Privacy Policy
Curio · Last updated 8 September 2026
What we collect
- As a guest: Curio keeps the reader-facing copy of your reading history, saves, likes, follows, preference profile and recent-search list on your device. You do not need an account to read. The separate, bounded anonymous measurements described below do not sync or recreate your guest library or personalization profile.
- If you sign in with Apple or Google: we receive a stable account identifier and, if the provider shares it, your email address. Apple's private-relay address is fine; we never require a "real" email.
- Account-scoped reader sync: while you are signed in, Curio syncs six bounded kinds of reader memory to your account so they can follow you across devices: saved-card IDs, liked-card IDs, followed categories, category preference scores, your recent Curio search terms, and recently seen-card IDs. This sync does not upload card bodies or your device settings.
- Anonymous service identity: Curio generates a stable random guest-service ID on first launch. It is not an Apple advertising identifier or IDFV and is not joined to an account, name or email. Curio sends it to our first-party API to mint scoped guest service sessions, apply abuse/rate limits and verify feature access. Wiping the app's local reader data replaces it.
- iOS purchases: Apple processes in-app payments and does not provide us with your payment-card or bank-account details. The app sends Apple's signed transaction data to our service to verify subscription access and purchased feed credits. For purchased feed credits, we store Apple's transaction ID, the service or account identifier used for the credit balance, the redemption date and the credit balance to deliver your credits and prevent duplicate redemption. If we cannot establish a service session, your purchase stays pending until it can be credited to your installation. Older purchase records may contain an IP address used as the credit identifier.
- No install-scoped retention collection in this release: Curio does not transmit install-scoped retention pulses, so its local return-loop state does not create server rows for active/value days, first-session summaries or guest return-loop cohorts. The first-party deletion endpoint remains available to erase an installation-measurement row that an older app build may already have created.
- Protection against erased data returning: when our service processes an installation-measurement erasure request, it removes any matching measurement rows and retains only a one-way hash of the installation identifier and the deletion date. This protection record contains no reading days, card identifiers, account ID or email. It is used only to reject delayed requests that could recreate erased data, including a delayed first upload; it is not used for analytics or advertising. These protection records currently have no automatic expiry while old requests can still use the identifier.
- Anonymous product diagnostics: Curio may send bounded event names and a fixed set of identifier or enumerated properties with a random ID that lasts only for the current app launch. Depending on the interaction, these properties may include a card identifier (which can be a title-derived slug), content type, category/topic identifier, experiment variant, app version/build and acquisition campaign tags. Subscription or trial success events also include the product identifier so we can evaluate the purchase flow. Some feedback events also include a closed in-app feed-surface label that cannot contain a search query, localized title or other user-entered text. These event logs do not include an account ID, email address, card body, IP address in the stored event record or advertising identifier, and they cannot be joined across app launches or to an account.
- Signed-in return-surface adoption: if you sign in, Curio may record that a named in-app return surface was shown or completed, with its variant, local day and time. These rows contain no card IDs or search text and are included in account export and deletion.
- Reader Stories you submit: the content and a display-name choice you set.
What we don't do in the Curio app
- The native Curio app does not embed third-party advertising or tracking SDKs.
- No selling of personal data.
- No collecting your contacts, precise location, or microphone/camera.
Website analytics and campaign attribution
These details apply when you visit trycurio.app; they are separate from the native-app practices above.
- Google Analytics 4: the website loads Google's tag using Consent Mode with analytics storage and Google's ad-related storage/signals set to denied by default. If you select Accept, analytics storage is granted; the ad-related settings remain denied. While analytics storage is denied, Google's tag may send limited cookieless measurement pings rather than setting analytics cookies. Google receives standard web-request information under its own privacy policy.
- Meta Pixel: the website does not load the Meta Pixel or send its PageView until you select Accept. After acceptance, it may record page views, a custom outbound App Store click, and a Lead only after a waitlist or test-access request is confirmed. Meta handles those requests under its own privacy policy.
- Campaign parameters: a landing URL may contain UTM parameters or advertising click IDs such as
fbclid,gclidorttclid. Before acceptance, the website keeps values from the current page in memory only. After acceptance, it may save campaign attribution in browser local storage so a later store click or confirmed signup can be connected to its source. Declining removes that stored attribution. Curio does not send an email address to GA4 or Meta in these website events. - First-party source beacon: social/content links may request a Curio endpoint under
api.trycurio.app/go/with a short source code and an arrival or store-click label. This request can occur independently of the analytics-cookie choice. The beacon URL does not include your email address or the incoming advertising click ID; like other web requests, it exposes ordinary request metadata to the hosting infrastructure. - Waitlist and Android-test forms: FormSubmit relays the email and form fields to Curio. Campaign fields are added to the form only after analytics consent, and Curio emits its signup event only after FormSubmit returns a JSON success response. FormSubmit's privacy terms also apply.
AI features
Some explanations may be AI-assisted. Prompts are processed by our AI provider to generate a response and are not used to identify you.
Your choices
- Log out to stop account sync. The local copy remains on that device; signing back in resumes sync.
- Delete your account & data any time in Settings → Account. This revokes existing Curio sessions, removes account-owned records (including synced reader memory, submissions, comments, rewards and return-surface adoption rows), and erases Curio's local reader data and guest-service ID on that device. It also requests erasure of installation-measurement rows. If that request cannot complete while offline, the app retains a local pending-erasure identifier and retries until the service confirms the request; the service retains the protection record described above.
- Reset personalization or clear local app data in Settings. Clearing only the device does not delete the signed-in account copy; use Delete account & data for that.
YouTube API Services
Curio's internal publishing tool uses YouTube API Services to upload Curio's own videos to Curio's own YouTube channel and to read that channel's statistics. By interacting with our YouTube channel you are also subject to the YouTube Terms of Service and the Google Privacy Policy.
- The tool accesses only our own channel's data (uploads, titles, descriptions, view statistics). It does not access, collect, or store any data about other YouTube users, and it does not use viewer data at all.
- Authorization tokens for our own Google account are stored locally on our own equipment and are never shared with third parties. No other user's Google data is requested or stored, so there is no third-party data to retain; any of our own cached channel statistics are refreshed or discarded within 30 days.
- You can review or revoke any application's access to a Google account at any time via the Google security settings page.
Contact
Questions or data requests: support@trycurio.app.