Skip to main content
curatorial
FeaturesGuidesPricingFAQ
Sign inStart free

Privacy
Policy

Last updated: June 2026

Curatorial ("we", "us", "our") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights. Questions? Email [email protected].

1. Who We Are

Curatorial is a research and exhibition management platform for curators, independent scholars, and cultural institutions. We are incorporated and operate as a pre-launch product (currently in beta access). Our platform is accessible at curatorial.app.

2. Data We Collect

Account Information

When you create an account: your email address, display name, and password (hashed — we never store it in plain text). If you sign in via Google or another OAuth provider, we receive your profile name and email from that provider.

Content You Create

Projects, artworks, exhibitions, research materials, annotations, documents, and any other content you upload or generate within the platform. This content belongs to you.

Messaging Channels (WhatsApp & Telegram)

If you connect a WhatsApp or Telegram account to use the Curatorial AI assistant, we collect your phone number or Telegram user ID, your display name, and the content of messages you send to the assistant. These messages are stored to maintain conversation context and are protected by the same access controls as your other account data.

Usage Data

Logs of features used, token consumption for AI features, and basic analytics (page views, errors). We use this to improve the product, not to build advertising profiles.

Payment Information

Billing is handled by Stripe. We store only a Stripe customer ID — your card details never touch our servers. See Stripe's Privacy Policy for how payment data is handled.

3. How We Use Your Data

  • To provide and operate the Curatorial platform
  • To run AI-powered features (research assistance, essay drafting, entity extraction)
  • To maintain conversation context for the AI assistant across sessions
  • To process payments and manage your subscription
  • To send transactional emails (account alerts, billing receipts)
  • To monitor platform health, detect errors, and improve performance
  • To comply with legal obligations

We do not sell your data. We do not use your content to train AI models without explicit consent.

4. Data Storage & Security

All user data is stored in PostgreSQL via Supabase, with Row-Level Security (RLS) policies enforced at the database level. This means your data is isolated — other users cannot access it even at the query level.

Data is hosted in the EU (Supabase EU region). All connections use TLS encryption in transit. Backups are encrypted at rest.

Access to production data is limited to authorised personnel and is logged. We follow the principle of least privilege — no human has standing access to your content.

5. Third-Party Services

We use the following sub-processors to operate the platform:

  • Supabase — database and authentication (EU-hosted)
  • Vercel — web hosting and serverless infrastructure
  • Stripe — payment processing
  • Anthropic / OpenAI / Google — AI model providers (messages sent for inference are subject to their data policies)
  • Meta (WhatsApp) — messaging channel; messages are routed through Meta's infrastructure per their Business Platform terms
  • Telegram — messaging channel; messages are routed through Telegram's infrastructure
  • PostHog — product analytics (anonymised)
  • Grafana / Sentry — error tracking and observability (no PII in logs)

6. Data Retention

We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it by law (e.g., billing records for tax purposes, retained for 7 years).

Conversation history from WhatsApp and Telegram is retained for 90 days of inactivity, after which it is purged.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request that inaccurate data be corrected
  • Deletion — request that your data be deleted ("right to be forgotten")
  • Portability — request your data in a machine-readable format
  • Objection — object to processing of your data
  • Restriction — request that we limit how we process your data

To exercise any of these rights, email [email protected]. We will respond within 30 days.

8. Cookies

We use cookies for:

  • Authentication — session cookies to keep you logged in (essential)
  • Analytics — anonymised usage tracking via PostHog (can be opted out)

We do not use third-party advertising cookies. Essential authentication cookies cannot be disabled without breaking the product.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be notified via email and a notice on the platform at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Contact Us

For privacy questions, data requests, or concerns, contact us at:

[email protected]General Support

Response time: Within 30 days (data requests) · Within 2 business days (general queries)

curatorial

The AI-native workspace for independent curators. Research, write, and plan exhibitions with intelligent tools.

Product

  • Features
  • Guides
  • Pricing
  • FAQ
  • Get Started

Account

  • Sign in
  • Create account
  • Reset password

© 2026 Curatorial. All rights reserved.

PrivacyTerms