Curato · Legal
Privacy Policy
Last updated 9 August 2026
Curato (“we”, “the service”) is operated by FOP Pendrakovska O.M., an individual entrepreneur registered in Ukraine (registration details available on request). This policy explains what we collect, why, how we protect it, and the rights you have. It is written to meet the Law of Ukraine “On Personal Data Protection” and, for visitors in the EU/UK, the GDPR. Using Curato means you accept this policy.
1. What we collect
- Email address — to create your account, sign you in with a one-time code, or through Google sign-in.
- Your details — name, date and time of birth, country, city, profession and hobbies. These are required to build your profile: the date and time feed the clearly-labelled astrological and numerological lenses, and the place informs the architecture of your generated rooms.
- Test data — your questionnaire answers and the room pairs you pick.
- Photos you upload (optional) — feed screenshots, a favourite photo of yourself, or a photo of your own room. These are sent to our AI providers for analysis or redesign and are never stored by us: they exist only for the seconds the request takes. Your device also shrinks them before sending, which strips embedded metadata such as location. We keep only the result — a qualitative reading, or the generated image.
- Your results — your profile, written readings and generated rooms. Generated images are stored so they stay in your gallery.
- Purchases — which pack you bought, its price and currency, and your generation balance. We never see or store card details; those go straight to our payment provider.
- Feedback — your “is this close to you?” ratings, stored without your identity.
- Product analytics — anonymous counters for how far people get through the flow (a screen was reached, a purchase completed). No names, no emails, no advertising profiles.
- Minimal technical data — a short-lived, per-server count of requests from your network address, only to stop abuse of AI generation.
2. Why we use it & on what basis
To build your profile, generate and store your rooms, sign you in, take payment, run the Family plan, and keep the service safe. Our legal bases are performance of a contract (delivering what you asked for), your consent (optional photo uploads), and our legitimate interest in operating and protecting the product. We do not sell your data and we do not use it for advertising.
3. A note on photos
A photo of your face could be considered sensitive data. That is exactly why we do not store your uploads — we read them, return a qualitative result, and discard the image. Every core feature works without uploading anything; the photo steps are skippable.
4. The Family plan — shared by design
If you invite someone into a Family plan, you are choosing to share: a space generated together is written into both galleries, marked as shared, and each of you can see and download it. Your own private rooms stay yours. Only invite someone you are comfortable sharing with, and write to us if you want a family link removed.
5. How it is stored & for how long
Accounts, saved results and orders are stored encrypted at rest (AES-256). Passwords, where you set one, are hashed — never held in readable form. One-time sign-in codes are stored hashed, expire in 15 minutes, and are consumed on use. We keep your data while your account exists: you can delete individual saved rooms, or ask us to erase your account entirely.
6. Cookies & on-device storage
We use only strictly necessary cookies, plus some data your browser keeps on your own device while you take the test. Nothing for advertising or tracking. Details are in our Cookie Policy.
7. Who else processes your data
- Anthropic — analysis of your answers and photos, and the written readings;
- Replicate and Google (image model) — generating and redesigning rooms;
- Vercel — hosting and encrypted storage;
- WayForPay — payment processing (they receive your payment data directly; we receive only the result and your email);
- Google — if you choose Google sign-in, we receive your email address, whether it is verified, and your first name;
- Resend — sending sign-in codes and invitations, where email delivery is enabled.
Each acts only on our instructions. Some are based outside Ukraine and the EU (e.g. the United States); where that involves a transfer of personal data, it is done under appropriate safeguards such as the providers’ standard contractual clauses.
8. Your rights
You may access, correct, export or delete your data, withdraw consent, or object to a particular use. EU/UK users hold the full set of GDPR rights (access, rectification, erasure, restriction, portability, objection). Email us to exercise any right and we will respond within 30 days. You may also complain to your data-protection authority.
9. Children
Curato is not intended for anyone under 16, and the date-of-birth picker does not offer younger years. We do not knowingly collect data from children.
10. Changes & contact
We may update this policy; the current version always lives on this page, with the date above. For any question or request: pendrakovskaya@gmail.com. This policy is governed by the law of Ukraine.