CURISNAP · TRUST & TRANSPARENCY
Privacy Policy
Updated September 6, 2026
1. Scope and operator
This notice describes CuriSnap at curisnap.app, including the hosted Studio. Updated September 6, 2026. CuriSnap is operated by an individual in the United States. Contact support@curisnap.app. The operator’s legal name, state and business address remain pending confirmation; this notice remains subject to completion and review.
2. Information processed
Google sign-in provides a verified account identifier, name and email address. CuriSnap never receives your Google password. When you request analysis, we process your selected photos, category and notes. Generated reports may include information from your notes. Hosting and identity services receive network information such as IP addresses and request headers. Remove personal documents, faces and addresses before submission.
3. When photos leave your device
Selecting a photo does not submit it. After sign-in and your explicit analysis confirmation, the browser prepares JPEG images and sends them to our Cloudflare-hosted service and automatically selected analysis services. If you also enable Numista coin research, up to two photos are sent to Numista when image search is configured and the item is classified as a coin. Completed reports are saved privately to your account. When you confirm photo storage, the JPEG copies prepared for analysis are saved privately with your report; original full-resolution files are not retained. Older reports may have no saved photos and allow you to attach copies without re-running analysis.
4. Service operation and usage records
We use account information to provide access and maintain your saved collection. We keep first-party operational records of sign-ins, report generation, report retrieval, report viewing, export and print requests, report changes, and external service calls to operate the service, diagnose failures and understand report use and returning account activity. These records are linked to an internal account identifier. Client viewing/export events are signals, not proof that a person read a report or saved a file. We do not add advertising pixels, cross-site identifiers or fingerprinting. Usage tables do not contain uploaded photos, notes, prompts, full request URLs, provider response bodies, IP addresses or browser fingerprints.
5. Services that receive information
CuriSnap automatically routes photos and notes according to the item category. Processing may use OpenAI or Claude through fal and OpenRouter, including an initial category classification. Optional coin research uses Numista. Google handles sign-in, and Cloudflare hosts the website, sessions and saved reports. Pages may load Google Fonts. Providers have their own terms and retention practices. Failed requests are not automatically retried through another processor. Optional online reference research sends the proposed candidate name and category through fal and OpenRouter to search services. It does not send uploaded photo files or the notes field in this additional step. The proposed name can contain information derived from your submission. Searches run only when you opt in; linked excerpts are checked against accessible source pages, not treated as authentication. OpenAI requests use store:false; this does not promise zero upstream retention.
6. Sessions, saved reports and retention
We use the essential __Host-curisnap cookie with Secure, HttpOnly and SameSite=Lax settings for a session lasting up to 7 days. Signing out invalidates that session but does not delete your account profile or reports. Account profiles are stored in Cloudflare Durable Objects and D1; reports and consented analysis photo copies remain privately in Durable Objects until you delete them. D1 stores a report index and operational statistics separately. Deleting a report removes its saved content and photos, while a minimal deletion/index record and operational records may remain for the retention periods below. Detailed events and external-call metadata are kept for up to 90 days, and daily account-activity records and generation summaries for up to 400 days, with daily cleanup. Account profiles and current report indexes remain until account deletion is processed. Pending delivery records are retried from durable storage; they may remain until delivery and cleanup. Numista catalogue identifiers may be saved, but transient licensed catalogue descriptions, images and prices are not copied into the statistics database. Request account-data deletion or access through support@curisnap.app. Rate-limit counters and request identifiers support abuse prevention. Downloaded exports and provider retention are separate.
7. Sharing and international processing
Data may be processed outside your country by the hosting, identity and AI services used for your request. This notice does not represent that a particular international-transfer safeguard is in place. Information may also need to be disclosed where required by applicable law or to address a genuine security incident. CuriSnap has not implemented advertising data sales or ad-targeting features in this preview.
8. Your choices and rights
You can browse guides without signing in, prepare or remove photos before submission, decline analysis, export a report, delete saved reports and sign out. To request account-data access, correction or deletion, contact support@curisnap.app using your account email. Do not send passwords, keys or identity documents. Applicable rights may include access, deletion, correction, portability, objection, restriction and complaints to your data protection authority. Requests already sent to providers cannot necessarily be recalled.
9. Security and age requirements
We use server-verified Google credentials, secure session cookies, same-origin and CSRF checks, account-scoped report access and server-side provider keys. No system can guarantee complete security. The service is intended for adults; do not upload children’s personal information or sensitive documents. Material changes to processing will be described in an updated notice.
10. Contact
Operator: an individual in the United States. Privacy and rights-request email: support@curisnap.app.