Useful context.
Strict boundaries.
This launch document describes the privacy behavior implemented in the product. A jurisdiction-specific privacy policy and data-processing agreement should be reviewed by counsel before public sales.
What the desktop handles
WitCue can process microphone audio, computer audio, user-selected documents, screenshots, session descriptions, and conversation text only when the customer invokes those features. Saved desktop session history remains on that Windows device unless a future sync feature is explicitly enabled.
What the service handles
The managed service authenticates the subscription, streams audio to the configured transcription provider, routes answer requests to configured model providers, and records metered usage. Operational logs are designed to omit transcripts, prompts, screenshots, credentials, activation codes, email addresses, and device names.
Credentials
Customers do not receive provider API keys. Desktop access and refresh tokens are stored using Windows protected storage. Service provider credentials and billing webhook secrets remain server-side.
Screen sharing
WitCue requests Windows capture protection and removes the native shadow from protected windows. Whether content is excluded still depends on Windows, the conferencing application, GPU path, and chosen capture mode. WitCue does not promise invisibility or bypass proctoring, monitoring, or security software.
Retention and deletion
Production launch configuration must specify provider retention, backend event retention, account deletion, and legal-request handling. Customers can sign out and revoke active devices through account controls.