Moty Studio Curio
Privacy Terms Account deletion

Curio · Moty Studio

Curio Privacy Policy

How Curio collects, uses, shares, retains, and protects personal data.

Effective date: 12 August 2026

This Privacy Policy explains how Moty Studio LLC, doing business as Moty Studio ("Moty Studio", "we", "us"), processes personal data when you use the Curio mobile application, its related support, and Curio pages on this website.

Curio is available only to people aged 18 or older and is not directed to minors.

1. Controller and contact

Moty Studio LLC, a Wyoming limited liability company, is the controller of the personal data described here. Registered address: 30 N Gould St, STE R, Sheridan, WY 82801, USA. Privacy and support contact: [email protected].

2. Our privacy position

  • We do not show advertising and do not use personal data for direct marketing.
  • We do not sell personal data or share it for cross-context behavioural advertising.
  • We do not make decisions producing legal or similarly significant effects through profiling.
  • Moty Studio does not train AI models on your content.
  • Optional PostHog product analytics, session replay, and surveys are disabled until you consent and can be disabled in Settings.

3. Data we process

CategoryExamples
Account and identityFirebase user ID, guest-account status, email, display name, profile photo URL, sign-in provider, and authentication/security records. Apple or Google may also process sign-in data under their own terms.
Profile and preferencesApp language, interests, travel style, content preferences, settings, notification choices, and account statistics.
LocationPrecise location while the app is in use, coordinates, map position, search area, and derived city, region, or country. We do not request background location.
Curio contentGenerated and saved guides, collections and their titles/descriptions, local picks, quiz answers/results, guide progress, sources, and usage credits.
Chat and mediaMessages you send about a guide and optional images; profile photos and feedback screenshots. Curio converts uploaded images to a bounded JPEG and removes EXIF metadata, including embedded GPS metadata, before upload.
PurchasesCurio Pass product, store, transaction and entitlement identifiers, purchase time, status, price/currency metadata, expiration, refund or chargeback state. Apple or Google processes payment details; we do not receive full card data.
Feedback and supportYour message, category, optional screenshot and email, device/app context, and support correspondence.
Diagnostics and securityIP address, app and OS version, device model, locale, network status, timestamps, Firebase installation/App Check tokens, crash/error traces and redacted operational logs.
Product analyticsWith consent: bounded app events, screen names, feature interactions, coarse technical context, masked session replay and short, structured survey responses. We prohibit raw prompts, chats, precise location, email, names, content, secrets and raw error text in PostHog events.
Website requestsCloudflare and requested third-party hosts may receive IP address, user agent, requested URL, timestamps and standard HTTP headers.

4. How data is collected

We receive data from you, from your device and permissions, from your activity in Curio, from authentication and app-store providers, and from service providers operating Curio. Location, camera, photo-library and notification access depend on your device choices. Curio also creates a guest account when you finish onboarding if you have not signed in.

5. Purposes and legal bases

If we rely on legitimate interests, we balance those interests against your rights and use data minimisation, redaction, access controls and short retention where practical. You are not required to grant optional permissions or analytics consent, but features needing location, media or notifications may not work without the relevant permission.

PurposeLegal basis where applicable
Create and secure accounts; deliver guides, maps, chat, quizzes, audio, collections, purchases and supportPerformance of our contract with you
Use precise location to show nearby places and create location-relevant resultsPerformance of our contract when you request the feature, plus your device permission
Prevent abuse, protect accounts, diagnose faults, enforce limits and keep the service reliableOur legitimate interests in security, fraud prevention and service integrity
Optional product analytics, replay and surveysYour consent, which you may withdraw at any time
Keep tax, accounting, transaction or dispute recordsCompliance with legal obligations and establishment, exercise or defence of legal claims
Respond to privacy requests and enforce our TermsLegal obligations, contract, and our legitimate interests

6. Artificial intelligence

Curio sends only the data needed for the requested AI feature from our US-hosted backend. Depending on the feature, this may include a place name and coordinates, city/country, language, interests, candidate places and public source material; guide text; quiz context; or your guide chat messages and optional processed image. Mistral receives guide text when you request generated audio.

We use OpenAI for place discovery and ranking, Google Gemini for portions of guide generation, Perplexity for guides, chat and quizzes, and Mistral for text-to-speech. Google Gemini is used as a paid service; under its applicable terms, submitted prompts and generated responses are not used to improve Google products, although limited security/abuse logging applies. Other providers process data under their applicable API terms and our configuration; we do not promise zero-data-retention where it has not been enabled and verified.

AI output can be inaccurate, incomplete or outdated. Do not include unnecessary personal or sensitive information in chats or uploads, and verify important information independently.

7. Recipients and providers

  • Google Firebase/Google Cloud: authentication, database, storage, backend functions, configuration and app integrity checks; Google and Apple for federated sign-in.
  • OpenAI, Google Gemini, Perplexity and Mistral: requested AI and audio features.
  • Mapbox: maps, location display and de-identified SDK usage/location telemetry; the map attribution control provides Mapbox's telemetry opt-out. OpenStreetMap/Overpass and Wikimedia projects: place and cultural content.
  • RevenueCat, Apple App Store and Google Play: purchases, entitlements, refunds, restoration and fraud signals.
  • PostHog EU Cloud: consented analytics, masked replay and structured surveys. Sentry: redacted diagnostics and performance traces, with international transfers possible. Wiredash: feedback and startup/device analytics used for product operation and improvement.
  • Cloudflare: delivery and security of this website.
  • Content hosts and source websites: Curio may fetch guide-source page titles, Google-hosted favicons, Gravatar's default avatar, a static Pexels image, and remote place images. Those independent sites receive standard request data and apply their own privacy policies.
  • Authorities, advisers or transaction counterparties where required by law, to protect rights and security, or in a corporate transaction subject to appropriate safeguards.

8. International transfers

Curio is operated by a US company for a worldwide audience. Firebase Authentication and Curio Cloud Functions process data in the United States; Firestore and the primary app storage bucket are located in the European Union. Providers may process data in the US, EU and other countries. Where required, transfers rely on applicable adequacy decisions, Data Privacy Framework participation, Standard Contractual Clauses or other lawful safeguards. You may contact us for information about applicable safeguards.

9. Retention

DataRetention
Account, profile and Curio contentUntil you delete the content or account, unless a shorter product rule applies or retention is needed for security, disputes or law.
Account deletion workflowDeletion starts immediately after secure acceptance and completes asynchronously. Retriable work is normally completed within 30 days. A minimal erasure tombstone and a hashed installation anti-abuse record may remain to prevent recreation or duplicate rewards; these do not contain your content.
Firebase AuthenticationIP addresses are generally retained for a few weeks; other authentication data remains until account deletion, then is removed from live and backup systems within up to 180 days under Firebase's published terms.
Uploaded mediaUntil replaced, the related chat/guide is deleted, or the account is deleted. Managed temporary upload files are removed after use or cache/identity cleanup.
PostHogSession replays: 30 days. Events and identified profiles: for the configured project period or until no longer needed, and identified data is included in account erasure. The local failed-event outbox expires known events after 30 days and unknown events after 7 days.
Sentry90 days.
WiredashUntil no longer needed for feedback, support and product analytics under the configured Wiredash plan. Local installation identifiers last until app data is cleared or the app is reinstalled.
AI providersAccording to the applicable paid/API terms and verified project configuration. Gemini applies limited security/abuse logging without a public fixed duration. We do not claim ZDR unless enabled and verified.
Map/content/network providersUnder each independent provider's policy. Examples include Mapbox IP logs generally up to 30 days, Wikimedia identifiable reader data generally up to 90 days, and Automattic/Gravatar web logs approximately 30 days.
Transactions and legal recordsUp to 7 years where required for tax, accounting, chargebacks, legal claims or compliance. Apple/Google transaction records follow their own policies.
Provider backups and security logsThey may remain for the provider's documented backup, abuse-prevention or legal period after live deletion.

10. Your choices

  • Change or withdraw location, camera, photo-library and notification permissions in device settings. You can use manual search without precise location.
  • Enable or disable optional analytics in Curio Settings. Withdrawal does not affect earlier lawful processing and stops future optional PostHog capture.
  • Use the Mapbox attribution control to access Mapbox's telemetry choice.
  • Edit supported profile/settings data, clear Curio's managed image cache, or delete your account.
  • Avoid sending optional feedback, screenshots, chat images or unnecessary personal information.

11. Your privacy rights

Depending on where you live, you may request access, a copy, correction, deletion, restriction, portability, or objection; withdraw consent; opt out of sale, sharing or targeted advertising (which Curio does not perform); and appeal a refusal where local law provides it. We will not discriminate against you for exercising a right. Email [email protected]. We may verify your identity and authority before acting. We aim to respond within 30 days, subject to lawful extensions.

EEA/UK users may complain to their local supervisory authority. Other users may contact the privacy regulator or attorney general available under local law.

12. Account deletion

The primary route is Curio Settings → Delete account. If you cannot access the device or complete reauthentication, use the account-deletion page or email us. Deletion removes the Curio account and associated content from active systems and requests deletion from integrated PostHog and RevenueCat records. It does not delete records independently held by Apple/Google, legally required transaction records, or data you separately sent to independent websites.

Deletion permanently removes unused Curio Pass time and does not automatically create a refund. Request any refund from Apple or Google, subject to their rules and mandatory consumer law.

13. Security

We use encryption in transit, provider encryption at rest, access controls, App Check, authentication, scoped security rules, input validation, redaction and monitored deletion workflows. No service is completely secure; protect your sign-in credentials and contact us if you suspect misuse.

14. Adults only

Curio is not intended for anyone under 18. We do not knowingly collect a minor's personal data. If you believe a person under 18 is using Curio, contact [email protected] so we can investigate and delete the account where appropriate.

15. Changes

We may update this policy as Curio or the law changes. We will update the effective date and provide an in-app notice for material changes. We will request a new acceptance where required.

16. Official provider information

These links provide more detail on key providers' current practices. Their terms may change independently.

  • Firebase privacy and security
  • Google Gemini API terms
  • OpenAI enterprise privacy
  • Perplexity API privacy and security
  • Mistral privacy policy
  • RevenueCat privacy
  • PostHog GDPR compliance
  • Sentry privacy
  • Wiredash
  • Mapbox privacy
  • Wikimedia privacy
  • OpenStreetMap Foundation privacy
Language
Deutsch English Español Français Italiano Nederlands

© 2026 Moty Studio LLC.

Contact: [email protected]