Privacy policy

What CurlCue knows about you, and what it does with it.

This policy covers the CurlCue app for iOS and this website. It says what is collected, why, who else handles it, and how to get it back or delete it. It is written from the app’s own code, not from a template, and it tries to say nothing the app does not actually do.

Last updated: September 8, 2026

The short version

  • CurlCue scores hair products against your hair. To do that it needs a hair profile, and it needs the photos you choose to scan or share. That is what this policy is mostly about.
  • There is no advertising SDK and no analytics SDK in the app. Apart from the services that make features work, the only third-party code in it is a crash reporter, and that is configured to send no personal details.
  • Photos of product labels are read by AI services to extract the text. Messages and photos you send to CurlCue AI go to Anthropic, along with your hair profile, so the answer is about your hair. Your account identity does not go with them.
  • A hair profile is not medical data, and CurlCue does not give medical advice.
  • We do not sell your data, and we do not share it for advertising.
  • You can export everything tied to your account, or delete the account and all of it, from the Profile tab. No email to us required.

What we collect, and why

Your account

Signing up asks for a username, an email address and a password. Sign-in is handled by Supabase Auth, which stores a hash of your password; CurlCue never stores or sees it in readable form. A forgotten password is reset with a six-digit code sent to your email. There is no sign-in through Apple, Google or any other account.

You can add a bio, an avatar, a banner image, and links to your Instagram, TikTok or website. The app also records your phone’s time zone, which it uses to reset weekly allowances and count streaks on your local calendar rather than ours.

You can take the hair quiz before creating an account. Until you sign up, your answers live only on your phone.

Your hair profile

The quiz asks about your curl pattern (family and type, 1a to 4c), length, strand thickness, density, porosity (or, if you are not sure, how your hair behaves on wash day, which the app uses as a stand-in), scalp condition, color, bleach or heat damage history, how often you use heat now, whether you are in a protective style, how often you wash, how you refresh between washes, the water hardness and climate where you live, the look you are steering toward (shine, volume, feel, frizz tolerance), care goals, and a budget preference.

This is what the score is built from. The one exception is the budget preference: it is stored, and the scoring engine does not read it.

If you use them, hair check-ins (moisture, definition and frizz on a 1 to 5 scale, with an optional note) and wash-day logs are stored too.

None of this is medical data in the sense of a health record or Apple’s HealthKit. CurlCue does not read or write HealthKit, does not diagnose anything, and does not give medical advice. If you have a scalp condition, ask a professional.

Photos

CurlCue asks for camera and photo-library access, and the permission prompts say why: the camera is used to scan ingredient labels and recognize products, and to take photos of your hair; the photo library is used for hair photos and product photos you choose to share. The app never reads your library on its own. It only receives the photos you pick.

  • Ingredient labels. The photos you take of an ingredients list are sent to Anthropic, which reads the text off them. While you are lining up the shot, the app also sends a small frame about once a second for framing tips (too dark, too far, not the label). Text detection for the live view itself runs on the phone.
  • The front of the bottle.When you add a product to the catalogue, the front photo goes to Google Cloud Vision to read the text on it, to Anthropic to sort that text into brand, name, category and size, and to Replicate to remove the background. Anthropic is also asked whether the photo shows a face, an ID card, a bank card, a screen of private messages or anything else that identifies a person. If it does, the app asks you to retake it, because an accepted front photo becomes that product’s picture for every CurlCue user.
  • Hair photos on your profile. You can pin up to three photos to your profile. Who can see them in the app (everyone, your connections, or nobody) is a setting you control, along with the visibility of every other profile field.
  • Photos in CurlCue AI and in posts. You can attach up to three photos to a CurlCue AI message; they are sent to Anthropic with the message. Photos in inspiration posts are shown to whoever can see the post.

Scans, submissions and the catalogue

Scanning a barcode records which product you scanned and when. If the barcode is not in CurlCue’s catalogue, the number, and only the number, is looked up at Open Beauty Facts, an open product database. Reading a label with the camera records that a read happened and which allowance paid for it: the weekly free allowance, credits you earned, or Pro. Products you save, verdicts you record and comparisons you run are stored against your account.

When you submit a product (brand, name, category, size, a price you saw, a link to buy it, photos), the submission is reviewed and, if approved, becomes part of the shared catalogue that every user scans against. A buy link is fetched once from our server to check that it leads to a product page, and any affiliate tags in it are removed. Approved submissions earn you scan credits.

Your routine

Your routine (the steps, the products in them, the order), saved routines, wash-day logs and check-ins, and the streaks, XP, badges and quests the app awards for keeping to it. Notifications about these stay inside the app; CurlCue sends no push notifications.

Community

If you use the community features, CurlCue stores what you post (routines, tips, and inspiration posts with a photo or a link and a caption), your comments, likes and bookmarks, who you follow and who follows you, follow and friend requests, invite links you create, the people you block, and the reports you file (a reason from a fixed list and an optional note). Reports are read by CurlCue so that we can act on them.

If you apply to be a verified creator, the application (the role you are applying for, a short bio, the hair types you work with, and your Instagram, TikTok or website links) is stored with your account.

Every profile field has its own visibility setting: public, connections only, or private. You can also make the whole account private.

CurlCue AI

CurlCue AI runs on Anthropic’s Claude models. When you send a message, the message, any photos you attached, your hair profile and your current routine are sent through CurlCue’s server to Anthropic, so that the answer is about your hair. Your account identity is not sent: Anthropic receives the content of the conversation, not who you are. The same path is used when the app asks the model to shape a routine, write a product verdict, or produce an insight.

Your conversation history is stored on your phone, not on our servers. What our server keeps is a usage log: when each request was made, which mode it was, which model answered, and how many tokens it used. That log exists to enforce daily allowances and to stop abuse.

Usage and allowance logs

For the same reason, the app keeps a log of label reads, AI requests and activity (check-ins, scans, wash-day steps) against your account. These logs power your allowances, streaks and badges, and let us answer “why did I run out”. They hold timestamps, counts and event types, not content.

CurlCue Pro

If you subscribe to CurlCue Pro, Apple handles the payment. CurlCue never sees your card or your Apple ID. RevenueCat, the service that manages the app’s subscriptions, receives the App Store transaction and your CurlCue user ID (a random identifier, not your email). It tells our server what happened (purchase, renewal, cancellation, expiry, billing issue, refund), and our server stores that status against your account so that Pro features unlock. Subscriptions are managed and cancelled in your App Store settings, not inside CurlCue.

Crash reports

CurlCue uses Sentry for crash reports, switched on only in builds that carry a reporting key. When it is on, a crash sends a stack trace, the device model, OS and app version, and your user ID. It is configured to send no IP address, no email or profile fields, no screenshots, no session recordings and no console logs, and web addresses in a report are cut at the question mark, so a signed photo link cannot end up in one.

App updates

When it starts, the app checks Expo’s update service for a newer version of its JavaScript. That request carries the app’s runtime version and platform so the service can decide which update applies. Nothing from your account goes with it.

This website

This site is hosted on Vercel. It sets no cookies, runs no analytics and stores nothing in your browser. Vercel, like any host, sees the technical details of a request (your IP address, browser and the page asked for) in order to serve it.

What we do not collect

  • No advertising SDK and no analytics SDK.Nothing in the app measures what you tap or how long you stay for anyone’s benefit but your own streak counter, which lives with your account.
  • No location.The app asks where you live only in the sense of “is your water hard” and “is it humid”, and you answer from a list.
  • No contacts. Invites are links you share yourself.
  • No microphone.
  • No HealthKit, and no health data in that sense. A hair profile is not a medical record.
  • No advertising identifier, and no tracking of you across other apps or websites.
  • No selling of personal data, and no sharing of it for behavioural advertising.

Who else handles your data

These are the companies whose systems your data passes through so that the app works. Each receives what is listed and nothing else. None of them is allowed to use it for its own advertising.

Third-party services, what each receives, and why
ServiceWhat it receivesWhat for
SupabaseEverything the app stores: account, hair profile, photos, posts, logs, entitlement status. Hosted in the United States (AWS, us-east-1).Database, sign-in, file storage and the server functions behind every feature.
AnthropicCurlCue AI messages with attached photos, your hair profile and routine; ingredient-label photos; camera frames while you aim at a label; the text read off front-of-bottle photos, and the photos themselves for the privacy, match and quality checks; submitted product details and buy links for verification. Never your account identity.CurlCue AI, label reading, catalogue checks.
Google Cloud VisionFront-of-bottle photos.Reading the text on the front of a product.
ReplicateFront-of-bottle photos.Removing the background from a product photo.
Open Beauty FactsA barcode number.Looking up a product that is not in the catalogue yet.
AppleYour purchase. Apple’s own privacy policy applies to it.Payment and subscription management for CurlCue Pro.
RevenueCatApp Store transactions and your CurlCue user ID.Subscription status.
SentryCrash reports, as described above, only in builds with reporting switched on.Finding and fixing crashes.
Expo (EAS Update)The app's runtime version and platform.Delivering app updates.
VercelRequests to this website.Hosting this website.
RetailersWhen you contribute a buy link, our server loads that link once to check it.Verifying product submissions.

Other CurlCue users see what you choose to show them: the profile fields you set to public or to connections, your posts and comments, and the products and photos you contributed to the catalogue.

We will disclose data if the law requires us to.

How long we keep it

Everything tied to your account is kept for as long as the account exists and deleted when you delete it. The usage logs have no separate clock; they go with the account.

Two things outlive an account:

  • Products, ingredient lists and product photos that were accepted into the shared catalogue stay in the catalogue, because other people’s scores are built on them. The record that you submitted them is deleted with you.
  • Copies may persist for a limited time in our database provider’s routine backups before those expire.

Your CurlCue AI conversation history lives on your phone and goes when you delete the app. Data exports you saved are yours.

Export and delete, from inside the app

Both are in the app, neither needs an email to us, and neither is gated behind Pro.

Export

Open the Profile tab, scroll to the Privacy section and tap Export my data. The app builds a JSON file of everything tied to your account (profile, hair profile, privacy settings, scans, saved products, submissions, routine, check-ins, posts, comments, follows, badges, allowance logs and the rest) and opens the share sheet so you can save it wherever you like. Nothing about any other user is included.

Delete

In the same section, tap Delete account. The app asks you twice, then deletes your data, your uploaded files and your sign-in, and signs you out. It cannot be undone.

Everything else

Camera and photo-library permission can be withdrawn at any time in iOS Settings. Profile photos, posts and comments can be deleted one at a time in the app. Every profile field has its own visibility setting, and any user can be blocked.

Your rights

If you live in California

The CCPA, as amended by the CPRA, gives you the right to know what personal information we collect and how it is used, to delete it, to correct it, and to opt out of its sale or sharing. CurlCue does not sell personal information and does not share it for cross-context behavioural advertising, so there is nothing to opt out of. We will not treat you differently for exercising any of these rights. Access and deletion are in the app; for a correction the app cannot make, or anything else, email us.

If you are in the EU, EEA, UK or Switzerland

The GDPR and the UK GDPR give you rights of access, rectification, erasure, restriction, portability and objection. The export in the app is your right of access and portability; deletion in the app is your right of erasure. Our legal bases for processing are: performing our contract with you, since the app cannot score products without a hair profile; your consent for the camera, your photo library and every photo you choose to share, which you can withdraw by deleting the photo or the permission; and our legitimate interest in keeping the service secure, enforcing allowances and preventing abuse, which is what the usage logs are for.

Your data is stored and processed in the United States. You can complain to the data-protection authority where you live.

Jeovany Gutierrez is the controller of this data. Requests that the app cannot fulfil itself go to support@curlcue.app; we may ask you to confirm you own the account first.

Children

CurlCue is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has an account, email us and we will delete it.

Security

Data travels over TLS. Every table in the database has row-level security, so a signed-in user can read and write only their own rows, and the keys for the AI and vision services live on the server, never in the app. No system is perfectly secure; if we learn of a breach that affects you, we will tell you.

Changes to this policy

We will post changes here and update the date at the top. If a change is significant, we will say so in the app before it takes effect.

Contact

Jeovany Gutierrez · support@curlcue.app