Privacy Policy
Last updated: August 14, 2026
1. Overview & Privacy Officer ¶
CurioChat.ai ("we", "us", or "our") is committed to safeguarding your privacy. This policy explains how we collect, use, disclose, and protect your personal information when you visit our website or use our services.
Who is accountable. CurioChat.ai and CurioChat are trading styles of Pierre Boutquin, carrying on business as Curio Chat Academy, a business name registered in Ontario, Canada. That business is accountable for the personal information described here, including information handled on our behalf by the service providers named in section 4. Our full legal name, registration number, business address, and telephone number are in our Terms & Conditions section 23.
- Privacy Officer
- Pierre Boutquin, Founder and Privacy Officer, Curio Chat Academy — hello@curiochat.com. This is the person responsible for our compliance with this policy and with applicable privacy law, and the person who answers access, correction, and deletion requests. Put "Privacy" in the subject line and we will route it immediately.
- If we do not resolve it
- You can complain to the Office of the Privacy Commissioner of Canada, or to the privacy regulator for your province or country where one has jurisdiction — in Québec, the Commission d'accès à l'information. We would rather you came to us first, but you are not required to.
2. What We Collect ¶
- Contact Details
- Name, email, address (if provided), and payment info for purchases.
- Account Data
- Email address and user profile data.
- Usage Data
- Pages visited, actions taken, IP address, browser/device info, and cookies (see Cookie Policy).
- Communications
- Emails or messages you send to us.
3. How We Use Your Information ¶
- To provide, maintain, and improve our services and website
- To process transactions and manage your account
- To send you transactional messages you have asked for or that a purchase requires — receipts, access details, scheduling, security notices
- To analyze usage and personalize your experience
- To detect, prevent, and address security or technical issues
- To comply with legal obligations and enforce our Terms & Conditions
Marketing email is a separate permission, and accepting this policy is not it. We send promotional or newsletter messages only where we have your consent, or another basis that Canada's Anti-Spam Legislation permits — such as an existing business relationship arising from a purchase or an enquiry, for the period that law allows. Reading this policy, buying a Product, or accepting our Terms does not by itself sign you up for marketing.
- Every commercial message identifies us by name and gives a mailing address and a working contact.
- Every commercial message carries a one-click unsubscribe that works for at least 60 days and that we action promptly.
- Unsubscribing from marketing never stops the transactional messages a purchase requires, and never affects the service you bought.
- You can withdraw consent at any time, by the unsubscribe link or by writing to our Privacy Officer.
4. How We Share Your Data ¶
- Service Providers
- Payment processors, email providers, analytics services (who may access data as necessary to provide their services).
- Legal Compliance
- When required by law, regulation, subpoena, or to protect rights and safety.
- Business Transfers
- If we merge, sell, or reorganize, your information may be transferred.
- No Sale of Personal Data
- We do not sell your personal information.
5. Client Materials & Service Engagements ¶
Alongside digital content and programs, we deliver done-with-you services, audits, and advisory work ("Services"). Each engagement is described in an Order Form. Sections 5 through 8 apply only to Services; they do not change how we handle the data described in sections 2 through 4.
- Client Materials
- The content, files, documents, workflows, prompts, and records inside the workspaces, folders, and accounts you approve for the engagement, together with anything else you give us to perform it. Client Materials are a separate data class from the personal, account, usage, and communications data above, and are handled under this section.
- Ownership
- You keep ownership of your Client Materials, accounts, credentials, business data, and pre-existing intellectual property. We keep our pre-existing frameworks, methods, templates, and know-how.
- Least-privilege access
- We ask only for the named workspace and folders the engagement requires, only for as long as the work requires, and only with your approval. We minimize what we copy and keep a delivery log.
- Purpose limitation
- Client Materials are used solely to deliver the engagement described in your Order Form — not for marketing, not for product development, and never for another client. We do not reuse identifiable client content, screenshots, metrics, or examples without your separate written permission.
Data we exclude. We do not request or retain, and you should not intentionally provide:
- passwords, API keys, private keys, session cookies, recovery codes, or unredacted credential files;
- payment-card data or government identity documents;
- patient, health, student, employment, financial-account, or other regulated records, unless a separate written data agreement is signed first;
- third-party confidential information you are not authorized to share; or
- folders unrelated to the agreed workflows.
If excluded data appears anyway, we stop work on that material, do not propagate the copy, tell you, and follow the incident and deletion path in section 8.
Personal information about other people, inside your Client Materials. Real workflows contain real people — a customer list, an inbox, staff names in a process document. Excluding regulated records does not make that go away, so these commitments cover it. For personal information inside your Client Materials, you decide why and how it is used and we act only as your service provider:
- We act only on your instructions
- We process that personal information solely to deliver the engagement described in your Order Form and on your documented instructions — never for our own purposes, never to build a profile, never for marketing, and never for another client. If an instruction appears to us to breach applicable privacy law, we say so before acting.
- You confirm you are allowed to share it
- You confirm you have the lawful authority — consent, or another valid basis, and any required notice to the people concerned — to give us access to that personal information for this purpose. You remain responsible for that, because you hold the relationship with those individuals; we cannot verify it from inside your workspace.
- Subprocessors are named before use
- Where a third-party AI, storage, or hosting provider will process your Client Materials, we identify it to you before we use it, we bind it to protections no weaker than these, and you may refuse it — see section 6. We keep a current list and tell you before adding one for your engagement.
- Safeguards and people
- Access is least-privilege and limited to those who need it to deliver your engagement, under confidentiality obligations. We use encryption in transit and at rest for material we hold, and we keep a delivery log of what was accessed.
- Incident notice runs to you
- A confirmed unauthorized access, disclosure, or loss affecting your Client Materials is reported to you without unreasonable delay and with the detail you need to meet your own reporting duties — what happened, what was affected, when, and what we did. Section 8 sets out the rest.
- We help with requests from individuals
- If one of your customers or staff asks us directly to access, correct, or delete their information, we do not answer for you — we refer them to you and tell you. We assist you in responding, at no extra charge for a reasonable volume.
- Return and deletion at closeout
- At the end of the engagement we return or delete the personal information in our working copies on the schedule in section 8, and record any exception we are legally required to keep.
Where a data processing agreement, a service-provider addendum, or a regulated-records agreement is required for your situation, we sign one. Ask, and it is attached to your Order Form — it does not cost extra, and it takes precedence over this section for that engagement.
Which document controls. This Policy and our Terms & Conditions govern general site, account, payment, and privacy matters. Where an accepted Order Form sets service-specific terms for a named engagement — scope, scheduling, workspace access, confidentiality, deliverables, or proof permissions — that Order Form controls for that engagement.
6. Confidentiality, Third-Party AI Services & Model Training ¶
- Confidentiality
- Both sides protect the other's non-public business, technical, and client information with reasonable care, and use it only to perform or receive the Service. We disclose it only to approved service providers, or where we are legally obliged to.
- Third-party AI and storage services
- We identify any third-party AI or storage service that will receive your Client Materials before we use it. You may refuse that transfer, and we will use a local or manual alternative where one is feasible.
- No model training
- We do not use Client Materials to train a CurioChat model, and we do not submit them for external model training. Any exception would need your separate, specific, written consent.
7. Recording, Measurement & Proof Permissions ¶
- Sessions are not recorded by default. A recording requires your affirmative consent naming the purpose, where it is stored, who can access it, and when it is deleted.
- Measurement is private. Agreeing to measurement lets us evaluate the service privately — a baseline, checkpoints, and a final measure. It does not authorize any public use.
- Taking part in an engagement never authorizes a testimonial, case study, screenshot, quote, metric, or public result claim. Public use requires a second, separate permission that names the exact statement or artifact and each surface where it may appear.
- Silence is "no". Permission is never a condition of price or service, and you can withdraw it at any time.
What happens when you withdraw permission. Tell our Privacy Officer, in any form of words. We stop all future use immediately, and we remove the quote, case study, screenshot, metric, or claim from every live surface we control — our website, our emails in progress, our social profiles, and our sales material — within 10 business days, and sooner where we can.
Two honest limits. We cannot recall an email already delivered, a printed page, a third party's repost, a search-engine cache, or an archive we do not operate — for those we ask, but we cannot compel. And we keep a record of what was published, when, with what permission, and when it was withdrawn, because that record is how we substantiate that the claim was permitted while it ran; it is kept for that purpose only and is never republished.
8. Service Data Retention, Deletion & Incidents ¶
- Temporary workspace copies and exports
- Deleted within 30 calendar days after the engagement's final readout, or earlier on verified request.
- Session recordings, where separately approved
- Delivered to you, and our copy deleted within 30 calendar days after the final readout.
- Credentials exposed by accident
- Work stops, the copy is not propagated, we ask you to rotate the secret, and any accidental local copy is deleted immediately. The incident note never records the secret itself.
- Delivery log, hours, and de-identified measurements
- Retained for up to 24 months so we can analyze delivery across engagements, then deleted or irreversibly aggregated. A client identifier only — no raw workspace content.
- Approved quotes and case-study evidence
- Retained while the claim remains published, plus the period needed to substantiate it. When you revoke permission, we withdraw the claim from future use.
- Contracts, invoices, tax, and dispute records
- Retained for the applicable legal and accounting period.
Closeout. At the end of an engagement we revoke or remove our access, return the agreed deliverables, delete temporary material on the schedule above, and record any exception. A failed deletion or revocation is an open incident, not a completed closeout — access stays blocked until it is verified.
Deletion requests. We acknowledge your request promptly and complete it within 30 calendar days, except for records we must keep by law or to establish a legal claim. Where an exception applies, we record it and its basis and tell you.
Incidents. A confirmed unauthorized access, disclosure, or loss is escalated immediately, contained, logged, and communicated to you without unreasonable delay. Alongside telling you, we do the following — these are legal duties, not courtesies, and they apply to every incident involving personal information we are accountable for, not only to service engagements:
- We assess real risk of significant harm. We consider the sensitivity of what was involved and the probability of misuse — identity theft, fraud, humiliation, damage to reputation or relationships, loss of employment or business opportunity.
- We report qualifying breaches to the regulator. Where a breach creates a real risk of significant harm, we report it to the Office of the Privacy Commissioner of Canada as soon as feasible, and to any other regulator with jurisdiction over the affected people, in the form and time that law requires.
- We notify the individuals affected. Directly where we can reach them, and indirectly where direct notice is not possible — as soon as feasible, in plain language, with what happened, what it means for them, what we have done, and what they can do.
- We notify other organizations that can reduce the harm — a payment processor, an employer, a law-enforcement body — where doing so is permitted and would help.
- We keep a record of every breach, reportable or not, for at least 24 months, and provide those records to the Commissioner on request. Recording it does not depend on our own judgement that it was serious.
9. International Data Transfers ¶
We operate from Canada, and your information is processed in Canada and in other countries where our service providers operate — principally the United States, and in some cases the European Union or the United Kingdom, depending on the provider and the region it serves you from.
The categories of provider that may process personal information outside Canada on our behalf:
- Web hosting and email delivery — serving this site and sending transactional and marketing email.
- Payment processing — taking payment and issuing receipts. Card details go to the processor, not to us.
- Analytics and marketing platforms — measuring site use and managing subscriptions.
- Video conferencing and scheduling — running and booking sessions.
- Cloud storage and AI services used in service delivery — named to you in advance and refusable, per section 6.
Two things follow from this, and we mean both. First, information held in another country is subject to that country's laws, and may be accessible to its courts, law enforcement, and national-security authorities under their legal processes. We cannot contract that away and we do not pretend otherwise. Second, transferring information to a provider does not transfer our accountability for it: it remains ours. We use providers bound by contract to protections comparable to those in this policy, limited to processing on our instructions, and — where a transfer needs a recognized legal mechanism such as standard contractual clauses — we put one in place.
Ask our Privacy Officer and we will tell you where a particular category of your information is processed and by what kind of provider.
10. Data Security & Retention ¶
- Data is stored securely using industry-standard safeguards, including encryption in transit and at rest.
- Access is limited to authorized personnel and trusted service providers, on a need-to-know basis.
How long we keep things. "As long as necessary" is not an answer, so here are the periods. Each runs from the trigger named, and at the end we delete the information or irreversibly de-identify it. Retention periods for Client Materials and service records are in section 8 and are shorter.
- Account data
- Kept while your account is open, and for 24 months after you close it or after your last sign-in, whichever is later — so you can be restored if you come back, and so course access can be re-verified. Deleted sooner on request, subject to the legal exceptions below.
- Contact details and marketing preferences
- Kept until you unsubscribe or ask us to delete them. After that we keep the minimum needed to honour the request — an email address on a suppression list — indefinitely, because that is the only way to guarantee we do not contact you again.
- Usage and analytics data
- Identifiable usage records for 26 months from collection, then deleted or aggregated. Cookie lifetimes are in our Cookie Policy.
- Payment and transaction records
- Seven years from the end of the tax year the transaction falls in — the period Canadian tax law requires. We never hold full card numbers; those stay with the payment processor.
- Communications with us
- Support and enquiry correspondence for 24 months from the last message in the thread. Correspondence forming part of a contract, complaint, or dispute is kept with the contract records below.
- Contracts, invoices, and dispute records
- Seven years from the end of the engagement or the resolution of the dispute, whichever is later.
- Security and access logs
- 12 months, so we can investigate an incident after the fact. Our administrative audit log is kept indefinitely because it is the record of who did what to your data — it holds actions and identifiers, not content.
- Breach records
- At least 24 months from the date of the breach, per section 8.
We may keep information past these periods only where the law requires it, or where it is needed to establish, exercise, or defend a legal claim that is live at the time. Where that applies to a deletion request, we tell you what we kept and why.
11. Your Rights & Choices ¶
- You can access, correct, or request deletion of your personal information by writing to our Privacy Officer (section 1). We respond within 30 days.
- You can withdraw a consent you gave us, at any time, subject to legal or contractual limits we will explain when you ask.
- You can ask what we hold, why we hold it, and who we have disclosed it to.
- You may unsubscribe from marketing at any time (unsubscribe links in all promotional emails).
- For cookies and tracking, see Cookie Policy for how to manage preferences.
- You can complain to a privacy regulator without going through us first (section 1).
Rights that come from where you live. We operate from Canada and our services are aimed at the Canadian and United States markets. Privacy laws elsewhere — including in Québec, the European Union, the United Kingdom, and California — grant residents further rights such as portability, erasure, objection, and restriction of processing. Where such a law applies to our handling of your information, we honour the rights it gives you, and you can exercise them through our Privacy Officer.
We state that as it is rather than claiming blanket compliance with every regime. We do not currently target or market to the EU or the UK, and this policy is not a full notice under the EU or UK General Data Protection Regulation. If we begin serving those markets, we will publish that notice — legal bases, recipients, transfer safeguards, retention criteria, and complaint routes — before we do, not after.
12. Children's Privacy ¶
Our services are not directed to children under 16. We do not knowingly collect personal information from minors.
13. Changes to this Policy ¶
We may update this policy occasionally. Major changes will be announced via email or on the website 7 days in advance.
14. Contact Us ¶
For questions, or to exercise any right in section 11, write to our Privacy Officer — Pierre Boutquin, Founder, Curio Chat Academy — at hello@curiochat.com, with "Privacy" in the subject line. Our postal address and telephone number are in Terms & Conditions section 23.