Legal
curlhood privacy policy
What changed on this date
- Curlhood now requires an account, and sign-in moved from an emailed code to a password, with Sign in with Apple and Sign in with Google alongside it.
- Crash reporting and product analytics are now switched on. An earlier version of this policy said they were off, and said we would update this page before enabling them. We did not do that in time, and this update corrects it.
- Account deletion moved into the app.
- This policy now describes voice search, which is rolling out. The audio is handled by your phone and never reaches us.
- Curlhood can now find a style from a photo, and read a product label with the camera. This policy describes both below, including exactly what leaves your phone and what does not. An earlier version of this page said Curlhood had no camera or photo feature. That was true when it was written and is no longer true, and this update corrects it.
- The providers table now names Anthropic, which answers your questions to the Curlhood Collective. That was already true before this date and was missing from the table.
- Our contact addresses changed. General questions go to hello@curlhood.app, and anything about your privacy, your data, or deleting your account goes to privacy@curlhood.app.
The short version
- Curlhood needs an account. You can create one with your email and a password, with Sign in with Apple, or with Sign in with Google. The account is how your work follows you to a new phone, and it is the only reason sync exists.
- Everything you build in Curlhood lives on your device. Your account holds a backup copy so you do not lose it. Deleting your account never wipes your device.
- Curlhood can find a style from a photo and read a product label with the camera. Both start only when you tap. A photo is used to answer that one question and is then discarded. It is never stored, never shown to anyone, and never sent to an AI company. We never ask you for a photo of your child, and no photo of anyone is ever kept.
- No ads. No selling or renting your data. No tracking you across other apps or websites. No social feed.
- You can delete your account from inside the app, in Settings, and you can erase everything on the device separately.
Applies to: the Curlhood iOS app (bundle id app.curlhood), operated by KIN Ventures, LLC, Austin, Texas.
What Curlhood stores
Curlhood is a guide for caring for curly hair. To do that job it keeps the information you enter, on your device:
- Your setup answers. The name you go by, whether you care for your own hair or someone else's, and your role (for example, mom or caregiver).
- Hair profiles. For each head of hair you set up: the name or nickname you chose, an age range for a child's profile (we ask for a range like "kid," never a birthdate), curl pattern, porosity, density, an optional scalp type, an optional goal, the dates of the last wash, deep condition, and trim, and a dated history of changes you make to the profile (for example, "porosity updated in May").
- Learning and care progress. Which skills you have practiced and when, which styles you have saved or completed, products you have saved to your shelf, and gentle rhythm counters like protective-style and nighttime streaks.
- Saved wash-day routines. The steps you build and reorder, with an optional link to a product on your shelf, and how a wash day turned out if you log it.
- Preferences that shape suggestions inside the app.
This all lives in the app's private storage on your phone. Deleting the app deletes it.
What Curlhood never collects
- Your photo library. Curlhood never browses, indexes, scans, or uploads your photo library. When you use the camera or choose a picture, it receives that one image, for that one search, and keeps none of it. See Photos you take for exactly what happens to it. Photos of children are never stored or shared through Curlhood, ever. This is a standing product rule, not a current gap. The style and lesson images you see in the app are editorial content we supply; they are never photos of Curlhood users or their families.
- Location, contacts, messages, or browsing history. The app does not request them.
- Advertising identifiers. There are no ads in Curlhood and no advertising partners.
About a child's hair
Curlhood is built for adults. Many of the people who use it are parents and caregivers looking after a child's curls, so a hair profile you create may describe a child's hair: for example, a nickname, an age range, and a curl pattern. Here is how we treat that honestly:
- You, the adult, enter and hold that information. The app has no child accounts, no child login, and no way for a child to use Curlhood independently. The account, the data, and every choice about it belong to the adult.
- A nickname is enough. The app suggests a placeholder ("Little One") and never requires a real name. We encourage you to use a nickname for a child's profile.
- An age range, never a birthdate. If you set up a child's profile, we ask for a general age range to tailor guidance, not an exact birthdate.
- It stays with you. A child's hair profile lives on your device and is backed up to your account. It is never shown to other users, and Curlhood has no social features.
- Curlhood is not directed to children under 13, and we do not knowingly collect personal information from a child. If you believe a child has created an account, contact us at privacy@curlhood.app and we will delete it.
Your account
How you sign in. Curlhood requires an account. You can create one three ways: an email address and a password, Sign in with Apple, or Sign in with Google. If you use Apple or Google, we receive the identifier they give us and, on first sign-in only, the name and email address you agree to share. Apple's Hide My Email is fully supported and we never see your real address if you use it. We do not receive your password from any of them, and we never see the password you set with us: it is handled by our authentication provider.
With an account:
- What syncs: your setup answers, hair profiles, skills and style progress, favorites, saved products, saved wash-day routines and their outcomes, care rhythm counters, and suggestion preferences. It is saved as one record tied to your account and protected so that only your account can read or write it.
- What we hold about you: your email address, the synced record above, and brief technical sign-in logs (like timestamps) kept only for a short period. That's the account.
- Sign out anytime. Signing out stops sync and leaves your data on your device.
Sync and sign-in run on Supabase, our database provider. Data is sent over encrypted connections and stored on Supabase's secure cloud infrastructure, in the United States (Oregon, us-west-2).
Crash reporting and analytics
We want to be precise here, because "analytics" is where many apps get vague:
- Crash reporting (Sentry). When the app breaks, it sends technical details to Sentry, our crash-reporting provider: the error, your device model, your operating system version, and the app version. It does not include your hair profiles or anything you have written, and it is not tied to your identity. We use crash reports for one purpose: repairing the app.
- Product analytics (PostHog). The app measures how its features are used so we can tell what is working: which screens are opened, which styles and tutorials are viewed, and whether a flow was finished or abandoned. It is tied to your account identifier so the numbers are not double-counted across your devices. It does not capture what you type, your hair profiles, or anything about the people you care for. We do not use it for advertising and we do not sell it.
- Neither tool is ever used for advertising, and we do not track you across other companies' apps or websites.
Speaking your question
Curlhood lets you speak a search question instead of typing it. Where the feature is available you will see a microphone on the search field. Tapping it turns what you say into text, and that text goes into the search box exactly as if you had typed it.
The audio never reaches us. Speech recognition is done by Apple, on your device wherever your iPhone supports it, and by Apple's speech service where it does not. We receive only the words as text. We never record, store, or send the audio anywhere, and we never build a voiceprint.
The microphone is only on while you are asking. It starts when you tap the microphone button and stops when your question ends. There is no background listening.
If you ask the Curlhood Collective a question, the text of that question is sent to answer it and is not kept afterward, whether you typed it or spoke it. Our usage measurements record that a question was asked and how long it was, never what it said.
You can refuse the microphone permission and everything still works. Typing is always the full experience, not a fallback.
Photos you take
Curlhood has two places where the camera is useful. Neither one opens on its own, and neither runs in the background. Both start when you tap.
Finding a style from a photo. On the ask screen you can take a picture or choose one, and Curlhood finds the styles in its library that look closest to it. The image goes to our own server, is turned into a numeric fingerprint, is matched against the library, and is discarded inside that same request. It is never written to a database, never placed in storage, never seen by another person, and never sent to an AI company. Nothing of the image survives the answer.
Reading a product label. You can point the camera at an ingredients list. Your iPhone reads the words on the device itself, using Apple's built-in text recognition. The picture never leaves your phone, and it is deleted as soon as the words are read. Only the ingredient names travel onward, to our server and then to Anthropic, so they can be explained back to you in plain language. The photo is never part of that.
Photos of a child. We never ask for one. If you photograph a style on your child's hair to find a match, that image is handled exactly like every other: used for the match, then discarded, with no copy kept. Curlhood stores no photos of anyone, so there is no gallery of children's hair inside it, and there never will be.
You can refuse the camera and photo permissions and everything else still works. Typing and browsing are always the full experience, not a fallback.
Service providers
Curlhood runs with the help of a small set of providers, each doing one job:
| Provider | Job | What reaches them |
|---|---|---|
| Apple | App distribution (App Store, TestFlight), and speech recognition when you use the microphone | Standard App Store install and update data, under Apple's own policies. Speech audio is processed by Apple, on your device where supported; it never reaches us |
| Supabase | Sign-in and sync database, and the servers that run search, photo matching, and the Curlhood Collective | Your email address and synced record, only if you sign in. A photo you search with passes through here, is matched, and is discarded in the same request |
| Anthropic | Answers your questions to the Curlhood Collective, and explains a scanned ingredients list | The words of your question, or the ingredient names read from a label, together with the hair traits that make the answer fit: curl pattern, porosity, and whether the hair belongs to a child. Never a photo, never your name, never your email |
| Expo (EAS Update) | Delivers app updates; the app checks for updates when it launches | Standard technical request data (app version, runtime version). Never your hair data |
| Sentry | Crash reports | Technical crash details as described above, not tied to your identity |
| PostHog | Product analytics | Which features are used, tied to your account identifier. Never what you type |
| RevenueCat | In-app purchases and membership status | Only active if a purchase key is configured in the build. When active, purchase receipts and entitlement status flow through RevenueCat; every tutorial and feature stays usable either way |
We do not sell, rent, or share your information for advertising or marketing. No data broker ever touches Curlhood data.
Deleting your data
- On your device: Settings inside the app has "reset everything." It erases all Curlhood data on the phone and starts the app over. Deleting the app from your phone does the same.
- Your account and its backup: open Settings, then Account, and choose to delete your account. We delete the account and its synced backup. If you signed in with Apple, we also revoke that sign-in with Apple. Your device keeps whatever is on it: deleting the account is not the same as erasing the app, and "reset everything" stays a separate control. If you would rather we did it, email privacy@curlhood.app from the address you signed in with and we will confirm within 30 days.
- Crash reports are retained by the provider for a limited period and then deleted. They are not tied to your account.
How long we keep things
Local data stays until you reset it or delete the app. Your synced record stays until you delete your account. We keep nothing about you after account deletion except records we are legally required to hold, if any.
Your rights
Depending on where you live, you may have the right to see, correct, export, or delete personal information we hold. With Curlhood, most of that is directly in your hands: the data is on your device, and the account holds only your email and your synced record. For anything else, email privacy@curlhood.app and we will help. We do not discriminate against anyone for exercising a privacy right.
Changes to this policy
If we change how Curlhood handles your information, we will update this policy, change the effective date, and, for meaningful changes, tell you in the app before the change applies.
Contact
KIN Ventures, LLC
Austin, Texas
hello@curlhood.app