BackCuratively

Privacy Policy

Curatively is a private vault for the things you love. This policy says what we collect, why, who touches it and how you take it back. It is written to be read.

Last updated 15 September 2026

Who we are

Curatively is made and run by ABZN LIMITED. When this policy says “we”, that is who it means. Questions go to contact@curatively.io.

What we collect

We keep only what the product needs to work:

  • Your account: the email address you sign in with (or the relay address Apple gives us when you use Sign in with Apple), and the sign-in codes we send to it.
  • Your page: your username, display name, bio and the saves you mark as favourites.
  • Your saves: the images you add, the links you save, the notes you write and when you saved them. For a link, we also fetch that page’s public title, description and preview image so the card has something to show.
  • Your directions: the brief you write, references you choose, your explanations and optional project-use feedback. Directions are private; using Share sends only the previewed text and source links to your chosen recipient or app.
  • Support feedback: messages you send through the app, linked to your account and submission time. Only the Curatively team can read them. They are deleted when you delete your account.
  • Optional usage analytics: if you turn it on, we record fixed action names and times, such as saving, searching, opening a source, saving a direction and connecting an assistant, with a fixed category for each (for example “photo” or “link”, never the content). We store them linked to your account ID and send the same events to PostHog under a random identifier that PostHog cannot connect to you. They contain no save content, images, source links, search text or IP-based location. Events expire within 31 days. Turning analytics off, or deleting your account, deletes the events already collected here and asks PostHog to delete its copy; PostHog completes that deletion on its own schedule, so it can take a few days to finish.
  • What the catalogue derives from your saves: tags, colours, a short description and a numerical “embedding” used for search. These are generated automatically; you never type them in.
  • Your plan: whether you have Plus, whether you have Discovery, until when, and where you bought it. Payment goes through Apple or Stripe; we never see your card.
  • Your direction and Discovery settings: the one line you write about what you are making, exploring or looking for; the reference sheet you attach, if any; your fit feedback on suggestions; and, if you subscribe to Discovery, your chosen days, time and time zone. Suggestions we find are private to you and are kept for up to 90 days unless you save one.
  • Your devices: a push-notification token per device, if you allow notifications, and the ordinary technical logs any server keeps (IP address, request time, browser or app version).
  • Connected tools: when you authorise an AI assistant or other app to use your vault, we record that grant so you can see it and take it back.

What we do not collect

We do not run advertising, sell data, or track you across other companies’ apps and websites for advertising. We use optional usage analytics (PostHog, only if you turn it on) and RevenueCat purchase analytics. Allowing AI processing or public sharing does not turn analytics on. Google (Gemini) automatically checks public profiles and published saves for safety; staff may review flagged content and investigate safety or copyright reports.

How we use it

Each thing above exists for one reason:

  • To sign you in and keep your vault attached to you.
  • To store, show and search your saves.
  • To catalogue your saves automatically so you never have to file anything.
  • To show your public page to people you share it with.
  • To deliver a notification you opted into.
  • To keep the service running and secure, and to answer you when you write to us.

Private by default

Saves start private. Your profile can be public after you allow public sharing; previously staff-approved profiles may remain visible without new AI processing. Saves you choose to publish appear immediately once public-sharing permission is enabled, unless restricted. We automatically review public content afterward using Google (Gemini) and remove content or restrict profiles that violate our rules. Anyone, including search engines, can see public pages. Unpublishing removes content from public listings, but previously issued image links can remain usable until they expire and copies already downloaded cannot be recalled.

Who helps us process it

We are a small team and rely on a few providers. Each one processes data only on our instructions, to run the service:

  • Supabase — hosts our database, file storage and sign-in, and sends the sign-in emails.
  • Cloudflare — serves this website and your public page.
  • Google (Gemini) — receives saved images, notes and link content to generate tags, colours and descriptions when you allow AI processing. Separately, it receives public profile text and photos, and the text and images of saves you choose to publish, for automatic safety checks after you explicitly allow public safety checks, separately from the optional catalogue AI setting.
  • Voyage AI — receives saved images and text, and search queries, to generate the embeddings that power search, only when you allow AI processing.
  • Exa — a web search provider that receives the text of your direction, the reasons in an attached reference sheet and your fit feedback, to find and read candidate pages, only when you allow research (the Discovery add-on). Google (Gemini) then receives the same text and the retrieved pages to choose and describe up to five suggestions a day.
  • Apple — handles Sign in with Apple and every purchase.
  • RevenueCat — validates purchases, manages access to paid features, and provides purchase analytics linked to your account ID.
  • Stripe — processes payments made on curatively.io and keeps the billing records for them (card details never reach us).
  • PostHog — receives fixed usage events under a random identifier, only if you turn usage analytics on, stored in the EU. It never receives your email, save content, links, search text or IP-based location, and no session recording or automatic tracking is used.
  • Expo — delivers push notifications to your device.

Your choice about AI

Optional catalogue and search AI processing is off until you explicitly allow it in Account. This permission covers existing and future saves and search queries shared with Google (Gemini) and Voyage AI. You can save, view, export and delete your content without allowing AI.

Research is a separate permission. It is off until you allow it, and it covers only your direction text, the reasons in a reference sheet you attach and your fit feedback — never the rest of your vault. Turning it off, pausing research or letting your Discovery subscription lapse stops new research; suggestions already found stay until they expire, and anything you saved stays yours.

You can withdraw permission in Account at any time to stop new catalogue and search AI requests. You can separately withdraw public-sharing permission in Account to hide your page and stop new safety checks; private saves are not sent for these checks. Requests already sent may finish; turning AI off does not undo processing that has already happened or delete existing catalogue descriptions. AI can make mistakes, so review its descriptions. Safety flags can hide public content without deleting your private save. Contact contact@curatively.io to appeal a restriction.

We have opted out of Voyage AI model training and retention for new inputs. Voyage deletes these inputs after processing. This setting does not undo processing of data sent before the opt-out on 5 September 2026. Google may retain Gemini inputs and responses for abuse monitoring under its service terms.

Tools you connect

You can let an AI assistant or another app read from and save to your vault through our connection for agents (MCP). Such a tool acts with your permission and sees what you see, until you revoke it. What that tool does with what it reads is governed by its own policy, not this one.

Where it lives and how long

Our providers store data in data centres in the United States and Europe. We keep your data for as long as your account exists. Sign-in codes expire within minutes; technical logs are kept for a short, fixed period and then discarded.

Your data is yours

You can export your entire vault — every image, link and note, in open formats — with one tap in the app, at any time, on any plan.

You can delete your account from the Account screen. That removes your profile, your vault, every save and every image immediately. Copies held in backups expire within thirty days.

Depending on where you live you may also have rights to access, correct, restrict or object to how your data is used, and to complain to a supervisory authority. Write to us and we will help.

Security

Everything travels over encrypted connections. Your saves are protected by per-row access rules in the database itself, so even our own code cannot read another person’s private saves. No system is perfect; if we ever learn of a breach that affects you, we will tell you.

Children

Curatively is not directed at children under 13 (or the higher age your country sets), and we do not knowingly keep an account for one. If you believe a child has made an account, write to us and we will delete it.

Changes

If this policy changes in a way that matters, we will say so in the app before the change applies. The date at the top is the date the words last changed.

Contact

Anything at all: contact@curatively.io.