CurbPage privacy policy

Last updated 2026-08-25

CurbPage manages bookmark profiles, one-time passwords, relative links, and a shared password vault. It runs in your browser and keeps its data in an encrypted local database.

CurbSoftware is the controller for this product and the CurbApps account. Questions: curbapps.com/contact.

Local-first by default

Your data lives in a local database inside the extension, encrypted at rest with a key generated on your device. Using CurbPage without a CurbApps account sends no product data anywhere.

What CurbPage does

  • Bookmarks permission: reads and writes your bookmarks to save, switch, and restore profiles. Nothing is uploaded unless you connect an account.
  • Downloads permission: saves the export files you explicitly request.
  • Notifications permission: confirms profile actions you take.
  • Camera, on demand: scanning a QR code to add an authenticator account. The stream never leaves the popup.
  • Optional Gist backup connects to api.github.com with a token you provide. It only runs when you start it.
  • Optional premium classification sends a page title and URL to our worker for a one-time result. They are used in memory only, never stored or logged.
  • Saved logins are encrypted under your account key. A master password wraps that key for recovery on CurbPlace, web, mobile, or another browser.
  • Connected sync (premium) uploads bookmarks, profiles, authenticator accounts, and vault entries as encrypted envelopes our servers cannot read.

If you use a CurbApps account

An account is optional. Creating one at curbapps.com collects your email and authentication data (processed by Supabase) and, if you pay, billing data (processed by Stripe). CurbSoftware never receives your card details.

Connected sync is zero knowledge. Before anything leaves the device it is encrypted with an account encryption key wrapped by a key derived from your master password. Our servers store ciphertext envelopes they cannot read. There is no password reset: if you forget a master password set on a vault, the data cannot be recovered.

Third-party requests

Any outbound requests this product makes are listed in the "What CurbPage does" section above. We do not embed analytics, ad trackers, or fingerprinting scripts.

Changes

If this policy changes, the date above changes with it. Material changes are announced in the product before they take effect.

Other CurbApps

Privacy