Curio · Moty Studio
Curio Privacy Policy
How Curio collects, uses, shares, retains, and protects personal data.
Effective date: 12 August 2026
This Privacy Policy explains how Moty Studio LLC, doing business as Moty Studio ("Moty Studio", "we", "us"), processes personal data when you use the Curio mobile application, its related support, and Curio pages on this website.
Curio is available only to people aged 18 or older and is not directed to minors.
1. Controller and contact
Moty Studio LLC, a Wyoming limited liability company, is the controller of the personal data described here. Registered address: 30 N Gould St, STE R, Sheridan, WY 82801, USA. Privacy and support contact: [email protected].
2. Our privacy position
- We do not show advertising and do not use personal data for direct marketing.
- We do not sell personal data or share it for cross-context behavioural advertising.
- We do not make decisions producing legal or similarly significant effects through profiling.
- Moty Studio does not train AI models on your content.
- Optional PostHog product analytics, session replay, and surveys are disabled until you consent and can be disabled in Settings.
3. Data we process
| Category | Examples |
|---|---|
| Account and identity | Firebase user ID, guest-account status, email, display name, profile photo URL, sign-in provider, and authentication/security records. Apple or Google may also process sign-in data under their own terms. |
| Profile and preferences | App language, interests, travel style, content preferences, settings, notification choices, and account statistics. |
| Location | Precise location while the app is in use, coordinates, map position, search area, and derived city, region, or country. We do not request background location. |
| Curio content | Generated and saved guides, collections and their titles/descriptions, local picks, quiz answers/results, guide progress, sources, and usage credits. |
| Chat and media | Messages you send about a guide and optional images; profile photos and feedback screenshots. Curio converts uploaded images to a bounded JPEG and removes EXIF metadata, including embedded GPS metadata, before upload. |
| Purchases | Curio Pass product, store, transaction and entitlement identifiers, purchase time, status, price/currency metadata, expiration, refund or chargeback state. Apple or Google processes payment details; we do not receive full card data. |
| Feedback and support | Your message, category, optional screenshot and email, device/app context, and support correspondence. |
| Diagnostics and security | IP address, app and OS version, device model, locale, network status, timestamps, Firebase installation/App Check tokens, crash/error traces and redacted operational logs. |
| Product analytics | With consent: bounded app events, screen names, feature interactions, coarse technical context, masked session replay and short, structured survey responses. We prohibit raw prompts, chats, precise location, email, names, content, secrets and raw error text in PostHog events. |
| Website requests | Cloudflare and requested third-party hosts may receive IP address, user agent, requested URL, timestamps and standard HTTP headers. |
4. How data is collected
We receive data from you, from your device and permissions, from your activity in Curio, from authentication and app-store providers, and from service providers operating Curio. Location, camera, photo-library and notification access depend on your device choices. Curio also creates a guest account when you finish onboarding if you have not signed in.
5. Purposes and legal bases
If we rely on legitimate interests, we balance those interests against your rights and use data minimisation, redaction, access controls and short retention where practical. You are not required to grant optional permissions or analytics consent, but features needing location, media or notifications may not work without the relevant permission.
| Purpose | Legal basis where applicable |
|---|---|
| Create and secure accounts; deliver guides, maps, chat, quizzes, audio, collections, purchases and support | Performance of our contract with you |
| Use precise location to show nearby places and create location-relevant results | Performance of our contract when you request the feature, plus your device permission |
| Prevent abuse, protect accounts, diagnose faults, enforce limits and keep the service reliable | Our legitimate interests in security, fraud prevention and service integrity |
| Optional product analytics, replay and surveys | Your consent, which you may withdraw at any time |
| Keep tax, accounting, transaction or dispute records | Compliance with legal obligations and establishment, exercise or defence of legal claims |
| Respond to privacy requests and enforce our Terms | Legal obligations, contract, and our legitimate interests |
6. Artificial intelligence
Curio sends only the data needed for the requested AI feature from our US-hosted backend. Depending on the feature, this may include a place name and coordinates, city/country, language, interests, candidate places and public source material; guide text; quiz context; or your guide chat messages and optional processed image. Mistral receives guide text when you request generated audio.
We use OpenAI for place discovery and ranking, Google Gemini for portions of guide generation, Perplexity for guides, chat and quizzes, and Mistral for text-to-speech. Google Gemini is used as a paid service; under its applicable terms, submitted prompts and generated responses are not used to improve Google products, although limited security/abuse logging applies. Other providers process data under their applicable API terms and our configuration; we do not promise zero-data-retention where it has not been enabled and verified.
AI output can be inaccurate, incomplete or outdated. Do not include unnecessary personal or sensitive information in chats or uploads, and verify important information independently.
7. Recipients and providers
- Google Firebase/Google Cloud: authentication, database, storage, backend functions, configuration and app integrity checks; Google and Apple for federated sign-in.
- OpenAI, Google Gemini, Perplexity and Mistral: requested AI and audio features.
- Mapbox: maps, location display and de-identified SDK usage/location telemetry; the map attribution control provides Mapbox's telemetry opt-out. OpenStreetMap/Overpass and Wikimedia projects: place and cultural content.
- RevenueCat, Apple App Store and Google Play: purchases, entitlements, refunds, restoration and fraud signals.
- PostHog EU Cloud: consented analytics, masked replay and structured surveys. Sentry: redacted diagnostics and performance traces, with international transfers possible. Wiredash: feedback and startup/device analytics used for product operation and improvement.
- Cloudflare: delivery and security of this website.
- Content hosts and source websites: Curio may fetch guide-source page titles, Google-hosted favicons, Gravatar's default avatar, a static Pexels image, and remote place images. Those independent sites receive standard request data and apply their own privacy policies.
- Authorities, advisers or transaction counterparties where required by law, to protect rights and security, or in a corporate transaction subject to appropriate safeguards.
8. International transfers
Curio is operated by a US company for a worldwide audience. Firebase Authentication and Curio Cloud Functions process data in the United States; Firestore and the primary app storage bucket are located in the European Union. Providers may process data in the US, EU and other countries. Where required, transfers rely on applicable adequacy decisions, Data Privacy Framework participation, Standard Contractual Clauses or other lawful safeguards. You may contact us for information about applicable safeguards.
9. Retention
| Data | Retention |
|---|---|
| Account, profile and Curio content | Until you delete the content or account, unless a shorter product rule applies or retention is needed for security, disputes or law. |
| Account deletion workflow | Deletion starts immediately after secure acceptance and completes asynchronously. Retriable work is normally completed within 30 days. A minimal erasure tombstone and a hashed installation anti-abuse record may remain to prevent recreation or duplicate rewards; these do not contain your content. |
| Firebase Authentication | IP addresses are generally retained for a few weeks; other authentication data remains until account deletion, then is removed from live and backup systems within up to 180 days under Firebase's published terms. |
| Uploaded media | Until replaced, the related chat/guide is deleted, or the account is deleted. Managed temporary upload files are removed after use or cache/identity cleanup. |
| PostHog | Session replays: 30 days. Events and identified profiles: for the configured project period or until no longer needed, and identified data is included in account erasure. The local failed-event outbox expires known events after 30 days and unknown events after 7 days. |
| Sentry | 90 days. |
| Wiredash | Until no longer needed for feedback, support and product analytics under the configured Wiredash plan. Local installation identifiers last until app data is cleared or the app is reinstalled. |
| AI providers | According to the applicable paid/API terms and verified project configuration. Gemini applies limited security/abuse logging without a public fixed duration. We do not claim ZDR unless enabled and verified. |
| Map/content/network providers | Under each independent provider's policy. Examples include Mapbox IP logs generally up to 30 days, Wikimedia identifiable reader data generally up to 90 days, and Automattic/Gravatar web logs approximately 30 days. |
| Transactions and legal records | Up to 7 years where required for tax, accounting, chargebacks, legal claims or compliance. Apple/Google transaction records follow their own policies. |
| Provider backups and security logs | They may remain for the provider's documented backup, abuse-prevention or legal period after live deletion. |
10. Your choices
- Change or withdraw location, camera, photo-library and notification permissions in device settings. You can use manual search without precise location.
- Enable or disable optional analytics in Curio Settings. Withdrawal does not affect earlier lawful processing and stops future optional PostHog capture.
- Use the Mapbox attribution control to access Mapbox's telemetry choice.
- Edit supported profile/settings data, clear Curio's managed image cache, or delete your account.
- Avoid sending optional feedback, screenshots, chat images or unnecessary personal information.
11. Your privacy rights
Depending on where you live, you may request access, a copy, correction, deletion, restriction, portability, or objection; withdraw consent; opt out of sale, sharing or targeted advertising (which Curio does not perform); and appeal a refusal where local law provides it. We will not discriminate against you for exercising a right. Email [email protected]. We may verify your identity and authority before acting. We aim to respond within 30 days, subject to lawful extensions.
EEA/UK users may complain to their local supervisory authority. Other users may contact the privacy regulator or attorney general available under local law.
12. Account deletion
The primary route is Curio Settings → Delete account. If you cannot access the device or complete reauthentication, use the account-deletion page or email us. Deletion removes the Curio account and associated content from active systems and requests deletion from integrated PostHog and RevenueCat records. It does not delete records independently held by Apple/Google, legally required transaction records, or data you separately sent to independent websites.
Deletion permanently removes unused Curio Pass time and does not automatically create a refund. Request any refund from Apple or Google, subject to their rules and mandatory consumer law.
13. Security
We use encryption in transit, provider encryption at rest, access controls, App Check, authentication, scoped security rules, input validation, redaction and monitored deletion workflows. No service is completely secure; protect your sign-in credentials and contact us if you suspect misuse.
14. Adults only
Curio is not intended for anyone under 18. We do not knowingly collect a minor's personal data. If you believe a person under 18 is using Curio, contact [email protected] so we can investigate and delete the account where appropriate.
15. Changes
We may update this policy as Curio or the law changes. We will update the effective date and provide an in-app notice for material changes. We will request a new acceptance where required.
16. Official provider information
These links provide more detail on key providers' current practices. Their terms may change independently.