Privacy Policy
Effective date: August 1, 2026
Curesso ("Curesso", "we", "us") is a personal AI assistant operated by an independent developer. This policy explains what data Curesso accesses, why, how it is protected, and the choices you have. Questions: curesso.ai@gmail.com.
What we access
Curesso only accesses data you explicitly connect, to perform the tasks you ask of it:
- Google sign-in (OpenID Connect) — your email address and basic profile, to create and authenticate your account.
- Google Calendar (if connected) — read and write your calendar events.
- Google Tasks (if connected) — read and write your task lists.
- Your messages and memory — the messages you send Curesso (via Telegram) and the long-term notes it keeps to remember your preferences and context.
- Telegram group messages (if you add Curesso to a group) — text messages sent in groups where you have enabled auto-translation or dictionary mode, including messages from group members who are not Curesso users, processed only to generate the translation or definition.
How we use it
We use this data solely to provide the assistant features you request — for example, checking your day, drafting a reply, creating an event, or recalling something you told it earlier. This holds whether the data is in its raw form or in any aggregated or anonymized form derived from it: we do not sell it, and we do not use it for advertising, credit or lending decisions, or any purpose other than providing the features you ask for.
Processing by AI providers
To generate responses, the content relevant to your request is sent to large-language-model providers (Anthropic, OpenAI, and/or Google) acting as our processors. These providers process the data only to return a result to Curesso and, under their API terms, do not use it to train their models.
Group features
A registered user can add Curesso to a Telegram group and enable auto-translation or dictionary mode. While a mode is on, each text message in the group is sent to an AI provider to generate the reply, and the usage is billed to the plan of the user who added the bot. Group messages are processed transiently and are never stored: we keep no copy of their content, and our logs record only technical metadata such as the group id, message length, and outcome — never the text itself. No provider uses this content to train models. Turning the mode off (/translate off or /dict off) or removing the bot from the group stops all processing.
Who we share data with
We do not sell your data and we do not share it with data brokers or advertisers. The only parties that handle your data are service providers that are strictly necessary to operate Curesso, each acting on our behalf:
- AI model providers (Anthropic, OpenAI, and/or Google) — process request content to generate responses, as described above.
- Cloud hosting provider (Fly.io) — runs your isolated per-user container and the encrypted database that stores your credentials and memory.
- Telegram — the messaging platform that transports the messages you exchange with the assistant.
- Payment processor (Stripe) — processes subscription payments. Stripe receives your email address and billing details when you subscribe; your card details are handled entirely by Stripe and never touch our servers.
We do not share your data with any other third parties except where required to comply with law or to protect the service and its users.
How we protect it
- Per-user isolation — your assistant runs in its own sandboxed container; data is not co-mingled between accounts.
- Encrypted credentials — connected account tokens are stored with envelope encryption (AES-GCM, per-row wrapped keys).
- Controlled egress and guardrails — outbound traffic is routed through a dedicated proxy, and deterministic checks guard against data exfiltration and prompt-injection attacks.
Retention and deletion
You stay in control of your data:
- Disconnecting an integration on your dashboard deletes the stored credentials for that integration and revokes Curesso's access on your container.
- You can revoke Curesso's access to your Google account at any time at myaccount.google.com/permissions.
- To delete your account and all associated data, email curesso.ai@gmail.com and we will remove it.
Children
Curesso is not directed to children under 13 (or the age required by your jurisdiction), and we do not knowingly collect their data.
Changes
We may update this policy as the service evolves. Material changes will be reflected by updating the effective date above.
Contact
For any privacy question or request, contact curesso.ai@gmail.com.