AI Transparency Notice
Version 2026-08-01 · Last updated August 2026
1. The provider
AI summarisation is performed by Google Gemini, accessed through the Lovable AI Gateway. Requests are made server-side from our backend, never from your visitors' browsers.
We do not train any model on your data, and we do not permit the provider to train on it. We do not use your feedback content to improve ClickCues' own models, because we do not operate any.
2. What is sent
| Field | Sent? | Notes |
|---|---|---|
| Feedback title | Yes | Scrubbed for credentials and email addresses first. |
| Feedback description | Yes | Scrubbed for credentials and email addresses first. |
| Page address | Partly | Origin and path only. Query strings and fragments are removed before transmission. |
| Browser, OS, viewport | Yes | Technical strings only, e.g. "Chrome 128", "macOS", "1440x900". |
| CSS selector of the pinned element | Yes | Structural selector only, never the element's value. |
3. What is never sent
- Screenshots. No image is ever transmitted to a model provider. Summarisation is text-only.
- File attachments. Never transmitted.
- Reviewer name or email address. Never transmitted, even when the reviewer supplies one.
- Your account details. No account email, billing data or team roster is transmitted.
- Console logs captured by the widget. Stored for your debugging, never sent to a model.
- Query strings, URL fragments and URL credentials. Stripped before storage and before transmission.
4. Redaction before transmission
Free text is passed through a server-side scrubber before it leaves our infrastructure. It replaces credential-shaped content with placeholders, including: bearer and basic authorisation headers, JSON Web Tokens, Stripe, Google, GitHub, Slack and AWS key formats, PEM private key blocks,password=-style assignments, card-length digit runs, email addresses and long opaque tokens.
This is a safety net, not a guarantee. A reviewer who types a secret in an unusual format may still have it transmitted. Treat feedback text as content a third-party processor will read.
5. Automated decision-making
AI output in ClickCues is advisory labelling only. It never approves or refuses anything, never affects billing, never affects access, and never produces a legal or similarly significant effect on any person. AI-generated fields sit alongside the reviewer's original words, which are always preserved unedited.
AI-generated fields are labelled in the interface so your team can tell them apart from what the reviewer actually wrote.
6. Accuracy
Summaries can be wrong. Severity suggestions can be wrong. Duplicate detection is a similarity heuristic and can produce false matches. Do not rely on AI fields as the record of what was reported; the raw submission is the record.
7. Turning it off
If you would prefer no AI processing on your workspace, email support@clickcues.com and we will disable enrichment for your projects. Existing feedback keeps working; you simply stop receiving generated titles, descriptions, severity and repro steps.
See also the Privacy Policy and Subprocessors list.