Skip to main content
OnCue

OnCue · Data handling

How OnCue handles your data

Resumes, interview history, and recordings stay on this computer by default. When you use cloud speech or a model, the content needed for that task leaves the device. The OnCue gateway does not store that content. The provider you use still processes it under that provider's terms.

What stays on this device

The resume workspace, target role, company, and job description, plus interview history, transcripts, and scores, are stored in local SQLite. Saved recordings are WAV files in the app data directory. The database file itself is not encrypted.

Keys and sign-in credentials

Bring-your-own-key provider keys sit in the local database with reversible obfuscation so they are not plaintext. That is not OS keychain protection. The hosted refresh token is written to the OS keychain when that store is available, and a reversible copy is also kept in the local database. The short-lived access token stays in memory. Provider keys are not sent to OnCue.

Where requests go with your own key

In bring-your-own-key mode, audio, transcripts, resume text, and job descriptions go from this device directly to the provider selected in the app. They do not pass through the OnCue gateway. Usage and retention follow that provider's terms.

What hosted mode stores

In hosted mode, the selected system-audio and microphone streams pass through the OnCue gateway to the transcription service. The question and the context needed for an answer pass through the gateway to the model service. If mock-interview question speech is on, the question text passes through the gateway for speech synthesis and the audio returns to the device. The gateway does not store audio, transcripts, prompts, resumes, or answers. When Gemini Live session resumption is used, Google may retain resumable session state during its two-hour handle window.

Account and payment records

The hosted service stores the account email, display name, salted password hash, sessions, quota, and the records needed for a payment order. It does not store plaintext passwords or payment passwords. Usage metadata is kept for 730 days, and security audit events for 30 days. Checkout currently uses WeChat Pay, which receives the merchant order number, product description, and amount.

What clearing local data removes

Clear local data in Settings removes history, settings, the resume workspace, recordings, provider keys, and the hosted refresh token from this device. It does not delete the hosted account or the billing records required to run the service. This page is not an account-deletion form.

Download OnCue See the resume optimizer data boundary →