Privacy policy
Last updated August 31, 2026
This policy explains what personal information the operator of the Curi service(“Curi”, “we”, “us”) collects when you use the Curi website and mobile app (the “Service”), why we collect it, who we share it with, and the choices you have.
The short version. We collect what the product needs and little else. We show no ads, we use no third-party advertising or analytics trackers, we do not use session replay tools, and we do not sell or rent your personal information to anyone. Your data lives with the infrastructure providers that run the Service, and you can permanently delete your account and its data yourself, in the app or on the web, at any time.
1. What we collect
1.1 Account information
You sign in with Apple, Google, or an email-based account. From your sign-in provider we receive your name, email address, and (for Google) profile picture, as the provider’s consent screen describes. Sign in with Apple lets you hide your real email address; that works with Curi.
1.2 Profile information
What you add to your profile: display name, username, and an optional profile photo. Your home city is a preference you pick from a list during onboarding or in Settings. We do not collect your device’s location. The app does not request location permissions at all.
1.3 Content and activity
What you do on Curi: events you save, RSVP to, or mark attended; reviews and ratings, including photos and short videos you attach; comments and RSVP notes; reactions; lists; favorite artists, events, and venues; artists you follow; friend requests and friendships; and reports you file or accounts you block.
1.4 Connected accounts (optional)
If you choose to connect a music account (currently SoundCloud, with others possible later), we store the access credentials the provider issues and the list of artists you follow there, so we can match them to the Curi catalog and personalize your feed. We do not post to your connected accounts. You can disconnect at any time in Settings, which removes the stored credentials.
1.5 Device and technical information
If you enable notifications, we store a push notification token for your device. Our infrastructure providers keep standard technical logs (such as IP address, device and browser type, and timestamps of requests) for security and operations; we do not build advertising or behavioral profiles from them.
1.6 Early access signup information
When gated access launches, joining the waitlist will involve providing your first and last name, email address, city, and state, and using an access code will create a record of which code your account redeemed. We will use this information to manage access to the Service and to contact you about it, and for nothing else.
1.7 What we deliberately do not collect
- No device location, and no location permissions.
- No contact list or address book access.
- No third-party advertising or analytics SDKs, pixels, or fingerprinting, on web or mobile.
- No session replay or screen recording tools.
- No sensitive categories: we do not ask for and do not want health, biometric, precise location, or government identifier data.
The event catalog itself (events, artists, venues) is assembled from publicly available listings and processed with automated tooling, including AI services. That pipeline processes public event information, not your personal information.
2. How we use information
- To run the Service: operate your account, show you the catalog and your feed, store and display your content, and connect you with friends.
- To personalize: rank events using your saved taste preferences, home city, follows, and activity. We do this to sort what you see, not to advertise to you.
- To notify you: send push notifications you have enabled (friend activity, artist shows in your home city, and similar) and service emails. You control notification categories in your device settings and in the app.
- To keep the Service safe: enforce our terms and community guidelines, act on reports and blocks, prevent abuse and fraud, and secure accounts.
- To improve the Service: understand aggregate usage from our own records and fix problems.
- To comply with law: meet legal obligations and respond to lawful requests, as described below.
3. What other people can see
Curi is a social product, and visibility is tiered. Your profile (name, username, photo, favorites) is visible to others; signed-in members can additionally see your past activity and public reviews; and your accepted friends can additionally see your upcoming plans, subject to the privacy toggles in Settings (public past activity, friends see upcoming plans, friends see your Interested saves, public RSVP notes). Reviews you mark private stay yours. Comments are visible to people who can see the event conversation. Web profile and event pages can be viewed outside the app with the same tiering, so anything set public may be visible on the open web.
One honest caveat while we are in early access: photos and videos attached to reviews are currently stored in a hosting bucket whose direct file links are not access-controlled, so a direct link to a media file could be opened by someone it was shared with even if your review is friends-only. Moving review media to fully private, signed-link storage is in progress and this policy will be updated when it ships. If that concerns you, hold off on attaching sensitive media to restricted reviews for now.
4. When we share information
We do not sell or rent personal information, and we do not share it with advertisers or data brokers. We share it only with:
- Infrastructure providers that run the Service on our behalf and process data under their agreements with us: Supabase (database, authentication, and file storage), Vercel (web hosting), Railway (catalog data pipeline), Expo (app delivery and push notification routing), Apple and Google (push notification delivery and app distribution), and Resend (email delivery). Their access is limited to what operating the Service requires.
- Other users and the public, according to the visibility rules in section 3.
- Third-party services you choose to use, such as a ticket seller you click through to or a music service you connect. What you do there is governed by their policies.
- Authorities, if we believe in good faith that disclosure is required by law, or reasonably necessary to protect the safety, rights, or property of Curi, our users, or the public.
- A successor, if Curi is involved in a merger, acquisition, financing, or sale of assets, in which case this policy continues to apply and we will provide notice of any material change in ownership or use of your information.
5. Cookies
The website uses cookies only to keep you signed in (authentication session cookies) and for one small convenience cookie that remembers that your account finished onboarding. These are strictly necessary for the Service to function. We set no advertising, analytics, or cross-site tracking cookies, which is why you will not see a cookie consent banner. Embedded players on artist pages (such as SoundCloud or Bandcamp) are loaded from those services and may set their own cookies when you interact with them, under their own policies.
6. Retention and deletion
We keep your information for as long as your account exists. When you delete your account (Settings, on web or in the app), your account, profile, reviews, photos and videos, comments, saves, lists, friendships, notification tokens, and connected-account credentials are permanently deleted. Content you contributed to shared spaces is removed with it. A small residue may persist for a limited period in encrypted backups and infrastructure logs before aging out, and we may retain specific records where the law requires it or where they are needed to enforce our terms (for example, records of a ban). Public event catalog data is not personal information and is retained independently.
7. Security
Data is encrypted in transit, access to production systems is restricted, and reads and writes are gated by per-row database access rules. No service can promise perfect security, and you use the Service at your own risk; please keep your sign-in method secure. If we learn of a breach affecting your personal information, we will notify you as applicable law requires. Report suspected vulnerabilities to support@curi.events.
8. Your rights and choices
Regardless of where you live, and without needing to qualify under any specific privacy statute, you can:
- Access and update your profile, content, and preferences directly in the app and on the web;
- Delete your account and data yourself, in Settings, with immediate effect;
- Control visibility with the privacy toggles in Settings and per-review visibility settings;
- Turn off notifications in the app and in your device settings, and unsubscribe from any non-essential email;
- Disconnect any connected music account in Settings; and
- Ask us for a copy of your data, for correction, or for deletion by emailing support@curi.events. We will verify the request against your account email and respond within the time applicable law requires (and in any case aim for 30 days). We will not discriminate against you for exercising any right.
State privacy laws such as the California Consumer Privacy Act grant residents of those states specific rights to know, access, correct, and delete personal information and to opt out of sales, sharing, and targeted advertising. Curi does not sell or share personal information as those laws define it and does not use your information for targeted advertising, so there is nothing to opt out of; the access, correction, and deletion rights above are available to everyone. Because we set no third-party tracking cookies, there is nothing for a Global Privacy Control or Do Not Track signal to switch off, and browsing with them enabled changes nothing about how the site treats you.
9. Age requirement
Curi is for adults. You must be 18 or older to use the Service. We do not knowingly collect personal information from anyone under 18; if we learn we have, we will delete the account and its data promptly. If you believe someone under 18 is using Curi, email support@curi.events.
10. Where data is processed
The Service is operated from the United States and our infrastructure providers store data in the United States. The Service is currently directed to users in the United States; if you use it from elsewhere, you understand that your information is transferred to and processed in the United States, where privacy laws may differ from those of your jurisdiction.
11. Changes to this policy
We will update this policy as the Service evolves (two known upcoming updates are described in sections 1.6 and 3). We will post changes here and update the date at the top; for material changes we will give notice in the app, on the site, or by email before they take effect.
12. Contact
Privacy questions and requests: support@curi.events.