CURVE

Privacy Policy

Effective July 11, 2026

Curve Memory ("Curve", "we") turns topics into explainers and flashcards you can study with spaced repetition. This policy describes what we collect, why, and what we do not do. We keep it short because our data practices are simple: we collect what the product needs to work, and nothing else.

What we collect

  • Account: your email address, username, and a hashed password — or, if you sign in with Google or Apple, the identifier and email they share with us.
  • Your content: the decks, explainers, and cards you create or generate, and the topics and prompts you submit to generate them.
  • Study activity: review events (which card, when, and how you rated it). This is the core of spaced repetition — it is how the app schedules your reviews.
  • Billing: payments are processed by Stripe. We store your Stripe customer reference, subscription status, and top-up history. Your card details never touch our servers.
  • Your own API keys (optional): if you bring your own LLM API key, we store it encrypted and use it only to run your generation requests.
  • Push tokens: if you enable notifications in the iOS app, we store the device push token needed to send them.
  • Operational logs: our servers keep standard request logs for reliability and abuse prevention.

How we use it

To run the product: generate your decks, schedule your reviews, sync across devices, process payments, send transactional email (verification, password reset, invites), and send notifications you asked for.

When you generate content, the topic and related prompts are sent to our AI providers (Anthropic and OpenAI) to produce your explainers and cards. Under their API terms, these providers do not use API data to train their models.

What we don't do

  • We do not sell your data.
  • We do not show ads.
  • We do not use third-party advertising or cross-site tracking, and we do not run third-party analytics trackers in the app.
  • We use cookies only to keep you signed in.

Who we share data with

Only service providers that run the product on our behalf: AWS (hosting and logs), Stripe (payments), Anthropic and OpenAI (content generation), SendGrid (transactional email), and Expo (push notifications). Each receives only what its function requires.

If you make a deck public, its content (not your study activity) is visible to anyone with the link.

Retention and deletion

Your data is kept while your account exists. You can delete your account from Settings in the app or on the web — this permanently removes your account, content, study history, and stored API keys. Residual copies in encrypted backups and operational logs expire on a rolling basis.

Security

All traffic is encrypted in transit. Stored API keys are encrypted at rest. Payment credentials are held by Stripe, not us.

Children

Curve is not directed at children under 13, and we do not knowingly collect their data.

Changes and contact

If this policy changes materially, we will note it here with a new effective date. Questions or requests: support@curvememory.com.

Back to Curve Memory