Curiosigo

Privacy Policy

Last updated: June 28, 2026

1. Data Controller Contact

Curiosigo is the controller of your personal data. If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact us at info@curiosigo.app.

2. Categories of Information We Collect

We categorize the information we collect and process into the following types:

Personal Identifiers: This includes your email address, account password, and OAuth authentication tokens required to connect with third-party tools like Google Drive.
User Content Data: This includes raw text notes, copied travel details, uploaded screenshots containing travel text, scraped external travel URLs, and final generated Excel itinerary spreadsheets.

3. Legal Basis for Processing & Data Retention

Legal Basis (GDPR): We process your information based on your explicit consent (granted when you actively accept these terms at sign-up) and the contractual necessity of performing the service you requested (generating and structuring your itineraries).

Data Retention: Raw text inputs and uploaded travel screenshots are processed in-memory and are deleted instantly upon completing the itinerary generation process. We do not store or cache user travel details on our servers for longer than twenty-four (24) hours, and only retain them temporarily for troubleshooting, debugging, and system diagnostic purposes. Account information, such as your email address and profile settings, is retained for as long as your account remains active. You may request the deletion of this data at any time via the process outlined in Section 8.

4. Information Sharing & "Do Not Sell" Statement

We do not sell, rent, or trade your personal information to third parties. We do not share your travel details or personal identifiers with external advertisers.

5. Google API Data Usage

Curiosigo integrates with Google Drive APIs using the narrowest possible scope: https://www.googleapis.com/auth/drive.file. This scope allows the application to only create new files or edit files created by Curiosigo itself. We do not access, view, or read any other files or folders in your Google Drive. All OAuth tokens are stored locally and are never shared, sold, or sent to external servers. This integration operates in tandem with our Terms & Conditions.

6. Third-Party Service Providers & Security Measures

Service Providers: We may employ third-party companies and individuals to facilitate our Service (such as cloud hosting infrastructure and database providers). These third parties have access to your personal data only to perform these operational tasks on our behalf and are strictly obligated by confidentiality agreements not to disclose or use it for any other purpose.

Security Measures: We utilize industry-standard encryption protocols (SSL/TLS in transit), firewalls, and strict access controls to protect your data during transit and at rest. In the unlikely event of a data breach that compromises your personal information, we are committed to notifying you in accordance with applicable legal requirements.

7. Cookies, Tracking, & Do Not Track / GPC

We only use essential functional session cookies to verify your login credentials and maintain your active planning session. We do not run third-party advertising trackers or tracking scripts that build user profiles across external websites.

DNT & GPC Signals: Our platform does not track users across third-party websites and therefore does not alter its behavior in response to automated browser "Do Not Track" (DNT) signals. However, we support and honor Global Privacy Control (GPC) signals to respect opt-out rights where technically feasible.

8. Your Data Rights & Deletion Requests

Regardless of your location, you have the right to access your personal information, request the correction of inaccurate data, or request the absolute deletion of your personal data. To submit a request to access, update, or permanently delete your account and personal data from our systems, please email us at info@curiosigo.app. We will respond to and complete data deletion requests within thirty (30) days of receipt.

9. Children's Privacy

Our services are not directed to children under 13 (or 16 depending on jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will take immediate steps to delete it.

10. International Data Transfers & Safeguards

Your information may be transferred to—and maintained on—computers located outside of your state, province, or country where data protection laws may differ. Where international data transfers occur, we rely on appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or adequacy decisions, to ensure a consistent level of protection.