Privacy Policy

Effective date: August 14, 2026 · Version: 1.3

Curio provides encrypted email for therapists in Canada. This Privacy Policy explains, in plain language, what personal information — including personal health information — we collect, how we use and protect it, who we share it with, how long we keep it, where it is stored, and the rights you have.

We follow Canada’s federal privacy law (PIPEDA) and the applicable provincial health-privacy laws, including Ontario’s PHIPA, Alberta’s Health Information Act (HIA), British Columbia’s PIPA, and Quebec’s Law 25. Where these laws set different standards, we apply the stricter one.


At a glance

  • We work for your therapist, not for ourselves. Your therapist decides what to send; Curio encrypts it, delivers it on their behalf, and keeps a secure record. We never use it for our own purposes.
  • We never sell your information, and we never use it to train artificial-intelligence models.
  • We store what we handle in Canada. Your own Google Workspace mailbox is hosted by Google and is outside our control — see Section 8.
  • No advertising, no product tracking. The Curio product runs no third-party analytics. Our marketing website uses analytics only if you choose to accept it — see Section 6.
  • You have rights — access, correction, complaint, and withdrawal of consent — see Section 5.
  • Questions? Email our privacy contact, Gabriel Borges, at privacy@curio.health.

This summary is for orientation only; the full policy below governs.


Words we use

  • Personal information — information about an identifiable person, such as a name or email address.
  • Personal health information (PHI) — information about a person’s health or care. Mental-health information is treated as sensitive in every Canadian jurisdiction.
  • Therapist — the regulated mental-health practitioner who holds a Curio account.
  • Client — the person a therapist communicates with through Curio.

1. Who We Are

Curio is an encrypted-email service for therapists and their clients, operated by Gabriel Borges (sole proprietor) in Canada. Your therapist is responsible for your care and decides what information to send. Curio’s role is to keep that information secure and deliver it safely on the therapist’s behalf — we do not use it for our own purposes.

Gabriel Borges is the individual responsible for the protection of personal information at Curio. For any privacy question, request, or complaint, contact privacy@curio.health (see Section 9).


2. Information We Collect

We collect only what we need to provide the service.

2.1 Information from therapists

2.1 Information from therapists
CategoryExamplesWhy we collect it
Account informationName, email address, practice nameTo set up and manage your account and sign you in
Email contentThe body and attachments of the emails you send through CurioTo encrypt, deliver, and — where a message is delivered through the secure portal — store them so the recipient can read them
Email detailsSender, recipient, subject, timestampsTo route and confirm delivery, and to keep an audit record
Billing informationSubscription status and a payment-processor reference (we never store your card number)To manage your subscription

2.2 Information about therapy clients

2.2 Information about therapy clients
CategoryExamplesWhy we collect it
Client email addressThe recipient address on a messageTo deliver the email
Client nameAs it appears in the emailPresent in the email we deliver
Message contentThe content of emails a therapist sends to a clientTo encrypt and deliver it, and to store it for secure-portal delivery

2.3 Information we collect automatically

2.3 Information we collect automatically
CategoryExamplesWhy we collect it
Access logsIP address, browser type, timestampsSecurity monitoring
Audit recordsAccount identifier, action, outcome, timestampPrivacy-law compliance and security investigation
Delivery detailsDelivery status and secure-transport resultsTo confirm secure delivery

2.4 What we do not collect

  • We do not store payment card numbers — these are handled entirely by our payment processor.
  • We do not collect health information about clients beyond the email content a therapist chooses to send through our service.
  • We do not use advertising trackers, analytics pixels, or third-party tracking tools inside the Curio product.
  • We do not collect biometric information.

3. How We Use Your Information

We use your information only to provide and protect the service:

  • To deliver your email — encrypting, routing, and delivering messages between therapists and their clients, including through the secure portal where a recipient’s mail server does not support encrypted transport.
  • To keep the service secure — verifying that encryption and access controls are working for each message.
  • To maintain an audit record — recording access and delivery events so we can demonstrate the service is handling information correctly.
  • To run your account — sign-in, sessions, and subscription management.

We do not:

  • use your information for marketing or advertising;
  • profile therapists or their clients;
  • sell, rent, or trade your information under any circumstances;
  • use your information to train, fine-tune, or improve any artificial-intelligence or machine-learning model; or
  • make automated decisions about you that have legal or similarly significant effects.

4. When We Share Information

Curio does not share your information with anyone except in these situations:

  1. To deliver your email — sending a message to the recipient the therapist chose is the service you asked us to perform.
  2. When required by law — for example, a valid court order or legal obligation.
  3. With service providers who work on our behalf — under written data-protection agreements (see Section 4.1).
  4. To notify you of a breach — as described in Section 4.2.

4.1 Our service providers

We rely on a small number of trusted providers, each bound by a written data-protection agreement and restricted to the service we engage them for. Everything we store is stored in Canada. One provider, Cloudflare, sits in front of our application and unlocks each request as it arrives, at whichever of its locations is closest to you. For someone in Canada that is normally a Canadian location, but we cannot promise it always will be. Nothing is stored there. Section 8 explains this in full.

4.1 Our service providers
ProviderRoleInformation handled
Google CloudSecure hosting and encryption of data, within CanadaStores encrypted information
Amazon Web ServicesOutbound email gateway and delivery, within CanadaProcesses email while it is being delivered
UpstashBackground processing and caching, within CanadaTechnical job data — no message content
Google WorkspaceTherapist email integrationIntegration only — the information you entrust to Curio stays in Curio’s systems
CloudflareSecurity and content delivery in front of our application, and DNSUnlocks each request to read and protect it as it passes through. Does not store it. See Section 8

The following providers do not receive any health information:

4.1 Our service providers
ProviderRoleInformation handled
StripePayment processingBilling details only — no health information
ResendService notificationsA secure link only — no health information
Google AnalyticsMarketing-website analytics, only if you consent (see Section 6)Anonymized website usage — no health information

We will give therapists advance notice before adding or replacing a provider that handles the information you entrust to us.

The full, current list of every provider we use — including what each one does and where it operates — is published at curio.health/subprocessors.

4.2 Breach notification

If a breach affects your information, we will notify:

  • the relevant privacy regulator, as required by law (for Ontario, the Information and Privacy Commissioner of Ontario);
  • affected therapists, at the first reasonable opportunity; and
  • affected individuals whose contact information is available to us through the service.

Therapists are also notified so they can reach any affected clients we cannot contact directly.


5. Your Rights

5.1 Access

You may ask for a copy of the personal information we hold about you. Email privacy@curio.health. We will respond within 30 days. A reasonable cost-recovery fee may apply. If we cannot provide certain information (for example, because it concerns another person), we will explain why.

5.2 Correction

If you believe information we hold is inaccurate or incomplete, you may ask us to correct it. We will respond within 30 days. If we make the correction, we will notify anyone we shared the incorrect information with in the past year. If we disagree, we will attach your statement of disagreement to the record.

5.3 Complaint

If you believe your privacy rights have been affected, you can complain to us at privacy@curio.health. We will acknowledge within 5 business days and respond substantively within 30 days.

You may also complain to a privacy regulator. Federally, and in Ontario:

Office of the Privacy Commissioner of Canada 30 Victoria Street, Gatineau, Quebec K1A 1H3 Phone: 1-800-282-1376 Website: www.priv.gc.ca

Information and Privacy Commissioner of Ontario 2 Bloor Street East, Suite 1400, Toronto, Ontario M4W 1A8 Phone: 416-326-3333 / 1-800-387-0073 Website: www.ipc.on.ca

If you live in another province, you may contact your provincial privacy commissioner — for example, the Office of the Information and Privacy Commissioner of Alberta or of British Columbia, or the Commission d’accès à l’information du Québec.

A therapist may withdraw consent at any time by closing their Curio account. When that happens, we stop processing information for that account and delete or return it according to the retention schedule in Section 7. Withdrawing consent does not affect anything done before the withdrawal, and some records (such as audit logs) may be kept where the law requires.

5.5 Be told about a breach

You have the right to be notified if your information is involved in a breach, as described in Section 4.2.


6. Cookies and Similar Technologies

  • In the Curio product — we use only essential sign-in cookies, so you stay securely logged in. We run no advertising, analytics, or third-party tracking inside the product.
  • On our marketing website (curio.health) — a consent banner runs before any analytics. If you accept, we use analytics to understand how the site is used. If you decline, nothing beyond what is necessary for the site to work is loaded. We do not use deceptive “dark patterns” to push you toward accepting, and you can change your choice at any time through the “Manage cookies” control in the website footer.

7. How Long We Keep Your Information

Every category of information has a defined retention period — we do not keep personal information indefinitely.

7. How Long We Keep Your Information
InformationHow long we keep it
Encrypted email contentWhile the therapist’s account is active, plus 30 days after the account closes
Email delivery details3 years after delivery
Therapist account informationWhile the account is active, plus 1 year after it closes
Client email addressesWhile the therapist’s account is active, plus 30 days after it closes
Audit logsAt least 10 years (required for health-privacy compliance)
Billing records7 years (Canadian tax and financial record-keeping rules)
Psychotherapy notesWhile the therapist’s account is active, plus 30 days after it closes (enhanced-protection category)

When a retention period ends, information is securely deleted. Audit logs are kept as an append-only record and are never altered or deleted during their retention period. Therapists may request earlier deletion of their data, subject to any legal retention requirements.

When a therapist closes their account, email processing stops immediately, email content and client data are deleted within 30 days, and account, audit, and billing records are kept only for the periods above.

The retention periods above cover Curio’s own records. Keeping the underlying clinical record — for the minimum period your professional college requires — remains the therapist’s responsibility.


8. Where Your Information Is Stored

We store the information you entrust to Curio — your encrypted message content, audit records, and account data — on encrypted servers located in Canada (Montreal). We do not store it outside Canada in the course of normal operations.

One part of the journey is different, and we want to be straightforward about it. Reaching our application means your request travels through Cloudflare, a security and content-delivery provider that protects the service against attack. Cloudflare unlocks each request to check and forward it, and it does that at whichever of its locations is closest to you. If you are in Canada that is normally a Canadian location, but it depends on how the internet routes you at that moment, and we cannot promise it will always be one. This lasts only as long as the request takes. Nothing is stored outside Canada — your messages, audit records, and account data are written only to Canadian servers, as described above.

We would rather tell you this plainly than let “in Canada” stand as a promise we cannot keep in every case. If you need a guarantee that no part of a request is ever handled outside Canada, contact us at privacy@curio.health before you rely on the service.

Your Google Workspace mailbox is different. Gmail stores your mailbox on Google’s own servers, which may be located outside Canada, and Google — not Curio — controls where that mailbox lives under your Workspace agreement. Curio encrypts the email you send and keeps a Canadian audit trail, but we cannot change where Google hosts your inbox. When we say Curio’s infrastructure is Canadian, we mean the records Curio holds, not your underlying Gmail account.

If a transfer of Curio’s records outside Canada were ever required (for example, for a legal proceeding), it would happen only with the therapist’s informed consent, appropriate safeguards, and a record of the transfer and its legal basis. Routine administrative access to our systems is always authenticated, encrypted, and logged, and does not result in your information being stored outside Canada.


9. How to Contact Us

For any question, request, or complaint about this policy or your privacy, contact the individual responsible for the protection of personal information at Curio:

Gabriel Borges Privacy: privacy@curio.health Account help: support@curio.health

We will acknowledge your message within 5 business days and respond substantively within 30 days. A mailing address is available on request and will be added here once a business address is registered.


10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make a material change, we post the updated policy on our website, update the effective date above, and ask therapists to review and acknowledge the new version before continuing to use the service. Previous versions are available on request.