Cue
Privacy Policy
Effective October 7, 2026
Who we are and what this covers
Cue is an operations platform for Applied Behavior Analysis (ABA) clinics. It is offered as a web application at app.cueaba.com and as native mobile apps for iOS, iPadOS, Android, Apple Watch, and Wear OS (together, the Service).
This policy explains what information the Service collects, why, how it is protected, and the choices available to you. It applies to clinic staff, clinicians, administrators, and family members who use the Service.
Cue provides the Service to clinics. Each clinic is the covered entity or business owner responsible for the client records it keeps in Cue. Cue processes that information on the clinic's behalf, as a business associate under HIPAA for US clinics (under Cue's Business Associate Agreement, app.cueaba.com/legal/baa) and as a processor under the GDPR and similar laws for other clinics (under Cue's Data Processing Agreement, app.cueaba.com/legal/dpa). Where this policy and a clinic's own notice differ regarding a client's health information, the clinic's notice governs.
Information we collect
Depending on how you use the Service, we collect the following categories of information.
- Account information: your name, work email address, phone number, role, credentials and licensure, and profile photo, provided by you or your clinic when your account is created.
- Clinical and operational records: client (kiddo) demographics, insurance and authorization details, session schedules, session notes, skill and behavior data, treatment plans, and related documents entered by your clinic. This is protected health information (PHI) belonging to the clinic and its clients.
- Messages: messages, attachments, reactions, and read receipts sent through Cue Chat, including care-team channels and family conversations.
- Location: precise device location when you clock in or clock out of a session, so the Service can verify that a home or community session occurred where it was scheduled (electronic visit verification). Cue does not collect device location continuously or while the app is in the background.
- Device and usage information: device model, operating system version, app version, language, push notification token, IP address, and logs of actions taken in the Service, used for security, support, and reliability.
- Billing and payroll information for staff: pay rates, hours, and payment statements maintained by your clinic. Tax identifiers are stored encrypted.
How we use information
- To operate the Service: scheduling, session documentation, data collection, authorization tracking, billing, payroll, messaging, and reporting for your clinic.
- To verify sessions: matching clock-in and clock-out location and time against the scheduled visit, as required by payers and state EVV programs.
- To send notifications you or your clinic enable, such as session reminders, co-sign requests, and chat messages. Notification previews withhold client details on the lock screen for channels that carry PHI.
- To keep the Service secure: authentication, audit logging, fraud and abuse detection, and incident response.
- To support you: answering questions and troubleshooting problems you report.
- To improve the Service using aggregate, de-identified usage data that cannot reasonably be linked to a person.
We do not sell personal information. We do not use client health information for advertising, and we do not show advertising in the Service.
Assistive AI features
Some features draft session notes, summaries, or briefings from information already in the Service. These features run only when a user invokes them or a clinic enables them. Information sent to an AI provider for these features is processed under a data processing agreement that prohibits the provider from training models on it. A clinician remains responsible for reviewing and approving any drafted clinical content.
How we protect information
- Encryption in transit for all connections and encryption at rest for stored data. Fields containing the most sensitive identifiers are additionally encrypted at the application layer.
- Access controls that limit what each user can see to their role and clinic, enforced on the server and in the database, not only in the app.
- Audit logs of access to client records.
- Biometric or passcode lock on the mobile apps, and automatic sign-out after inactivity.
- Offline data cached on a mobile device is stored in encrypted storage and removed when you sign out.
- Regular vulnerability scanning of our software dependencies and a process for responding to security reports.
No system is perfectly secure. If we learn of a breach affecting your information, we will notify the affected clinic and, where required by law, affected individuals and regulators.
How long we keep information
Clinical and billing records are retained for as long as the clinic maintains its account and for the period the clinic instructs or the law requires afterward, commonly six to ten years for health records. Account information is kept while your account is active and deleted or de-identified within a reasonable period after it is closed. Location records are kept with the session they verify. Server logs are kept for a limited period for security purposes.
Your choices and rights
- Location: you can deny or revoke location permission in your device settings. Session verification features will not work without it, and your clinic may require it for home and community sessions.
- Notifications: you can turn push notifications off in the app or in your device settings.
- Access and correction: you can review and update your own profile in the app. Requests about client records should go to the clinic that holds them, and we will assist the clinic in responding.
- Deletion: you can ask your clinic administrator to close your account, or contact us at the address below. We will delete or de-identify your information unless we must keep it to meet a legal or contractual obligation.
- Residents of California and other states with privacy laws may have additional rights, including the right to know what information we hold, to request deletion, and not to be discriminated against for exercising these rights. Contact us to exercise them.
Children
The Service is used by adults who work at or receive services from a clinic. Information about children is entered by clinics and families in the course of care and is protected as health information. We do not knowingly create accounts for children under 13.
Where information is processed
Clinics on app.cueaba.com are hosted in the United States. Clinics on Cue's European platform, eu.cueaba.com, have their clinical database and application servers in Frankfurt, Germany, separate from the US platform.
Some services Cue relies on, such as email delivery and AI features, may process limited information in the United States. For clinics outside the United States, those transfers are covered by Cue's Data Processing Agreement and the EU Standard Contractual Clauses. The current list of sub-processors and their locations is at app.cueaba.com/legal/subprocessors.
Changes to this policy
We may update this policy from time to time. We will post the new version here with a new effective date and, for material changes, notify clinic administrators in the Service.
Contact us
Questions about this policy or your information can be sent to support@cueaba.com. To report a security concern, use security@cueaba.com.