Applies to: the Curialis application (iOS via TestFlight / App Store and web at curialishealth.com), operated by Curialis Technologies, LLC (“Curialis,” “we,” “us,” or “our”).
The short version
Curialis is a personal wellness and self-tracking companion. It is not a medical device and does not diagnose, treat, cure, or prevent any condition.
You give us personal information that depicts your state of wellness so the Application can work: readings, meals, check-ins, messages to your companion, and - only with your permission - data from Apple Health.
Your information is not visible to other Curialis members. It is stored on our servers, where a small Curialis team can see it, and parts of it are sent to outside service providers - including an AI provider - to generate your summaries, observations, and companion replies.
We do not sell your information, show you advertising, use your wellness information for marketing, share it with data brokers, or track you across other companies' apps and websites.
You can delete your account from inside the Application, and deleting it deletes your information from our systems, with the narrow exceptions described below.
1. What Curialis is, and is not
Curialis is a wellness companion: it keeps your readings, meals, exercise, and check-ins in one place, reflects them back to you, and points out things worth a conversation with your care team. Nothing in the Application is a medical diagnosis or a treatment recommendation. Curialis is not for emergencies and is not monitored in real time; if you think you are having a medical emergency, call 911.
Some members participate in a small test program. If that is you, the in-Application disclosures you accepted describe the program; this policy applies to you in full.
2. Information we collect
a. Information you give us
Account and Profile Information
When you create an account, we collect your name, email address, password (stored only as a secure hash), time zone, program details (such as your cohort and phase), and - optionally - your sex, which is used only for wellness estimates that depend on it, as well as any other information you elect to provide during registration.
Physiological Data
Blood pressure, resting heart rate, weight, blood oxygen saturation, blood glucose, laboratory results, answers to the brief mood and anxiety questionnaires (PHQ-2 and GAD-2) if you complete them, and other biometric measurements you log or import.
Certain connected devices, such as heart rate monitors, continuous glucose monitoring devices, activity trackers, exercise equipment, scales, and/or wearables, that integrate with the Application, may allow us to collect Physiological Data with your permission.
Nutrition Information
Meal logs, food and beverage intake, calorie estimates, sodium intake, and other nutrition-related data you log or import
Physical Activity Data
Exercise session, movement, steps, workout duration and intensity, and other activity data you log or import. Certain connected devices that integrate with the Application may allow us to collect Physical Activity Data with your permission
Sleep and Well-Being Data
Sleep duration and quality, stress levels, mood, energy levels, and other subjective well-being data you log or import
Medical History and Clinical Records
Diagnoses, medications, treatment plans, clinical parameters, thresholds, and instructions you disclose or import from electronic health records, applications, or other sources.
If you add a clinician's name, role, phone number, or email address, or email a summary to someone, we hold that person's contact details because you gave them to us. We use them only to show them back to you and to send what you asked us to send.
Conversational Data
All text or voice inputs you provide to the Application, including questions, comments, concerns, goals, and any other information you share in conversation with the Application
Imported and Synced Data
If you choose to connect the Application to Apple Health or similar applications, wearable devices, fitness trackers, or other third-party platforms, we collect the data you authorize us to access from those sources, which may include all categories of health and wellness information listed above
Device Usage and Information
We automatically collect information about your device and how you interact with the Application, including: Device type, operating system, unique device identifiers, IP address, and mobile network information; Application usage data, including features accessed, screens viewed, session duration, frequency of use, and interaction patterns; crash reports, error logs, diagnostic data, and performance metrics
Location Information
We do not currently collect precise geolocation data. We may infer your general location (city or region) from your IP address for analytics and service improvement purposes.
Feedback and Communications
We collect any feedback, survey responses, comments, suggestions, or other communications you provide to us during the Beta Program, including through weekly surveys, interviews, or support requests. Before we store it, we automatically remove personal details it contains - names, phone numbers, email addresses, street addresses, and dates. That does not make it anonymous: what is left is still your own words, and it stays linked to your account.
Information from Apple Health (only with your permission)
If you connect Apple Health, we read the categories you approve - such as steps, active energy, workouts, heart rate and heart-rate variability, sleep, blood oxygen, respiratory rate, wrist temperature, walking metrics, and blood-pressure readings from a connected cuff. The connection is read-only: Curialis never writes anything to Apple Health, and never stores your Apple Health data in iCloud. You can change or revoke this permission at any time in the iOS Health Application. Changing what you share stops future syncing; it does not remove what was already synced - you can remove that by deleting individual entries or your account.
b. Information collected automatically
Sign-in records
Our authentication infrastructure records the IP address and browser/device identifier (User-Agent) of each sign-in session, linked to your account. We use these only to operate sign-in; they are deleted with your account.
Usage information
Which pages of the Application you open and when, notification opens, and technical telemetry about the AI requests the Application makes on your behalf (timing and size - not separate copies of content). This is linked to your account.
Product analytics
We use PostHog to count product events (for example, "a check-in was logged"). These events carry no wellness values, no free text, and no account identity - the event vocabulary is a closed, reviewed list. They do include a random device-scoped identifier that is stable on your device, and PostHog's servers - like any internet service you connect to - can observe your IP address and browser type when events are delivered. Analytics begins when you open the Application.
Push tokens
If you enable notifications, we hold the device token needed to deliver them. Notification payloads are generic and carry no wellness content.
Crash and error reporting
No crash/diagnostic service currently receives data from the Application.
c. Information we create
Summaries and Observations
Derived Wellness Estimates
The Application computes and stores wellness estimates from your data - currently a recovery-readiness estimate and a 'cardio age' estimate - even when they are not displayed in the Application. They are part of your data and are deleted with your account.
Safety Records
If a reading crosses a safety threshold, the Application creates an escalation record, which includes a snapshot of the values that triggered it (see §7 for how these behave when you remove an entry).
What we do NOT collect
- Location
- Contacts
- Photos
- Documents
- Browsing History
- Advertising Identifiers
3. How we use your information
To run the Application for you
Storing your entries; generating your summaries, briefs, trends, and companion replies; and delivering notifications you have enabled.
AI Processing
Your companion's replies, your morning and weekly summaries, and food-recognition all work by sending relevant parts of your information to an AI provider (see §5). This includes a daily automated process that prepares your morning summary without any action by you that day.
Automated safety detection, and what it does
The Application automatically checks readings against general safety thresholds and checks companion messages for signs of out-of-range results.
To improve the Application
Two ways, both disclosed in the Application:
- The feedback you send us, and
- An occasional extra AI request made to test an improvement to your companion.
Before either, personal details are removed from your words (names, phone numbers, email addresses, street addresses, dates). That does not make it anonymous - it remains your words, linked to your account, and the small Curialis team reads feedback to fix and improve the product.
To operate the Application
Authentication, security, debugging from our own logs, and required record-keeping
We do not use your information for advertising or marketing, we do not sell it, and we do not use Apple Health data for anything other than providing and improving the Application’s health features.
4. Who at Curialis can see your information
A small Curialis team operates the service and can see member information, including your name and the things you write, in order to run the Application safely - for example, reading feedback and fixing bugs. Access is limited to the team operating the product.
5. Service providers and other recipients
We use a small set of service providers to run Curialis. Each receives only what its role requires. We never sell your information, and no recipient may use it for its own advertising.
Amazon Web Services (AWS)
Role: AI processing (Amazon Bedrock, running Anthropic models) and Amazon Bedrock AgentCore Gateway web search (used for some food and health-reference lookups)
What reaches it: The content needed for each AI request: your messages and relevant wellness values and history, with personal identifiers removed from free text. Your name and account identity are never included.
AgentCore web-search queries carry the search terms only, with identifiers removed, capped in length.
Supabase
Role: Database and sign-in infrastructure
What reaches it: All stored information described in §2, including sign-in IP addresses recorded by its authentication service.
Vercel
Role: Application hosting and computing
What reaches it: Your information passes through its infrastructure whenever you use the app, as with any hosted service.
PostHog
Role: Product analytics
What reaches it: Count-style events only - no health values, no free text, no account identity; a device-scoped random identifier; IP visible at delivery (see §2c).
Resend
Role: Email delivery
What reaches it: Recipient email address and fixed, content-free templates. One template carries a secure link that opens a health summary (see §6).
Apple
Role: Push notifications; Application distribution
What reaches it: Device push tokens and content-free notification payloads; TestFlight tester emails.
Google Workspace
Role: Our staff mailbox
What reaches it: Emails you send us, and internal pseudonym-only alerts.
Our primary service providers generally process data in the United States. Some lookups use public reference services that may process requests outside the United States, as described for food lookup below. If you use a non-Apple browser for web push, that browser's push service (for example Google's or Mozilla's) delivers your content-free notifications.
Recipients that are not service providers — food lookup: when you search for a food, the Application first looks it up in USDA FoodData Central, a public United States government database. If that lookup does not find a matching packaged product, the Application may look up the food name or barcode in Open Food Facts (world.openfoodfacts.org), a public crowdsourced food database that may process requests outside the United States. In both cases, only the food search text or barcode is sent — without your name, account, or any member identifier. A food-name cache reduces how often these lookups happen. Do not treat Open Food Facts as part of the USDA disclosure.
AI training: Under AWS Bedrock's service terms, content submitted for inference is not used to train models and is not shared with the model vendor for training.
Legal and safety disclosures: We may disclose information if required by law, or as needed to protect a member's vital interests consistent with §3.
Business transfers: if Curialis is ever acquired or reorganized, your information may transfer with the service, under this policy's commitments.
6. Sharing you direct
Care-team summary links
When you share a wellness brief, we email your chosen recipient a secure expiring link - never a file or the data itself. You can revoke it at any time. Be aware that anyone who has the link can open the summary while it is valid; send it only to the person you intend. Link usage is metered and links are stored only as cryptographic hashes on our side.
Exports
You can download your trends as a CSV file and your clinical brief as a PDF. These are yours once downloaded; protect them as you would any health record.
7. Editing, removing, and what "remove" means
You can edit or remove your own entries from the Today tab (and food entries in chat).
The Mechanics of Removal
A removed entry is hidden from your app and excluded from your summaries; it may persist internally (marked as removed) until your account is deleted, which removes it entirely.
Entries tied to an out-of-range reading are locked and cannot be edited or removed while your account exists - this preserves the integrity of a member’s record. The out-of-range record's snapshot of the triggering values also persists for as long as your account does, even if you remove the underlying reading.
Saved memories, day notes, and day tags are the exception: deleting them removes them immediately and permanently.
8. Retention, and deleting your account
While your account exists, we retain your information; the product does not currently run automatic deletion or time-based purging.
You can delete your account from inside the app (Settings → Delete account). Deleting it:
- deletes your wellness data, entries, conversations, memories, summaries, derived estimates, sign-in records (including IP addresses), and profile from our production database, and deletes your sign-in identity;
- Deletes your feedback, including the text of what you wrote;
- Keeps one thing, with your identity severed: the operational audit trail (records that an escalation fired, that data was accessed, that the account was deleted) is retained for accountability, with your account identifier replaced by a random value that is not linked to you anywhere;
- Takes effect immediately in the app; residual copies in service providers' operational systems (such as email-delivery logs holding your email address) clear on those providers' cycles.
Our database plan currently maintains no customer-accessible backups, so there is no separate backup copy of deleted data on our side.
9. Information on your device
To make logging resilient, the app briefly stores drafts on your device (for example, a blood-pressure entry mid-typing) and caches recently viewed pages. Signing out - or any end of your session - clears these, and drafts expire on a short timer. On a shared device, sign out when you finish.
10. Security
We protect your information with, among other measures: encrypted connections (TLS) for all traffic; database row-level security so that an app session can read only its own account's rows; a closed, reviewed vocabulary for analytics so wellness content cannot leave through that channel; an allowlist that restricts which outside reference services the app's servers may contact; automatic removal of personal identifiers from free text before AI processing; and share links that are random, expiring, revocable, and stored only as hashes. No internet service can promise perfect security, and we will not pretend otherwise; we notify affected members and authorities of breaches as the law requires.
11. Our commitments for Apple Health data
For data obtained through HealthKit, in addition to everything above: we never use it for advertising, marketing, or use-based data mining; we never sell it; we never share it with third parties except service providers processing it for the app's health features as described in §5, or at your direction; we never write to HealthKit; and we never store HealthKit data in iCloud.
12. HIPAA Does Not Apply
Curialis is not a healthcare provider, health plan, or healthcare clearinghouse. We offer the Application directly to you as a consumer. We are not a “covered entity” or “business associate” under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), and your health information is not protected by HIPAA. However, your information is protected by this Privacy Policy and applicable federal and state privacy laws, including state consumer health data privacy laws.
Use of the Application does not create a doctor-patient, therapist-client, or other professional healthcare relationship.
13. Your rights (including Washington consumer health data rights)
This section serves as our Consumer Health Data Privacy Policy for the purposes of Washington's My Health My Data Act and similar laws.
What we collect, from where, and why: §2 (categories and sources) and §3 (purposes) are written to be that list.
Who receives it: §4. We share consumer wellness data only with the processors in §5, the USDA FoodData Central and Open Food Facts food lookups described there, and recipients you direct in §6. We do not sell consumer health data and do not share it with affiliates.
Your rights: to access your data; to confirm whether we collect it; to withdraw consent; to have it deleted (§8 - including our statement about backups); to a list of third parties with whom it has been shared; and not to be discriminated against for exercising rights.
How to exercise them: in-app (edit, remove, export, revoke shares, delete account) or by emailing privacy@curialishealth.com from your account email. We respond within the time the applicable law requires. If we decline a request, we will say why, and you may appeal by replying to our response; appeals are reviewed by Curialis Privacy Team.
14. Children
Curialis is for adults. It is not directed to anyone under 18, and we do not knowingly collect information from anyone under 18.
15. Changes to this policy
When we change this policy, we will update the effective date, and for material changes we will notify you in the app and re-request your acceptance where the change concerns how your health data is used. The in-app disclosures you accept are versioned, and a change re-prompts every member.
16. Contact
If you have any questions or complaints regarding Curialis’ privacy practices and/or this Privacy Policy or want to communicate an opt-out request to Curialis, or want to exercise your rights to access, review, correct, delete or object to the processing of your information, please contact us via email at:
Curialis Technologies, LLC
P.O. Box 41
West Jefferson, North Carolina 28694
privacy@curialishealth.com (privacy and rights requests)
support@curialishealth.com (general and corporate)