Curiosigo
Last updated: June 28, 2026
Curiosigo is the controller of your personal data. If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact us at info@curiosigo.app.
We categorize the information we collect and process into the following types:
• Personal Identifiers: This includes your email address, account password, and OAuth
authentication tokens required to connect with third-party tools like Google Drive.
• User Content Data: This includes raw text notes, copied travel details, uploaded
screenshots containing travel text, scraped external travel URLs, and final generated Excel itinerary
spreadsheets.
Legal Basis (GDPR): We process your information based on your explicit consent (granted
when you actively accept these terms at sign-up) and the contractual necessity of performing the service
you requested (generating and structuring your itineraries).
Data Retention: Raw text inputs and uploaded travel screenshots are processed in-memory
and are deleted instantly upon completing the itinerary generation process. We do not store or cache
user travel details on our servers for longer than twenty-four (24) hours, and only retain them
temporarily for troubleshooting, debugging, and system diagnostic purposes. Account information, such as
your email address and profile settings, is retained for as long as your account remains active. You may
request the deletion of this data at any time via the process outlined in Section 8.
We do not sell, rent, or trade your personal information to third parties. We do not share your travel details or personal identifiers with external advertisers.
Curiosigo integrates with Google Drive APIs using the narrowest possible scope:
https://www.googleapis.com/auth/drive.file. This scope allows the application to only
create new files or edit files created by Curiosigo itself. We do not access, view, or read any other
files or folders in your Google Drive. All OAuth tokens are stored locally and are never shared, sold,
or sent to external servers. This integration operates in tandem with our Terms & Conditions.
Service Providers: We may employ third-party companies and individuals to facilitate
our Service (such as cloud hosting infrastructure and database providers). These third parties have
access to your personal data only to perform these operational tasks on our behalf and are strictly
obligated by confidentiality agreements not to disclose or use it for any other purpose.
Security Measures: We utilize industry-standard encryption protocols (SSL/TLS in
transit), firewalls, and strict access controls to protect your data during transit and at rest. In the
unlikely event of a data breach that compromises your personal information, we are committed to
notifying you in accordance with applicable legal requirements.
We only use essential functional session cookies to verify your login credentials and maintain your
active planning session. We do not run third-party advertising trackers or tracking scripts that build
user profiles across external websites.
DNT & GPC Signals: Our platform does not track users across third-party websites and
therefore does not alter its behavior in response to automated browser "Do Not Track" (DNT) signals.
However, we support and honor Global Privacy Control (GPC) signals to respect opt-out rights where
technically feasible.
Regardless of your location, you have the right to access your personal information, request the correction of inaccurate data, or request the absolute deletion of your personal data. To submit a request to access, update, or permanently delete your account and personal data from our systems, please email us at info@curiosigo.app. We will respond to and complete data deletion requests within thirty (30) days of receipt.
Our services are not directed to children under 13 (or 16 depending on jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will take immediate steps to delete it.
Your information may be transferred to—and maintained on—computers located outside of your state, province, or country where data protection laws may differ. Where international data transfers occur, we rely on appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or adequacy decisions, to ensure a consistent level of protection.