# Privacy policy

> What Curate collects, what it never touches, where it is stored, and how to get all of it back or delete it.

- Canonical: https://www.getcurate.ai/privacy/

---

Legal

# Privacy policy

Last updated 30 September 2026.

The short version

We don't train anything on your content. Everything is stored and processed in the EU. Analytics tells us which screens you open and whether a save worked, never what is in your library, and you choose whether to share it when you create your account, and can change that in Settings at any time. You can export everything or delete everything, at any time, on any plan.

## 1\. Who we are

Curate is operated by Curate (“Curate”, “we”, “us”). For the purposes of the UK and EU General Data Protection Regulation we are the data controller for the personal data described here. You can reach us about anything in this policy at [privacy@getcurate.ai](mailto:privacy@getcurate.ai).

## 2\. What we collect

### Your account

An email address, and an identifier from Apple or Google if you sign in that way. If you use Sign in with Apple and choose to hide your email, we receive Apple’s relay address and never see your real one. We also store the region your account belongs to, your subscription status, and the date your monthly allowance resets.

### What you save

The links, text, photographs and documents you send to Curate, and everything we derive from them: the extracted article or recipe, its title, ingredients, method, tags, highlights and your read state. We store this so the app can do its job, and so your library is there on every device you sign in to.

**A saved item keeps its own copy of what the page said.** That is a deliberate product decision, so your library survives a page changing or disappearing.

### The browser extension

The extension reads the page you are on **only when you click its button**, and only that page: it asks for access to no website when you install it, and it never sees what you browse. What it reads – the address, title, image and any recipe markup – is shown to you before anything is saved, and sent to Curate only when you press Save.

*All tabs* reads the addresses of the pages open in that window, and asks for permission to do so at the moment you use it. If you never use it, you are never asked.

In your browser it stores your sign-in, the tags you have used before so it can offer them, and any page saved while you were offline that has not been sent yet. Signing out removes all of it. With your consent, it also reports whether a save worked – never what you saved.

### How you use the app

With your consent, we collect usage analytics through Google Analytics for Firebase and crash reports through Firebase Crashlytics: which screens you open, whether an action such as a save succeeded or failed, the type of device, the app version, and a random identifier for your installation.

**We never put your content into analytics.** No titles, no links, no page text, no ingredients, no highlights, and never what you searched for. This is a technical rule in how the apps are built, not only a promise in a policy.

### Payments

Subscriptions bought on iPhone or Android are processed by Apple and Google. We receive a confirmation that a subscription is active and its plan and renewal date. We never see or store your card details, and no payment data is held on Curate’s systems.

### When you write to us

If you use the support form on our website, or email us, we store what you send: your email address, your name if you give one, the subject you pick and your message, along with the language the page was in and which app version you were using. If you were signed in when you wrote, the message is linked to your account so that we can look at what you are describing. We use it to answer you and to fix what you reported, and for nothing else. The form is the same thing as the email address: both arrive in the same place, and both are stored in the EU alongside the rest of Curate.

## 3\. Consent, and what happens if you say no

Before any analytics are collected we show you what we measure and what we never touch, and then we ask. **Analytics are off until you say yes**, and you can change your mind at any time in Settings under Privacy and data.

Saying no breaks nothing. Every part of Curate works identically either way. When analytics are declined, Google’s consent mode transmits a signal that carries no identifier and writes nothing to your device, so that we can count how many people declined without knowing who they are.

## 4\. How we use what we collect

-   To run the product: storing your library, syncing it and searching it.
-   To process what you save: reading a page, extracting an article, structuring a recipe, reading text out of a photograph or a document, and suggesting tags.
-   To manage your account, your allowance and your subscription.
-   To tell you when something you saved is ready, or failed, or is going unused.
-   With your consent, to understand which parts of the app work and which do not, and to fix crashes.

We do not sell personal data, we do not share it with advertisers, and we do not build profiles for advertising. Curate runs no advertising and does not use the advertising identifier on your device.

## 5\. AI processing

Turning what you save into something usable means sending it to a model. We use third-party inference providers for this, under contracts that require them to process your content only to return the result to us.

-   **Your content is not used to train any model.** Not ours, not theirs.
-   **Our providers are held to zero retention**, meaning your content is not stored after the request completes.
-   **Inference runs on European endpoints**, in line with the rest of our processing. Today that provider is Google, through Vertex AI in the same `europe-west1` region as everything else.

## 6\. Where your data lives

All user content is stored and processed in the European Union, in Google Cloud’s `europe-west1` region in St. Ghislain, Belgium. This is true regardless of where you live. Where a service provider necessarily operates outside the EEA, transfers are made under the European Commission’s Standard Contractual Clauses.

## 7\. How long we keep things

-   **Your library** is kept for as long as your account exists. An item you delete goes to Trash and is permanently removed 30 days later, and each one tells you how long it has left.
-   **Photographs and documents you upload are kept for the life of your account, and they survive deleting the item they produced.** We keep the original file so we can read it again if extraction improves, and so a restored item comes back whole. Deleting the item does not delete the file it came from. Closing your account does.
-   **What you write to support** is kept for as long as the correspondence is useful and no longer than two years, and then deleted. Closing your account does not delete it, because a question about why you closed it is a question we may still need to answer.
-   **Analytics and crash data** are retained for 14 months and then deleted or aggregated.
-   **Account records** and records of payment we are required to keep for tax and accounting purposes are kept for as long as the law requires, after your account is gone.

## 8\. Your rights

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to how we process it, and take it elsewhere. Two of these are buttons in the app rather than requests you have to make of us:

-   **Export everything.** Settings, Export everything. Your whole library in a portable format that is not tied to Curate. Free on every plan, always.
-   **Delete my account and everything in it.** Settings, Privacy and data. All of your server-side content, including uploaded files, is removed within 30 days.

For anything else, write to [privacy@getcurate.ai](mailto:privacy@getcurate.ai). You also have the right to complain to your local data protection authority.

We rely on **contract** as our lawful basis for running the product you asked for, **consent** for analytics and for notifications, and **legitimate interests** for keeping the service secure and working.

## 9\. Security

Data is encrypted in transit with TLS and at rest. Sign-in tokens are held in the platform’s own secure store, such as the iOS Keychain. No client application talks to our database directly; everything goes through Curate’s own API, where the rules live.

## 10\. Children

Curate is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, write to us and we will remove it.

## 11\. Cookies and this site

This marketing site sets no cookies. It uses Google Analytics to count visits, but with storage consent denied by default and never asked for, which is the state in which Analytics writes nothing to your browser and sends no identifier. So we can see that a page was viewed, and roughly which country and which referring link it came from, and nothing that identifies you or follows you between visits or across other sites. Your IP address is used to derive that approximate location and is not stored. None of it is used for advertising. The typeface is served from our own domain rather than a font network. The web app stores a sign-in session and a local copy of your library in your browser, both of which are cleared when you sign out.

## 12\. Changes to this policy

If we change this policy in a way that materially affects you, we will tell you in the app before the change takes effect. The date at the top is always the date of the current version.

## 13\. Contact

[privacy@getcurate.ai](mailto:privacy@getcurate.ai) for anything in this policy, or [hello@getcurate.ai](mailto:hello@getcurate.ai) for everything else.
