemini copies: deleted by Google after 48 hours.
- Audio: never stored; processed in real time and immediately discarded.
9Data security
- All traffic uses HTTPS/TLS; audio streams use encrypted WebSocket (WSS).
- Third-party API keys are stored server-side and never exposed in client code.
- Uploaded files are accessible only to you, enforced via row-level security.
- The Supabase backend is hosted in the EU West region.
No system is perfectly secure, but we take reasonable precautions to protect your data.
10Your rights
Depending on your jurisdiction, you may have rights to access, rectify, erase, port, object to, or restrict processing of your personal data. To exercise any of them, contact contact@sidecue.app. We respond within 30 days, or the timeframe required by law.
11International data transfers
Our authentication and storage run in the EU (West) via Supabase. Third-party services such as Deepgram and Google Gemini may process data in the United States or other regions. By using the Service, you acknowledge that your data may be processed outside your country of residence.
12Browser permissions
- tabCapture: capture audio from a browser tab. Sidecue does not request microphone access.
- offscreen: process tab audio in the background.
- sidePanel: display cue cards, transcript, and settings.
- storage: save settings and your session locally.
- identity: complete Google OAuth sign-in.
- activeTab & scripting: inject the floating overlay when you request it.
Audio capture requires an explicit two-step action: click the Sidecue icon to connect, then click Start. No audio is captured or sent anywhere until you press Start, and stopping the session immediately releases the stream.
13Changes to this policy
We may update this policy from time to time. For material changes we’ll update the effective date and, where feasible, notify you. Continued use after changes take effect constitutes acceptance.
14Contact
Michał Włosik EFC
ul. Północna 16/5, 54-105 Wrocław, Poland
Email: contact@sidecue.app