Curio
PrivacyTermsSupport
Español

Your information

Privacy Policy

What Curio collects, why it needs it, who processes it, and how to delete it.

Effective September 16, 2026

1. Who is responsible

Gopin S.A.S. operates Curio and is responsible for the personal information described in this policy. Our address is Calle 122 #19-59, Bogotá, Colombia. You can contact us at steve.avador@icloud.com.

This policy applies to the Curio iOS app, this website, and support conversations with us. Curio is intended only for people who are at least 18 years old.

2. Information Curio handles

  • Account and profile information: email address, display name, avatar choices, authentication identifiers, and account status.
  • Learning information: interests, learning goals and preferences, lesson and practice activity, answers, progress, completions, XP, streaks, collectibles, and notification choices.
  • Voice and explanation information: temporary audio, speech transcripts, typed explanations, delivery measurements, feedback, coaching plans, and related learning reports.
  • Content you request or create: topics, pasted source text, photos you choose to share, custom lessons or practice stories, generated text and images, and the records needed to deliver and manage that content.
  • Social information: when you create a permanent account, Curio creates a leaderboard profile using your display name, avatar, a short username based on your name, and the country or region configured on your device. While leaderboard visibility is on, other users may see those fields with your eligible weekly XP and active days. Curio also handles friend connections and invitations, leaderboard activity, blocks, and reports you submit about other users or content.
  • Purchase information: product, entitlement, subscription status, renewal status, transaction identifiers, and related dates supplied by Apple and RevenueCat. We do not receive your full payment-card number.
  • Analytics and attribution information: app installs and opens, screen views, onboarding and feature interactions, lesson and practice outcomes, purchase-flow events, technical failures, installation or device identifiers, and available advertising-source, campaign, ad, keyword, and click information used to measure Curio’s own marketing.
  • Support and technical information: messages you send us and basic logs such as app version, device or operating-system details, language, time zone, IP address, request identifiers, and error or security events.

3. Where it comes from

We receive information directly from you, automatically when you use Curio, from your device settings such as its configured country or region, and from service providers such as Apple and RevenueCat when they confirm purchases or subscription access. Curio does not request location permission to set your leaderboard country.

4. Why we use it

  • Create and secure your account and keep you signed in.
  • Deliver lessons, practice, speech feedback, custom content, progress, social features, and notifications you request.
  • Process purchases, restore access, and provide subscription support.
  • Respond to support, privacy, safety, and account requests.
  • Protect Curio and its users, prevent abuse or fraud, debug failures, and comply with law.
  • Improve reliability and product experience using aggregated or de-identified information where practical.
  • Measure the performance of Curio’s own marketing campaigns and attribute installs and subscription outcomes without showing third-party ads inside Curio.

5. Voice and artificial intelligence

Some Curio features use AI to transcribe speech, give feedback, and create learning material and illustrations. Before sending your information to OpenAI or ElevenLabs, Curio shows a separate permission sheet explaining the information, recipients, and purpose. Starting a lesson, accepting the Terms of Use, or allowing microphone access does not grant this permission.

ElevenLabs receives your voice recordings to turn speech into text, including while you speak. OpenAI receives recordings when needed for transcription, plus transcripts, written explanations, topics, source text and photos you choose to share, your preferred language, relevant lesson content, and measurements of your speaking delivery to give feedback or generate content. Generated text and illustrations may also be sent to OpenAI for quality checks and follow-up feedback. Depending on the feature, Supabase or Cloudflare carries and processes these requests through encrypted connections. Apple may process speech when its speech-recognition service is used.

Curio sends only the information needed for the feature you request. Avoid including passwords, payment details, identity documents, or sensitive medical information in your recordings or source material. Curio does not use your content to train general-purpose AI models. OpenAI does not train on API content by default. ElevenLabs offers a separate account-level training opt-out; its handling of submitted content depends on that setting and its service terms. Provider retention is explained in section 9.

You can choose “Not now” without sending information for that AI action. The feature will pause; content that does not require a new AI request remains available. If you later choose an action that needs AI, Curio will ask again. Withdraw permission in Profile → Settings → AI processing. Withdrawal stops new AI requests from the app; it does not undo requests already sent or delete saved results. To delete saved information, use the options in sections 10 and 11.

AI results can be incomplete or incorrect. Review them before relying on them. Curio does not use AI to make legal, employment, credit, medical, or similarly significant decisions about you.

6. Analytics and attribution

Curio uses PostHog Cloud US to understand how the app is used and to diagnose technical failures. Before you create a permanent account, PostHog assigns a random analytics identifier. After account creation or sign-in, Curio associates later analytics with your Curio account identifier and may add your email address and display name to the PostHog profile. Events also include app and device details such as app version, device model, operating-system version, screen name, language or time zone, IP address, and technical error or crash details.

Curio sends PostHog events about app lifecycle, onboarding steps, feature and paywall use, lesson and practice completion, timing and performance measurements, your AI-processing choice, and repeated-tap diagnostics with screen or control context and an approximate tap position. Ordinary product-analytics events do not include raw recordings, speech transcripts, typed explanations, lesson source text, custom topics, or generated lesson content. PostHog session replay is not enabled.

Curio uses Appstack to attribute an installation and selected conversion events to Curio’s own campaigns. Appstack automatically records an install and receives a stable Appstack installation identifier, device and app attributes, IP address and user agent, available Apple Ads attribution, and campaign or click parameters. Curio sends Appstack only the standard sign-up, login, and tutorial-complete events without custom personal fields. Curio passes the Appstack identifier and available attribution parameters to RevenueCat so subscription results can be measured against the campaign that led to the install. Appstack may send conversion signals to an advertising platform only when Curio enables that integration.

The current Curio build does not request App Tracking Transparency permission and does not access a usable IDFA. If Curio later adds tracking that requires Apple’s permission, we will update this notice and request permission before that tracking begins.

7. Who helps us provide Curio

We share only the information reasonably needed for the service with processors working on our behalf or with a platform you choose to use.

We require service providers that receive your personal information, including OpenAI and ElevenLabs, to provide the same or greater protection as described in this policy. Their applicable data-processing agreements require confidentiality, appropriate security, limits on processing, and safeguards for subprocessors. We remain responsible for choosing and configuring these services and for helping you exercise your privacy rights.

  • Supabase: authentication, database, storage, and server functions.
  • Cloudflare: secure delivery and custom lesson processing.
  • OpenAI: speech transcription, learning analysis, content generation, and illustration generation.
  • ElevenLabs: live and recorded-speech transcription.
  • RevenueCat: subscription status, entitlement management, and connection of subscription results to Appstack attribution data.
  • PostHog (United States cloud): product analytics, onboarding and feature measurement, account-linked analytics profiles, and technical diagnostics.
  • Appstack: installation and campaign attribution, conversion measurement, and delivery of conversion signals to advertising platforms that Curio enables.
  • Apple: App Store distribution, in-app purchases, device permissions, and platform services.
  • Authorities or other parties when required by law, needed to protect rights and safety, or involved in a corporate transaction subject to appropriate safeguards.

8. What we do not do

We do not sell your personal information or show third-party ads inside Curio. Curio does not request permission to track you across other companies’ apps or websites.

9. Retention

We keep account information and saved learning content while your account is active. Curio keeps temporary recordings on your device only while the active feature needs them and does not intentionally save raw audio in its server database. Transcripts, generated content, feedback, and learning reports may be stored with your account. This does not mean that third-party providers retain no information.

OpenAI may retain API content in abuse-monitoring records for up to 30 days by default, with exceptions required by law or its safety policies. Curio disables stored response history where supported. ElevenLabs may retain submitted audio and transcripts under its service terms for service delivery, security, and legal obligations. Curio does not promise zero retention at either provider. Contact us to request deletion of information already shared; provider deletion procedures and legal exceptions may apply.

PostHog analytics and diagnostic records are kept under Curio’s configured analytics-retention period or until we complete a verified deletion request. Appstack keeps installation and attribution data while Curio’s service agreement is active and the data is needed for attribution and analytics, unless it is deleted or anonymized earlier. Advertising platforms enabled by Curio and Apple or RevenueCat may keep their own transaction or campaign records under their policies and legal duties.

After account deletion, limited information may remain temporarily in encrypted backups, security logs, records awaiting a processor’s deletion cycle, purchase records held by Apple, or records we must preserve by law. These records are isolated from ordinary use and expire under the applicable schedule.

10. Your choices and rights

  • Review and update your profile, username, country, leaderboard visibility, and notification choices in Curio. Turning leaderboard visibility off hides your public profile and World and Friends ranking entries without deleting your private learning progress or friendships.
  • Decline microphone, speech-recognition, or notification permissions in your device settings. Review or withdraw AI permission in Curio at Profile → Settings → AI processing. Features that need a declined permission pause until you allow it. Choosing a feature that needs AI after declining will show the permission sheet again.
  • Object to or ask us to stop analytics or attribution processing associated with you by emailing us. Curio does not currently offer a general analytics switch inside the app.
  • Request access, correction, information about use, portability where available, objection, consent withdrawal, or deletion by emailing us.
  • If Colombian data-protection law applies, you may also request proof of authorization and submit a complaint to the Superintendencia de Industria y Comercio after first completing the applicable request process with us.

11. Delete your account

Open Curio, go to Profile → Settings → Account → Delete account, and confirm. Curio deletes your authentication account, account-linked database records, custom stories, generated lessons and images, and the corresponding RevenueCat customer profile. The app also asks Appstack to delete data for the current installation and resets the PostHog identity stored on your device. This cannot be undone.

Resetting the on-device PostHog identity does not by itself erase analytics already sent to PostHog. Appstack deletion applies only to the installation where you delete the account. To request deletion of previously transmitted PostHog records or attribution data from another installation, email us from the address connected to your account. We may need to verify that the account belongs to you, and processor deletion may complete asynchronously.

Deleting Curio does not cancel an Apple subscription. Cancel it separately in Apple subscription settings to prevent a future renewal. Apple may retain transaction history under its own legal obligations.

If you cannot access the app, email steve.avador@icloud.com from the address connected to your account.

12. International processing and security

Our providers may process information in Colombia, the United States, and other countries where they operate. We use contractual and technical safeguards appropriate to the service, including access controls, encrypted network connections, and owner-scoped records. No online service can guarantee absolute security.

13. Changes and contact

We may update this policy as Curio changes. We will update the effective date and provide additional notice when a change materially affects your rights. For privacy questions or requests, email steve.avador@icloud.com or write to Gopin S.A.S., Calle 122 #19-59, Bogotá, Colombia.

Questions?

Email Curio support.

steve.avador@icloud.com

Operated by Gopin S.A.S.

Calle 122 #19-59, Bogotá, Colombia

For adults 18 and older.

© 2026 Curio. All rights reserved.

Privacy Policy · Curio