Privacy Policy
Last updated: September 3, 2026
This Privacy Policy explains how Curilio (“Curilio,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the Curilio staff-training platform available at app.curilio.com and its related applications and services (the “Service”). Please read it alongside our Terms of Service.
1. Who we are and how this policy applies
Curilio provides a platform that businesses use to deliver training courses and quizzes to their staff and to track completion. This policy applies to two groups of people:
- Account users — the owners, administrators, and managers who create a business on Curilio and sign in to configure training and view results. For their account information, Curilio is the data controller.
- Trainees (employees) — the staff members whose names and email addresses a business adds so they can be assigned training. For this information, the business that added them is the data controller and Curilio acts as its service provider / processor, handling the data on the business’s behalf and under its instructions.
If you are a trainee and want to access, correct, or delete your information, please contact your employer first. We will support them in responding to your request.
2. Information we collect
Information account users provide. When you create an account and set up a business, we collect your email address, your business name and optional logo, your location names, and your selected plan tier. We do not use passwords anywhere in the Service: you and every other user sign in by requesting a one-time numeric code (or a one-time sign-in link) sent to your email address, and we never collect or store a password for any account user or trainee.
Information businesses provide about trainees. To assign training, a business adds each trainee’s full name, email address, and assigned location. Trainees sign in with the same one-time email code described above. When a trainee first signs in we create an authentication record for them keyed to that email address.
Training activity. As trainees work through courses, we record quiz answers, scores, the number of attempts, which modules and courses have been completed, and the dates and times of that activity.
Task completion photos. Where a business configures a recurring task or checklist that requires a photo to confirm completion, the trainee’s uploaded photo is stored using our cloud storage provider and is visible to that business’s authorized account users. Businesses are responsible for configuring photo requirements appropriately and for instructing staff not to include other people, or other sensitive subject matter, in these photos.
Billing information. If a business subscribes to a paid plan, our payment processor collects the billing details needed to process the subscription, such as the account owner’s name, billing address, email address, and payment card information. We do not receive or store full payment card numbers ourselves; our payment processor handles and secures that information directly.
Administrative activity. We keep an audit log of significant actions taken by account users — for example inviting or removing a team member, creating or assigning a course, or deleting data — together with the acting user’s email address and a timestamp.
Information we collect automatically. When the Service is used, our infrastructure providers automatically log technical data such as IP address, browser and device type, pages requested, and timestamps, for security and reliability. We use a small number of essential cookies and browser storage entries to keep you signed in and to remember training progress and interface preferences on your device. We do not use advertising cookies, and we do not sell or share personal information for cross-context behavioral advertising.
Analytics on our public website. Our public marketing pages use Google Analytics to understand how visitors find and move around the site, so we can improve it. Google Analytics sets cookies and collects information such as pages viewed, approximate location derived from IP address, referring website, and device and browser type. We use it only to see aggregate patterns, not to identify individual visitors.
Google Analytics runs only on our public marketing pages. It is not loaded on the signed-in application, so trainee training activity, quiz results, and task completions are never sent to it. You can opt out across all websites using Google’s browser opt-out add-on, or by blocking cookies in your browser settings. Blocking it has no effect on your ability to use the Service.
3. How we use information
- To provide, operate, maintain, and improve the Service;
- To deliver assigned training to trainees and to show completion and quiz results to their business’s authorized account users;
- To authenticate users, secure accounts, prevent fraud and abuse, and keep an audit trail;
- To send transactional and service messages, such as one-time sign-in codes, team invitations, and important notices about the Service;
- To respond to support requests and communicate with you about your account;
- To comply with legal obligations and to establish, exercise, or defend legal claims.
Where the law requires a legal basis for processing, we rely on the performance of our contract with account users, our legitimate interests in operating and securing the Service, your consent where we ask for it, and compliance with legal obligations. For trainee data, the business that added the data is responsible for the legal basis and for providing any required notice to its staff.
4. How we share information
We do not sell personal information. We share it only as described here:
- With the employing business. Trainee identity and training results are visible to the owners, administrators, and (within their assigned location, where applicable) managers of the business that added the trainee. That visibility is the core purpose of the Service.
- With service providers. We use Google LLC for cloud hosting, database, file storage, and authentication (Firebase Authentication, Cloud Firestore, Firebase Storage, and Firebase App Hosting on Google Cloud) and for website analytics on our public marketing pages (Google Analytics), Stripe as our payment processor to handle subscription billing and payment card information, and a transactional email provider to deliver account emails. These providers process data on our behalf under contractual confidentiality and security obligations.
- For legal and safety reasons. We may disclose information if required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect the rights, property, or safety of Curilio, our users, or the public.
- In a business transfer. If Curilio is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction; we will require the recipient to honor this policy or give you notice and choice.
5. International data transfers
Our infrastructure providers may store and process data on servers located in the United States and other countries. Where personal information is transferred out of your country, we rely on appropriate safeguards such as standard contractual clauses offered by our providers.
6. Data retention
- Account and business configuration data is kept for as long as the business account is active.
- Trainee records and training history are kept until the business deletes them or closes its account. A business may “archive” a trainee, which retains their training history while preventing further sign-in.
- Audit-log entries are retained for up to 12 months.
- Backups are retained on a rolling basis for a limited period and then overwritten.
When a business account is deleted, we delete or irreversibly anonymize the associated personal information within 30 days, except where we are required to retain it to comply with a legal obligation or to resolve a dispute. Before that data is removed, the business may request a one-time export of its course content as described in the Terms of Service.
7. How we protect information
We use technical and organizational measures designed to protect personal information, including encryption in transit (HTTPS), access controls and least-privilege permissions, database security rules that isolate each business’s data, and separation of quiz answer keys from the content shown to trainees so that answers are scored on our servers and not exposed in the browser. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a security breach that affects your personal information, we will notify you and, where a business is the controller of the affected data, that business, without undue delay, and we will provide information reasonably needed to help you meet any notification obligations you may have.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Account users can update much of their information directly in the app. To make a request, contact us at support@curilio.com. We may need to verify your identity before acting. If you are a trainee, we will refer your request to your employer, who is the controller of that data. You also have the right to lodge a complaint with your local data protection authority.
9. Age of trainees
The Service is used by businesses to train their own staff, and staff in the industries we serve may include minors who are legally employed. Curilio does not independently verify the age of any trainee. We rely entirely on the business that adds a trainee to confirm that the trainee is of legal working age in their jurisdiction and that the business has obtained any parental or guardian consent required by applicable law for the collection and processing of that trainee’s information. The Service is not directed to children as consumers, and we do not knowingly collect personal information directly from children. If you believe a trainee’s information was provided to us without a required consent, contact us and we will work with the responsible business to address it.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above, and for material changes we will provide a more prominent notice within the Service or by email. Your continued use of the Service after an update takes effect means you accept the revised policy.
11. Contact us
Questions or concerns about this policy or our handling of personal information can be sent to support@curilio.com.