Legal

Privacy Policy

How Curatx collects, uses, and protects your information.

📅 Effective date: May 9, 2026  ·  Last updated: May 9, 2026

1 Overview

Curatx, Inc. ("Curatx", "we", "us", or "our") operates the AI Engineering Platform available at curatx.ai and weave.curatx.ai (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your information.

By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Service.

Summary: We collect only what is necessary to provide and improve the Service. We do not sell your personal data. Your code and knowledge graph data remain yours and are never used to train shared AI models without your explicit consent.

2 Information We Collect

Account & Contact Information

When you register or book a demo, we collect:

  • Name and email address
  • Company name and job title
  • Password (stored as a cryptographic hash — never in plain text)
  • Billing information processed by our payment provider (we do not store card numbers)

Usage & Platform Data

As you use the Service, we automatically collect:

  • Log data: IP address, browser type, pages visited, timestamps
  • Feature usage telemetry: which platform features are used and how often
  • Error reports and crash diagnostics
  • Session duration and navigation patterns

Code & Repository Data

When you connect a code repository or workspace, Curatx ingests:

  • Repository metadata (file structure, commit history summaries)
  • Code content indexed for knowledge graph construction
  • Architecture decision records (ADRs), runbooks, and documentation you choose to include
  • Agent session memories and knowledge graph entries you generate

Integration Data

If you connect third-party services (GitHub, GitButler, Jira, Slack, etc.), we receive only the data necessary to deliver the connected feature — such as repository names, pull request metadata, or issue identifiers. We do not read or store content beyond what is needed to operate the integration.

3 How We Use Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Build and maintain your team's knowledge graph
  • Power AI Coding Agent suggestions grounded in your codebase context
  • Authenticate users and manage access controls
  • Send transactional emails (account confirmations, billing receipts, security alerts)
  • Respond to support requests and communicate about the Service
  • Detect, investigate, and prevent security incidents and abuse
  • Comply with legal obligations
  • Analyse aggregate, anonymised usage trends to improve product features
We do not use your code or knowledge graph data to train shared or general-purpose AI models. Curatx's AI features operate on your data within your isolated tenant environment only.

4 Sharing & Disclosure

We do not sell, rent, or trade your personal information. We may share data in the following limited circumstances:

Service Providers

We engage trusted third-party vendors to help operate the Service (e.g., cloud infrastructure, payment processing, analytics). These providers access data only as needed and under confidentiality obligations.

Business Transfers

If Curatx is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

Legal Requirements

We may disclose information if required to do so by law, court order, or a valid government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

With Your Consent

We may share information for any other purpose with your explicit consent.

5 AI & Code Data

Curatx is an AI Engineering Platform that processes your source code, documentation, and architecture decisions to build a knowledge graph unique to your organisation. We treat this data with the highest level of care:

  • Tenant isolation: Your knowledge graph and code indexes are stored in logically isolated environments and are never accessible to other customers.
  • No model training: Your code and memory data are not used to train, fine-tune, or improve any AI model that is shared with other customers or the public.
  • Inference only: Code context is retrieved and passed to AI models solely at query time to generate responses for your team.
  • Model providers: Curatx uses third-party AI model providers (including Anthropic) to power inference. Data sent to these providers is subject to their data processing agreements, which prohibit use of customer data for model training.
  • Deletion: Upon account termination, all code indexes, knowledge graph data, and stored memories are deleted within 30 days.

6 Data Retention

We retain personal account data for as long as your account is active or as needed to provide the Service. You may request deletion of your account at any time by contacting privacy@curatx.ai.

  • Account data: Retained for the duration of your subscription plus 90 days
  • Code & knowledge graph data: Deleted within 30 days of account closure
  • Usage logs: Retained for up to 12 months for security and debugging purposes
  • Billing records: Retained for 7 years as required by applicable tax law

7 Security

We implement industry-standard technical and organisational measures to protect your data:

  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Role-based access controls limiting internal access to customer data
  • Regular vulnerability scanning and penetration testing
  • Audit logging of all access to production systems
  • Incident response procedures with customer notification commitments

No method of transmission over the internet is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your information, we will notify you in accordance with applicable law.

8 Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data ("right to be forgotten")
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing of your data for certain purposes
  • Restriction: Request that we restrict processing in certain circumstances
  • Withdraw consent: Where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at privacy@curatx.ai. We will respond within 30 days. We may need to verify your identity before processing your request.

If you are located in the European Economic Area (EEA), UK, or California, additional rights may apply under GDPR, UK GDPR, or the California Consumer Privacy Act (CCPA) respectively.

9 Cookies

Curatx uses cookies and similar tracking technologies to operate and improve the Service.

Essential Cookies

Required for the Service to function. These cannot be disabled and include session authentication tokens and security cookies.

Analytics Cookies

Help us understand how users interact with the platform so we can improve it. These are anonymised and do not identify individual users.

Preference Cookies

Remember your settings (e.g., theme, language) across sessions.

You can control cookies through your browser settings. Disabling essential cookies may prevent the Service from functioning correctly.

10 International Transfers

Curatx is headquartered in the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US or other countries where our service providers operate.

Where required, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or other lawful transfer mechanisms to protect data transferred from the EEA or UK. You may request a copy of these safeguards by contacting privacy@curatx.ai.

11 Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send an email notification to account holders
  • Display a notice within the platform for 30 days following the change

Continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes.

12 Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Curatx, Inc.
Privacy Team
privacy@curatx.ai

For general enquiries: hello@curatx.ai

If you are located in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.