This Privacy Policy explains how Curio (operated by Gökberk İnce, sole proprietor, Türkiye — referred to below as "Curio", "we", "us") collects, uses, stores, shares, and protects information when you use the Curio iOS application and the curioplaces.app website (collectively, the "Service"). Curio is designed for people aged 13 and over. Optional device access and usage analytics use the choices described below; using Curio does not enable optional analytics.
Data we collect
Account information
When you sign in with Apple or Google via Supabase Auth we receive your email, display name, profile photo URL (if available), and a unique provider ID. We also store a Curio username you choose, optional bio, and your selected language and home country.
User-generated content
Any travel list you create — places, day plans, curator notes, cover images, prices, and metadata — is stored in our database. If you publish a list, that content becomes visible to other users and renderable on social-media unfurls via curioplaces.app.
Trip activity
When you start a Trip, we record the trip itinerary, your check-ins (timestamp + place reference), and any photos you take inside Trip mode. Photos are uploaded to Supabase Storage in a private bucket associated with your account.
Purchases & tips
Purchase records (which list you bought, which creator received a tip, currency, amount, and Apple transaction ID) are processed through Apple StoreKit and reconciled with RevenueCat. We never see your payment card or Apple ID password.
Referral data
If you redeem an invite, we record the inviter's referral code, the timestamp, the device's coarse IP for fraud prevention, and the outcome. Anti-fraud guards include a 60-second account-age window, an IP-match check, and a self-referral block.
Push tokens & analytics
We collect APNs/FCM device tokens to deliver push notifications you opt into. Optional usage analytics is off by default on this device. If enabled in Settings, Firebase Analytics receives guide and publication IDs, the screen area and order in which a guide appeared, the ranking version and organic or sponsored placement, visible duration, and actions such as opening or saving a guide, starting a new trip, or opening Share. Our custom guide events do not include account IDs, private notes, photos, precise location, search text or purchase amounts.
After you opt in, Firebase can also process basic app and supported in-app purchase events, resettable app-instance identifiers, and device/network information such as approximate region. Advertising consent remains off. Turning analytics off in Settings stops collection and clears pending analytics on this device; it does not remove events Firebase already received. The choice applies to this device.
Public guide previews also offer a separate, optional measurement checkbox. If you enable it, a random link token can connect that preview to opening the app and a server-verified purchase or trip start within 24 hours, provided you also allow analytics in the app. The server can temporarily link it to your signed-in account to verify and deduplicate outcomes. It stores a token hash, never private notes or photos, and reports aggregate counts to creators and administrators. Raw attribution records are retained for up to seven days and daily totals for 90 days. No fingerprinting or advertising cookies are used. Turning this option off stops adding the token to the app link; it does not erase prior totals.
How we use it
- To provide the core Service: accounts, lists, purchases, trips, and search.
- To prevent fraud, abuse, and spam (especially in the referral program and reviews).
- To pay creators and reconcile platform fees and refunds with Apple.
- To send transactional emails, push notifications you opted into, and creator earnings updates.
- To improve guide discovery through optional usage analytics.
- To comply with applicable law and respond to lawful requests.
Lawful bases (GDPR)
We rely on the following lawful bases under GDPR Article 6: (a) contract — to provide the Service you signed up for; (b) legitimate interests — fraud prevention, product security; (c) consent — for optional usage analytics, push notifications, optional camera/photo access, and calendar integration; (d) legal obligation — tax, accounting, and lawful disclosure requirements.
Third-party processors
We share the minimum data required with the following sub-processors, each bound by a data processing agreement:
| Processor | Purpose | Region |
|---|---|---|
| Supabase | Auth, Postgres database, Storage | EU |
| Vercel | Web hosting and serverless functions | Global edge |
| Apple StoreKit | In-app purchases and refunds | Global |
| RevenueCat | Subscription & purchase analytics | US |
| Firebase | Optional analytics and push delivery (FCM) | US |
| Google Places API | Place metadata enrichment (read-only) | US |
| Apple Sign-In, Google Sign-In | OAuth identity providers | US |
Device permissions
- Location (when in use) — to center the map on your current city and surface nearby places. We do not log background location.
- Camera & photo library — to capture trip memories and upload list cover images.
- Calendar (full access, opt-in) — to add planned trips to your calendar with your explicit confirmation.
- Notifications — for trip reminders, list updates, and creator earnings.
Data retention
We retain account data while your account exists. When you delete your account, we erase personal identifiers within 30 days, except where retention is required by law (e.g., tax records related to purchases — kept for 5 years per Turkish tax law). Public content you published may persist as anonymized data for the integrity of other users' purchases and reviews.
Your rights
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — delete your account from in-app settings.
- Portability — receive a machine-readable export.
- Restriction & objection — limit how we process your data.
- Withdraw consent — at any time, with no effect on prior lawful processing.
- Lodge a complaint — with your local supervisory authority (e.g., KVKK in Türkiye).
California rights (CCPA/CPRA)
California residents may request the categories and specific pieces of personal information we collected; the categories of sources; purposes; and categories of third parties with whom we share information. You may also request deletion or correction. We do not sell or share personal information for cross-context behavioral advertising.
International transfers
Some processors are located outside the EU/EEA, UK, or Türkiye. Transfers rely on Standard Contractual Clauses or equivalent mechanisms and are limited to what is necessary to operate the Service.
Children's privacy
Curio is not directed to children under 13 (or the higher minimum age in your jurisdiction). We do not knowingly collect data from such users. If you believe a child has provided us data, contact us and we will delete it.
Security
Data is encrypted in transit (TLS 1.2+). Database access is governed by row-level security so users can only read their own private data. OAuth flows use PKCE and nonce verification. We rotate keys, monitor access logs, and run periodic security reviews.
Changes to this policy
We may update this Privacy Policy as the Service evolves. Material changes will be announced in-app and via email at least 14 days before they take effect. Your continued use after the effective date constitutes acceptance of the revised policy.