Privacy policy

Last updated October 5, 2026

What we collect

Your account email, the product photos and notes you upload, the outputs we generate for you, and usage records such as credits spent and job history. Payment details are handled by our payment processor and never stored by us. If you leave your email on one of our free tools, we keep that email, which tool you used and whether you ticked the box to get tips and offers. If you connect Curvi to an assistant such as ChatGPT, we also keep a record of that connection and receive what the section on assistants below describes.

How we use it

To run the service: analyzing your photos, generating your packs, billing your plan and supporting your account. We send your photos to AI providers only to process your own requests, on API tiers that do not train on your inputs.

We email you about your account, the packs you make and your payments. If you have an account, we also send a few emails with product tips and offers, such as a reminder to make your first pack. Each of those has a one click unsubscribe link, and you can turn them off any time under Settings, Emails. If you left your email on a free tool, we send you tips and offers only if you ticked the box to get them, and we email you when packs are back only if you asked us to. We send email through Resend, and we keep a record of which emails we sent and who unsubscribed, stored as a scrambled code of your address rather than the address itself.

Sharing

We do not sell your data. We share it only with the infrastructure providers that run the service, such as hosting, storage, authentication, email delivery (Resend) and AI processing, each bound by their own data agreements. When you publish a share page for a pack, the images on it and the product title are public to anyone with the link, and to everyone if you also list it in the gallery. Share page images are served without their original photo metadata. You can take a share page down at any time. When you use Curvi from ChatGPT or another assistant, we send the results you ask for to that assistant, so OpenAI receives them when you use ChatGPT or Codex.

The companies that process data for us today are Supabase, Render, Cloudflare, Stripe, OpenAI, Anthropic, Google (Gemini API), Black Forest Labs and fal. Our subprocessors page says what each one does and what it receives.

Using Curvi from ChatGPT and other assistants

When you connect Curvi to ChatGPT or another assistant, the assistant receives a private id for your Curvi account and your email address when you sign in, plus any other sign in details it asks for, which the connect page lists.

For each request we receive a sign in token for your Curvi account, the photos you attach, the choices the assistant sends, and hints the assistant adds: your language, an approximate location (city, region, country, time zone and rough coordinates), the app or browser in use, and anonymous ids for you, the conversation and your organization. We do not store these hints. We do not receive your conversations. Photos for a pack are kept like any other upload; photos sent only for a credit estimate or a main image check are not stored.

We send back what the assistant asks for, and the company that runs the assistant receives it: OpenAI for ChatGPT and Codex. That can be:

  • your account email and workspace name
  • product titles, pack ids, pack status and how far a pack has got
  • the channels each pack is for, file names and types, image previews and download links, and how long the links work
  • credits held and credits used, the credits a pack would need, your workspace's credit balance, and a signed code for an estimate and how long it is valid
  • your workspace's optional monthly credit budget, its monthly limit, remaining headroom, active credit holds, delivered credits used this month, and the UTC period start and end
  • image check results, the size of a checked photo and the rules it was checked against
  • stored product fidelity measurements for delivered files: average color difference, largest color difference, share of exactly matching pixels, number of pixels compared, measurement limits, type of image measured, and whether the file is the original upload
  • the channels a pack would leave out and why
  • the channels Curvi offers, other names it accepts for them, their sizes, the pack sets, backgrounds and scene styles, and which of them your plan includes
  • a short message about each request, and whether it repeated an earlier one

Connection records, which say which assistant can use which workspace and when it was last used, stay until you close your account, including after you disconnect, so a disconnected assistant cannot come back without asking you. Request logs, which include IP addresses, are kept for up to 30 days. You can disconnect at any time in Settings, Connected apps.

Retention and deletion

WhatHow long we keep it
Original files you upload, such as product photosWe delete them once they are 30 days old and no pack from the last 30 days used them. A photo shown on a share page stays until you take that page down.
Your pack filesWe keep them while your account is open.
Temporary processing files, such as cutouts we reuseWe delete them within about 7 days.
Photos you try in the free preview without an accountWe delete them within 2 days.
Records of the assistants you connect, such as ChatGPTWe keep them until you close your account, including after you disconnect, so a disconnected assistant cannot come back without asking you.
Pack help reports, replies and related internal notesWe keep open reports while your workspace exists. We delete resolved reports and their history after 180 days, or when the workspace is deleted. A report does not extend the lifetime of your original photos.
Optional credit budget settings and changesWe keep the current setting while your workspace exists and its change history for 365 days. Deleting the workspace deletes both.
Completion webhook settings and delivery recordsWe keep endpoint settings until you remove them or delete the workspace. We delete completion events and delivery records after 30 days. We do not store receiver response bodies.
Your account and workspaceWhen you delete your account, we delete your workspace with its products, photos, packs and files straight away. The rows below say what we keep after that.
The renewal terms you agreed to when you bought a planWe keep this record for 3 years after you agree, or 1 year after your plan ends if that is later, including after you delete your account, because renewal laws require it.
Records of the billing emails we sent youWe keep this record for 3 years after you agree, or 1 year after your plan ends if that is later, including after you delete your account, because renewal laws require it.
Encrypted copies of our databaseWe keep them for up to 180 days, so data you delete can remain in them until then.
Request logs and error reportsWe keep them for up to 30 days.

You can download your data or delete your account at any time in Settings. You can also ask us to delete your data, and we honor applicable privacy laws, including GDPR and CCPA requests.

Cookies and analytics

We use essential cookies to keep you signed in. We also use analytics cookies from PostHog to learn which pages help sellers, and the OpenAI Ads pixel to measure which ads bring sellers here, but only if you accept them in the cookie banner. If you decline, or have not chosen yet, neither of them loads and no analytics or advertising cookie is set. You can change your choice at any time from Cookie settings in the site footer.

If you accept, we also keep one first party cookie for 90 days that remembers the first page you opened here, the site that sent you and any campaign tags in that link. When you create an account, we store with it how you found us: that first visit if you accepted, the campaign tags and share or referral code in the link you followed, the page where you clicked Start free, and your answer to "How did you hear about Curvi?" if you gave one. We use it only to learn which places bring sellers, and you can ask us to delete it any time. Declining cookies deletes that cookie.

How we count visitors

We count visits to this site ourselves, without cookies and without storing anything on your device. When a page opens, your browser tells our server which page it was, any campaign tags in its link and, for the first page of a visit, which site sent you there. Our server mixes your IP address and browser details with a random code that changes every day and a secret key that is kept apart from our database. We keep only the scrambled result and whether the page was opened on a phone, tablet or computer. We never store your IP address or your full browser details. Each daily code is deleted once two days have passed, and copies in our database backups expire on the backup schedule. Without the daily code, the scrambled result cannot be traced back to an IP address or matched with a visit on another day. We use the count only to see how many people visit, never to identify anyone.

Who we are and how to reach us

Curvi is run by AIManagement Inc., 131 Continental Drive, Suite 305, Newark New Castle, DE 19713.

Privacy questions and requests go to support@curvi.ai. We reply within two business days.