Effective date: 30 September 2026 Last updated: 30 September 2026
Questions, or a request about your data? [email protected]
Curricular keeps the record a student builds — the extracurricular and supercurricular activities they do, the hours they log, the competitions they enter — and turns it into a portfolio they can use when they apply to university. This policy explains what it stores, who else ever sees any of it, and how to have it deleted. It covers the Curricular app for iPhone. Our other apps each have their own policy — see all policies.
It is deliberately specific rather than boilerplate, because many of the people using this app are under 18.
1. What Curricular uses, at a glance
| Data | Why | Required? |
|---|---|---|
| Email address | So your account exists and your record survives a new phone | Yes |
| Your name | To sign you in, and to put a name on a portfolio you export | Yes |
| Academic goals, career interests, target university and country, the year you are in, the subjects you take, the year you finish | The questions the introduction asks, which shape what the advisor suggests | Yes |
| Activities — title, description, organisation, role, category, dates | The record itself | Yes |
| Check-ins — hours, notes, timestamps | The hours behind each activity | Yes |
| Rhythms — the days and times you plan to work | Reminders, and the optional calendar entry | No |
| Competition results — name, level, result, date, notes | The competition record | No |
| Proof files — a photo or PDF of a certificate | Evidence kept with a result | Only if you attach one |
| Advisor conversations — your question and the reply | So the advisor can follow what you are asking | Only if you use it |
| A count of advisor questions asked, and whether you subscribe | To apply the free allowance and the subscription | Yes |
| Usage events and crash reports | To find out what is broken and what nobody uses | No — see §4 |
What Curricular does not use: advertising identifiers, your contacts, your photo library beyond the single image you pick, your location, your microphone, your health data, or anything you do in other apps and on other websites. Curricular shows no advertising — see §6.
Curricular has no social features. No student can see another student's record, there is nothing to publish, and there is no leaderboard, feed or profile that anybody else can read.
What never leaves your phone
- Reminders. Every notification Curricular sends is scheduled by your own device. There is no push server, so no list exists anywhere of who is reminded or when.
- Calendar entries. If you turn the calendar switch on for a rhythm, the app writes an event to the calendar already on your device. It asks for write-only access: it has no ability to read anything else in your calendar, and no reason to want it.
- Unsent hours. A check-in logged without a connection waits on the device until it can be sent.
- Answers given before you have an account. The introduction runs before sign-up; until you create an account those answers exist only on your phone.
2. Who is responsible for your data
2.1 The data controller is:
Dexlin Av. del Mediterráneo, Loc 4 29670 Marbella, Málaga, Spain [email protected]
2.2 We are not required to appoint a Data Protection Officer; the contact address above reaches the person responsible.
2.3 Your record is held in Google Firebase (Firestore and Cloud
Storage), in Google's nam5 region in the United States, under a path that
belongs to your account. §11 explains what that means for you if you are in the
UK or the EU.
2.4 One account cannot read another's. That is enforced by rules on the server rather than by the app on your phone, so it holds even against a modified copy of the app, and the two records the app is not allowed to edit — the advisor counter and your subscription state — are written only by our server.
3. Why we are allowed to use it (EU/UK legal bases)
| What | Basis |
|---|---|
| Your account, your activities, your hours and your portfolio | Contract — you asked us to keep them, and the app does not work without them |
| Answering a question you put to the advisor | Contract — it is the service you asked for |
| Keeping the service working, preventing abuse, fixing crashes | Legitimate interests — ours in running a working app, balanced against your interest in not being surprised |
| Reminders and notifications | Consent — asked for separately, refusable, withdrawable in system settings at any time |
| Writing to your calendar | Consent — one switch per rhythm, and a system permission you can revoke |
| Usage analytics | Consent |
| Records of purchases | Legal obligation — tax and accounting |
Withdrawing consent does not undo what was done while it was given, and it does not affect anything relying on a different basis above.
4. Who else sees your data
Only the companies that run the parts of Curricular we do not. Each acts on our instructions and may not use your data for its own purposes.
| Who | What they get | What for |
|---|---|---|
| Google Firebase | Your account, your record and any proof files you upload | Sign-in, database, file storage, the server functions the app calls |
| Google Gemini | The question you asked, the recent conversation, and your record as described in §5 — never your name, email address, account identifier or proof files | Answering advisor questions |
| RevenueCat | An anonymous customer id and your subscription status | Knowing whether Curricular Plus is active |
| PostHog (EU) | Usage events and crash reports, tied to your account id | Finding out what is broken and what nobody uses |
| Apple | Payment details, which we never see | Payments, and distributing the app |
No free text is ever sent to analytics. Not an activity title, not the notes on a check-in, not the university you typed in, not a question you asked the advisor. What is sent is that something happened and its shape: that an activity was created and which category it was, how many hours a check-in was for, which screen of the introduction you reached. Your name and email address are not sent as profile properties.
Crash reports contain the file and line where the crash happened, the app version, the operating system version and the device model.
Session replay is not enabled. PostHog is installed but does not record your screen.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not share your record with your school.
5. What the advisor is told
Questions to the advisor are answered by Google Gemini, called from our server and never from your phone. Our server builds the context itself, from your own documents, and deliberately leaves out everything that says who you are: no name, no email address and no account identifier. Your proof files are never sent either.
What the model is given is your record, so that its advice fits you rather than any student:
- your profile answers — the subject you want to study, your dream university, the country you are applying in, the year you are in, the subjects you take now and the year you finish;
- your activities — ideas, current and finished, with the role, organisation and description you gave them, the hours you logged, your rhythm, and your most recent check-in notes;
- your competition results.
It also gets the last ten exchanges of the conversation, so it can follow what you are asking. Anything you typed is shortened before it is sent. Leaving out your identity is enforced on the server and is tested against a list of fields that must never appear in a prompt.
Google's use of data submitted through the Gemini API is governed by their own terms.
6. Advertising
Curricular contains no advertising, and no advertising SDK. It does not read your device's advertising identifier, it will never ask you for tracking permission, and nothing in it is funded by anybody other than the people who subscribe.
7. Payments and subscriptions
Curricular Plus is sold through the App Store, not by us, and managed for us by RevenueCat. Apple takes the payment and we never see your card number.
We receive, through RevenueCat, an anonymous customer identifier and whether a subscription is active, so the app knows to switch Plus on. Our server records nothing more than that the account is subscribed, which product it is, and when it runs out. Refunds are handled by Apple under their own policies, and the Manage Subscription route in your profile is the way to both.
8. Students under 18, and children
Curricular is built for secondary-school students, and many of them are under 18. That shapes the whole design rather than a paragraph at the end:
- no advertising, and no tracking across other apps or sites;
- no sale or sharing of personal information, ever;
- no free text in analytics, and nothing identifying sent to the AI provider;
- the narrowest version of every permission — write-only calendar access, and a photo picker that hands over only the image you choose rather than access to your library;
- no social features, so nothing a student writes is visible to anybody else.
Curricular is not directed at children under 13, and we do not knowingly collect their data. If you believe a child under 13 has an account, write to [email protected] and we will remove it.
If you are a parent or guardian and want to see what is stored about your child, or have it deleted, write to the same address and we will help.
9. How long we keep it
| What | How long |
|---|---|
| Your account, activities, hours and portfolio | Until you delete them, or delete your account — the point of the app is a record still there when you apply |
| A proof file | With the result it belongs to — deleting the result deletes it |
| Advisor conversations | Until you delete your account |
| Usage events | 12 months |
| Purchase records | 6 years, because tax law says so |
| Backups | Up to 30 days after deletion, then gone |
10. Deleting your account
Delete Account on the Profile screen removes your profile and everything under it — activities, check-ins, rhythms, competition results, proof files and advisor conversations. A process on our server then removes the last record, the advisor counter and subscription state that the app itself is not permitted to delete. Analytics events already recorded are not tied back to a deleted account.
You can also ask at [email protected] and we will erase everything in §1 within 30 days. Purchase records survive only where tax law requires them, and are kept for nothing else.
Signing out leaves nothing readable on the phone. Deleting the app from your phone does not delete your account, and does not cancel a subscription — cancel that in your Apple account settings.
11. Your rights
If you are in the UK or EU, you have the right to:
- access the data we hold about you, and get a copy;
- rectify anything wrong;
- erase it;
- restrict how we use it;
- object to processing based on legitimate interests;
- port it to another service in a machine-readable form;
- withdraw consent at any time, for notifications, calendar access or analytics.
The app already does most of this for you: everything is editable in place, the portfolio export produces a copy of your whole record as text or as a PDF, and deleting your account is a button. For anything else, write to [email protected] and we will answer within 30 days. All of these rights are free to exercise.
If you think we have got it wrong, you can complain to your local supervisory authority — in Spain the Agencia Española de Protección de Datos (aepd.es), in the UK the Information Commissioner's Office (ico.org.uk).
If you are in California, you have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for asking. As above: we do not sell or share personal information, so there is nothing to opt out of.
12. International transfers
Curricular's database and file storage are in the United States, and the providers in §4 are mostly United States companies. If you are in the UK or the EU, that means your record is transferred outside it. Where it is, the transfer relies on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. PostHog, which receives the analytics events, is hosted in the European Union.
13. Security
Everything in transit is encrypted. Access to your record is enforced by server-side rules rather than by the app, so it holds even against a modified client, and those rules are tested against an emulator before every change. Proof files can only be written to a path that begins with your own account identifier, and anything that is not an image or a PDF, or is over the size limit, is refused.
No system is perfect and we will not pretend otherwise. If you find a problem, please tell us at [email protected] before telling anyone else, and we will credit you if you would like us to.
14. Changes to this policy
If we change this in a way that matters, we will say so in the app before it takes effect, and update the date at the top. Smaller corrections are made quietly and the date still moves.
15. Contact
Dexlin Av. del Mediterráneo, Loc 4 29670 Marbella, Málaga, Spain
Privacy and data requests — [email protected] Anything else — [email protected]
Like our other policies, this one is written in plain English on purpose. If any part of it is unclear, that is a fault worth reporting, and the address above will reach us.