Privacy policy
CureSpy holds what you tell it about your illness. This says exactly what that is, why, who else can see it, how long it is kept, and how to get rid of it. It was written from the code, not from a template.
Last changed September 19, 2026.
Who holds it
Croissant Software, MB, a company registered in Lithuania, of an address to be published here, is the data controller — the one answerable for what happens to your data. Write to the contact address to be published here about anything on this page.
What CureSpy stores about you
Everything below is in our own database. Nothing is held that is not listed here.
- Your account: your name, your email address and whether it has been confirmed, when the account was made, which plan you are on, and your role on the site (member, or admin for the people who run it).
- How you sign in: a password, stored only as a hash (which cannot be turned back into the password); or, if you sign in with Google, Google's identifier for you and the tokens Google gives us to confirm it is you. Never your Google password.
- Your sessions: for each device you are signed in on, a random token, when it expires, the IP address and the browser it was made from. This is how "sign out of every device" works, and how a stolen session can be told from your own.
- One-time codes and sign-in links: while a six-digit code we emailed you is valid (ten minutes), a hash of it and how many times it has been tried; while the sign-in link in an email about your studies is valid (seven days, one use), a hash of it. Then they are deleted.
- Rate limiting: to stop someone guessing passwords or codes, the address a request came from and how many requests it has made in the last minute. Overwritten continuously.
- About you, all optional: year of birth, sex, country, time zone and language. When you sign up, the country is suggested from where your connection appears to come from and the language your browser asks for; you can change or clear it. The time zone is read from your browser whenever you visit, so emails can go out at a sane hour. Leave any of them blank and it still works.
- What you follow: the conditions and the studies, and when you started following each.
- Your questions: each question you ask about a study, the answer you were given, when, and how much text it took — so you can read it again, so the next question can follow on from the last, and so the daily limit can be counted.
- What we emailed you: each email about your studies — its subject, the paragraphs written for it, which developments went into it and when — so nothing is sent twice and you can read it again on the site.
- Your email settings, including a private token that makes the unsubscribe link at the bottom of every alert work without signing in.
The part that is about your health
The conditions you follow, the year of birth and the sex you may give, and the questions you ask can all reveal something about your health or a relative's. That is sensitive by law, and we hold it only because you chose to give it, for the purpose you gave it: to watch research for you. You can take any of it back at any time — clear the field, stop following, or delete the account — and it is gone.
We never draw conclusions about your health from it. It is not used to decide anything about you, is not profiled, and is not sold or shared for advertising or research.
What is sent to an AI model, and what is not
To write the plain-language text, the official study records — which are public — are sent to a language model run by OpenAI, through Cloudflare's AI Gateway. When you ask a question in the questions panel, your question and your earlier questions about that study go the same way, together with the record, so the answer can follow on.
Your name, email address, year of birth, sex, country and the list of what you follow are never sent to the model, and it is never told who is asking. Do not put anything about yourself into a question that you would not want a third party to process; the panel is for asking about the study.
OpenAI processes these requests under its API terms, which do not allow it to use them to train its models. Cloudflare's gateway keeps a log of each request and its answer for a limited time, and may serve an identical request from its cache instead of asking the model again.
What CureSpy does not do
- No analytics script, no advertising and no third-party trackers on any page. Nothing records whether you opened an email or which link in it you clicked.
- No cookies beyond three of our own: the one that keeps you signed in, the one that remembers your language, and — for the fifteen minutes between typing your email and entering the code — the one that carries the address between the two steps. There is no cookie banner because there is nothing to ask about.
- No card details. Payment for the Supporter plan is taken by Paddle.com on its own pages; CureSpy learns only that the plan is active and when it renews, never the card.
- No medical records, and no connection to any clinic, hospital or health system. Nothing we hold comes from one, and nothing goes to one.
Why the law allows it
- Your account, sessions, what you follow, your questions and your email settings are held to provide the service you signed up for — the contract between us.
- Anything that reveals your health — the conditions, year of birth, sex, and the questions — is held with your explicit consent, which you give by entering it and can withdraw at any time by removing it.
- Session addresses, rate limiting and error logs are held in our legitimate interest in keeping the service secure and working, which we have weighed against the small intrusion they involve.
Who else handles it
Nobody sees your data except companies that process it for us, on our instructions, under contracts that bind them to this policy:
- Cloudflare, Inc. (United States) hosts the site and the database, sends the emails, and relays the AI requests. Data is stored and processed in Cloudflare's network, which includes locations in the European Union and the United States.
- OpenAI, L.L.C. (United States) runs the language model, for the public study records and your questions, as described above.
- Google LLC (United States), if you choose to sign in with Google, in the ordinary way of a Google sign-in.
- Paddle.com Market Ltd (United Kingdom), if you buy the Supporter plan, as the merchant of record for the payment.
- The registers themselves — ClinicalTrials.gov, CTIS, PubMed — receive only the names of conditions and the numbers of studies, in the course of reading them. They receive nothing about you.
Data leaving the European Union
Cloudflare, OpenAI and Google are American companies, so some of your data is processed in the United States. Each is bound by the European Commission's standard contractual clauses and, where certified, the EU–US Data Privacy Framework, so that it has the same protection there as here.
How long it is kept
- Stop following a condition or a study, and the fact that you followed it is deleted immediately.
- Sessions end when you sign out, when they expire, or when you sign out everywhere. One-time codes last ten minutes. Rate-limit counts last one minute.
- Your account and everything under it are kept until you delete the account, from your account page. Deletion is immediate and complete: the profile, what you followed, your questions, the record of emails sent and your sessions go with it.
- An account that has not been signed in to for twenty-four months is deleted too, after a warning by email a month before and a week before.
- Error logs, which can include an account identifier or the number of a study, are kept by Cloudflare for a few days and then gone. Emails already sent to you are in your inbox; we keep no copy of their contents.
How it is protected
Everything travels over encrypted connections. Passwords and one-time codes are stored only as hashes. Secrets that let the site talk to its providers are kept outside the code. The people who run CureSpy can reach the database, and do so only to keep it working. If something ever went wrong with your data, we would tell you and the Lithuanian data protection authority as the law requires.
What you can ask for
You can see everything stored about you on your account and home pages, change it there, and delete it there — that is access, rectification and erasure without asking anyone. If you want a copy of your data in a file, want something corrected that the pages do not let you correct, want processing restricted or object to it, or believe something is being held that should not be, write to the contact address to be published here; we answer within a month. You can also complain to the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt), or to the data protection authority where you live.
Children
Accounts are for adults. A parent may follow research on a child's behalf; the account and its data are the parent's. If we learn that a child holds an account, we delete it.
Changes
If this policy changes in a way that matters, we will email you at least thirty days before the change applies. The date at the top is the date of the current version.