Privacy policy
CureSpy holds what you tell it about your illness. This says exactly what that is, why, who else can see it, how long it is kept, and how to get rid of it. It was written from the code, not from a template.
Last changed October 9, 2026.
Who holds it
Croissant Software, MB, a company registered in Lithuania, of an address to be published here, is the data controller — the one answerable for what happens to your data. Write to the contact address to be published here about anything on this page.
What CureSpy stores about you
Everything below is in our own database. Nothing is held that is not listed here.
- Your account: your name, your email address and whether it has been confirmed, when the account was made, which plan you are on, and your role on the site (member, or admin for the people who run it).
- How you sign in: a password, stored only as a hash (which cannot be turned back into the password); or, if you sign in with Google, Google's identifier for you and the tokens Google gives us to confirm it is you. Never your Google password.
- Your sessions: for each device you are signed in on, a random token, when it expires, the IP address and the browser it was made from. This is how "sign out of every device" works, and how a stolen session can be told from your own.
- One-time codes and sign-in links: while a six-digit code we emailed you is valid (ten minutes), a hash of it and how many times it has been tried; while the sign-in link in your weekly email is valid (seven days, one use), a hash of it. Then they are deleted.
- Rate limiting: to stop someone guessing passwords or codes, the address a request came from and how many requests it has made in the last minute. Overwritten continuously.
- About you, all optional: year of birth, sex, country, time zone and language. When you sign up, the country is suggested from where your connection appears to come from and the language your browser asks for; you can change or clear it. The time zone is read from your browser whenever you visit, so emails can go out at a sane hour. Leave any of them blank and it still works.
- What you follow: the conditions and the studies, and when you started following each.
- Your questions: each question you ask about a study, the answer you were given, when, and how much text it took — so you can read it again, so the next question can follow on from the last, and so the daily limit can be counted.
- What we emailed you: for each weekly email, the week it covered, its subject, its language, which conditions' briefings it carried and when it went — so the same week is never sent twice. When an email to you cannot be delivered, the reason the mail service gives and when, so we stop retrying an address that bounces and can see that mail is failing.
- Your email settings, including a private token that makes the unsubscribe link at the bottom of every email work without signing in.
- Counts of the steps into the service — someone arrived at the home page, signed up, confirmed their address, followed a condition, asked a question, unsubscribed — each with only its time and, for an arrival, the campaign name the link carried. Nothing in them says who: no account, address or browser. They show where the way in loses people.
The part that is about your health
The conditions you follow, the year of birth and the sex you may give, and the questions you ask can all reveal something about your health or a relative's. That is sensitive by law, and we hold it only because you chose to give it, for the purpose you gave it: to watch research for you. You can take any of it back at any time — clear the field, stop following, or delete the account — and it is gone.
We never draw conclusions about your health from it. It is not used to decide anything about you, is not profiled, and is not sold or shared for advertising or research.
What is sent to an AI model, and what is not
To write the weekly briefings and the plain-language text, public material is sent to a language model run by OpenAI, through Cloudflare's AI Gateway: study records, research abstracts from PubMed, the results study teams post, and the text of medicine regulators' decisions. A briefing is written once for each condition and week and shared by everyone who follows that condition, so it carries nothing about any reader. When you ask a question in the questions panel, your question and your earlier questions about that study go the same way, together with the record, so the answer can follow on.
Your name, email address, year of birth, sex, country and the list of what you follow are never sent to the model, and it is never told who is asking. The line in your weekly email about studies you starred is worked out by our own code from your stars, not by the model. Do not put anything about yourself into a question that you would not want a third party to process; the panel is for asking about the study.
OpenAI processes these requests under its API terms, which do not allow it to use them to train its models. Cloudflare's gateway keeps a log of each request and its answer for a limited time, and may serve an identical request from its cache instead of asking the model again.
Analytics on the public pages, only if you say yes
On the public pages — the home page, the example briefing, these legal pages, and the sign-up and sign-in pages — we ask whether we may use Microsoft Clarity to see how people use them: where they click, how far they scroll, where they give up. Clarity shows us this as recordings of the page and as maps of where clicks land. Nothing of it loads until you say yes; if you say no, or say nothing, it is never loaded.
Clarity is never loaded on a page you see after signing in, nor on the page where you choose a condition, so it never sees the conditions or studies you follow or the questions you ask. Anything typed into a box is hidden before it leaves your browser, and so are email addresses and numbers on the page; the screen that shows your email address while you enter your code is hidden entirely.
If you say yes, Clarity sets its own cookies — _clck and _clsk on this site, and others on Microsoft's own domains — to join your visits into one recording, and we tell it you have refused advertising storage. Clarity is provided by Microsoft Ireland Operations Limited, which by its own terms handles the data it collects as a data controller, under the Microsoft Privacy Statement (privacy.microsoft.com). Recordings are kept for 30 days, and a random sample, and any we mark, for up to nine months. You can change your answer at any time with "Cookie settings" at the foot of the public pages; when you withdraw it, we tell Clarity to stop and delete its cookies on this site.
What CureSpy does not do
- No advertising and no third-party trackers on any page you see after signing in, or on the page where you choose a condition. Nothing records whether you opened an email or which link in it you clicked.
- Four cookies of our own: the one that keeps you signed in, the one that remembers your language, the one that carries your email address between typing it and entering the code (an hour), and the one that remembers your answer to the analytics question (six months). If you use the light or dark switch, your choice is kept in your browser's own storage and never sent to us. Crisp, the chat in the corner, sets its own cookie to keep a conversation going (see below).
- No card details. Payment for the Supporter plan is taken by Paddle.com on its own pages; CureSpy learns only that the plan is active and when it renews, never the card.
- No medical records, and no connection to any clinic, hospital or health system. Nothing we hold comes from one, and nothing goes to one.
Why the law allows it
- Your account, sessions, what you follow, your questions and your email settings are held to provide the service you signed up for — the contract between us.
- Anything that reveals your health — the conditions, year of birth, sex, and the questions — is held with your explicit consent, which you give by entering it and can withdraw at any time by removing it.
- Session addresses, rate limiting and error logs are held in our legitimate interest in keeping the service secure and working, which we have weighed against the small intrusion they involve.
- If you say yes to analytics on the public pages, Microsoft Clarity runs with your consent, which you can withdraw at any time from "Cookie settings".
Who else handles it
Nobody sees your data except companies that process it for us, on our instructions, under contracts that bind them to this policy:
- Cloudflare, Inc. (United States) hosts the site and the database, sends the emails, and relays the AI requests. Data is stored and processed in Cloudflare's network, which includes locations in the European Union and the United States.
- OpenAI, L.L.C. (United States) runs the language model, for the public material and your questions, as described above.
- Google LLC (United States), if you choose to sign in with Google, in the ordinary way of a Google sign-in.
- Paddle.com Market Ltd (United Kingdom), if you buy the Supporter plan, as the merchant of record for the payment.
- The public sources themselves — PubMed, ClinicalTrials.gov, the EU Clinical Trials Information System (CTIS), the US Food and Drug Administration (FDA) and the European Medicines Agency (EMA) — receive only the names of conditions and the numbers of studies we search for; from the regulators we only download the files they publish for everyone. They receive nothing about you.
- Crisp IM SAS (France) runs the chat in the corner of every page. Its script loads with the page and sets its own cookie so a conversation carries on; if you write to us, Crisp carries what you write, the page you wrote from and your browser. What you write — including anything about your health — is kept with the conversation until we delete it, so write only what you need to.
Data leaving the European Union
Cloudflare, OpenAI and Google are American companies, so some of your data is processed in the United States. Each is bound by the European Commission's standard contractual clauses and, where certified, the EU–US Data Privacy Framework, so that it has the same protection there as here. If you say yes to analytics, Microsoft Ireland may pass Clarity's data to Microsoft in the United States under the same clauses.
How long it is kept
- Stop following a condition or a study, and the fact that you followed it is deleted immediately.
- Sessions end when you sign out, when they expire, or when you sign out everywhere. One-time codes last ten minutes. Rate-limit counts last one minute.
- Your account and everything under it are kept until you delete the account, from your account page. Deletion is immediate and complete: the profile, what you followed, your questions, the record of emails sent and your sessions go with it.
- An account that has not been signed in to for twenty-four months is deleted too, after a warning by email a month before and a week before.
- Error logs, which can include an account identifier or the number of a study, are kept by Cloudflare for a few days and then gone. Emails already sent to you are in your inbox; we keep their subject and which briefings they carried, not a copy of the email.
How it is protected
Everything travels over encrypted connections. Passwords and one-time codes are stored only as hashes. Secrets that let the site talk to its providers are kept outside the code. The people who run CureSpy can reach the database, and do so only to keep it working. If something ever went wrong with your data, we would tell you and the Lithuanian data protection authority as the law requires.
What you can ask for
You can see everything stored about you on your account and home pages, change it there, and delete it there — that is access, rectification and erasure without asking anyone. If you want a copy of your data in a file, want something corrected that the pages do not let you correct, want processing restricted or object to it, or believe something is being held that should not be, write to the contact address to be published here; we answer within a month. You can also complain to the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt), or to the data protection authority where you live.
Children
Accounts are for adults. A parent may follow research on a child's behalf; the account and its data are the parent's. If we learn that a child holds an account, we delete it.
Changes
If this policy changes in a way that matters, we will email you at least thirty days before the change applies. The date at the top is the date of the current version.