CURA Privacy Policy
Last updated September 9, 2026 (v2.3)
CURA puts every one of your DMs in one place, which is exactly why we owe you a privacy policy with real substance, not vibes. This page tells you who we are, every category of data we handle, why we handle it and on what legal basis, which companies touch it, where in the world it travels, how long we keep it, and what rights you have under the laws of Canada (PIPEDA), the EU (GDPR), the UK (UK GDPR), and California (CCPA/CPRA). One promise up front, because other companies fudge it: your message content in our primary database is encrypted at rest, but we hold the key. That is not end-to-end encryption, and we will never call it that.
Who we are (the "controller")
In plain English: CURA is made by CURA Intelligence in Ontario, Canada. For your personal data, we are the ones responsible, and you can reach a human at hello@curavision.ai.
CURA is operated by CURA Intelligence, based in Ontario, Canada. For the purposes of the EU GDPR and UK GDPR, CURA Intelligence is the "data controller" of your personal data. Under Canada’s PIPEDA, we are the organization accountable for it, and our designated privacy officer is reachable at hello@curavision.ai — that address goes to a person, not a queue. We serve users in Canada, the United States, the EU, and the UK, and this policy is written to meet the requirements of all four regimes. We do not currently have an establishment in the EU or UK.
What we collect, why, and our legal basis
In plain English: Every category we hold, what it’s for, and the specific legal ground we rely on — no catch-all "and other purposes" clause.
Where GDPR or UK GDPR applies, we need a legal basis under Article 6 for each thing we do. Here is the complete inventory.
Account and login data — your email, name, and password (stored only as a hash — we cannot read it), or your name and email from Google or Apple if you sign in that way, plus a two-factor authentication secret if you turn 2FA on. Purpose: creating your account, signing you in, and securing it. Legal basis: performance of our contract with you (Art. 6(1)(b)); keeping accounts secure is also our legitimate interest (Art. 6(1)(f)).
Platform connection data — when you connect a platform, we store what that connection method requires: OAuth-issued access tokens (held by our integration providers Composio or Unipile, or by us for platforms we connect natively), linked-device session credentials for WhatsApp, phone-number sign-in sessions for Telegram, and API credentials you paste in for certain integrations. Connection credentials we store are encrypted at rest. For OAuth platforms we never see your password at all. The exception is Telegram: if your Telegram account has a two-step-verification password, its sign-in protocol requires it once to complete the login — it reaches our server for that single step and is never stored. Legal basis: contract (Art. 6(1)(b)).
Message content from your connected inboxes — the messages themselves sync to our servers so your unified inbox can exist. Your messages inevitably contain personal data about the people you talk to; we process that content only to show it to you and act on your instructions, never for our own purposes. Legal basis: contract (Art. 6(1)(b)); for our handling of your correspondents’ data, legitimate interest (Art. 6(1)(f)) in providing you a functioning inbox, which their local law may frame differently — see "The people you talk to" below.
Content you create — posts, captions, C.C. chat conversations, messages you exchange with other CURA users, your publishing history, and your schedules. Legal basis: contract (Art. 6(1)(b)).
Call data — the call buttons in CURA hand off to WhatsApp, Instagram, Telegram or your phone’s own dialer: the call happens there, not here, and we receive nothing about it — no number, no duration, no recording. Separately, CURA has an AI calling feature that places calls through a telephony provider; it is not enabled for customer accounts today. Where it is enabled it processes the number dialled, call timing and duration, a transcript where the feature produces one, and the other party’s number and what they say. Legal basis: contract (Art. 6(1)(b)); you are responsible for having the right to place and, where applicable, record calls (see the Terms, Section 7).
AI processing data — when you invoke C.C., the text involved is sent to Moonshot AI (the "Kimi" model). Text you submit for publishing is also screened by our automated moderation system, which uses the same provider. When you talk to C.C. by voice, your audio is processed by ElevenLabs, whose bundled language model is currently OpenAI’s GPT-5 — so your voice-conversation content reaches OpenAI through ElevenLabs. Certain advanced assistant features, where enabled, are processed by Anthropic. We send only what the invoked feature requires, not your whole inbox. Legal basis: contract (Art. 6(1)(b)). See the transfers section, because Moonshot AI is a company in the People’s Republic of China and we address that honestly there.
Payment data — payments are processed by Stripe. Your card number goes to Stripe and never touches our servers; we keep only your plan and payment status. Legal basis: contract (Art. 6(1)(b)) and legal obligation for tax and accounting records (Art. 6(1)(c)).
Usage and metering data — credits, quotas, and per-action usage events (for example, that a C.C. send happened and what it cost in credits — not the content). Legal basis: contract (Art. 6(1)(b)); preventing abuse is also our legitimate interest (Art. 6(1)(f)).
Security audit logs and IP addresses — records of security-relevant events like logins, failed attempts, token refreshes, and 2FA changes, including the IP address they came from. IP addresses are also recorded when you submit our waitlist, application, or contact forms, to prevent abuse. Legal basis: legitimate interests in keeping CURA secure (Art. 6(1)(f)).
Waitlist and application data — if you join the waitlist or apply for access before having an account: your name, email, and whatever you tell us about yourself and your use case. Legal basis: taking steps at your request before entering a contract (Art. 6(1)(b)) and legitimate interest in running an orderly beta (Art. 6(1)(f)).
Push notification tokens — if you enable notifications, the device token needed to deliver them. Legal basis: contract (Art. 6(1)(b)).
Survey answers and correspondence — always voluntary; skip every survey forever and nothing changes. Legal basis: consent for surveys (Art. 6(1)(a), withdrawable anytime); legitimate interests for handling email you send us (Art. 6(1)(f)).
We do not use any of this for advertising, we do not build profiles to sell, and we collect nothing beyond this list.
The people you talk to
In plain English: Your inbox contains other people’s words. We hold them only to show them to you, and they can invoke rights too.
A unified inbox necessarily stores messages written by people who never signed up for CURA — your correspondents. We process their message content, names, handles, and (for calls) phone numbers solely so that you can read, answer, and act on your own conversations. We never use correspondents’ data for our own purposes, never enrich or profile it, and never contact them ourselves.
If you are a correspondent of a CURA user and want your data corrected or removed from that user’s CURA account, email hello@curavision.ai — we will act on it, and where the request concerns the relationship between you and the CURA user, we may need to involve them. Depending on where you live, you may have statutory rights to access or erasure against us as well; we honor those as the law provides.
What we never collect
In plain English: No platform passwords, no card numbers, no ad trackers, no data sale. Ever.
For OAuth platforms we never see your password. Telegram is the one exception, and only for the single sign-in step described above. We never see or store your card number — that is Stripe’s job. We run no ads, use no third-party analytics trackers, set no tracking cookies, and we do not sell your personal information or share it for advertising. We built CURA so we would not have to.
How your messages are protected — and the honest limits
In plain English: Messages in our primary database are encrypted at rest, but CURA holds the key. Some working stores are not yet encrypted. This is not end-to-end encryption.
Your message content in CURA’s primary database is encrypted at rest (Fernet symmetric encryption). Here is the part most policies bury: the server holds the encryption key. That means this protection is real against stolen disks, leaked backups, and storage-level theft — an attacker with the raw storage sees ciphertext. It is not protection against a fully compromised server, and it is not end-to-end encryption, where only your devices could ever decrypt. We will never describe CURA as end-to-end encrypted while this architecture is what runs.
A further honest limit: some internal working stores are not yet encrypted at rest — the inbox sync cache, WhatsApp linked-device session files, and call logs. They live on access-controlled servers, and bringing them under the same at-rest encryption is active engineering work; when it is done, this paragraph changes.
What else is real and running: hashed passwords, optional two-factor authentication with recovery codes, signed session tokens with refresh-token rotation that detects reuse of a stolen token, rate limiting on our endpoints, encrypted stored connection credentials, and security audit logging. No human at CURA reads your message content in the ordinary course of running the service.
The AI, plainly (automated processing disclosure)
In plain English: C.C. acts on what you invoke, publish-screening is automated, humans don’t review your content by default, and no algorithm here makes legally significant decisions about you.
When you ask C.C. to draft, send, summarize, or otherwise act on messages, that text is processed by Moonshot AI’s Kimi model. When you speak to C.C., your audio is processed by ElevenLabs, and the conversational reasoning runs on ElevenLabs’ bundled model, currently OpenAI’s GPT-5. Certain advanced assistant features, where enabled, are processed by Anthropic. Posts you submit for publishing pass through an automated content screen (a local filter plus, for some content, the same Moonshot AI models) before they go out; this screening exists to block prohibited content, is tuned to never block a normal post, and its outcome can be surfaced to you rather than silently applied.
By default, no human — at CURA or at these providers acting for us — reviews your AI interactions. C.C. is an assistant, not an autopilot: it acts on your instruction, and you remain the sender of anything it sends. CURA makes no automated decisions about you that produce legal or similarly significant effects within the meaning of GDPR Article 22 — no algorithmic account bans, no automated credit or eligibility decisions. If that ever changes, this policy changes first and we tell you.
Who else touches your data (subprocessors)
In plain English: Every provider, each doing one job, each listed with what it actually receives — including the ones whose pipes your messages travel through.
Composio (platform connections) — runs OAuth flows and holds access tokens for several platforms, and the content of messages read from or sent to those platforms transits Composio’s systems in both directions. Never receives your CURA password.
Unipile (platform connections) — provides hosted connections for several messaging platforms; it holds those platform sessions, and message content for those platforms transits and may be cached in Unipile’s systems.
Moonshot AI / Kimi (AI text processing and publish screening) — receives the text you ask C.C. to act on and text screened on the publish path. Moonshot AI is based in the People’s Republic of China; see the transfers section.
ElevenLabs (voice) — receives your voice audio and voice-conversation content when you use voice features.
OpenAI — two ways. ElevenLabs’ bundled language model is currently OpenAI’s GPT-5, so voice-conversation content reaches OpenAI through that pipeline; and where an OpenAI key is configured, our text-rewriting feature calls OpenAI directly with the text you submit to it.
Anthropic (advanced assistant features, where enabled) — receives the content those specific features process.
Stripe (payments) — receives your card and billing details directly; we receive back only plan and payment status.
Twilio (telephony) — used only by the AI calling feature described above, which is not enabled for customer accounts today. Where it runs, Twilio receives the phone numbers involved and carries the call.
AI-detection services (TextLab) — if you use TextLab’s detection features, the text you submit there is sent to third-party detectors to be scored. Those are currently GPTZero, Originality.ai and Copyleaks.
Notion — when you join the waitlist or apply for access through our website, that submission (your name, email, and what you tell us) is stored in a Notion database we use to manage the invite list. It is not used for anything else.
SendGrid — sends our transactional email (for example the reminder before a subscription renews). Receives your email address and the message we send you; never your message content.
Our hosting provider — runs the servers where your data lives at rest.
That is the full list. None of them receive your data for advertising, and we do not add anyone quietly: if this list changes, this page changes and its version number moves.
Where your data travels (international transfers)
In plain English: Data lives in Canada, flows to US providers for payments, voice, and connections, and — for AI text features — to Moonshot AI in China. Here’s what covers each hop.
CURA is based in Canada, which holds an EU adequacy decision for commercial organizations subject to PIPEDA, and a UK adequacy finding — so data coming to us in Canada from the EU or UK rests on those decisions.
United States: Stripe, ElevenLabs, OpenAI (via ElevenLabs), Anthropic, Composio, Unipile, and Twilio process data in the US. For EU/UK data, these transfers rely on the EU–US Data Privacy Framework and its UK extension where the provider is certified, or on Standard Contractual Clauses / the UK IDTA otherwise.
People’s Republic of China: this is the transfer we will not gloss over. When you use C.C.’s text features, and when text is screened on the publish path, that text goes to Moonshot AI in the PRC. China has no EU or UK adequacy decision, so this transfer requires Standard Contractual Clauses (EU) and the IDTA or UK Addendum (UK), backed by a transfer impact assessment — and you should know that PRC law can compel companies there to provide data to authorities, which limits what any contract can guarantee. If you are not comfortable with that, do not use C.C.’s text features and do not publish through CURA: those are the flows that reach Moonshot.
How long we keep things (retention)
In plain English: Content lives for the life of your account; operational records have fixed windows; close the account and your data goes with it.
Account data, platform connections, message content, created content, publishing history, and call records: kept for as long as you have an account, because they are the account. When your account is deleted, we delete them. Usage-metering events are kept for up to 400 days for billing accuracy and abuse prevention; scheduled posts that have finished — published, failed, or cancelled — are pruned after 90 days. Security audit logs are kept only as long as needed for security and legal purposes. Survey answers: until you ask us to delete them, or your account goes. Stripe retains its own payment records under its own policy, as payment processors are legally required to do. Under PIPEDA’s breach rules we must keep records of any data breach for 24 months. Data at our AI and integration providers is governed by our agreements with them and their retention terms. Deleted data may persist briefly in short-lived backups before those cycle out.
Your rights, wherever you live
In plain English: Access, export, correct, delete, object, port — email hello@curavision.ai and we act, within the deadlines each law sets.
Two of these you can do yourself, right now, without asking us: open Profile → Your data to download your data as a JSON file — your account, your conversations, what you created, your connections and your usage records — or to delete your account and its data permanently. The export explains what it contains and how to ask for anything it does not cover. For anything else — correction, restriction, objection, or a question about what we hold — email hello@curavision.ai from your account address. We will verify it is really you, we never charge for a first request, and we never penalize you for asking.
What deletion actually does: it erases your account and message content from our database, purges the copies held by our inbox service, revokes the connections you authorized at the providers that hold them, and removes the WhatsApp linked-device credentials from our servers. Where a provider is unreachable at that moment we record exactly what could not be cleared and finish it by hand — so ask us and we will tell you the state of your deletion rather than guess. Two things are kept on purpose: payment records, unlinked from you, because tax law requires it; and deleted data can persist briefly in short-lived backups before those cycle out.
EU (GDPR) and UK (UK GDPR): you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability in a machine-readable format (Art. 20), objection to processing based on legitimate interests (Art. 21), and to withdraw consent at any time where consent is the basis (Art. 7(3)). We respond within one month, extendable by two more for complex requests, and we will say so if we extend. You may complain to your local supervisory authority (EU) or the ICO at ico.org.uk (UK) — though we would appreciate the chance to fix it first.
Canada (PIPEDA): you have the right to access the personal information we hold about you, to challenge its accuracy and completeness and have it amended, and to withdraw consent subject to legal or contractual restrictions. We respond within 30 days. If we fall short, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
California (CCPA/CPRA): you have the right to know what personal information we collect, use, and disclose (this policy is that disclosure, and you can request your specific data); the right to delete; the right to correct; and the right to non-discrimination for exercising any right. We do not sell your personal information, and we do not share it for cross-context behavioral advertising — and we have not done either in the preceding 12 months — so there is nothing to opt out of, but if that ever changed we would provide the required opt-out first. We do not use or disclose sensitive personal information beyond what is necessary to provide CURA. We respond within 45 days, extendable once by 45 more with notice. You may use an authorized agent with written permission.
Whatever your jurisdiction, we extend the strongest of these as a baseline: every CURA user can access, export, correct, and delete their data.
If there is a breach
In plain English: If your data is breached, we tell the regulators the law requires and we tell you — plainly and fast.
If a breach of personal data occurs, we will notify the relevant supervisory authority within 72 hours where GDPR or UK GDPR requires it, report to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible where the breach creates a real risk of significant harm under PIPEDA, and comply with US state breach notification laws including California’s and New York’s 30-day notice rule. Beyond the legal minimums: if your data is involved, we will tell you what happened, what was exposed, and what we are doing about it, in plain language, without burying it.
Children
In plain English: CURA is for adults — 18 and over.
CURA is not directed to children, and you must be at least 18 to have an account. We do not knowingly collect personal information from anyone under 18; if we learn we have, we will close the account and delete the data. If we lower this age in the future, we will update this policy and apply the protections the law requires for minors first.
Changes to this policy
In plain English: Meaningful changes get an email before they take effect, and every version is numbered and dated.
This policy carries a version number and date at the top, and we keep prior versions available on request. Small clarifications get a refreshed date. Meaningful changes — anything that alters what we collect, who receives it, where it travels, or how long we keep it — get an email to you before they take effect. This policy is governed by the laws of Ontario, Canada, without limiting any protection your local law gives you that cannot be contracted away.
Contact us
In plain English: hello@curavision.ai — our privacy officer reads it, and answers.
Questions, requests, or something in this policy that does not sit right? Email hello@curavision.ai. That address reaches CURA Intelligence’s privacy officer in Ontario, Canada. Privacy questions do not go into a queue to die: a person reads them, and a person answers. If you are in the EU or UK you may also contact your supervisory authority; in Canada, the Office of the Privacy Commissioner; in California, the Attorney General — but we would genuinely like the first shot at making it right.