Public Alpha privacy notice

Measure discovery without building a surveillance profile.

This notice describes the data behavior implemented and operationally verified for CurioBeam's Public Alpha. EdgeOne Makers is the selected web-hosting/CDN path after a successful live compatibility PoC. The final curiobeam.com cutover, production-domain verification, and public privacy contact still must be completed before external Alpha invitations begin.

Browsing

No consumer account is required

Normal browsing, search, discovery pages, and app pages do not require a CurioBeam consumer account. Admin authentication is a separate restricted system for CurioBeam editors.

Analytics

A small first-party discovery funnel

Public Alpha analytics measure a limited set of product events: searches, filter use, no-result searches, result opens, app views, and clicks to active official app destinations. Keystrokes, hovers, scrolling, clipboard contents, session replay, and full form payloads are not analytics events.

Accepted analytics events use a random first-party cookie named cb_session for up to 30 minutes so CurioBeam can connect a short search → app → outbound journey. The cookie is HttpOnly, SameSite=Lax, and Secure on HTTPS. It is not derived from an email address, login, IP address, device fingerprint, or user-agent string.

Network data

What product analytics does not store

The analytics database does not store raw IP addresses, hashed IP addresses, user-agent strings, browser or device fingerprints, cross-site identifiers, external tracking IDs, or permanent anonymous visitor profiles.

Request addresses can be transformed with a process-random salt and held briefly in process memory for abuse rate limiting; that value is not inserted into the analytics database. The selected EdgeOne Makers runtime has separate infrastructure observability outside the product analytics system. Current EdgeOne Makers documentation states that project runtime/function logs are retained for 24 hours by default. CurioBeam does not treat those platform logs as product analytics or use them to build visitor profiles.

Search text

Bounded, reduced, and automatically expired

Retained search text is bounded to 256 Unicode code points. Obvious email-address patterns and long numeric sequences are replaced with redaction markers before storage. Structured filters are allow-listed and bounded.

Retained raw search text receives a 30-day expiry timestamp. The production database runs a daily scheduled purge that removes query text after it expires while preserving non-query event metrics. The scheduled operation has been verified with an actual expired-row run. Because the purge runs daily, this notice does not promise deletion at an exact second after the 30-day expiry point.

Submissions

The Alpha form asks for an app URL

The current public submission flow accepts an app URL without an account or payment. It also contains a hidden anti-bot honeypot field. The Alpha form does not ask for a submitter name, email address, or marketing profile. Submitted product URLs enter CurioBeam's review workflow and may be matched to an existing product to avoid duplicates.

Database and authentication

Supabase is hosted in Canada Central

CurioBeam's hosted production database and restricted admin authentication foundation use Supabase in the Canada Central region (ca-central-1). Public application access is mediated through bounded server-side operations and database authorization rules rather than unrestricted public table access.

Admin authorization is a separate restricted family: authentication alone does not grant editorial authority. The Admin application uses an authenticated Supabase user session plus CurioBeam-owned database role and RLS/RPC checks, and it is not designed to receive the Supabase service-role secret in browser code.

Web hosting

EdgeOne Makers is the selected Alpha web runtime

CurioBeam has selected Tencent EdgeOne Makers as the Public Alpha web hosting/CDN path after live testing of the Next.js application on an EdgeOne project domain. The compatibility gate covered representative public routes in desktop and mobile Chromium and verified normal server-rendered page delivery before the custom-domain cutover.

EdgeOne Makers provides the web runtime, edge delivery, TLS for bound domains, and platform observability. Its runtime/function log console currently retains logs for 24 hours by default. EdgeOne also documents separate access-log products and controls; CurioBeam will record the actually enabled production settings at final cutover rather than imply that optional logging features are active.

Retention and control

No hidden promise beyond the implementation

Raw search-query text follows the 30-day expiry and operational daily purge described above. Other bounded Alpha event fields are retained for product measurement until a broader production retention schedule or aggregation policy replaces them. CurioBeam will update this notice when account/claim features, new processors, or materially different data flows are enabled.

Before external Public Alpha invitations, CurioBeam will also publish the final privacy contact and re-check that this notice matches the actual custom-domain, hosting, logging, database, and authentication configuration then in use.