CureKit — Privacy Policy
Version: 2.0 Effective date: 2026-07-12
⚠️ IMPORTANT MEDICAL NOTICE CureKit is a home medication organization tool. It is not a medical device and does not provide clinical advice, diagnoses, prescriptions, or dosage recommendations. If in doubt about medication or health matters, always consult a qualified healthcare professional.
1. Introduction
This Privacy Policy explains what personal data CureKit collects, for what purposes, with whom it is shared, for how long it is retained, and what rights the user has over that data, under the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679).
By creating an account or using the CureKit app, the user confirms that they have read and understood this Policy, which complements the Terms and Conditions of Use.
2. Data Controller
The data controller responsible for the personal data collected through CureKit is Tiago Costa, holder of the CureKit service, as an individual sole trader.
📧 Contact for privacy matters: privacidade@curekit.app
3. What Data We Collect
3.1 Account data
- Name
- Password (stored only as a hash — never in plain text; via bcrypt, Supabase Auth)
- Account creation date
3.2 Kit and medication data
For each Kit the user is an Owner or Member of:
- Kit name
- Commercial name and active substance of the medication
- Expiry date, quantity, storage location
- Reason for purchase / associated symptoms (free text)
- Photo of the packaging
- Additional notes (free text)
- History and archive of deleted/expired medications
3.3 Subscription data
- Subscribed plan (Personal, Family Plus, Caregiver, Professional) and status (trial, active, cancelled)
- Subscription identifier with the payment processor (RevenueCat)
CureKit does not collect or store credit card or payment data — this is managed exclusively by the Apple App Store (StoreKit 2) or Google Play Store (Play Billing), through RevenueCat as an abstraction layer.
3.4 Usage and device data
- Notification preferences (configured expiry alerts)
- Minimal technical logs necessary for the service to function (e.g., sync errors) — no sensitive data in these logs
CureKit does not use advertising cookies or third-party trackers for marketing purposes.
4. Purposes for Which We Use Your Data
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and manage the account, authenticate the user | Performance of contract (Art. 6(1)(b)) |
| Synchronize and share the medication inventory between members of the same Kit | Performance of contract |
| Send expiry alerts configured by the user | Performance of contract |
| Process the subscription and billing (via App Store/Google Play) | Performance of contract |
| Service communications (e.g., changes to Terms, security notices) | Legal obligation / legitimate interest |
| Comply with legal obligations (e.g., responding to data subject requests) | Legal obligation (Art. 6(1)(c)) |
5. Data Sharing
5.1 Within a Kit
Medication data recorded in a Kit is visible to all members of that Kit (Owner, Member R+W, Member R), according to each person's role — this is the core purpose of the service and does not constitute sharing with third parties.
5.2 Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, real-time sync | EU — Frankfurt (eu-central-1) |
| RevenueCat | Subscription management and payment abstraction | Processes subscription identifiers; does not receive medication data |
| Apple App Store / Google Play | Payment processing and billing | According to Apple's and Google's own policies |
| Google Cloud (Vertex AI / Gemini) | Automatic recognition of medication data from packaging photos (AI scan feature) | EU — europe-west1 (Belgium) |
A Data Processing Agreement (DPA) is in place with Supabase. Where a subprocessor processes data outside the EU/EEA, CureKit ensures appropriate transfer mechanisms (e.g., European Commission Standard Contractual Clauses).
5.3 CureKit does not sell personal data to third parties, nor does it use it for targeted advertising.
6. Where Data Is Stored
All personal and medication data is stored exclusively in the European Union, in Supabase's eu-central-1 region (Frankfurt, Germany), in compliance with GDPR.
7. Data Security
- Row-Level Security (RLS) active on all tables — each user only accesses data for Kits they are a member of
- Communications encrypted via HTTPS/TLS
- Passwords never stored in plain text (bcrypt via Supabase Auth)
- Photos stored with private access policies, restricted to members of the corresponding Kit
- No sensitive data (passwords, medication details, personally identifiable information) is written to technical logs
8. Data Retention
- Data is retained while the account is active
- After subscription cancellation, data remains accessible in read-only mode for 30 days (see Terms and Conditions §5.6)
- After this period without reactivation, data is permanently deleted, unless export was requested beforehand
- When deleting the account (Art. 17 GDPR — right to erasure), the following are deleted: the user's personal data and all Kits they are an Owner of (including medications and history of those Kits). Members of those Kits immediately lose access. Kits where the user is only a Member are not affected — only their own participation in them is removed.
9. Your Rights
Under GDPR, the user has the right to:
- Access — obtain confirmation and a copy of their personal data
- Rectification — correct inaccurate or incomplete data
- Erasure ("right to be forgotten") — request deletion of their data, available directly in Profile & Settings → Delete account
- Portability — receive their data in a structured, machine-readable format (JSON/CSV), available in Profile & Settings → Export data
- Objection — object to certain processing based on legitimate interest
- Restriction — request restriction of processing in certain circumstances
To exercise these rights, in addition to the options directly available in the app, the user may contact privacidade@curekit.app. We will respond within a maximum of 30 days.
If you believe your rights have not been respected, you may file a complaint with the competent supervisory authority — in Portugal, the National Data Protection Commission (CNPD): https://www.cnpd.pt
10. Minors
CureKit is intended for users aged 18 or over. We do not intentionally collect data from minors as account holders — minors may only appear in a Kit as information recorded by a responsible adult (e.g., a child's medications), never as holders of their own account.
11. Changes to This Policy
This Policy may be updated periodically. Material changes will be communicated by email and/or in-app notification, with a request for renewed consent when legally required. The current version is always accessible in Profile & Settings → Legal documents.
12. Contact
For questions related to this Privacy Policy or the processing of your personal data:
This Privacy Policy was drafted for product purposes and should be reviewed by a lawyer specialized in data protection before publication.