Privacy Policy
Effective 14 May 2026 · Last updated 14 May 2026
Translations of this document are provided for convenience only; the English version governs.
1. Introduction
This Privacy Policy (the "Policy") describes how Curio Design ("Curio", "we", "our", or "us") collects, uses, and discloses information about you in connection with your access to and use of the website at designbycurio.com and related applications, APIs, and tools (collectively, the "Service"). It supplements and forms part of our Terms of Service.
2. Information we collect
We collect the following categories of information in the course of operating the Service:
| Category | Examples | Source |
|---|---|---|
| Account information | Email address, display name, OAuth provider identifier, profile image URL | Provided by you or by your selected authentication provider |
| Subscription information | Plan tier, billing cycle, period start and end dates, subscription status | Curio and PayPal |
| Payment metadata | PayPal subscription identifier, transaction identifiers, last four digits of payment card, billing country. Full card numbers and security codes are processed and stored by PayPal; Curio does not receive or store them. | PayPal |
| Usage events | Design Package views, downloads, share-link generations, recorded with timestamp, plan tier at the time, and Credits consumed | Your client device |
| Feedback (Max subscribers only) | Subject, body, category, and timestamp of feedback submissions | Provided by you |
| Technical and access information | IP address, browser type and version, operating system, referrer URL, language preference | Automatically collected via Cloudflare |
3. How we use information
We use the information described above for the following purposes:
- to provide, maintain, and operate the Service, including authenticating you, displaying your subscription status, and enforcing usage Credits;
- to process payments and issue receipts;
- to detect, prevent, and respond to fraud, abuse, scraping, or violations of our Terms of Service;
- to communicate with you about your Account, billing, service announcements, and material policy updates;
- to analyze aggregate usage patterns in order to improve the Service and decide which Design Packages to produce next; and
- to comply with applicable legal obligations.
We do not use your personal information for behavioral advertising, and we do not sell your personal information to third parties.
4. Legal bases for processing
Where the EU or UK General Data Protection Regulation applies, our legal bases for processing your personal data are:
- Performance of a contract — to provide the Service you have requested and to fulfill our obligations under the Terms of Service.
- Legitimate interests — to operate, secure, and improve the Service, prevent abuse, and pursue commercially reasonable analytics.
- Compliance with legal obligations — where retention or disclosure is required by law.
- Your consent — where we ask for it specifically, for example for optional communications.
6. Service providers
We engage a limited number of third-party service providers (sometimes called "subprocessors") to operate the Service. Each provider receives only the data needed for the function described below, and is contractually required to protect that data.
| Provider | Function | Data shared |
|---|---|---|
| Supabase | Authentication, database, file storage | Account, subscription, and feedback records |
| PayPal | Recurring billing and payment processing | Email address, plan tier, billing address as you provide it |
| Cloudflare | Content delivery, DNS, and abuse mitigation | Request metadata (IP address, user agent) |
| GitHub and Google | OAuth sign-in (only if you choose to sign in via these providers) | OAuth profile data (email, provider identifier, display name, avatar URL) |
| Google Analytics | Aggregate site usage measurement (page views, sessions, referrers, country-level geography) | Pseudonymous cookie identifier, IP address (truncated by Google), page URL, user agent |
Each provider processes your data in accordance with its own privacy policy, which applies in addition to this Policy.
7. Disclosure of information
We disclose your personal information only in the following circumstances:
- to the service providers listed in Section 6, for the purposes described;
- where required to comply with valid legal process, applicable law, or a binding governmental request;
- to protect the rights, property, or safety of Curio, our users, or the public;
- in connection with a merger, acquisition, financing, or sale of assets, provided that the recipient is bound by terms no less protective than this Policy; and
- with your consent or at your direction.
8. Data retention
We retain personal information only for as long as necessary for the purposes for which it was collected, or as required by law:
- Account and subscription records — for the duration of your Account, plus a short period thereafter to permit reactivation.
- Usage events — capped at the most recent 200 events per user; older events are discarded automatically.
- Billing records — retained for at least seven (7) years, or for a longer period if required by applicable tax, accounting, or audit laws.
- Feedback — retained until you request deletion or until the Service is discontinued.
9. Your rights
Subject to applicable law (including the EU/UK GDPR, the California Consumer Privacy Act and California Privacy Rights Act, and the mainland China Personal Information Protection Law), you may have the right to:
- access the personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion of your personal information, subject to any retention required by law;
- object to, or restrict, certain processing of your personal information;
- receive a portable copy of your personal information in a structured, machine-readable format;
- withdraw consent, where processing is based on consent; and
- lodge a complaint with a competent data protection authority.
To exercise any of these rights, send a request from the email address registered to your Account to [email protected]. We will respond within thirty (30) days, and may extend this period by up to a further two (2) months where necessary for complex requests, in which case we will notify you of the extension and its reason within the initial 30 days. We may request additional information to verify your identity before proceeding.
California residents: Curio has not sold personal information in the preceding twelve (12) months and does not currently share personal information for cross-context behavioral advertising. You have the additional right under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA") to opt out of any future sale or sharing — should our practices change, an opt-out link will be added to this Policy and made available via the request channel above.
10. International transfers & EU representative
Our service providers operate globally. Your personal information may be processed in jurisdictions other than the one in which you reside, including the United States. Where required by law (for example, the Standard Contractual Clauses under the GDPR), we put appropriate safeguards in place to protect cross-border transfers of personal data.
If you are located in the European Economic Area, United Kingdom, or Switzerland and wish to raise a data-protection matter, you may contact us at [email protected]. Where required under GDPR Article 27, we will designate a representative in the Union and publish their contact details in this Section once Service availability to EEA users commences.
11. Children's privacy
The Service is not directed at children under the age of thirteen (13), and we do not knowingly collect personal information from children under that age. If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will delete such information promptly. If you believe that a child has provided personal information through the Service, please contact us at [email protected].
12. Security
We apply technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include transport-layer encryption (HTTPS) for all traffic, encryption at rest through our hosting provider's standard mechanisms, and access controls based on the principle of least privilege. No method of transmission or storage is entirely secure; in the event of a personal-data breach affecting you, we will notify you without undue delay where required by law.
13. Changes to this Policy
We may update this Policy from time to time. For material changes, we will update the "Last updated" date at the top of this document and notify active users by email at least seven (7) days before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
14. Contact
For questions about this Policy, data-subject requests, or any other privacy-related matter, contact us at [email protected]. See also our Terms of Service.