← CuraJournals

Privacy Policy

Last updated October 5, 2026

This policy describes how the operator of CuraJournals ("we") handles your information when you use CuraJournals on the web or in the mobile app. The short version: we collect what the product needs to work, we do not sell your data, we do not run ads or third-party advertising trackers, and you can export or delete everything at any time.

What we collect

  • Account: name, email, a hashed password (never the password itself), and profile image.
  • Professional profile: specialty, subspecialty, keywords, career stage, and reading preferences — used to personalize your digest and briefings.
  • Content you create: questions you ask the Ask feature and their answers (stored as conversations), saved articles, and article ratings.
  • Usage: which articles were served to you and their read/reviewed status, digest history, internal logs of AI usage (token counts and cost — used to enforce fair-use limits), and monthly counts of the Ask questions that got an answer and of the audio read to you in the AI voice.
  • Listening records: for each sentence we prepare to read to you in the AI voice (including passages fetched just ahead of playback), a one-way fingerprint (hash) of the sentence, not the sentence itself, with its length, the month it was counted in, and when it was first and last requested. This lets you replay a sentence on any device without it being counted again. Safety lines, such as the spoken caveat, are not recorded. The fingerprints can be matched against text stored in CuraJournals, so we treat them as part of your reading history.
  • Device: timezone, and — if you enable notifications on mobile — a push token.
  • Reports about AI-generated text: when you use the “Report” link on a summary, briefing or Ask answer, we store the reason you selected, any note you write, and a copy of the exact text you were looking at.

We do not collect patient data, and you must not enter patient-identifying information anywhere in CuraJournals (see our Terms).

How we use it

  • To build and deliver your personalized literature digest and briefings.
  • To answer your questions in the Ask feature, using your recent digest as context.
  • To send push notifications you have opted into.
  • To enforce usage limits and prevent abuse.
  • To count your monthly use of Ask and of the AI voice, show it to you in Settings, and apply plan limits if paid plans are introduced.

We do not sell personal data, we do not share it with advertisers, and we do not use third-party analytics or advertising SDKs.

Service providers (sub-processors)

CuraJournals is built on the following services, which process data on our behalf to provide the product:

  • Anthropic — AI summaries, briefings, and Ask answers. Data involved: Article text, your questions, and your specialty/experience profile.
  • OpenAI — Text-to-speech audio. Data involved: The text you choose to have read aloud (briefings, summaries or abstracts, article and journal titles, and Ask answers; in Drive Mode, also the profile keyword an article matched), including the next few passages fetched just ahead of playback, plus a narrator-style instruction built from the specialty and subspecialty in your profile and the voice style you choose in Settings (mood, delivery, accent and emphasis) (no name, email, or account ID).
  • Google (Gemini API) — Text-to-speech audio, when you choose a Gemini voice. Data involved: The text you choose to have read aloud (as for OpenAI above, including the next few passages fetched just ahead of playback), plus the voice style you chose (mood, delivery, accent and emphasis); nothing from your profile, and no name, email, or account ID.
  • Supabase — Database hosting. Data involved: All account data listed above.
  • Vercel — Application hosting. Data involved: Request traffic and server logs.
  • Expo — Mobile push notifications. Data involved: Your device push token and notification content.
  • NCBI / PubMed, Europe PMC, Crossref, Unpaywall — Literature retrieval. Data involved: Search queries and article identifiers (not linked to your account by these services).

Cookies and local storage

The web app sets a first-party session cookie to keep you signed in, and uses your browser's local storage for display and read-aloud preferences (for example theme, font size, voice and speed). The mobile app keeps the same kind of preferences on your device. There are no advertising or cross-site tracking cookies.

Retention

A weekly job deletes the following once they are more than 120 days old:

  • digests, counted from the day each was built;
  • Ask conversations, counted from the last answered message in the conversation;
  • your reading history — which articles you opened and which you marked reviewed — counted from when each was recorded;
  • internal logs of AI usage (token counts and cost);
  • listening records, counted from the last time each sentence was requested.

Two kinds of content are kept longer:

  • Saved articles are kept until you unsave them or delete your account, however old they are.
  • Content under an open report. While a report about AI-generated text is open or under review, the article, digest or Ask conversation it concerns — and the papers an Ask answer cited — are kept past 120 days. Once the report is resolved they follow the usual schedule.

Your account, profile and settings, your article ratings and your monthly listening totals are kept while your account exists, as are logs of the literature searches run to build your digests (which include the search terms taken from your profile). Reports you file about AI-generated text are not on the 120-day schedule; see below. Your monthly count of Ask questions is deleted shortly after the month ends.

Deleting your account (Settings → Delete account, on web or mobile) permanently removes your account and associated content — profile, digests, conversations, saved articles, ratings, reading and listening history, and usage counts — from the production database. AI usage and search logs are not deleted with the account: your user identifier is removed from both, and the search terms from search logs, so we can reconcile aggregate usage and reliability. AI usage logs still age out after 120 days.

One exception, stated plainly. If you reported AI-generated text as wrong, unsafe or offensive, that report is kept after your account is deleted — with your user identifier removed, so it is no longer linked to you. It holds the reason you chose, any note you wrote and the AI text you reported. We keep it because a report that something unsafe was generated has to outlive the account that filed it; otherwise deleting an account would erase the record of what went wrong. If you would like a report you filed removed entirely, email hishamgb@gmail.com.

Your rights

  • Export: download a JSON copy of your data at /api/account/export while signed in.
  • Delete: remove your account and data from Settings at any time.
  • Questions or requests: hishamgb@gmail.com.

Security

Passwords are hashed with bcrypt; transport is encrypted (HTTPS); database access is restricted to the application. No system is perfectly secure — if we learn of a breach affecting your data we will notify you.

Children

CuraJournals is intended for medical professionals and trainees and is not directed at children under 16.

Changes

We will update this page when our practices change and revise the "last updated" date above. Material changes will be announced in the app.