Privacy Policy
简体中文Curio (the “App”) is a personal hobby journal and archive. We believe your data belongs to you. Curio does not operate an account system or a developer-run server that receives your records, and it does not build user profiles, serve ads, perform remote behavior analytics, or track you across apps.
1. Where your data is stored
- Structured records: Hobbies, items, inventory, sessions, ratings, notes, and places you explicitly save are stored on your device. If you enable iCloud sync, Apple CloudKit syncs them to the private database of your Apple Account.
- Places and coordinates: After you select, enter, or confirm a place or fishing spot, its name, address, locality, region, and selected coordinates become part of that profile or record and follow the storage rules above. Curio does not copy Apple’s place database into a public directory or send your private location history to the developer.
- Media attachments: Photos, videos, and voice recordings that you add are stored on your device. If iCloud sync is enabled, they may be mirrored to Curio’s app directory in your own iCloud Drive.
- System capture and imports: The Share extension, the Journaling Suggestions system picker, and competitor-history imports process only content you explicitly select. The Share extension copies selected content to a file-protected on-device App Group inbox that is excluded from system backups; it remains there until you move it into a recoverable draft or explicitly discard it. A Journaling Suggestions candidate is kept briefly in process memory, while a temporary competitor-export copy is removed after validation. Only content you confirm and save becomes part of your Curio archive.
- Preferences, reminders, and system search: Appearance, personal terms, notification preferences, logging level, and watermark settings remain on your device. When you enable or schedule a reminder, iOS schedules a local notification. Eligible private profiles may be projected into the on-device Core Spotlight index for system search and shortcuts. The index is rebuildable and is not a copy on a developer server.
- The developer does not receive or read these records through a developer-run server. Apple processes iCloud data under your account settings. When iCloud sync is off, Curio continues with local-only storage.
2. Permissions and on-device processing
- Camera: Used when you choose to take a photo attachment. The photography light meter uses the live rear-camera view and camera exposure information to calculate exposure settings. It does not save the meter view as a photo or upload it, and its state is discarded when you leave the tool.
- Photos: Used to select attachments, read EXIF metadata, review a photo selection, request system-confirmed deletion of selected library photos, and save share cards or imported photos. When a selected image contains GPS data, the single-photo or batch watermark tools may send the coordinates to Apple Maps to reverse-geocode a locality or region. Curio displays the place name but does not save or show the image’s precise coordinates in a Curio record. iOS presents its own confirmation before photo deletion.
- Microphone: Used only after you start a voice note, to record an audio attachment.
- Speech Recognition: Used to transcribe a voice note you start. Apple’s speech-recognition service may process the audio and related data; whether processing stays on device depends on the system, language, and network conditions. The developer does not run a server that receives this speech data.
- Location and Maps: Curio requests your current location only after you open a Places or Fishing map, use nearby search, or tap the locate control. It is used to center the map, sort nearby results, or help you choose a place. Curio does not continuously track location in the background or send your current location to the developer. If you then confirm and save a place or spot, its coordinates become part of your record. You can still search, create a place manually, or choose a fishing spot manually after denying location access.
- Files and external storage: Curio accesses only files, folders, or devices you authorize through the system file picker, for purposes such as importing an official export, browsing photos, reading file dates, and importing selected photos into your library.
- Journaling Suggestions: Curio reads a suggestion only after you open Apple’s system picker and select it. The selected suggestion may provide a date, photos, places, and a walking or running summary. Curio turns these into an editable draft. It cannot browse your complete journal or suggestions you did not select, and nothing is saved to your archive until you confirm it.
- Label text recognition (OCR): Apple Vision recognizes text on device only in a label image you take or select. Curio creates editable candidates that are never applied automatically. The image and recognized text are not uploaded for this feature.
- Notifications: Local notifications are limited to dates you set for revisit reminders, plant checks, opened-wine reviews, beauty reviews, continuations, active brew steps, and monthly or annual archive-ready reminders you explicitly enable. Content is derived on device and scheduled by iOS. Curio does not use marketing push notifications, and the developer does not receive notification content.
You can turn off Camera, Photos, Microphone, Speech Recognition, Location, or Notifications at any time in iOS Settings. Disabling a permission affects only the related feature.
3. Apple services and third-party processing
Curio includes no third-party analytics, advertising, or tracking SDK and does not collect an advertising identifier. Features you choose to use may call Apple CloudKit / iCloud Drive, StoreKit, Speech Recognition, Photos, Maps, Location Services, Journaling Suggestions, Notifications, Core Spotlight, Vision, and AVFoundation. Apple processes relevant data under its terms and your system settings. Label recognition and photography metering run on device.
4. Data the developer does not collect
The developer does not collect your hobby records, media attachments, saved places, precise current location, device identifiers, behavior events, or crash diagnostics, and does not sell or share personal data with advertisers. Curio currently has no developer-operated login, analytics, advertising, or remote-inference service. The App Store build does not request Health access or read from or write to HealthKit.
5. Sync, backups, export, and deletion
- Cross-device sync: When enabled, CloudKit and iCloud Drive keep data current across devices signed in to your Apple Account. Turning sync off does not automatically delete data already stored in iCloud.
- Historical backups: You may separately enable rolling recovery copies in iCloud Drive. Curio creates them on a best-effort basis. They can contain private photos and recordings and use your iCloud storage. You can view and delete each copy. Clearing all historical copies also turns off automatic creation; you may enable it again later.
- Complete backup: My → Complete Backup can create a
.curiobackupfile containing the four structured data tables, portable preferences, and photos, audio, video, and thumbnails referenced by active records. Curio first attempts to fetch active media that exists only in iCloud and will not claim a backup is complete if any required file is missing. - Handing off a backup: A backup leaves Curio only after you choose a destination through the iOS file picker or share sheet. It may contain private records and media. Store it carefully; a third-party file service or receiving app applies its own privacy terms.
- Restore: Curio validates the format, manifest, and file integrity before import. A confirmed restore replaces the current Curio data; if restoration fails, the original data is retained. Save a separate current backup first when possible.
- Deleting a record: Curio has no trash. Deleting an item, inventory entry, or session erases its name, notes, rating, coordinates, inventory details, and attachment metadata and removes related media locally and from a verified private iCloud mirror. A minimal content-free sync tombstone remains only to prevent an offline old device from resurrecting the deletion. Complete backups do not reintroduce deleted content or media.
- Deleting an attachment: Removing an attachment deletes the local file and, when iCloud is available and account identity is verified, its mirrored copy.
- Uninstalling Curio deletes local app data but does not automatically delete copies already in iCloud. To remove cloud data, first delete visible historical backups in Curio, then open iOS Settings → Apple Account → iCloud → Manage Account Storage, find Curio, and delete its data.
6. Purchases
Curio Plus, Curio Lifetime, and the Lifetime upgrade for existing Plus owners are one-time, non-consumable in-app purchases. They are not subscriptions and do not renew automatically. Apple App Store handles transactions, receipts, local pricing, and refunds; the developer does not receive your card details. See the Terms of Use for current benefits. The price shown by the App Store at purchase is controlling.
7. Children
Curio is offered for ages 18 and over. It includes personal alcohol-tasting records and optional private cigar and pipe archives that adults must add themselves. It is not directed to children, and we do not knowingly collect children’s personal information.
8. Changes to this policy
If this policy changes materially, this page will be updated with a new effective date.
9. Operator and contact
Operator: Lu Qi (individual developer)
China app filing: 皖ICP备2026006682号-4A
Privacy and support email: sdu.phonism@gmail.com