Legal
Privacy Policy
This page explains what information Curio Garden handles, where some of that information is stored, and the third-party services involved when you browse, save bookmarks, sign in, or listen to audio.
Last updated: August 11, 2026
Overview
Curio Garden is an informational reading and listening experience built around Wikipedia content. You can browse without an account, or you can sign in to sync bookmarks, build a listening playlist, and save listening progress across devices.
The service is designed to keep some convenience features on your device when you are signed out, while storing signed-in bookmarks on the service so they can follow your account. The sections below name the other signed-in information Curio Garden stores.
Information Curio Garden may handle
- Account information from Clerk, such as a stable account identifier and, depending on your sign-in method, profile details like your name, email address, or profile image.
- Signed-in bookmark data, including saved article slugs, titles, and timestamps, so bookmarks can sync across devices.
- Personal Playlist data, including playlist order, episode-generation status, generated episode files, and private RSS feed token.
- Signed-in article listening progress, including heard ranges and qualification timestamps, and the latest listening section and position so playback can resume across signed-in devices, along with topic-badge credit earned from qualifying listening.
- Signed-in article-audio export records and generated files, plus account-linked generation quota windows used to limit repeated or unusually heavy audio-generation requests.
- Browser-stored data for signed-out use, such as guest bookmarks, reading history, listening history, and interface preferences like theme and playback settings.
- Basic technical and analytics data used to operate and improve the service, such as performance and diagnostic information from hosting and analytics providers.
- AI and audio operational records, including provider attempts, measured usage and response sizes, cache reuse, and aggregate signed-in listening progress. These records help compare provider costs with generated and reused audio.
- Information you choose to submit through the feedback form. This may include a feedback message, optional details about your browser, device, assistive technology, or other environment, an optional contact email, and whether you opt in to invitations for future research. When you choose “Give feedback on this article,” the article title, article identifier, and saved Wikipedia revision are also included so the feedback can be connected to the page you were using.
How this information is used
- To sign you in and keep your session working securely.
- To sync signed-in bookmarks across devices.
- To remember signed-out preferences and local convenience data.
- To deliver audio features, improve reliability, and understand service performance.
- To prevent abuse, protect the service, and troubleshoot issues.
- To understand feedback and access barriers, improve the product, and contact you about your feedback or future research only when you choose to provide an email address for that purpose.
AI and audio cost records
Curio Garden keeps limited operational records to understand the cost and reliability of AI and audio generation. This ledger does not store article or narration text, page titles, full URLs, account identifiers, network addresses, or raw provider error messages. Raw provider-attempt, cache, generation-observation, and listening-contribution records are scheduled for deletion after 90 days using bounded cleanup batches, so a cleanup backlog can retain a record longer. Reduced daily totals, opaque duplicate-prevention receipts, and aggregate provider cost statements may be kept longer for accounting and service planning.
Listening comparisons use the signed-in article progress Curio Garden already stores. The ledger does not observe guest listening or listening in external podcast and download clients. Those external uses are treated as unknown rather than as unused audio.
For these comparisons, Curio Garden temporarily keeps the current signed-in listening session’s exact heard ranges and start time. This session accumulator expires after about two hours without activity in that session. An hourly bounded cleanup clears expired session accumulators and older accumulators that lack an expiry, continuing in batches through any backlog even when cost observation is off. A live session accumulator and its expiry are included in your account data export.
Feedback and research
The feedback form is available without signing in. A message is required when you submit feedback. Environment details and a contact email are optional unless you opt in to research invitations, in which case an email address is needed so an invitation can reach you. You do not need to share a medical condition or diagnosis to describe an access need, report a barrier, or suggest an improvement.
Feedback is used to understand what is working, identify barriers, and decide what to improve. If you provide an email address, it may be used to follow up about your feedback. Curio Garden will use it for research invitations only if you opt in. Feedback is not automatically joined to your signed-in account. Curio Garden removes the contact email from stored feedback when it reaches 180 days and turns off the related research opt-in. An hourly cleanup works in bounded batches and immediately schedules additional batches until any backlog is drained. The feedback message and any environment details remain so the team can continue to understand product issues and access barriers. Article context also remains with article-specific feedback. You can share feedback on the feedback page.
To limit repeated submissions, the server derives an opaque, secret-salted identifier from the request's network address. Curio Garden does not store the raw network address with your feedback. The separate quota record's active window ends after one hour. An hourly cleanup deletes expired quota records in bounded batches of up to 500 until the current backlog is gone.
What stays on your device
When you use Curio Garden while signed out, some data may be stored in your browser using local storage so the app can remember things like bookmarks, reading history, listening history, and theme preference.
When you later sign in, guest bookmarks on that device may be imported into your account once so they can sync. Local history and similar convenience data remain device-local in this version of the app. Device-local information is outside Curio Garden’s server-side account data.
Third-party services
- Clerk is used for authentication and account sessions, including social sign-in providers such as Google if enabled.
- Convex stores application data used for signed-in features such as synced bookmarks, playlist episodes and audio, private feed access, listening progress, badge credit, and article-audio exports. It also stores anonymous feedback, any contact or research details you choose to provide, article context attached to feedback, and opaque submission-quota records.
- Hosting and analytics providers may process limited technical data to run the site and measure performance.
- Wikipedia content is displayed under its own licenses and policies.
- Audio generation may use Microsoft Edge TTS or OpenAI synthetic speech services. OpenAI speech is reserved for signed-in listening and trusted personal audio generation.
Shared article and audio caches and aggregated analytics are not treated as account-owned data. They may remain when an individual account record is removed because they support the public service and do not represent that account’s private playlist or listening history.
Your choices
- You can browse Curio Garden without creating an account.
- You can clear browser storage through your browser settings if you want to remove device-local guest data.
- If you sign in, you can remove saved bookmarks from your account in the app.
- From the Account & data page, you can download a portable JSON copy of your server-side account data. It includes bookmarks, Personal Playlist order and episode status, listening progress, topic-badge credit, personal feed state, and metadata about article-audio exports and generation quota windows. The exported listening progress includes the latest saved section and position. While the feed URL is active, the active private RSS feed token is included and remains a bearer credential, so keep the export private. Revoked feed tokens are not included. The export contains metadata about article-audio exports, not the generated audio files themselves. Device-local history and preferences, anonymous feedback, shared caches, and aggregated analytics are excluded.
- From the same Account & data page, you can permanently delete your Curio Garden account. Deletion removes the Clerk sign-in and profile Curio Garden uses, signed-in bookmarks, Personal Playlist records and account-linked generated episode files, private RSS feed access, signed-in listening progress, topic-badge credit, account-linked article-audio export records and generated files, and related generation quota windows. Deletion also removes the latest saved listening section and position. Private RSS access is turned off as the deletion is accepted. Some removal may finish in the background after sign-in ends.
- A limited technical deletion record is retained while account-owned cleanup or Clerk deletion is pending, including while a failed step is being retried. The final 24-hour grace period begins only after account-owned cleanup and Clerk deletion both succeed. At the end of that period, the record is deleted if a final safety check confirms no account-linked data remains; otherwise cleanup and the grace period restart. This temporary record prevents signed-in data from being recreated by an old session or in-progress audio job. Browser-only history and preferences are not removed automatically. Files already downloaded to a device or podcast app cannot be recalled. Anonymous feedback, shared article and audio caches, and aggregated analytics remain because Curio Garden does not treat them as account-owned data.
- A private RSS URL is a revocable bearer credential: anyone who has the address can use it. From the dashboard, you can replace the address or turn the feed off without deleting your playlist. Replacing or turning off the feed stops future access through Curio Garden’s feed and media routes. Previously downloaded, cached, or directly accessed copies cannot be recalled.
- If you use Google sign-in, you can also manage that connection from your Google account permissions.
Changes to this policy
Curio Garden may update this Privacy Policy from time to time as the service changes. Material updates will be reflected by updating the date at the top of this page.
Questions about Curio Garden's privacy practices can be sent through the feedback page.