AI Transparency Notice

    Version 2026-08-01 · Last updated August 2026

    ClickCues uses a third-party AI model to turn raw feedback into a clearer title, description, severity and repro steps. This page states precisely what leaves ClickCues, what never leaves, and what you can turn off.

    1. The provider

    AI summarisation is performed by Google Gemini, accessed through the Lovable AI Gateway. Requests are made server-side from our backend, never from your visitors' browsers.

    We do not train any model on your data, and we do not permit the provider to train on it. We do not use your feedback content to improve ClickCues' own models, because we do not operate any.

    2. What is sent

    FieldSent?Notes
    Feedback titleYesScrubbed for credentials and email addresses first.
    Feedback descriptionYesScrubbed for credentials and email addresses first.
    Page addressPartlyOrigin and path only. Query strings and fragments are removed before transmission.
    Browser, OS, viewportYesTechnical strings only, e.g. "Chrome 128", "macOS", "1440x900".
    CSS selector of the pinned elementYesStructural selector only, never the element's value.

    3. What is never sent

    • Screenshots. No image is ever transmitted to a model provider. Summarisation is text-only.
    • File attachments. Never transmitted.
    • Reviewer name or email address. Never transmitted, even when the reviewer supplies one.
    • Your account details. No account email, billing data or team roster is transmitted.
    • Console logs captured by the widget. Stored for your debugging, never sent to a model.
    • Query strings, URL fragments and URL credentials. Stripped before storage and before transmission.

    4. Redaction before transmission

    Free text is passed through a server-side scrubber before it leaves our infrastructure. It replaces credential-shaped content with placeholders, including: bearer and basic authorisation headers, JSON Web Tokens, Stripe, Google, GitHub, Slack and AWS key formats, PEM private key blocks,password=-style assignments, card-length digit runs, email addresses and long opaque tokens.

    This is a safety net, not a guarantee. A reviewer who types a secret in an unusual format may still have it transmitted. Treat feedback text as content a third-party processor will read.

    5. Automated decision-making

    AI output in ClickCues is advisory labelling only. It never approves or refuses anything, never affects billing, never affects access, and never produces a legal or similarly significant effect on any person. AI-generated fields sit alongside the reviewer's original words, which are always preserved unedited.

    AI-generated fields are labelled in the interface so your team can tell them apart from what the reviewer actually wrote.

    6. Accuracy

    Summaries can be wrong. Severity suggestions can be wrong. Duplicate detection is a similarity heuristic and can produce false matches. Do not rely on AI fields as the record of what was reported; the raw submission is the record.

    7. Turning it off

    If you would prefer no AI processing on your workspace, email support@clickcues.com and we will disable enrichment for your projects. Existing feedback keeps working; you simply stop receiving generated titles, descriptions, severity and repro steps.

    See also the Privacy Policy and Subprocessors list.