Legal
Privacy Policy
What CrowdCue collects, why, who it is shared with, and how long it is kept.
Last updated 5 September 2026
CrowdCue (“we”, “the service”) is operated by Tanay Arya, an individual based in India. This policy explains what the service collects, why, who it goes to, and how long it is kept. Questions go to apps@tanayarya.com.
Who is responsible for your data
CrowdCue has two kinds of user, and the answer differs for each.
- Organizers create events. For an organizer’s own account data, we are the controller.
- Attendees ask and upvote questions at somebody else’s event. The organizer decides to run that event and what to do with the questions, so for event content the organizer is the controller and we act as a processor on their behalf. If you asked a question at an event and want it removed, the fastest route is the organizer running it — though you can also write to us.
What we collect
If you organize an event
- Your email address. Sign-in is a six-digit code sent to your inbox; there is no password. Your address is stored so we can recognise the account and attach your events to it.
- Your events. Event name, optional description, the join code, status, and the times it was created, opened and closed.
- A session cookie so you stay signed in. See the Cookie Policy.
If you join an event
- No account, no email, no name unless you choose to add one. Questions are anonymous by default; a display name is optional and capped at 40 characters.
- The text of your question and any polls you vote in.
- An anonymous identifier — a random value in a cookie on your device, used only to stop one person upvoting the same question twice and to show you your own questions. It is not linked to your name, email or any account. In our database it is stored as a one-way digest that is different for every event, so it cannot be read back out or used to follow you between events.
Everyone
- Your IP address is read from the network request to rate-limit abuse (for example, someone requesting hundreds of sign-in codes). It is held briefly in memory for that check and is not written to our database.
- Usage analytics. We record aggregate, event-level metrics about how the product is used — how many questions and votes an event received, which features get used, and errors — so we can keep the service reliable and decide what to improve. These are counts and technical signals, not a profile of you, and they are not sold or used for advertising.
AI processing of questions
CrowdCue uses an AI model to notice when two people have asked the same thing, so an organizer sees one question with the combined votes instead of five near-identical ones.
- What is sent. When a question is posted, its text is sent to our AI provider — currently OpenAI — together with the text of up to 30 recent questions from the same event, so the model can compare them.
- What is not sent. No email addresses, no display names, no account details, no cookie identifiers, and nothing from any other organizer’s event.
- What comes back. A yes/no verdict, the id of the matching question and a confidence score. The model never edits, rewrites or deletes anyone’s question; a merge only ever combines votes, is labelled as automatic, and can be undone by the organizer.
Treat anything you type into a question as leaving our systems. Question text is processed by a third-party AI provider under that provider’s terms, and depending on those terms and the plan in force it may be retained for a period or used to develop and improve their models. Do not put passwords, financial details, health information, or anything else confidential into a question.
If no AI provider is configured for a deployment, this step is skipped entirely and only word-for-word repeats are merged, which happens locally with no data leaving our systems.
Why we are allowed to use it
- To provide the service — showing questions, counting votes, keeping you signed in. Without this the product cannot work (contract / legitimate interests).
- To keep it safe — rate limiting and abuse prevention (legitimate interests).
- To improve it — aggregate usage analytics and duplicate detection (legitimate interests).
- Because you chose to — adding your name to a question is optional and entirely up to you (consent).
Who we share it with
We do not sell personal data. We share it only with the providers that run the service:
- Supabase
- Database and authentication. Stores accounts, events, questions and votes.
- OpenAI
- Duplicate detection, as described above. Receives question text only.
- Our hosting and email providers
- Serving the application and delivering your six-digit sign-in code.
We will also disclose data where the law requires it, or where it is necessary to investigate abuse. Some of these providers operate outside India, so your data may be processed abroad under the safeguards those providers offer.
How long we keep it
- Attendee content — questions, votes and poll answers are deleted 30 days after an event is closed. The event itself (its name and statistics) is kept for the organizer.
- Organizer accounts are kept until you ask us to delete them.
- The attendee cookie lasts up to 180 days, or until you clear it.
Your rights
Depending on where you live, you can ask for a copy of your data, ask us to correct or delete it, object to how we use it, or withdraw consent. Write to apps@tanayarya.com and we will respond within 30 days.
For a question you asked at an event, tell us the event and roughly when you asked — since we deliberately do not know who you are, that is usually what we need to find it. You can also delete the cookie from your browser at any time, which permanently severs the link between you and anything you have posted.
Children
CrowdCue is not directed at children under 13, and organizers must not use it to collect questions from children under 13 without the consent of a parent or guardian. If you believe a child has posted personal information, contact us and we will remove it.
Security
Data is encrypted in transit. Attendee identifiers are stored as one-way digests, the identity cookie is signed and marked httpOnly so page scripts cannot read it, and access to the database is restricted by row-level security so one organizer cannot read another’s events. No system is perfectly secure, and we cannot guarantee absolute security.
Changes
If this policy changes we will update the date at the top of this page. Material changes to how we use your data will be announced in the product before they take effect.
Contact
Tanay Arya — apps@tanayarya.com