Privacy policy
Effective 15 July 2026 · Last updated 17 July 2026
Cura keeps your conversations and your assistant's files on our servers, uses them only to run your assistant, and deletes them when you delete your account. Message content goes to the companies that run the language models, and nowhere else. There are no ads, no third-party analytics, and we never sell personal data.
1. Who we are and what this policy covers
Cura is a personal-assistant service operated by [LEGAL ENTITY NAME] ("Cura", "we", "us"). This policy describes what personal data we collect through the Cura app and the website at [DOMAIN], how we use and disclose it, how long we keep it, and the rights you have over it.
Cura is currently in private testing. A public support address will be listed here before launch; until then, testers can reach us on the channel they were invited through, and the contact details in section 12 apply once published.
2. Personal data we collect
We collect the following, and nothing else — no contacts, no location, no advertising identifiers, no analytics profiles:
- Account details. Signing in with Apple gives us a one-way hash of your Apple identifier, which lets the same Apple ID reopen the same account and tells us nothing else about you. If you choose to share your name at sign-in, we keep it so your assistant can address you. Your phone holds a sign-in credential; our servers store only its hash. We also hold a token Apple issues us at sign-in, used for exactly one purpose: telling Apple to sever the link when you delete your account. It is discarded at that point.
- Your conversations. The messages between you and your assistant: your chat history, and your assistant's working material. These may contain any personal data you choose to include in them.
- Your assistant's files. Your assistant keeps plain-text files about your life — tasks, schedule, preferences, notes — together with a history of every edit to those files, so its work can be checked. Both are deleted with your account.
- Calendar data, only if you connect a calendar. Section 5 covers Google Calendar. If you turn on the Apple Calendar mirror, events from your phone's calendar are copied into your assistant's files each time you open the app.
- Operating data. A push-notification token, your timezone, whether notifications are enabled, and usage accounting: token counts and processing costs per session, with no message content in them.
We collect all of this directly from you or from your use of the service. We do not buy data about you, and we do not collect data about you from other sources.
3. How we use personal data, and our legal bases
We use your data for one purpose: to provide and operate your assistant. In more detail, and with the legal bases that apply where laws such as the EU and UK GDPR require one:
- Providing the service — storing your conversations and your assistant's files, sending your recent conversation and relevant files to a language-model provider to generate replies, keeping your calendar in step if you connect one, and delivering notifications. Legal basis: performance of our contract with you.
- Operating and securing the service — usage accounting, enforcing spend and message limits, debugging problems, and investigating abuse. Legal basis: our legitimate interest in running a working, safe service.
- Meeting legal obligations — keeping and disclosing what the law compels, as described in section 4. Legal basis: legal obligation.
We do not use your data for advertising, do not build profiles from it, do not use it to train models ourselves, and do not sell or rent it to anyone. Automated processing here produces your assistant's replies; we make no automated decisions about you that have legal or similarly significant effects.
4. How we disclose personal data
Four companies process portions of your data so the service can work. Each receives only what its role requires, and each has its own privacy policy:
- Anthropic runs the language models. When your assistant works, your recent conversation and its relevant files are sent to Anthropic to generate the reply. Anthropic's privacy policy.
- OpenRouter carries those requests between our servers and Anthropic. OpenRouter's privacy policy.
- Apple handles Sign in with Apple and delivers push notifications, so message content passes through Apple's notification service on the way to your phone. Apple's privacy policy.
- Google is involved only if you connect Google Calendar, as described in section 5. Google's privacy policy.
Beyond those four:
- During the testing period, the team can open an account's messages and files to debug a problem or investigate abuse.
- If the law compels us — a court order, a lawful demand from a public authority — we may have to disclose data. We will disclose no more than the demand requires, and will tell you unless the law forbids it.
- If Cura changes hands — a merger, acquisition, or sale of assets — your data may transfer to the successor, who will remain bound by this policy or one at least as protective, and we will notify you before the transfer takes effect.
There are no other disclosures. We do not sell personal data, and we do not share it for advertising.
5. Google Calendar
Connecting Google Calendar is optional. If you connect one, we ask for two narrow permissions:
- Read your list of calendars (
calendar.calendarlist.readonly), so that Settings can show you which calendars exist and let you choose which ones your assistant reads and which one it writes to. - Read and write events (
calendar.events), so that your assistant can see your schedule, keep it in step with its own files, create or change events you asked for, and pass on your answers to invitations.
Events from the calendars you chose are copied into your assistant's files on our server. Because your assistant reads those files, event details can be part of what is sent to Anthropic when it works; that is how it knows your schedule. Google data is never used for advertising, never sold, and never shared beyond what this section says. Disconnecting the calendar in Settings deletes our stored tokens, and so does deleting your account. You can also revoke Cura's access yourself at myaccount.google.com/permissions.
Cura's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. How long we keep personal data
We keep your data for as long as your account exists, because your assistant works from it. We keep nothing on a separate schedule of its own: deleting your account deletes the data, as section 7 describes, except for the two items listed there and anything we are legally required to retain for longer.
7. Deletion
You can delete your account in the app's Settings, yourself, without asking anyone. Deletion is immediate. It removes your assistant's files with their whole edit history, your messages, your calendar connection and its tokens, your name, and every device credential.
Two things remain after deletion:
- the one-way hash of your Apple identifier, kept so that if you ever sign in again the same Apple ID gets a fresh account instead of a duplicate; and
- anonymous usage totals — token counts and costs with no message content in them.
Subscriptions, once they exist, belong to your Apple ID and are managed in the App Store; deleting your account does not cancel one.
8. Your rights
Depending on where you live, laws such as the EU and UK GDPR and the California Consumer Privacy Act (CCPA) give you rights over your personal data. We honour these rights for everyone, wherever you live:
- Access. You can ask what personal data we hold about you and receive a copy of it, in a portable format where the law provides for one.
- Correction. You can ask us to correct inaccurate data.
- Deletion. You can delete your account and its data yourself, in the app, at any time (section 7), or ask us to do it.
- Objection and restriction. You can object to, or ask us to restrict, processing based on our legitimate interests.
- Withdrawal of consent. Where processing rests on your consent — connecting a calendar is the main case — you can withdraw it at any time by disconnecting in Settings, without affecting the lawfulness of processing before withdrawal.
We do not sell or share personal data as the CCPA defines those terms, so there is nothing to opt out of under it. Exercising any of these rights costs you nothing and changes nothing about how you are treated.
To exercise a right that isn't built into the app, contact us as described in section 12. We may ask you to confirm control of your account before acting, and we will respond within the deadlines the applicable law sets. If you live in the EU or UK, you also have the right to lodge a complaint with your data protection authority.
9. International transfers
Our servers are located in [SERVER LOCATION]. The providers listed in section 4 process data in the United States and elsewhere. Where data protection law restricts transfers across borders — as the EU and UK GDPR do — we rely on the safeguards those laws recognise, such as adequacy decisions and standard contractual clauses, and on the corresponding commitments in our providers' terms.
10. Security
Traffic between the app and our servers is encrypted with TLS. Each account's data is stored in its own directory, separate from every other account, and sign-in credentials are stored only as hashes. No transmission or storage is perfectly secure, but if a breach ever touches your data, we will tell you promptly, and will notify regulators where the law requires it.
11. Children
Cura is not directed at children under 13, and we do not knowingly collect data about them. If we learn that we hold such data, we will delete it.
12. Contact
Questions about this policy, or requests under section 8, go to [CONTACT EMAIL]. During private testing, the channel you were invited through works too.
13. Changes to this policy
If this policy changes, the "Last updated" date at the top changes with it, and anything material is announced in the app before it takes effect. Earlier versions are available on request.