Privacy Policy

1. Who we are

Cura is operated by CURA VENTURES GROUP LTD, a company registered in England and Wales under company number 17220795, with its registered office at 128 City Road, London, United Kingdom, EC1V 2NX.

CURA VENTURES GROUP LTD is the data controller for personal data processed through the Cura app and the Cura website.

For privacy questions, requests about your data, or anything covered by this policy, please write to contact@curaventuresgroup.com.

2. What Cura is

Cura is a personalised skin and hair information service. After an optional survey, Cura builds a profile of your skin and hair preferences and generates routine guidance, ingredient analysis, and product fit recommendations. You can scan product barcodes and ingredient labels, ask follow-up questions through Ask Cura, and take an optional face-scan reading.

Cura is informational. It is not a medical service, not a medical device, and not a substitute for a dermatologist or other qualified clinician.

3. The personal data we collect

Account and authentication. Email address, pseudonymous user identifier, session tokens.

Profile and survey data. Display name, age confirmation, skin and hair characteristics, allergies and sensitivities, routine habits, lifestyle inputs, and, where you choose to answer, hormonal-cycle questions. Some of this may be special-category data under UK or EU law; we process those items only on explicit consent (see section 12).

Profile and routine outputs. The AI-generated profile reading and routine derived from your survey answers.

Saved products and routine assignments. Products you add to your private inventory and any routine slot you assign them to.

Product scans and ingredient analysis. Barcode data and ingredient strings resolved through third-party product databases, stored in our global product catalogue without a link to your account. Your personal fit analysis (Cura Score, ingredient highlights, cautions) is linked to your account.

Face scan (optional). If you choose to take a face scan, the image is sent to our AI provider for analysis. Cura does not intentionally save the raw image to your account or to permanent storage on our servers. The image is used temporarily for processing and then deleted or discarded after the scan completes, subject to any temporary technical caching by your device, your operating system, or our service provider. Only the derived structured analysis is stored on your account.

Product and ingredient label photos. If you take a photo of a product or ingredient label, the image is sent to our AI provider for label reading. Cura does not intentionally save the raw image to your account or to permanent storage on our servers. The image is used temporarily for label reading and then discarded after processing, subject to any temporary technical caching by your device, your operating system, or our service provider. The resulting product identity and ingredient list are stored in our global product catalogue and, where you save the product, against your account.

Ask Cura messages. Your messages, any photos you attach, and the AI's responses, processed by our AI provider and stored on our servers so the conversation has continuity. Please do not enter emergency information, highly sensitive personal information, or unnecessary personal information into Ask Cura. If you have a medical emergency, contact emergency services in your country.

Subscriptions and payments. Cura receives subscription status, entitlement state, product ID, transaction metadata, and renewal or cancellation status from Apple, Google, or RevenueCat. We do not see or store your full payment card number.

Location (optional). If you grant location permission, your approximate location is used to look up the local UV index from a public weather provider for sun-protection guidance. We do not request or use precise location.

Diagnostics and crash data. Crash reports and performance telemetry through a third-party error-reporting provider (Sentry), with personal identifiers pseudonymised. Aggregate product-analytics events (for example, "survey started", "paywall viewed") through a third-party product- analytics provider (PostHog) so we can understand where the app helps and where it falls short. We do not send your survey answers, your photos, your messages with Cura, or your email address to PostHog.

4. What we do not collect

We do not collect contacts, microphone audio, browser history, advertising identifiers, or precise location. We do not use third-party advertising networks. We do not sell personal data.

5. How we use your data

We use the data above to create and run your account, generate your profile reading and routine, analyse products you scan or save, answer your Ask Cura questions, manage your subscription, keep the app reliable and secure, show local UV guidance, send you service messages, comply with our legal obligations, and prevent abuse or fraud.

6. AI processing

Cura uses Anthropic to build your profile reading, generate routine guidance, power Ask Cura, and read product or ingredient labels. Anthropic processes the data on our behalf to return a result.

Under our processor terms with Anthropic, Cura user data is not permitted to be used to train Anthropic's models.

AI responses are informational and may be incomplete or wrong. Check anything material with a qualified professional.

7. Product scans and barcode providers

We query Open Beauty Facts, Barcodelookup, EAN-Search, and our AI provider's web-search capability to identify products you scan. Those providers receive only the barcode, image, or query string we need to identify the product. They do not receive your account identity, your profile, or your other personal data. Resolved product data is stored in our global catalogue without a link to you.

8. Subscriptions and payments

Paid subscriptions are sold and billed by Apple (App Store / StoreKit) or Google (Google Play Billing). RevenueCat receives subscription state from those platforms and tells Cura whether you have an active entitlement.

Cura receives subscription status, entitlement state, product ID, transaction metadata, and renewal or cancellation status. We do not see or store your full payment card number. Refunds are handled by Apple or Google under their own policies.

9. Affiliate links

Some product recommendations in Cura link to a brand or retailer website. Cura may earn a small commission if you click an affiliate link and complete a purchase, at no additional cost to you. Affiliate commission does not change the price you pay and does not override Cura's profile-based fit logic. Recommendations are based on fit to your profile, not on commission.

10. Location

If you grant location permission, your approximate location (city or region level) is used to look up the local UV index from a public weather provider. We do not collect or use precise location. If you decline the location permission, the app continues to work and only the local UV guidance is unavailable.

11. Legal bases (UK and EU)

We rely on the following lawful bases:

Contract. Account creation, subscriptions, delivery of app functionality, and generating your profile, routine, and recommendations from your survey answers.

Explicit consent. Sensitive survey answers, allergies and sensitivities, hormonal-cycle questions where asked, the optional face scan, and optional permissions such as camera, photos, and location.

Legitimate interests. Security, abuse prevention, fraud detection, service reliability, crash diagnostics, and product improvement, provided those interests are not overridden by your rights.

Legal obligation. Accounting, tax, fraud prevention, and where we are required by law to retain or disclose data (for example a lawful request from a regulator or authority).

You can withdraw consent at any time. Withdrawing consent does not affect lawful processing carried out before the withdrawal.

12. Special-category data

Some Cura inputs may be considered special-category personal data under UK and EU data protection law, including:

  • Skin and hair concerns, sensitivities, and allergies
  • Lifestyle or wellbeing inputs that touch on health
  • Hormonal-cycle questions where you choose to answer
  • Face-scan-derived analysis

We process special-category data only with your explicit consent or where another lawful basis under Article 9 UK GDPR applies. You can withdraw your consent at any time by editing your survey, deleting your account, or contacting us.

13. Who we share data with

Service providers acting on our instructions:

  • Supabase: application database, authentication, edge functions
  • Anthropic: AI processing
  • RevenueCat: subscription state mirror
  • Apple, Google: payment platforms
  • Sentry: crash and error reporting
  • PostHog: aggregate product analytics (event names and structured counts only; EU region)
  • Open-Meteo: public weather API
  • Open Beauty Facts, Barcodelookup, EAN-Search: product databases
  • Affiliate networks and merchants, only when you click an outbound product link

We share personal data with public authorities only where required by law. We do not sell personal data and do not share it for cross-context behavioural advertising.

14. International transfers

Cura is operated from the United Kingdom. Some of our processors operate outside the UK and EEA. Where required, we rely on appropriate safeguards including the UK International Data Transfer Addendum and Standard Contractual Clauses.

15. Your rights

Under UK and EU data protection law you have the right to:

  • Access your personal data
  • Have inaccurate personal data corrected
  • Have your personal data deleted
  • Restrict or object to processing
  • Receive a portable copy of certain data
  • Withdraw consent at any time, without affecting prior lawful processing
  • Lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority

To exercise a right, write to contact@curaventuresgroup.com. We aim to respond within 30 days.

16. Account deletion

You can delete your Cura account inside the app at Profile → Delete account.

You can also request deletion at any time by emailing contact@curaventuresgroup.com or by using the public form at www.mycura-app.com/delete-account.html.

On deletion we remove your account record, profile, survey answers, routine, saved products, fit analyses, Ask Cura transcripts, and any face-scan-derived analysis. We may retain limited records where required by law (for example for tax, accounting, fraud prevention, or security) and we may retain anonymous, non-personal product data in our global catalogue, which is not linked to you.

17. Retention

Account, profile, survey, routines, saved products, fit analyses, Ask Cura transcripts, derived face-scan analysis: while your account exists, until you delete it, or earlier if no longer needed for the purposes above.

Crash and performance logs: up to 90 days, unless required longer for security or debugging.

Payment and accounting records: up to 7 years where required by UK accounting and tax law.

Anonymous global product catalogue data: not linked to your account and not deleted with account deletion.

Security and fraud logs: retained as long as reasonably necessary for the purpose.

18. Children

Cura is intended only for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we learn that an under-18 user has created an account or submitted personal data, we will take reasonable steps to delete it. The app includes an age confirmation before account creation and the start of the survey.

19. Security

We protect personal data using:

  • TLS encryption in transit
  • Encryption at rest where the underlying service provider supports it
  • Row-level security on application database tables
  • Scoped, server-side API keys for third-party services
  • Server-side handling of third-party calls so credentials are not exposed to the app
  • Access controls on internal tools

No service can be perfectly secure. If a personal data breach materially affects you, we will notify you and, where required, the relevant supervisory authority in line with applicable law.

20. Changes

If we change this policy materially, we will update the "Last updated" date and, for significant changes, notify you in the app or by email. Continued use after a change means acceptance.

21. Contact

CURA VENTURES GROUP LTD
128 City Road, London, United Kingdom, EC1V 2NX
contact@curaventuresgroup.com
Company number 17220795 (England and Wales).