PRIVACY
Privacy policy
This policy explains what CurveMora processes and how it is used.
1. Information we process
We process account identifiers, display name, email when supplied by you or Google, avatar when supplied by Google or X, passkey public-key credentials and usage counters, preferences, Sources, Learning Items, Reviews, notes, Breaks, exports, and limited technical usage information.
2. Passkeys
Passkeys use WebAuthn. CurveMora stores a credential identifier, public key, counter, device type, backup status, name, and timestamps. We do not receive or store fingerprints, face data, device PINs, or private keys.
3. How information is used
Information is used to authenticate you, keep each account's data separate, calculate deterministic Review schedules, synchronize data, provide exports, prevent abuse, diagnose failures, and improve the service.
4. Optional AI features
Raw capture text is sent to OpenAI only when you request an AI capture draft. Optional Weekly AI interpretation sends aggregate review facts such as counts, minutes, rating proportions, overdue-item count, predicted retention, and recorded importance; it does not send Source or Learning Item titles, tags, notes, or raw capture text. Generic AI economics telemetry does not store prompt or response text.
5. Service providers
CurveMora uses Neon for PostgreSQL data storage, Vercel for hosting, Google and X for optional sign-in, Resend for email-address verification, and OpenAI for optional AI-assisted features. Each provider processes data under its own terms and privacy commitments.
6. Sharing
Learning content is private to the authenticated account by default. CurveMora does not sell learning content or send Source titles, notes, or raw capture text in product analytics or generic AI-generation economics telemetry.
7. Retention and deletion
Core account and learning data remains until you delete it or the account. Structured AI-assisted capture cache records are purged after 30 days and bounded AI-generation operational telemetry after 90 days; account deletion may remove them earlier. Infrastructure backups may have limited additional retention.
8. Security and choices
We use HttpOnly session cookies, user-scoped database access, input validation, encrypted session payloads, and short-lived WebAuthn challenges. You can export data, manage passkeys, disconnect by signing out, or delete the account from Account settings.
9. Changes
Material changes will be reflected by updating this page and the effective date. Region-specific legal rights may apply in addition to this policy.