Privacy — Curio

Plain language, no legalese. Effective 2026-08-07.

What we store

  • Your email address, used to sign in via magic links — no passwords.
  • The artifacts you publish and every version of them.
  • Comments and reactions left on your artifacts, and yours on others’.
  • Any connected-app grants you’ve approved (see Connected apps below).

Analytics

We use PostHog for product analytics, identified by a pseudonymous user id — never your email or name. We don’t autocapture page content, we don’t record sessions, and there are no advertising trackers. Nothing is sold to anyone.

Only artifact owners can see a lifetime count of successful non-owner review-page opens. Owner opens, plus missing, private, denied, and unverified email-gated opens, do not increment it. It is an aggregate, not unique visitor tracking, and Curio does not attach reviewer identity to that count.

Billing

Billing is handled by Polar as merchant of record. Curio never sees your card number.

Cookies

Curio uses a session cookie to keep you signed in and an analytics cookie set by PostHog that holds a pseudonymous, randomly generated id — no email, no name. If you change the artifact dashboard layout or sorting, exactly two dashboard preference cookies remember those choices. They are first-party browser cookies retained for one year and contain no account or artifact data. Curio does not save those choices to your account or persist them in server-side data.

Sharing

Each artifact is private, link-shared (anyone with the unguessable URL can view it), or email-restricted — the owner sets this per artifact and can change it at any time. Share links are excluded from search indexing.

Connected apps

Chat clients like Claude or ChatGPT only get access through an OAuth grant you approve explicitly. You can revoke a grant instantly from Settings, and the underlying tokens — like personal API tokens — are stored hashed, never in plaintext.

Deletion

Settings offers permanent, self-serve account deletion. It removes your artifacts, versions, and comments, and detaches your identity from anything that has to remain — for example, a comment you left on someone else’s artifact is kept but reassigned to a “Deleted user” placeholder instead of your name.

Contact

Questions about any of this? Email [email protected].

Privacy — Curio