Privacy Policy
This policy describes CuratorNote's reviewed Hong Kong privacy commitments alongside implementation facts from the released application and service.
Effective date
This policy takes effect on 2026-08-02, as recorded in the approved publication fixture.
Scope
This policy covers the CuratorNote web application and public website. PING BUSINESS & TECHNOLOGY LIMITED acts as the data-controller/data-user. The governing privacy jurisdiction is Hong Kong SAR (HK) under the Personal Data (Privacy) Ordinance (Cap. 486). No registered address, DPO appointment, or additional jurisdiction is implied.
Data we receive
Authentication accepts an email address or, when configured and selected, a Google OAuth response using scope openid email. The service derives a salted hash from the normalized email for identity lookup. OTP verification stores a code hash rather than the plain code, and that OTP expires after five minutes. Turnstile can process a challenge token and request IP information for bot checks. The production Google-enabled status, Google provider reference, and OTP email provider identity remain pre-deploy evidence gates; the recorded OTP provider is Cloudflare Email Service.
Data stored on your device
The browser can keep local-first workspace data in IndexedDB. A browser-created encryption key is used for protected content, and the user's master-password flow controls access to encrypted records. Device security, browser extensions, downloaded exports, and loss of credentials remain outside the protection CuratorNote can provide.
Data stored or processed by the service
The service receives server-visible metadata needed to authenticate requests, route records, synchronize state, and operate storage. Cloudflare storage uses D1 for tenant data and R2 for media objects at release 2527a67c25b0e625831464ce3cc0b827e582986d; Durable Objects configured: false. Encrypted content is accompanied by operational identifiers, versions, and timestamps. API keys are stored as hashes. Comments are currently unavailable. No product analytics are configured, and encrypted-profile release status remains audited-release-limitation.
Authentication and cookies
The committed code lifetimes are 5 minutes (300 seconds) for an OTP code; OAuth state has a 10-minute (600-second) lifetime; and the session cookie and token have a 30-day (2592000-second) lifetime. Expiry prevents later authentication use; it is not a promise of immediate physical row erasure. The reviewed cookies are cn_session and cn_oauth_state; both are HttpOnly and SameSite=Lax, and Secure in production.
Service providers
The committed configuration identifies Workers, D1, R2, Email Service and the conditional service Turnstile; the website deployment target is Pages. Google OAuth is available only when configured. The complete production subprocessor inventory currently has 2 approved entries and remains a pre-deploy gate, as do the OTP provider and Google-enabled status. CuratorNote does not promise Hong Kong-only data residency.
Retention and deletion SLA
Account and service data needed to provide CuratorNote is retained while an account is active and the service is used, only while the relevant purpose remains necessary. After identity and authority are verified, PING BUSINESS & TECHNOLOGY LIMITED will delete or irreversibly anonymise ordinary-production personal data within 30 calendar days. This is a company SLA and explicitly non-statutory; it is not a deadline required by the PDPO. A case-specific hold may retain only necessary data for only the necessary period for law, fraud, a security incident, a dispute, or legal claims.
Provider continuity copies
No fixed provider backup duration is published because the provider lifecycle evidence remains pre-deploy-required. Where residual continuity copies exist and cannot practicably be edited record by record, the approved policy requires isolation from ordinary use, the provider's documented lifecycle, and reapplication of deletion before restored data returns to ordinary use. These controls must be evidenced before final policy approval.
Security boundaries
CuratorNote uses browser encryption for protected note content and stores password-derived or API credentials as verification material where implemented. Server-visible metadata, authentication information, traffic information, compromised devices, authorized exports, and content a user deliberately shares remain important boundaries. No security mechanism eliminates every risk.
Your choices and deletion
Send privacy, access, correction, or deletion requests to support@curatornote.com. The current per-item media action is not sufficient evidence that an underlying R2 object was removed. Until a separately committed backend provides server-authoritative object-key resolution, fail-closed R2 deletion, and retry idempotency, complete ordinary-production erasure requires a verified support-assisted workflow under the company SLA. That workflow, mailbox ownership, controlled receipt, and response-log evidence remain pre-deploy gates.
Contact CuratorNote privacyAccess and correction
A statutory data access request is handled within 40 days after receipt, subject to permitted PDPO grounds; if full compliance is not possible, written inability and reasons are given within that period and compliance follows as soon as reasonably practicable. A statutory data correction request follows an earlier access-request copy and is handled without a fee within 40 calendar days after receipt. Partial compliance and written reasons are due within that period; refusal notice and reasons cannot be deferred, and refusal particulars are logged for 4 years. Official correction guidance: https://www.pcpd.org.hk/english/resources_centre/publications/files/dcr_e.pdf.
International and legal notices
By using CuratorNote, users represent that they are at least 18. This is a contractual eligibility rule; the current code does not enforce it. Cloud and other processors may handle data outside Hong Kong for disclosed service purposes only, with contractual or other safeguards for purpose, security, onward transfer, retention, erasure, and deletion assistance.
Changes
We may update this policy as the product, infrastructure, or legal requirements change. Material revisions will carry a new effective date and a clear publication record, and the implementation will be re-audited when the policy changes.
Contact
The owner-attested contact for privacy rights and deletion requests is support@curatornote.com. Live inbox receipt, ownership, and response logging must pass the pre-deploy gate before this draft becomes final.
Contact CuratorNote privacy