Product Terms
Some products have additional, product-specific terms that apply in addition to the Privacy Policy and Terms of Service above. Where a product supplement conflicts with those documents in respect of that product, the supplement controls. As we release more products — such as Syneuro and Binary — each will appear here as its own supplement.
What Cura is
Cura is an ambient life manager. It gathers information from the sources you choose to connect, writes a short daily brief, and keeps a schedule, a diary, focus sessions and a small set of panels you arrange yourself. It runs on the web at cura.meredic.com and as an Android application. Cura is built on four commitments, which are product principles and contractual undertakings:
- Glass box, not black box. Every line in your brief and every panel decision traces back to the source signal that produced it.
- Visible, reversible boundaries. You can always see what Cura can see, per source, and disconnect any source in one step without breaking the app.
- Propose, confirm, act. Cura proposes; you confirm; only then does it act, log the action, and offer an undo. Cura does not take actions on your behalf without your confirmation.
- Nothing starts quietly. Every source and every optional signal ships switched off, and you turn on what you want Cura to see. One thing does not follow that rule: the training corpus described in § 4 is on unless you switch it off. It is named here so that you do not have to find it there. If what Cura collects changes, this supplement and the notice inside the app change with it, and the date at the top moves.
Information Cura processes
- Account data. Your email address and basic account metadata. You sign in with a code sent to your email, or with Google. Cura also records one line a day for each screen you open, so we can tell whether it is being used.
- Content you create. Schedule blocks, to-dos, routines, diary entries and any photos in them, boards and panels, focus sessions, chat messages and any photos in them, and your settings.
- Connected sources. Each is off until you turn it on, and Cura requests only the scopes that feature needs. Today these are your Google Calendar (read); your recent Gmail headers — sender and subject only — if you switch that on; and the calendar mirror, which writes blocks you created in Cura into a separate Google calendar named Cura and touches no other calendar.
- Device signals (Android). Screen time, sleep and steps from Health Connect, and notifications. Each is off by default and needs your permission twice — once in Cura, once in Android. These signals do not stay on the device: the figures, and a shortened title and body of a notification, are sent with your brief to the language model. We do not retain them; what is retained is the brief produced from them.
- Operational logs. A per-user activity record of each read of your data and each action you accepted, so you can review what Cura did and why.
If you switch on Health Connect, Cura processes sleep and step data, which is health-related information. Financial data and precise location are not collected.
Where Cura runs, and security
Cura runs on one server that we operate ourselves, in Seoul, South Korea. Every query is scoped to your account by row-level access controls, so nobody else can reach your rows. Credentials and API keys are held only in that server environment and are never embedded in the app. Connections to connected services use OAuth; we store access and refresh tokens securely and never see your passwords for those services.
We hold administrative access to that machine, which means a person here can technically read what is on it. That is true of any service of this size, and we would rather write it down than let it be inferred.
AI processing, and model training
Cura uses your data to provide the service to you: to generate your brief, to answer you in chat, to build and update your panels, and to surface proposed actions for your confirmation. To do that, the relevant signals are processed by Google’s Gemini models through the Gemini API, called from our server environment and never from the app. We do not sell, rent, or share your personal data with third parties for their marketing purposes, and there is no analytics or advertising tracker in the app.
What Cura sends the language model, and what comes back, is kept so that a smaller model can be taught to do the same job. This is on unless you turn it off, in Settings under Account. What is kept is whatever was sent for that call, which can include diary text and, where you have connected those sources, sleep and step figures and the shortened content of notifications. Before anything is kept, sign-in codes, email addresses and long digit strings are removed, and what remains is held on a separate server under a random identifier that is not your name and cannot be traced back to you from that server alone. Turning the setting off stops the next one from being kept, and the same screen deletes everything already held.
Until 23 August 2026 this worked the other way round: nothing was kept unless you switched it on. We changed the default, and we are recording that here because a default you were not told about would not be a choice you made.
Google user data accessed through Cura is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements. Cura requests the minimum scopes needed for a feature and only at the point you enable it.
The two ways your data leaves Cura
Apart from the language model described above, there are two ways data in Cura reaches anyone else, and you start both of them.
- A shared day. You can create a read-only link to a single day. Anyone holding that link sees that day’s times and titles — not your steps, your notes or your diary — until the day ends, and you can stop it sooner from the schedule. We record that a shared link was opened, never who opened it.
- Other assistants. You can connect Cura to an outside assistant such as Claude or ChatGPT. This is off by default. If you connect one, what it asks for — your schedule, your diary, your calendar, your boards — leaves for that company’s systems and is governed by that company’s terms rather than ours. You can cut the connection at any time, though that cannot reach back into what has already been taken.
Your controls, retention & deletion
You can disconnect any source at any time from the app, which stops further access under that source, and you can delete individual content as you go.
To delete your account, write to support@meredic.com; the account goes, and everything described above with it. A person does this by hand today, so allow a day — a one-tap control is being built and this clause will change when it ships. We retain your data for as long as your account is active and delete or anonymise it after deletion, except where we must retain limited records to meet legal obligations. To request an export, use the same address.
Beta software
Cura is early software and may change, contain errors, or be interrupted. It is provided “as is” without warranties of any kind, and you should not rely on it as the sole record of time-critical commitments. The limitation of liability in our Terms of Service applies to your use of Cura.
Eligibility
Cura is for people aged 14 and over. Under the Korean Personal Information Protection Act a younger person needs a parent or guardian to consent on their behalf, and we cannot yet collect that consent properly. Until we can, a guardian should write to support@meredic.com and set an account up together with the child.
Privacy enquiries: privacy@meredic.com · Security: security@meredic.com
