Privacy Policy

Last updated: 2026-06-11

This Privacy Policy explains how Curfl (“Curfl”, “we”, “us”) collects, uses, shares, and protects personal data when you use our service: Instagram comment-to-DM automation, link-in-bio pages, lead management, and related features (the “Service”).

We act as the data controller for the personal data described here. If you have questions, contact us at support@curfl.com.

1. Information we collect

Account data: your email address, name (if provided), and authentication credentials (passwords are hashed by our authentication provider; we never see them in plain text).

Workspace and content: the link page content you create (titles, bios, links, themes, customization, uploaded images) and the business proposals you receive through your page.

Instagram / Meta data: when you connect a Meta account, we receive your Instagram Business/Creator account information and an access token. To run the automations you configure, we process public comments on your posts and send direct messages on your behalf.

Public link page visitor data: button clicks and coarse analytics, a randomly generated visitor identifier stored in a cookie, and IP address used in hashed form for de-duplication.

Leads: when your automations run, we store the Instagram username/display name and interaction metadata of people who triggered them.

Payment data: payments are processed by our Merchant of Record, Creem. We do not store full card numbers; we retain your subscription status and related identifiers.

AI / MCP connections: if you connect an AI client via MCP, we store access tokens (in hashed form) that identify the connection, and an audit log of the tool calls made on your behalf.

Cookies: an essential session cookie, a locale-preference cookie, and a visitor identifier cookie on public pages.

2. How and why we use your data (legal bases)

To provide and operate the Service, including creating your workspace and rendering your link page — performance of a contract.

To run the comment and DM automations you configure — performance of a contract and, where required, your consent.

To secure the Service, prevent abuse, and enforce limits — our legitimate interests.

To process subscriptions and payments — performance of a contract.

To comply with legal obligations, and otherwise with your consent where the law requires it.

3. Sharing and processors

We share personal data with service providers that process it on our behalf: Supabase (database, authentication, file storage, and hosting), Creem (payment processing as Merchant of Record), and Meta (to read the comments and send the direct messages you configure).

When you connect your own AI client through MCP, the data you allow that client to access is shared with that AI and its provider. This connection is under your control and you can revoke it at any time from your dashboard.

We do not sell your personal data, and we do not share it for third-party advertising.

4. International transfers

Our providers may store and process data in countries other than your own. Where personal data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms where applicable.

5. Data retention

We retain personal data while your account is active and for as long as needed for the purposes described above. We delete or anonymize data when it is no longer needed, or upon a valid request.

When you disconnect a Meta account, we revoke our access and delete the stored access token. Inactive or expired connection tokens and authorization codes are removed on a recurring basis.

6. Your rights

Subject to applicable law (including the GDPR and UK GDPR), you may have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent at any time.

You also have the right to lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact us at support@curfl.com.

7. Security

We protect data using encryption in transit, hashing of secrets and tokens, row-level access controls, and least-privilege access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Children

The Service is not directed to children under the age required by your jurisdiction (generally 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

9. Use of Meta Platform data

Data obtained through Meta (including Instagram) is used only to provide the features you enable, consistent with Meta’s Platform Terms and Developer Policies. We do not use it for unrelated purposes, and we delete it upon disconnection or upon your request.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated date above and, for material changes, take reasonable steps to notify you.

11. Contact

For privacy questions or requests, contact us at support@curfl.com.

Privacy Policy | Curfl