togetherup
Terms of Use Privacy Policy
v1.0 Sign in
Privacy notice · CureforU

Privacy Policy

What we store, why we store it, who can see it, how long we keep it, and how to get it back or have it erased — written plainly, with the legal detail kept where it belongs.

Effective1 September 2026
Versionv1.0
StatusDraft
Applies toAll users of the app
Contactprivacy@cureforU.com
Reading time9 minutes

In short. We collect what running a community space requires and nothing more. We do not sell personal data, we do not advertise, we run no analytics or tracking tools, and we do not use your messages to train machine-learning models. Health information you choose to share is special category data and is processed only with your explicit consent, which you can withdraw at any time.

01Who is responsible for your data

Two parties are involved, and which one is responsible depends on the data.

DataCureforUYour organisation
Your account, sign-in, and platform settings
Controller
—
Membership, channels, and what is discussed in them
Processor
Controller
Moderation decisions inside a community
Processor, escalations only
Controller
Platform security, hosting, and the audit log
Controller
—

CureforU operates the Platform from Belgium. Where we act as a processor, we do so under a Data Processing Agreement with the organisation and only on its documented instructions. Questions about either role go to privacy@cureforU.com.

02What we collect

Everything below is data the application actually stores. Nothing here is aspirational, and nothing it stores is left out.

  • Account details — your first and last name, email address, a hash of your password (never the password itself), your language, and whether your email has been verified.
  • Sign-in identities — which sign-in methods you have linked: a password identity, and the Google account identifier if you choose Google sign-in.
  • Sessions and sign-in records — a device label, browser user agent, IP address, when the session was last active, when it was revoked, and any elevated-access window for platform staff.
  • Preferences — theme, text size, desktop and sound notification settings, and which organisation you used last.
  • Organisation membership — your role, the display name you use in that organisation, and your profile photo.
  • Channel membership and join requests — which channels you belong to, and requests you have made to join closed ones, with their outcome.
  • Messages — what you write, whether a message was edited, deletion markers left in place of removed messages, and the join and leave notices shown in a channel's timeline.
  • Files you attach — the file itself, along with its name, type, size, and image dimensions.
  • Reactions, mentions, and pins — the emoji you react with, who you mention, and which messages are pinned.
  • Read and delivery receipts — how far you have read in each channel and how far your messages have reached others.
  • Presence — whether you are online, when you were last seen, and whether you have chosen to appear offline.
  • Muted channels — which channels you have muted, and until when.
  • Moderation — reports you file or that are filed about your content, and the outcome of each review.
  • Invitations — the invited email address, who sent the invitation, and its state.
  • Security tokens — email-verification, magic-link, and password-reset requests, stored hashed and short-lived.
  • Consent record — when you accepted these documents, which version of each, whether you consented to the use of health-related information, and whether you gave those confirmations by ticking boxes or by continuing past a notice. GDPR Art. 7(1) requires us to be able to demonstrate it.
  • Audit log — moderation, membership, role, and administrative actions, written to an append-only, hash-chained log so tampering is detectable.

We do not collect location data, contact lists, advertising identifiers, or behavioural profiles, and we run no analytics or tracking tools of any kind.

03Health-related information

Some communities on the Platform relate to health conditions and patient advocacy. Anything you share that reveals health status or medical circumstances is special category data under GDPR Article 9.

  • We process it only on the basis of your explicit consent (Art. 9(2)(a)). You are asked for it separately when you create your account, and it is optional — you can use the Platform without giving it, and we record which version of this notice you saw when you did.
  • You may withdraw that consent at any time from Settings → Privacy, or by emailing privacy@cureforU.com. Withdrawal takes effect immediately and does not affect processing that was lawful before it. Withdrawing stops future use; it does not delete what you have already posted — use your right of erasure for that.
  • Do not post another person's health information without their explicit consent.
  • We do not analyse, classify, or profile message content for health information, and we never use it for advertising or research.

04Why we process it, and on what basis

Every purpose has a lawful basis under GDPR Article 6. There are no others.

  • Running the service — delivering and storing messages, syncing read state, rendering your roster and channels, sending the emails the service depends on. Contract, Art. 6(1)(b).
  • Security, safety, and moderation — authenticating you, rate-limiting abuse, handling reports, and keeping the audit log. Legitimate interests, Art. 6(1)(f) — our interest in a safe community and the members' interest in not being harmed.
  • Legal obligations — retaining records we are required to retain and responding to lawful requests. Art. 6(1)(c).
  • Optional notifications — desktop and sound alerts you switch on yourself. Consent, Art. 6(1)(a), withdrawable in your settings at any time.
  • Health-related content — as described above. Explicit consent, Art. 9(2)(a).

05Who can see what

Visibility follows the role model your organisation configures.

  • Members see the channels they have joined, the organisation roster, and the display names and presence of other members.
  • Chat Group Managers see everything a member sees, plus join requests and reports in the channels they manage.
  • Admins and Organisation Owners see the full roster, invitations, role history, and every moderation queue in their organisation, and may access membership and activity data for administration.
  • Reporters stay private — the person whose content was flagged is not told who flagged it.
  • Platform staff at CureforU may access data only where necessary to operate the service, investigate an escalated report, or comply with the law. Administrative access requires re-authentication into a time-limited elevated session, and every action taken in it is recorded in the audit log and marked as staff action.

06Who processes data for us

A small number of vetted providers, each bound by a data-processing agreement:

  • Application and database hosting — in the European Union (Frankfurt). Within the EEA.
  • Object storage for attachments and profile photos — an EU-region-restricted bucket. Within the EEA.
  • Transactional email delivery — a US-headquartered provider that relays verification, invitation, and notification emails. Transfers are covered by Standard Contractual Clauses; the provider receives only the recipient address and the content of the email itself.
  • Real-time message transport — EU-hosted, carrying messages in transit between connected clients; it stores no personal data at rest.
  • Google — only if you choose Google sign-in. We receive your verified email address, name, and Google account identifier; your relationship with Google is governed by their own terms.

We do not sell personal data to anyone, and we do not share it with advertisers, data brokers, or analytics providers — we use none.

07How long we keep it

  • Messages and attachments are kept for as long as the organisation's space exists, unless you or a moderator delete them. Deleted messages are removed from view and replaced with a marker showing that something was removed.
  • Moderation records and the audit log are retained for 12 months for security and compliance, including after you leave an organisation.
  • Sessions expire and are swept automatically; you can revoke them yourself at any time.
  • Security tokens — verification, magic-link, and password-reset requests — are short-lived and single-use.
  • Presence holds only your current status and last-seen time; it keeps no history.
  • Invitations expire on their own schedule and are retained in their final state as a record of who was invited.
  • When you delete your account, your personal data is erased or pseudonymised. Records we are legally required to retain — chiefly audit entries — survive for their retention period and no longer.

08Your rights

Under the GDPR you have the right of:

  • Access (Art. 15) — a copy of the personal data we hold about you.
  • Rectification (Art. 16) — correction of anything inaccurate; most of it you can edit yourself in your profile.
  • Erasure (Art. 17) — deletion of your account and personal data.
  • Restriction (Art. 18) — to have processing paused while a dispute is resolved.
  • Objection (Art. 21) — to processing based on legitimate interests.
  • Portability (Art. 20) — your data in a portable, machine-readable form.

You may also withdraw consent at any time — the health-related information consent from Settings → Privacy, and notification alerts from your notification settings — without affecting processing that was lawful before withdrawal. Send other requests to privacy@cureforU.com; we respond within one month. Requests that would erase another person's record — a report they filed, for instance — are reviewed individually so both people's rights are weighed.

If you are not satisfied, you may lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données) at www.autoriteprotectiondonnees.be, or with the supervisory authority where you live.

09Security

Data is encrypted in transit with TLS and at rest by the hosting provider. Passwords are stored only as salted hashes; sign-in tokens, magic links, and reset tokens are stored hashed and expire quickly. Sessions can be revoked individually or all at once, and every administrative action is written to an append-only, hash-chained audit log so tampering is detectable.

In the event of a personal data breach we notify the supervisory authority as required by GDPR Art. 33, and — where the breach poses a high risk to your rights — we notify you without undue delay under Art. 34.

10Automated decisions

No decision that produces legal effects or similarly significantly affects you is made solely by automated means. Automated checks may flag content or rate-limit suspicious activity, but a person reviews every moderation outcome before action is taken.

11Cookies and local storage

Only what the service strictly needs — so no cookie banner is required, because there is nothing optional to consent to:

  • A session cookie that keeps you signed in.
  • A CSRF token that protects forms from cross-site abuse.
  • Your theme and text-size preference, so the app looks the same each time you return.
  • A small amount of device-local storage for conveniences such as your recently-used emoji. This never leaves your device.

There are no advertising, tracking, or analytics cookies, and no third-party scripts of any kind.

12Children

You must be at least 16 years old to create an account, as set out in the Terms of Use. We do not knowingly collect personal data from anyone below that age; if we learn that we have, we delete the account and its data.

13Changes to this notice

We may update this notice. Material changes are communicated by email or in-app notice at least 14 days before they take effect, and the effective date and version at the top of this page always tell you which notice applies. Your consent record keeps the version you accepted, so a later revision never changes what you agreed to.

14Contact us

Privacy questions, data-subject requests, and complaints go to privacy@cureforU.com. You may also contact the Belgian Data Protection Authority (Autorité de protection des données) directly.

CureforU

Belgium · Privacy & data protection: privacy@cureforU.com

On this page
Who is responsible What we collect Health information Why, and on what basis Who can see what Who processes data for us How long we keep it Your rights Security Automated decisions Cookies and local storage Children Changes to this notice Contact us
togetherup
Privacy Terms © 2026 CureforU