Privacy policy

What we collect, why we have it, who else sees it, and how long we keep it. Written to be read rather than to be defensible.

In force from
23 August 2026
Operated by
GetG Technology Private Limited

The short version

If you run webinars on Cued, we hold your account details and your billing history. If you attended somebody's webinar, the organiser holds your details and we only store them on their behalf — ask them, not us, and we will help them answer you.

We share data with a small number of named processors: a payment provider, a speech-to-text provider, an advertising platform and our own hosting. Each is listed below with what it receives. We do not sell personal data to anybody, and we never will.

Two different roles

This is the part most policies skip, and it decides who you should be asking about what.

  • For organisers and site visitors we are the controller. We decide what to collect and why, and this policy governs it.
  • For webinar attendees we are a processor. The organiser who ran the webinar decides what to ask you, why, and what to do with it afterwards. We hold it on their instructions and act on their behalf. Their privacy policy governs it, not ours.

If you registered for a webinar and want your data removed, contact the organiser who ran it. If they do not respond, write to us at info@getgrahak.co and we will chase it.

What we collect

If you have an account

  • Your name, email address, company name, and phone number if you give one.
  • Your timezone, taken from your browser, so schedules read correctly.
  • A password, stored only as a one-way hash. We cannot read it.
  • Your billing history — plan, amounts, dates and payment status. Card details never reach our servers; they go directly to Razorpay.
  • Your webinars: recordings you upload, the chat you write, the questions your attendees send, and the attendance figures that result.
  • How you arrived — the advertising click identifier and campaign parameters, if you came from an ad. This is kept on your account so a later subscription can be attributed to the campaign that caused it.

If you attended a webinar

  • Whatever the organiser asked for on their registration form — usually a name and email.
  • Whether you joined, how long you watched, and anything you typed into the chat or the raised-hand button.
  • Your IP address and browser user-agent, recorded with the registration.

All of that belongs to the organiser. We do not use it to market to you, and we do not combine it with anything else we hold.

If you filled in a form on one of our ads

We keep the name, email and phone number you gave, along with which campaign brought you and the advertising click identifier — whether or not you went on to create an account. That is how we know how many people got that far and then stopped, which is the only way to tell whether a campaign is working.

We may email you about the product on the strength of it, because you asked us to be in touch. Reply and say stop and we will, and if you never create an account the record is deleted after a year whether you ask or not.

If you just visit the site

  • Standard server logs: IP address, page requested, time, browser.
  • Advertising and analytics identifiers set by the Meta pixel, if you have not blocked it. See cookies below.

Why we have it

  • To provide the service — you cannot run a webinar without an account, and attendees cannot join without registering.
  • To take payment — a subscription needs a billing record.
  • To keep it working and secure — logs, rate limiting, abuse investigation.
  • To tell you about the product — service notices you cannot opt out of because they concern your account, and product updates you can.
  • To measure our advertising — described in full below, because it is the part people most reasonably object to.

Who else sees it

These are all the third parties that receive personal data from us. There are no others.

Razorpay — payments

Receives your name, email and the amount when you subscribe or top up. Card and bank details go straight to them and never touch our servers, so we could not disclose them if we were asked to. Governed by Razorpay's own privacy policy.

OpenAI — transcription and cue generation

Read this one if you upload recordings. When you use the automatic cue writer, the audio of the recording you selected is sent to OpenAI to be transcribed, and the resulting transcript is sent back to generate chat messages. If your recording contains personal data — names, customer details, anything said aloud — that data goes with it.

This only happens when you press the button. It is never done automatically, and a webinar you never run the cue writer against is never sent anywhere. Any reference material you attach is sent with it, so do not attach anything you would not want processed by a third party.

Meta — advertising measurement

When you arrive from one of our ads, sign up, or subscribe, we report that event to Meta so we can tell which advertising works. What is sent is your email, phone number and name hashed with SHA-256 before it leaves our servers — Meta can match those against accounts it already has, but cannot read them or learn anything about you it did not already know. Your IP address, browser user-agent and the advertising click identifier are sent unhashed, because Meta requires that.

We do not report anything about webinar attendees to Meta. This is only about people who visit our own site and sign up for our own product.

Email delivery

Reminders to your attendees are sent through your own mail server if you have configured one, in which case we hand the message to your provider and nobody else sees it. Otherwise they go through ours.

Hosting

Everything else — the application, the database, your uploaded recordings — sits on servers we control, in India. Recordings are stored and served from our own infrastructure and are not handed to a third-party video platform.

Cookies

We use as few as we can get away with.

  • Essential. A session token so you stay signed in, a CSRF token, and a short-lived signature that authorises video playback. Without these nothing works.
  • Preference. Your light or dark theme choice. It never leaves your browser.
  • Advertising. _fbp and _fbc, set by the Meta pixel on our marketing pages, used to connect an ad click to a signup. Blocking them costs you nothing — the site works identically.

The advertising pixel runs on our own marketing and landing pages only. It is not loaded on an organiser's registration page or inside a webinar room, so attending somebody's webinar does not put you into our advertising.

How long we keep it

  • Account and billing records — while your account exists, and for as long afterwards as tax law requires us to keep the invoices.
  • Source recordings — the original upload is deleted about a week after it has been processed. The streamable version is kept while the webinar exists.
  • Transcripts — kept with the recording, so regenerating cues does not have to re-transcribe. Deleted with it.
  • Archived webinars — 30 days, then deleted along with their registrations, attendance and messages.
  • Advertising event records — 180 days. These hold only hashed identifiers.
  • Landing form submissions from people who never signed up — one year, then deleted automatically. If you did create an account it is kept with the account, because it is part of how you got here.
  • Server logs — a short rolling window, for security and debugging.

Your rights

Under India's Digital Personal Data Protection Act, and equivalent law elsewhere, you can ask us to show you what we hold, correct it, delete it, or stop using it. Write to info@getgrahak.co and we will answer within 30 days.

Two honest caveats. If you are an attendee rather than an account holder, the request has to go to the organiser — we will forward it and press them, but the data is theirs to delete. And we cannot delete records we are legally required to keep, such as invoices.

Security

Passwords are hashed, not stored. API tokens and third-party credentials are encrypted at rest. Video is served over signed, expiring URLs so a link cannot be shared indefinitely. Traffic is HTTPS throughout. None of that makes a breach impossible, and if one happens that affects you we will tell you and the regulator rather than hoping nobody notices.

Children

Cued is a business tool and is not for anybody under 18. We do not knowingly collect data from children. If you believe a child's data has reached us through an organiser's registration form, tell us and we will remove it.

Changes

If we change this materially we will email account holders before it takes effect rather than quietly updating the date at the top.

Contact

GetG Technology Private Limited, trading as Cued.
Privacy and data-protection grievances: info@getgrahak.co