Your data, explained in plain language.
This notice describes the personal data the current Curata service can collect, why it is used, and which providers help process it. Curata is operated by Quintin de Groot in Winterthur, Switzerland.
Last updated July 2026
Who is responsible
Contact and operator
The responsible operator is Quintin de Groot, Ernst-Jung-Gasse 18, 8400 Winterthur, Switzerland. Questions about this notice or requests concerning personal data can be sent to info@curata.ch.
Data categories
What the service can hold
Account and profile
Email address, name, profession, country, institution type, career stage, referral source, authentication information, account timestamps, and email preference. Some profile fields are optional.
Topics and editions
Selected topics, topic suggestions, the topic set used to assemble an edition, and cached personalised introduction text. The research pipeline also stores paper, synthesis, verification, and processing records by topic and edition.
Library and contributions
Saved-paper details, collections, notes, reading status, reminders, feedback, alpha-questionnaire answers, and any free-text message or topic suggestion you submit.
Team features
Team name and profile fields, membership and role, invitee email addresses, shared papers and notes, journal-club threads, comments, and recorded takeaways.
Service operation
A throttled last-seen timestamp, delivery and background-job status, and records needed to prevent duplicate curation or email sends. Infrastructure providers may also process standard request information such as IP address and browser or device metadata.
Billing, if enabled
The data model can store a Stripe customer identifier and subscription status. If Stripe checkout is enabled and used, Stripe processes payment details; Curata should not need to store full card numbers in its application database.
Purposes
Why the data is used
- To create and authenticate an account and keep it secure.
- To build, display, and deliver the topic editions a user requests.
- To provide personal library, reminder, team, and journal-club features.
- To send account messages, team invites, requested reminders, and opted-in briefs.
- To operate background jobs, prevent duplicate work, diagnose failures, and support users.
- To review submitted feedback, alpha-testing responses, and topic requests and understand aggregate service use.
- To administer subscriptions and payments if billing is enabled.
Where the GDPR applies, the basis depends on the activity: providing the requested service, legitimate interests in secure and reliable operation, consent for optional communications, or compliance with a legal obligation where required.
Service providers
Who helps run Curata
Curata uses specialist providers for specific parts of the service. The data sent depends on the feature being used.
- Supabase provides authentication and database infrastructure. It receives account, profile, session, and application data stored for the service.
- Anthropic provides models used for research triage, classification, synthesis, selected judging, repair, and topic-based introductions. Inputs can include topic names, audience descriptions, citation data, abstracts, and generated synthesis text. The pipeline does not need to send a reader's name or email for these tasks.
- Google Gemini is used to check synthesis sections against their supplied source abstracts. Inputs can include synthesis text, PMIDs, and abstract text.
- NCBI PubMed receives topic search queries and returns citation and abstract records used by the curation pipeline. Curata can also send paper identifiers when it checks for free full-text links for displayed or saved papers.
- Trigger.dev runs scheduled and on-demand background work. Job payloads can include topic slugs, internal user identifiers, or saved-paper identifiers. Tasks then retrieve the data needed to curate editions and deliver email; email work can process a recipient name and address together with the relevant brief, reminder, or paper details.
- Infomaniak SMTP is used to deliver service email, including briefs, reminders, and team invitations. It processes the recipient address and message content.
- Stripe is the configured payment provider for checkout and subscription handling if billing is enabled.
Provider processing locations, retention settings, and contractual transfer safeguards depend on the accounts and deployment regions configured outside this repository. Contact Curata for the current details relevant to a particular request.
Your device
Cookies, local storage, and caching
Supabase authentication uses cookies to maintain a signed-in session. Curata also stores an app-theme preference in the browser's local storage. A service worker can cache static resources such as styles, scripts, fonts, and images for performance; the current caching rules exclude page navigations, API requests, authentication traffic, and React Server Component responses.
The current application code does not include a third-party advertising tracker or a general-purpose web analytics tag. The service does record limited operational activity, including the account's last-seen timestamp described above.
Sharing
No advertising-data business model
Curata does not use personal data for third-party advertising in the current implementation. Data is disclosed to the providers described in this notice only as needed to supply their part of the service, and may also be disclosed when required by law or necessary to protect the service and its users.
Team content is visible to the relevant team members according to the feature: for example, team administrators can manage invites, and members can see shared-library or journal-club material. Avoid placing patient-identifying or other confidential clinical information in notes, feedback, comments, or suggestions.
Retention and deletion
How long information is kept
The current implementation does not define one public retention period that applies to every category above. Account and feature data is kept while needed to provide and operate the service, resolve support or security issues, and meet applicable obligations. Provider logs and backups can follow separate schedules that must be confirmed in the provider accounts.
A deletion request can be initiated from settings. A team owner must first delete the team so that other members are not orphaned. The effect of deletion differs by record: some personal records are linked to the account for deletion, while authorship on shared team records can be detached rather than deleting the team's content. Contact Curata if the automated request cannot complete or needs manual follow-up.
Your choices
Access, correction, email preference, and requests
Profile details and the brief-email preference can be changed in account settings. Depending on the law that applies to you, you may also have rights to request access, correction, deletion, restriction, portability, or objection, and to withdraw consent for optional processing. These rights can have legal limits.
Send requests to info@curata.ch. Curata may need enough information to verify that the request concerns your account before acting on it.
Security
Access controls, with realistic limits
The application uses Supabase authentication, server-side authorization checks, and database row-level access policies to separate personal and team data. No online service can promise absolute security. If you believe account or personal data has been exposed, contact info@curata.ch promptly.
