Privacy Policy
Last updated: February 6, 2026
Curiary (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application and web application (collectively, the “Service”).
Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Display name (optional)
- Profile information you choose to provide
Tasting Data
When you use Curiary to log tastings across any category (cheese, wine, coffee, whiskey, tea, beer, chocolate, olive oil, meat, and non-alcoholic beverages), we store:
- Tasting notes, scores, and ratings you enter
- Photos you upload
- Tags and categories you assign
- Date and time of tastings
Usage Data
We may automatically collect limited information about how you use the Service:
- Device type and operating system version
- App or browser version
- Crash reports and performance data (opt-in only)
We do not use analytics to build advertising profiles. Any analytics we collect are used solely to improve the Service.
Purchase Information
If you subscribe to a paid plan, your payment is processed by Apple (iOS) or Stripe (web). We receive:
- Subscription status (active, expired, etc.)
- Transaction identifiers
We do NOT receive or store your payment card details.
How We Use Your Information
We use your information to:
- Provide and maintain the Curiary Service
- Sync your data across your devices
- Process your subscription
- Send important service updates (never marketing)
- Improve the Service based on aggregate usage patterns
- Respond to your support requests
We do not use your data to build advertising profiles, sell to third parties, or power recommendation algorithms.
Data Storage and Security
Your data is stored securely using Supabase, a trusted cloud infrastructure provider hosted on AWS. We implement industry-standard security measures including:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest
- Row-level security policies (your data is accessible only to you)
- Regular security audits
- Secure authentication via Supabase Auth
Data Sharing
We do NOT sell your personal information. We share data only in these limited circumstances:
- Service Providers: With trusted providers who help us operate the Service (Supabase for hosting, Apple/Stripe for payments), bound by confidentiality agreements.
- Legal Requirements: When required by law, legal process, or to protect our rights.
- With Your Consent: When you explicitly authorize sharing (e.g., exporting a public tasting page).
Cookies and Tracking
The Curiary web application uses only essential cookies required for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics that follow you across websites.
Your Rights and Choices
You have the right to:
- Access: Request a copy of your data
- Export: Export your tasting data at any time (available in app settings)
- Delete: Request deletion of your account and all associated data
- Correct: Update or correct your information
To exercise these rights, use the in-app settings or contact us at privacy@curiary.com.
Data Retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or compliance purposes.
Children’s Privacy
Curiary is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe we have collected such information, please contact us immediately and we will delete it.
International Data Transfers
Your data may be processed in countries other than your own (including the United States). We ensure appropriate safeguards are in place for such transfers in compliance with applicable law.
European Users (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
- Legal basis: We process your data based on your consent (account creation), contractual necessity (providing the Service), and legitimate interests (improving the Service).
- Right to restriction: You may request we restrict processing of your data.
- Right to portability: You may request your data in a machine-readable format (use the export feature).
- Right to object: You may object to processing based on legitimate interests.
- Right to lodge a complaint: You may file a complaint with your local data protection authority.
For GDPR inquiries, contact privacy@curiary.com.
California Users (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of its sale. We do not sell personal information. To exercise your California privacy rights, contact privacy@curiary.com.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or by email. Continued use of Curiary after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our practices:
- Privacy inquiries: privacy@curiary.com
- General support: support@curiary.com