CuriOra CuriOra

Legal

Privacy Policy

Last updated:

Public URL for stores and forms: https://curiora.in/privacy

Related: Terms of Service

1. Who we are

This Privacy Policy describes how CuriOra (“we”, “us”, “our”, the “Controller” for the purposes of applicable privacy law) collects, uses, stores, and shares information when you use:

  • CuriOra Parent — web and mobile app for parents/guardians
  • CuriOra Kids — mobile app installed on a child’s device
  • Related websites (including this marketing site) and our backend services

CuriOra is the brand name for this digital wellbeing service. For the full registered legal entity name and official address, contact privacy@curiora.in. Primary operations and support contacts use the curiora.in domain.

Governing jurisdiction (primary): India. Where local law gives you stronger rights, we honour those rights as required.

CuriOra helps families build healthier screen habits: parents set calm limits, pair child devices, review usage insights, and approve extra time or quests. CuriOra is a digital wellbeing and parenting tool. It is not a medical, diagnostic, or therapeutic service.

Privacy requests: privacy@curiora.in
General support: support@curiora.in

2. Who this product is for

  • Parents / guardians (adults) — You must be at least 18 years old (or the age of majority in your place of residence) and legally able to create an account and provide information about a child. Parents sign in with email one-time codes (OTP). They add child profiles, set limits, generate pairing codes, and manage devices.
  • Children use CuriOra Kids on a device after a parent pairs it. Children do not create email passwords or independent Parent accounts. Device identity is established by a 6-digit pairing code typed on the kids device (camera is not required for pairing).

If you provide a child’s information (for example a nick name and birth year), you represent that you are a parent or legal guardian (or otherwise authorised) and that you may lawfully provide that information and enable monitoring on the child’s device.

3. Information we collect

3.1 Parent / guardian account

  • Email address (required for OTP sign-in, account recovery, and security notices)
  • Optional mobile number — if provided, used for account identification / uniqueness and future account-recovery or contact features where offered; stored with your parent profile
  • Display name and relationship to the child (for example mother, father, guardian)
  • Family / workspace name (system-generated from the parent display name if not provided; not collected as a required registration field)
  • Locale preferences
  • Account lifecycle data (created date; if closed: soft-delete timestamp and reason)
  • Trial / licensing flags tied to the parent identity (for example whether an intro trial was claimed)
  • Parent device push notification tokens (when notifications are enabled)

3.2 Child profiles (provided by parents)

  • Child nick name (a display name chosen by the parent — not required to be a legal name)
  • Birth year (to support age-appropriate defaults and reporting)
  • Avatar / display seed

We do not require a child’s legal name, email, password, or social login.

3.3 Devices & pairing

  • Pairing codes and pairing status (codes are short-lived secrets issued by the parent; pairing is code entry only, not camera-based)
  • Device name, platform (Android / iOS), device type
  • App version, last seen / heartbeat times, online status where available
  • Optional battery level and monitoring health signals
  • Push notification tokens for the kids device (when notifications are enabled)

3.4 Screen-time & app usage (kids device)

With parent setup and device permissions, CuriOra Kids may collect app usage information needed to apply the parent’s plan, for example:

  • Application package names and display names
  • Categories / tags assigned by parents or defaults (educational, entertainment, games, social, blocked, etc.)
  • Provisional categorisation — newly seen apps that are not yet reviewed by a parent may be treated as entertainment (or another default) for limit counting until the parent confirms a category
  • Session start/end times and durations
  • Daily and historical aggregates used for limits, streaks, and reports
  • Blocked-app or limit-reached events related to the parent plan

On Android, this typically relies on system capabilities such as Usage Access and, for enforcing restricted apps and showing pause screens, Accessibility services enabled on the device. These permissions are controlled in device settings and can be revoked there. See Section 7 for more detail.

3.5 Parent decisions & wellbeing features

  • Schedule and limit settings (daily entertainment budgets, bedtime, study windows)
  • App policy rules (allowed, limited, blocked apps; optional per-app caps)
  • Extra-time / extension requests and parent approvals or denials
  • Bonus tasks / quests and completions, including optional proof photos a child attaches when completing a task (camera used only for that purpose — see Section 7)
  • Optional daily reflections or mood check-ins entered in the kids experience
  • Recovery challenges, achievements, points/stars where those features are used
  • Insights or recommendations generated from family usage patterns (see Section 4 — not solely automated decisions with legal or similarly significant effects)
  • Tamper / trust signals (for example monitoring permission revoked, missed check-in)

3.6 Proof photos (optional)

  • Purpose: help a parent verify that a bonus task / quest was completed
  • Who can see them: the parent account holder and any co-guardians invited to the same family workspace (approvals / alerts views)
  • What we do not do: we do not use proof photos for facial recognition, biometric identification, advertising, or sale to third parties
  • Retention: kept while needed for the task approval flow and family history, and deleted or made inaccessible when the parent deletes related content or closes the account (subject to short-lived backups)

3.7 Technical & security data

  • IP address and approximate request metadata processed by our hosting provider
  • Authentication tokens (access / refresh) stored on the parent client after OTP verification
  • Logs needed to operate, secure, and debug the service
  • Email delivery metadata when we send OTP or product emails (via our email provider). OTP codes are credentials — do not share them; we never ask for your OTP by phone or chat support

3.8 Marketing website

Our public website may collect standard server logs (for example pages visited, browser type, IP) needed to host and secure the site. We do not require an account to read this Privacy Policy. We do not use third-party advertising cookies on the marketing site in the current release. If we add analytics tools later, we will update this Policy and, where required, obtain consent.

4. How we use information

  • Create and secure parent accounts (email OTP verification)
  • Operate family workspaces, child profiles, and device pairing
  • Apply parent-configured limits, study mode, bedtime, and app policies
  • Show kids-facing status, reminders, rewards, and request flows
  • Provide parents with approvals, insights, and reports
  • Generate optional product insights or recommendations from usage patterns to help parents guide screen time — these are assistive tools, not solely automated decisions that produce legal or similarly significant effects about a person
  • Send transactional emails (OTP, welcome / setup guidance, security notices)
  • Send push notifications related to limits, requests, or device health when enabled
  • Prevent abuse, debug issues, and improve reliability and safety
  • Maintain licensing / trial history on a retained parent identity when an account is closed
  • Comply with law and enforce our terms

We do not sell personal information. We do not use kids’ usage data for third-party advertising or interest-based ads in CuriOra Kids.

5. Legal bases (where applicable)

Depending on your location, we process data under one or more of:

  • Contract — to provide the CuriOra service you request
  • Legitimate interests — security, product improvement, fraud prevention
  • Consent — where required (for example certain notifications, optional features, or device permissions you enable)
  • Legal obligation — when we must retain or disclose information by law
  • Parental / guardian direction — for children’s data processed to deliver parental-control features the parent enables (subject to applicable children’s privacy laws)

Under India’s Digital Personal Data Protection framework and similar laws, we process personal data for lawful purposes described in this Policy. Parents should only provide information they are allowed to provide.

6. How we share information

We share data only as needed to run CuriOra:

  • Service providers (subprocessors) under contract, including approximately:
    • Cloud hosting & database — store and run the API and data
    • Email delivery (e.g. Resend) — OTP and transactional email
    • Push infrastructure (e.g. Firebase Cloud Messaging) — device notifications when enabled
    Providers process data only on our instructions and for the purposes above.
  • Within the family workspace — co-guardians you invite may see family controls, child profiles, usage insights, requests, and quest proofs for that workspace
  • Legal / safety — if required by law, valid legal process, or to protect rights, safety, and security
  • Business transfers — if we reorganise or transfer assets, data may move under appropriate safeguards

Internal CuriOra operations tools (for example CRM metrics) are designed for aggregated product metrics and are not a substitute for parent support access to your private family dashboard.

7. Device permissions (CuriOra Kids)

Depending on platform and features, CuriOra Kids may ask for:

  • Internet — sync rules, usage, pairing, and notifications
  • Usage access — measure app time for the parent plan
  • Accessibility (Android) — with your acknowledgement in the Kids app, used only to: detect which app is in the foreground; support screen-time enforcement; apply study mode, bedtime, blocked apps, and daily limits; and show a pause/block screen when restricted. We do not use Accessibility to read passwords, messages, emails, banking, or payment information. Before enabling, the Kids app presents an in-app disclosure and requires “I understand and agree.”
  • Notifications — reminders, limit alerts, and quiet monitoring status
  • Camera — only when a child attaches optional proof photos to complete a bonus task / quest. Camera is not used for device pairing (pairing uses a typed 6-digit code). Camera is not used for continuous capture or advertising.
  • Microphone — only if you enable a speech-related feature in a future or optional build; not used for core screen-time features or pairing in the current product

You can revoke permissions in the device system settings. Some features will stop working without the corresponding permission.

8. Data storage, security & location

We store account and family data on cloud infrastructure used to operate CuriOra (including our API and database providers). Primary operational contacts and brand presence are associated with India. Data may also be processed in other regions where our service providers operate.

International transfers: when personal data is processed outside your country, we rely on appropriate contractual and organisational safeguards with providers (for example data-processing terms) and on your use of the service under this Policy and applicable law.

We use technical and organisational measures appropriate to the service, including encrypted transport (HTTPS), access controls, and authentication tokens for parent sessions. No method of transmission or storage is 100% secure.

9. Retention & account closure

  • Active accounts — we keep data while the parent account and family workspace are active and as needed to provide the service.
  • Close account (Parent) — when a parent closes their account after email OTP confirmation, we remove family workspace data for workspaces they own, including child profiles, devices, usage history, schedules, app policies, requests, quest completions, proof photos, and related content we store for that family.
  • Retained parent identity (soft-delete) — we may keep a minimal closed parent record such as email, optional phone number if stored, soft-delete metadata, and licensing / trial flags so the same identity can reactivate later without unfairly reclaiming a one-time trial, and for security and compliance. Sign-in is blocked until the parent re-registers / reactivates. Family and usage data from the closed workspace are not restored from this minimal record.
  • Proof photos — retained for quest verification and family history until deleted with the account/workspace or earlier if you remove related content through product controls (where available).
  • Backups & logs — residual copies may persist for a limited period (typically up to about 30–90 days) in backups or security logs, then expire under our retention schedules, unless a longer period is required by law or an active dispute.

10. Your choices & rights

Depending on your location (including India, the EU/UK, and other regions), you may have rights to access, correct, delete, or export personal data, withdraw consent where processing is consent-based, or object to certain processing.

  • Update profile details in CuriOra Parent where available
  • Close the parent account from in-app settings (email OTP confirmation)
  • Revoke device permissions on the kids phone
  • Uninstall CuriOra Kids or Parent apps
  • Contact us at privacy@curiora.in for privacy requests

We may need to verify that the request comes from the parent account holder. Some data may be retained where we have a lawful reason (for example licensing history or legal obligations), as described in Section 9.

11. Children’s privacy

CuriOra Kids is a parent-directed experience: it is designed to be installed and used under parental setup and supervision. We do not knowingly allow children to create independent Parent accounts. Child profile and usage data are processed to deliver the parental-control and wellbeing features the parent enables.

Parents should use age-appropriate settings and review permissions on the child’s device. If you believe we have collected a child’s information inappropriately, contact privacy@curiora.in and we will take reasonable steps to review and address the issue, including deletion where required.

If you use CuriOra in a country with specific children’s privacy rules (for example COPPA in the United States for under-13s), the parent/guardian is responsible for providing any required consent for the child’s use of the service. Contact us if you need help with a parental consent or deletion request.

12. International users

CuriOra may be accessed from different countries. By using the service, you understand that your information may be processed in countries other than your own, including where our service providers are located, subject to this Policy and applicable law. See Section 8 regarding transfers and safeguards.

13. Terms of Service

Use of CuriOra is also governed by our Terms of Service , which cover acceptable use, parental responsibilities, licence to use the apps, and limitations of liability. If there is a conflict between the Terms and this Privacy Policy about personal data, this Privacy Policy controls for privacy matters.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and change the “Last updated” date. Material changes may also be communicated through the Parent app or email where appropriate.

15. Contact

Privacy: privacy@curiora.in
Support: support@curiora.in
Website: https://curiora.in
Jurisdiction (primary): India

For the full legal entity name and registered office address, email privacy@curiora.in.

App store listings

Use this public URL in store listings and data-safety forms:

https://curiora.in/privacy