Policy
Privacy
Last updated September 1, 2026
Who this covers
This policy describes the Curate website and the Curate API. The website is a product landing page. Accounts, bookmarks, and collections live on the Curate server when you use the product.
This website
The public site does not ask you to sign up or save bookmarks. It stores only your theme choice (light or dark) in your browser.
Pages load fonts from Google Fonts. Password-reset pages on the Curate app also load styles from public CDNs.
What the service stores
When you create an account, Curate stores:
- Name, username, email, and a hashed password
- Bookmarks you save (title, URL, category, tags, and notes)
- Collection names and descriptions
- A short-lived reset token if you ask to change a forgotten password
How it is used
That data is used only to run your account, keep your library, send a password-reset email when you ask for one, and return your bookmarks to the client you signed in with.
Where it lives
Account and library data sit in the MongoDB database for the Curate instance you use. Password-reset email is sent through Brevo. Session cookies are used on the password-reset pages so those forms can work.
What we do not do
- We do not sell your data.
- We do not run ads on Curate.
- We do not include analytics SDKs on this site.
- Your library is private. There is no public feed.
Deleting your data
You can delete individual bookmarks and collections from your library. Deleting your account removes the account, bookmarks, and collections stored for you on this server.
Contact
For privacy questions, contact the developer at email.
If this policy changes, the date at the top of this page will change.