SECURITY & PRIVACY
What we collect, and who else touches it.
Curia Technologies handles two very different kinds of information: ordinary business details about the people who contact us, and medical records belonging to injured people who have never heard of us. They are kept apart, deliberately, and this page explains both.
Last updated 19 August 2026.
Artificial intelligence is part of this service
Curia uses AI models to read medical records and produce audit reports. This is not incidental. It is how the audit works. Every report says so on its face.
A person at Curia reads every report before it reaches a firm, and no report is legal advice. AI output is a starting point for a qualified professional, never a substitute for one. Your files are not used to train anyone’s models.
What we collect from the website
When you fill in a form we collect your name, your firm or practice, your email address, your phone number if you give it, and whatever you write in the message box. We collect it because you asked us to contact you, and we use it for that.
Like every website, ours records ordinary technical details when you visit: IP address, browser, which pages loaded. We do not run advertising trackers on this site and we do not sell anything about you to anybody, ever.
The form asks you not to include patient names or medical details, because that is not the right place for them. If you send them anyway we will move them somewhere appropriate or delete them.
What we collect inside the portals
If your firm or practice works with us, we hold the accounts of the people you tell us to give access to, the case reference numbers you use, what stage each case is on, the amounts owed between firms and practices, and the records practices send.
The database deliberately holds no patient names, no diagnoses and no documents. A case is a reference number and a stage. Everything identifying lives in Google Drive under an agreement that covers health information. That split is the single most important design decision in this product.
Medical records
When a practice sends records for a case, those records are protected health information and we handle them as a business associate of the firm and the practice.
No protected health information moves before a Business Associate Agreement is signed. Records go from the sender’s browser directly to Google Drive. They do not pass through this website. They are encrypted in transit and at rest. Access is limited to the people working the file. A person at Curia reviews each record before a firm can see it.
When an audit is run, the documents are read by an AI model under an agreement covering health information. That agreement requires the model provider to hold the data for 30 days. It is not used for training.
How access is controlled
Curia uses controlled, role-based access and secure workflows for sensitive information. Where Curia performs services involving protected health information for a covered entity, the parties use appropriate Business Associate Agreements and required safeguards.
The controls are in the database, not just on the screens. Every table enforces row-level security, so a firm’s sign-in can only ever return that firm’s rows. Records are invisible to a firm until a person at Curia reviews and releases them, and the release itself is what grants access to the document.
Every time someone opens a record, the open is written to an access log that can only be added to. It cannot be edited and cannot be deleted, by anyone, including us, and each entry is stamped with the signed-in identity by the database itself. Who saw what is a matter of record, not memory.
Who else touches your information
These are the companies your information actually passes through. They are service providers acting on our instructions, not buyers of your data.
Vercel
Runs this website.
Your IP address and browser details when you visit. Never medical records. The site is built so documents cannot pass through it.
Supabase
The database behind the portals.
Accounts, organisations, case reference numbers, stages, amounts owed, enquiries from the form. No patient names, no diagnoses, no documents.
Google (Workspace and Drive)
Where documents are stored.
Medical records and the audit reports written about them, under a signed agreement covering health information.
Anthropic
The AI that reads records during an audit.
The documents themselves, when an audit is run, under a signed agreement covering health information. Not used to train models. Held for 30 days, which that agreement requires.
Resend
Sends our email.
Your name and email address when we reply to you or notify you.
If we ever add another company to this list, this page changes before the data moves.
What we never do
We do not sell your information. We do not rent it, trade it, or hand it to data brokers. We do not use medical records for marketing. We do not let one firm see another firm’s files. The database itself refuses, which is a stronger guarantee than a promise about screens.
How long we keep things
Enquiries from the website: three years, unless you ask us to remove them sooner.
Case data and records: for as long as we are working with your firm, and afterwards for the period your own retention obligations require. Firms and practices have their own legal duties about how long files are kept, and ours follow yours rather than overriding them. We will agree the specifics in writing before you send us anything.
Your rights
- See it. Ask what we hold about you and we'll send it.
- Correct it. Tell us what's wrong and we'll fix it.
- Get it back. Ask for a copy in a form you can take elsewhere.
- Have it removed. Ask us to delete it. Some records we are required to keep, and we'll tell you which and why rather than quietly keeping them.
- Tell us to stop. Ask us to stop emailing you, or to stop processing your information, and we will.
Write to admin@curiatechnologies.net and a person will answer. If a patient wants to exercise rights over their medical records, that request goes through the firm or practice holding the relationship, we’ll help them action it.
If something goes wrong
If information is exposed, we will tell the firms and practices affected, and we will do it quickly rather than quietly. Where the law requires notice to individuals or regulators, we will give it. We would rather tell you about a problem than be found to have sat on one.
Children
This service is sold to businesses and is not directed at children. Medical records we handle may relate to a minor who was injured; those are handled under the same agreements as every other record, through the firm representing them.
Changes
When this page changes we will update the date at the top. If a change materially affects how we handle your information, we will tell you rather than relying on you to re-read it.
Questions about any of this go to admin@curiatechnologies.net.
Curia Technologies · Florida, United States. This page describes our actual practice and is not legal advice. It is not a substitute for the Business Associate Agreement or the services agreement, which govern in the event of any conflict.