Curie
Privacy Notice
This notice explains what Curie collects, why, the legal bases it relies on, and the choices a parent or guardian has. Version 2026-08-20 (last updated 20 August 2026).
Who operates Curie, and the scope of this notice
Curie is a product for children, created and used only through an account held by an adult. The operating entity is: Friedland Group Ltd.
Registered address: A registered postal address will be published here before public launch.
If you have a question about this notice, contact support@curie-ai.co. See also our Contact & Data Requests page.
This notice covers the adult account holder (who creates and pays for the account) and the child profile(s) that adult creates and manages under it. Where something applies only to a child profile, this notice says so; our separate Children's Privacy Notice and Notice to Parents & Parental Permission focus specifically on the child side and should be read alongside this one.
What we collect
Adult account holder: name, email address, and authentication credentials. Sign-in and password handling is managed by Supabase's authentication service; Curie does not see or store a plain-text password. Billing name and payment details are entered directly with Stripe; Curie itself holds only limited billing metadata (such as plan and subscription status), never full card numbers.
Child PIN security material: if a parent sets an optional PIN for switching to a child's profile, Curie stores a salted one-way hash of that PIN (so it cannot verify sign-in by itself) plus a separately encrypted copy that only a signed-in parent on the account can ask the server to decrypt, so a parent who forgets a PIN can recover it. The plain PIN is never logged and is not visible to Curie staff in the ordinary course of business.
Child profile data: a first name or nickname (never a full legal name), an age or age band, chosen interests and subjects, an optional avatar, and settings the adult controls (voice on/off, history on/off, alert categories).
Saved history, only if a parent switches it on for that child: the child's question text and activity metadata for each turn — the mode used (text or voice), the world or subject explored, the time, and any awareness flag — so a parent can review what their child has been asking about. Curie's generated answer text is not currently stored as part of this saved history. Whether or not history is on, the question or spoken audio for that turn is still transmitted to OpenAI to produce the response; see "How AI processing works" below for how that is handled.
Voice audio and transcripts: for live spoken conversation, the child's device streams audio directly to OpenAI over a real-time connection (WebRTC) to have the conversation; for read-aloud, or where a transcript is produced, audio or text passes through to OpenAI and only the resulting text is stored. Curie does not intentionally store raw voice recordings in its own database; see "How AI processing works" below.
Safety/awareness flags: where a parent has turned on gentle awareness alerts, lightweight keyword-based tags may be attached to a saved question (for example, that it touched on a big-feelings or safety-related topic) so the parent can see the alert. These are not a clinical assessment.
Subscription and billing metadata: plan, status, renewal date and similar account-level information needed to run Curie Family; full payment details are held by Stripe, not Curie.
School enquiries: the name, email, school and message submitted through the Schools page, used only to respond to that enquiry.
Communications preferences and send logs: whether an adult has opted into optional account or product email, and delivery records (such as recipient, template, subject and whether an email was sent, failed or bounced) kept to operate and troubleshoot that email, via Resend. Curie does not track whether an email has been opened or read.
Technical and security metadata: sign-in timestamps, device/browser type, IP address at the time of a request, and basic error/audit logs, used to keep the service secure and working.
What Curie deliberately does not seek from a child
Curie is built to need as little as possible from a child. Unless a future feature changes this — in which case we will update this notice and ask for fresh parental consent before turning it on — Curie does not ask a child for their email address, phone number, home address, school name, precise/real-time location, photographs of themselves, or biometric identifiers (such as fingerprints, voiceprints used for identification, or facial recognition data).
Voice audio is processed to have a spoken conversation, not to identify who is speaking, and Curie does not build a voiceprint of a child.
Why we use it, and how we keep it minimal
- To create and secure the adult account and any child profiles linked to it.
- To generate age-appropriate answers, illustrations and, where enabled, spoken responses.
- To let a parent review saved history, adjust settings, and see gentle awareness alerts they have chosen to turn on.
- To operate subscriptions and billing for Curie Family.
- To send account, billing and safety-relevant email to the adult — never marketing email to a child.
- To respond to school enquiries.
- To keep the service secure, diagnose faults, and prevent abuse.
Curie asks each child-profile field to earn its place: if a feature does not need a piece of information to work, Curie does not collect it. Curie does not sell children's personal information, and does not use it for targeted or behavioural advertising, under any circumstance.
UK GDPR: our lawful bases for processing
For users in the UK (and, correspondingly, the EU where relevant), Curie intends to rely on the following lawful bases. This mapping is a launch-counsel item — it reflects Curie's current, good-faith position, to be reviewed and confirmed by UK counsel before public launch, and is not a claim of regulatory sign-off:
- Contract: processing the adult account holder's own information that is necessary to perform that adult's contract with Curie — for example, to provide the account and, on paid plans, the subscription.
- Legitimate interests, for the core child-profile and AI processing: creating and operating a child profile, and generating an answer to a question a parent has asked Curie to help with, is presently intended to rest principally on Curie's legitimate interests in providing the parent-requested learning service — not on consent as the basis for that core processing. This is subject to a documented, children-specific legitimate interests assessment (as part of a broader data protection impact assessment) that gives extra weight to the child's rights, freedoms and best interests, and includes safeguards such as data minimisation, high-privacy defaults and parental control described elsewhere in this notice.
- Consent: used only where Curie has chosen consent as the basis for genuinely optional, non-core processing (for example, an optional feature a parent can leave switched off), and for any processing that is legally required to be consent-based (such as certain PECR-governed communications, or special category data if that were ever involved). Because a Curie profile is used by a child, Curie also applies parental authorisation and age-appropriate verification for any consent it does collect for a child under 13, reflecting the additional relevance of UK GDPR Article 8 to children's data.
- Legitimate interests, for security and reliability: keeping the service secure, preventing fraud and abuse, and maintaining service reliability, where appropriate and not overriding the child's interests.
- Legal obligation: where Curie or a processor must keep or disclose specific information to comply with the law (for example, certain financial records).
Curie is not designed to solicit special category data (such as data about a child's health, ethnicity, religion or sexual orientation) from a child or parent. If a child incidentally shares something like this in a question, Curie does not treat that as a basis for processing it for any purpose beyond generating and, where relevant, briefly flagging that single answer, and Curie will suppress, minimise or delete such content on request rather than build a record from it.
US COPPA: how Curie treats children under 13
Curie is a child-directed service, and COPPA applies to the personal information Curie collects from children under 13. Curie applies a single, conservative COPPA-style control set to every Curie child profile regardless of the age band selected, unless and until a legally reviewed age or market design specifically decides otherwise; this is a deliberately cautious product choice, not a claim that COPPA legally treats every child profile as under 13.
- Direct notice: the Notice to Parents & Parental Permission is presented to the adult before a child profile is created, describing what is collected, why, and who it is shared with.
- Verifiable parental consent (VPC): before any non-exempt collection, use or disclosure of a child's personal information at public launch, Curie must have a parental consent method that is legally appropriate under COPPA for the sensitivity of the data involved, and this must be enabled before Curie is available to the public. During the current beta, the in-product authorisation a parent gives (see the Notice to Parents & Parental Permission) is a pre-launch product-permission mechanism, not a claim that it satisfies COPPA's VPC requirement.
- Parental rights: a parent can review what has been collected about their child, request deletion, and direct Curie to stop further collection or use of their child's information, at any time (see "Your rights" below).
- Minimisation and retention: Curie collects only what a feature needs and does not keep a child's personal information for longer than is reasonably necessary to provide the service, honour parental choices, or meet a legal obligation.
- No unnecessary conditioning: a child's ability to use Curie's core features is not conditioned on providing more personal information than is reasonably necessary for that feature.
- Integral service providers: Curie discloses a child's information to a small number of third parties (see "Processors" below) strictly to operate the service on Curie's behalf, and not for those providers' own independent use. Disclosure to a processor that is integral to the service is described to parents in this notice and the Notice to Parents & Parental Permission, and, ahead of public launch, will require verifiable parental consent before collection unless a COPPA exception applies.
Nothing in this notice should be read as a statement that Curie has been certified, approved or reviewed by the FTC or any COPPA Safe Harbor programme; Curie makes no such claim.
US state privacy rights
Depending on where you live, and where a US state comprehensive privacy law applies to Curie and your account, you may have rights such as the right to know what personal information is held about you, to correct or delete it, and to obtain a copy of it. Curie does not claim these rights apply to every user in every state, and does not claim any particular statutory threshold is or is not met; if a right does not apply as a matter of law in your case, Curie will still generally try to honour a reasonable request where practical.
Curie does not sell personal information and does not engage in targeted or cross-context behavioural advertising, so there is no "opt out of sale/sharing" mechanism to operate — there is nothing being sold or shared for that purpose in the first place.
To exercise a state privacy right, use the Contact & Data Requests page; we will verify the request and respond within the time required by applicable law.
UK Children's Code (Age Appropriate Design Code)
Curie is designed with the UK Information Commissioner's Age Appropriate Design Code in mind, in particular:
- Best interests of the child as a primary consideration in product decisions affecting children.
- High-privacy defaults for a child profile (for example, history and voice start off; sharing is limited to what a parent switches on).
- Age-appropriate, plain-language transparency, including the child-readable section of our Children's Privacy Notice.
- Data minimisation, and no use of a child's data in ways that are detrimental to their wellbeing.
- Limited, purpose-specific sharing with processors, never with unrelated third parties for their own purposes.
- Parental controls over settings, history and account deletion, and no design intended to nudge a child to weaken their own privacy.
- No profiling of a child for marketing or advertising purposes, and internal review of higher-risk features (such as voice and age-assurance) as the product develops.
This section describes our design intent and current practice; it is not, and should not be read as, an endorsement, review or approval of Curie by the Information Commissioner's Office (ICO) or any other regulator.
Who we share information with (processors and subprocessors)
Curie uses a small number of specialist providers ("processors") to operate the service. Curie is the controller — it decides what to collect and why — and each processor acts only on Curie's instructions, under contract, and is restricted from using family data for its own purposes such as advertising. Each is integral to a core feature: without it, that part of Curie could not function.
- Supabase — Database, authentication and file storage (Curie's own backend). Data involved: Adult account details, child profile details, saved question history where enabled, school enquiries, email logs. Hosted infrastructure provider acting on Curie's instructions.
- OpenAI — AI answer generation, read-aloud speech and live voice conversation. Data involved: The child's question text or spoken audio for the current turn, plus limited context such as age band and interests. Curie sends requests with storage of response state disabled where the API supports it. Curie does not claim Zero Data Retention unless that has been separately approved for our account.
- Stripe — Subscription payments for Curie Family. Data involved: Adult name, email and payment details entered directly with Stripe. Curie never receives or stores full card details. Stripe may retain billing records where required by law.
- Resend — Sending Curie's account, billing and announcement email. Data involved: Adult email address and message content. Children are never emailed directly by Curie.
Curie does not otherwise sell, rent or share personal information with third parties for their own marketing purposes.
How AI processing works
When a child asks a question or speaks to Curie, the text or audio for that turn — along with limited context such as age band and interests — is sent to OpenAI to generate the answer, and, for read-aloud or live voice, the speech itself.
Curie sends these requests to OpenAI in a stateless mode (`store: false`) where the API supports it, so Curie itself does not ask OpenAI to retain the response, and Curie does not intentionally store raw voice recordings in its own database once a turn has been processed. This does not mean the turn is forgotten everywhere: OpenAI, as the API provider, may still retain the inputs and outputs of a request, or data used for its own abuse and safety monitoring, for a limited period under OpenAI's API data-retention terms, regardless of Curie's own storage choices. Curie does not claim that OpenAI's Zero Data Retention (ZDR) has been enabled for its account, and does not claim any other modified-retention arrangement is in place, unless and until that has actually been confirmed with OpenAI; treat any statement to the contrary as an error and let us know.
See the AI & Safety page for how answers are shaped to be age-appropriate and what always-on safeguards apply.
International transfers
Curie and its processors may store and process data in the United States, the United Kingdom and other countries. Where personal data is transferred internationally, Curie relies on the safeguards its processors provide — such as the UK's International Data Transfer Addendum or standard contractual clauses — and will update this notice if that changes materially. We have not independently audited every processor's transfer mechanism against every jurisdiction's current requirements, and will correct this notice promptly if we learn it is inaccurate.
Security
Curie uses measures such as encryption in transit, salted hashing for PINs and passwords, access controls, and authentication to protect family data. No online service can guarantee perfect security, and Curie does not claim its measures are unbreakable. Curie will tell affected users and, where required, regulators, about any incident that affects their personal data.
Retention
- Account data is kept while the account is active, and for a limited period afterwards to allow recovery and to meet legal obligations.
- Saved conversation history — a child's question text and activity details, not Curie's generated answer text — is kept only while a parent leaves history switched on for that child. Turning history off stops new turns being added to that saved history from that point on; it does not, by itself, delete history already saved — a parent can clear or delete existing history separately from the Parent area or by request, and it is deleted automatically if the child profile is removed.
- Curie does not intentionally retain raw voice audio in its own database beyond what is needed to process a live conversation turn.
- Billing and payment records that Stripe is legally required to retain (for tax, audit or fraud-prevention purposes) are retained by Stripe according to its own obligations, even after a Curie account is closed.
- Email logs and delivery records held by Resend are kept only as long as needed to operate and troubleshoot account and billing email.
- Security and audit logs are kept for a limited period to investigate incidents and are then deleted or anonymised.
Your rights, and requesting them
As the adult account holder, you can, at any time from the Parent area or by contacting us:
- Review and export a child's saved question history.
- Correct a child profile's name, age band, interests or subjects.
- Turn history, voice or specific alert categories on or off, which stops further collection/use of the relevant data going forward.
- Withdraw a previously given optional permission for a child profile.
- Delete a child profile, or close the whole account, which removes the associated personal data other than what Curie or a processor must keep for legal, security or accounting reasons.
Depending on where you live, you may also have statutory rights — for example under UK GDPR, US COPPA, or applicable US state privacy laws — to request access, correction, deletion or portability of personal data, and to object to certain processing. We verify that a request comes from the account holder before acting on it, to protect the child. Contact us using the details on the Contact & Data Requests page and we will respond within the period required by applicable law.
If you are in the UK and remain unhappy with how we have handled your personal data after contacting us, you have the right to complain to the Information Commissioner's Office (ICO). Raising this right does not mean the ICO has reviewed or approved Curie's practices.
Children's privacy
Curie is designed to be used by children only through a profile an adult creates and manages. See our separate Children's Privacy Notice and Notice to Parents & Parental Permission for details specific to child profiles, including a plain-language section written for children themselves.
Changes to this notice
We will update the version date above whenever this notice changes materially. Where a change materially affects what we collect or do with a child's personal information, we will also ask the account holder to re-confirm consent to the updated notice before it applies to their child's profile.
