Privacy Policy
Last updated: September 17, 2026 · Part A covers the curator app and app.curator.so, Part B this website · Controller: Goldgräbe Cyber & Cipher, Hohlstrasse 465, 8048 Zürich, Switzerland, hi@curator.so
This policy explains which personal data curator processes, why, and which rights you have — under the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).
Part A — the curator app and app.curator.so
1. What data we process
- Account: e-mail address or Apple ID identifier (Sign in with Apple), passkey public keys, display name. Accounts created anonymously carry a technical placeholder address until you add a login.
- Media: the photos and videos you actively upload for curation, including their metadata (capture time, camera data, GPS position, file name).
- Curation data: suggestions, your decisions (accept/reject), notes and markings, learned preference rules.
- AI assessments: a machine assessment of each item with a short description and a numeric image vector used to group similar shots.
- Usage: technical events (e.g. "post viewed") for debugging and product improvement — no third-party tracking, no advertising IDs.
- Sign-ins: time, IP address and device identifier ("user agent") of each sign-in and sign-out, to protect your account; IP and device identifier are removed automatically after 90 days.
- Push: device tokens, if you allow notifications.
- Device key: a random identifier the app creates once and keeps on your device; it is sent when an account is created and used to grant the free month and the welcome gift once per device. It contains no hardware identifiers.
- Diagnostics and feedback: crash reports and problem reports you send from the app (app and iOS version, device model, the report text), and ratings or feedback you submit.
- Credits: a transaction history of every credit movement on your account (grants, purchases, spends, refunds), which you can inspect in the app.
2. Why (purposes and legal bases)
The core of the service is the AI-assisted selection and preparation of your photos into post suggestions (Art. 6 (1) (b) GDPR — performance of contract). Operation, support, security and abuse prevention rest on our legitimate interest (Art. 6 (1) (f)). Push notifications are sent only with your consent (Art. 6 (1) (a)), revocable in your system settings.
3. AI processing by processors
For analysis and composition, your media are transmitted in reduced form (downscaled copies, never the originals) to AI providers and processed there exclusively to provide the service — this is the core of what curator does, and it cannot be done without it. Current provider: Google (Gemini models via the paid Gemini API, USA/EU) for scoring, selection, composition and captions. Google acts as our processor under its Gemini API terms and data processing addendum; transfers to the USA rest on the EU standard contractual clauses that form part of those terms. Under the paid API terms, inputs are not used to train the provider's models and are retained only briefly for abuse monitoring. The original files remain on our own infrastructure. Should we add or replace a provider, we will name it here before it processes your media.
Two further recipients, each strictly purpose-bound and never receiving media content: the OpenStreetMap Foundation (Nominatim, United Kingdom) receives, for photos with location data, a deliberately imprecise coordinate (rounded to roughly one kilometre) to derive a place name for the caption — never your exact position. Resend (USA) sends, on our behalf, transactional e-mails (account mail, and the legally required confirmations for withdrawal and cancellation declarations) and receives your name, e-mail address and the content of the message for that purpose.
Ad measurement (iOS app only). To see whether our own ads on Instagram and Facebook lead to installs, the app uses Apple's SKAdNetwork and our server sends Meta Platforms Ireland Ltd. a few product events (app installed, app opened, AI disclosure accepted, free month started, purchase with price). Meta receives an opaque, randomly salted identifier, your device model, iOS version and app build — never your photos, name, e-mail address or an advertising identifier; app-tracking is always reported as off. To read a campaign's conversion rate ourselves, our website reports campaign visits to the app server as a keyed hash of the network address (never the address itself, deleted after 30 days); if the app is first opened from the same network within three days, the account is tagged with that campaign name — a statistical match, nothing more, and it never leaves our servers. We use no Meta software inside the app. Legal basis: our legitimate interest in measuring our advertising (Art. 6 (1) (f) GDPR). Apple's SKAdNetwork itself delivers only an anonymous, delayed conversion value and cannot identify you.
4. Hosting and storage
Storage and processing take place on self-operated infrastructure in Switzerland. Backups are created regularly and overwritten in rotation. Your media and curation data remain stored until you delete them or give up your account.
What deleting actually does: the image file and every version derived from it are removed from storage, along with location, capture time, file name, the image vector and all AI assessments. The only thing left behind is a contentless marker that a file once existed at that spot — it prevents the same file from being uploaded again on the next sync. Deleting your account removes that marker too. Data leaves the backups with the backup rotation.
What we cannot undo: reduced copies already transmitted to the AI providers are subject to their own deletion schedules; we cannot remove them ourselves.
5. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, and the right to lodge a complaint with a supervisory authority (in Switzerland: the FDPIC). In the app you can delete individual media or whole time ranges at any time; a machine-readable export of all your data is available in Settings ("Export data"). For everything else: hi@curator.so.
6. Cookies
Only one technically necessary session cookie is set, for login on app.curator.so. No tracking, no third-party cookies, no advertising. Fonts and all other parts of the web app are served by us — nothing is loaded from third-party servers when you visit.
7. Purchases & billing
Purchases (subscriptions, credits) run exclusively through Apple's in-app purchase. We receive no payment data — no card numbers, no bank details — only signed transaction confirmations from Apple (product, transaction ID, expiry date of a subscription). We store these to maintain your balance and subscription status, to rule out double crediting, and to meet statutory retention duties. Purchase events flow into our product statistics in anonymised form.
Withdrawal and cancellation: if you send us a withdrawal or cancellation declaration, we store your details (name, contract reference, e-mail, optional reason) together with the time of receipt, in order to send the legally required confirmation of receipt and to process the declaration. Legal bases: Art. 6 (1) (b) and (c) GDPR.
Part B — the curator.so website
8. What the website collects, and why
Self-hosted usage analytics. We run our own, first-party analytics on our own server: page views, App Store badge taps, which page sections you scroll to and how long you stay, referrer and campaign tags (UTM), your browser's user-agent string, language and timezone (as a coarse, country-level location signal — we use no IP geolocation service), and a salted hash of your IP address — the raw IP is never stored. A random session ID is kept in your browser's localStorage so the funnel works. No third-party analytics service receives this data. If you arrive from one of our ad campaigns, the campaign name together with a keyed hash of your network address (not the address itself) is passed to our own app server and deleted there after 30 days, so we can see whether the campaign led to an app install (see section 3 above). Legal basis: our legitimate interest in understanding and measuring our website (Art. 6 (1) (f) GDPR).
No cookies, no third-party scripts. The website sets no cookies and loads nothing from Meta, Google or any other third party. The Space Grotesk and Inter typefaces are served from our own server.
9. Where it lives and how long we keep it
Website analytics data is stored on our own server in Switzerland and kept for at most 24 months. If you signed up for early access before the App Store launch, we keep your e-mail address on our update list and write to you when something big ships, a few times a year at most (legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in informing people who asked to hear from us). Every such mail has an opt-out: reply "stop" or write to hi@curator.so and you are removed. Nothing is sold, rented, or shared with anyone beyond the services named above.
10. Changes
If this policy changes materially, we update this page and the date above.