1. Introduction and who we are
ProcureCore is a procurement and studio collaboration app for interior-design professionals on iOS and macOS. This policy covers the app and its associated cloud service.
ProcureCore is provided by Curated Design Limited (“Curated Design”), a company registered in England and Wales under company number 16720521. Our registered office is Floor 1, 8 Park Crescent, London W1B 1PG. For privacy, account, or support questions, email info@curateddesign.studio.
This policy covers the ProcureCore application. Curated Design Limited’s interior design services are covered by a separate privacy notice at curateddesign.studio/privacy-notice/.
2. Roles and responsibilities
Curated Design decides how account, subscription, support, security, and service-operation information is used. Studios using ProcureCore decide which client, supplier, project, and team information they enter and why. Curated Design and the providers listed below process workspace content so that we can supply the service.
Each studio and user is responsible for having an appropriate reason and authority to add information about clients, suppliers, colleagues, and other people. If you use ProcureCore for an employer or studio, that organisation may be the appropriate contact for questions about the workspace information it controls.
3. Information ProcureCore handles
Account and identity
- Email address, Supabase user identifier, and Sign in with Apple identifier where that sign-in method is used.
- Authentication and session records.
- Studio membership and role: owner, admin, member, or viewer.
Workspace and business content
- Projects, descriptions, clients, suppliers, products, placements, and source URLs.
- Client and supplier names, email addresses, phone numbers, physical addresses, and other contact details.
- Budgets, prices, currencies, tax settings, procurement totals, and related financial records.
- Placement, order, approval, payment, delivery, and tracking information.
- Notes, comments, issues, audit history, team membership, and role information.
- Product images, project-cover images, studio logos, file attachments, and studio branding.
- Approval attestations and optional drawn signatures.
Subscription information
- Subscription product, purchase, renewal, and expiration state.
- Entitlement state and an opaque ProcureCore billing identifier.
Apple processes App Store payments. Curated Design does not receive your full payment-card details through ProcureCore.
Optional AI information
- Your question and up to 12 earlier turns from the current in-memory conversation.
- A freshly generated, limited studio or project snapshot, including studio name and currency, and relevant project budgets, spend, and order or delivery status.
- Client names, placement issue notes, and tracking references only when you explicitly turn on “Include client & notes”. This setting is off by default.
Operational information
- Sync revisions, request identifiers, request state, quota state, error categories, and timestamps.
- Limited diagnostics that you choose to include in a support request.
4. How information is collected
Information may come from you, authorised teammates, Apple authentication and App Store services, RevenueCat, supplier websites during product import, and the technical operation of the service. A supplier website receives an ordinary network request from your device and can observe information normally associated with that request, such as its IP address.
5. Where information is stored
ProcureCore keeps a local working copy or cache on your device. Workspace records synchronise to ProcureCore’s Supabase-hosted database, and images and attachments use private file storage. ProcureCore no longer stores application data in its own CloudKit container.
Authorised studio members can access workspace information according to their role. Curated Design technically operates the service and may access server-held information where reasonably necessary for support, security, maintenance, legal compliance, or service delivery. Operational access is restricted to legitimate needs.
Workspace records and the files uploaded with them are currently hosted in the European Economic Area. If that changes we will update this policy.
6. Studio collaboration and sharing
Workspace content is shared with authorised members of that studio. Owners and admins manage access; members can work within the permissions given to them; viewers have read-only access. Do not upload information you are not entitled to share.
If someone leaves a studio or transfers ownership, shared business records may remain available to the other authorised members. Personal attribution is removed or anonymised where the service supports it.
7. Product importing
In the normal shipping configuration, ProcureCore retrieves a supplier product page from your device. The supplier site receives a normal web request. ProcureCore extracts suggested details for you to review and correct before saving.
Supplier content can be incomplete, outdated, or inaccurate. ProcureCore does not currently depend on or advertise a Curated Design-hosted import service.
8. Optional AI assistant
Studio Pro includes an optional AI assistant backed by Anthropic’s commercial API. For each request, ProcureCore may send your question, up to 12 previous turns from the current conversation, and a newly generated limited studio or project snapshot. The snapshot may include studio name and currency and relevant budgets, spend, and order or delivery status.
Client names, placement issue notes, and tracking references are included only when you turn on “Include client & notes”, which is off by default. AI requests do not include images, supplier account details, or project or client addresses.
Chat messages are held in memory by the app and are not saved to its local database or to Supabase. The in-memory conversation disappears when you clear or dismiss it or when the app exits. Supabase stores only the request ID, studio ID, request state, and timestamps needed to enforce quotas and keep an operational audit; it does not store the question, snapshot, conversation, or answer.
Anthropic processes prompts and responses to generate an answer. Under Anthropic’s standard commercial API terms, inputs and outputs may be retained for up to 30 days, subject to legal, safety, and usage-policy exceptions. Anthropic states that commercial API content is not used to train its generative models by default. Read Anthropic’s current information about commercial data retention and commercial data and model training.
AI responses may be incomplete, outdated, or wrong. Check important information before relying on it.
9. Subscriptions and RevenueCat
Apple handles App Store billing. RevenueCat helps ProcureCore manage subscription and entitlement information. It receives purchase history, subscription state, technical information needed to operate its service, and an opaque customer identifier. Public studio UUIDs and ordinary workspace content are not used as RevenueCat customer identities or provided for subscription processing.
Cancellation and refund requests are managed through Apple. Deleting your ProcureCore account does not cancel or refund an App Store subscription; you must manage the subscription separately through your Apple account.
10. Service providers
- Apple provides the device platform, Sign in with Apple, and App Store billing. See Apple’s Privacy Policy.
- Supabase provides authentication, hosted database synchronisation, private file storage, and Edge Functions. See Supabase’s Privacy Policy.
- RevenueCat manages subscription status and entitlements. See RevenueCat’s Privacy Policy.
- Anthropic processes requests to the optional AI assistant. See the Anthropic Privacy Centre.
- Resend delivers ProcureCore’s account emails, such as sign-in confirmation and password reset. It receives the recipient’s email address and the contents of that message. See Resend’s Privacy Policy.
- Supplier websites receive product-import requests made from your device.
ProcureCore includes the Supabase and RevenueCat SDKs. It contains no advertising SDK, does not use advertising identifiers, does not sell personal data, does not use cross-app behavioural tracking, and contains no behavioural analytics SDK. RevenueCat still processes purchase information, and ProcureCore keeps limited operational, billing, quota, and audit records needed to run the service.
11. Purposes and lawful bases
We use information to:
- create accounts and provide ProcureCore;
- synchronise and share work with authorised studio members;
- manage subscriptions and entitlements;
- provide optional AI responses;
- protect the service, prevent abuse, and troubleshoot problems;
- support account and data deletion; and
- meet legal, regulatory, accounting, or dispute-resolution obligations.
We allocate a lawful basis to each of those purposes.
Creating accounts, providing ProcureCore, synchronising and sharing work with authorised studio members, and providing optional AI responses: performance of our contract with you.
Managing subscriptions and entitlements: performance of our contract with you, and compliance with a legal obligation for the billing records we are required to keep.
Protecting the service, preventing abuse, and troubleshooting problems: our legitimate interests in operating a secure and reliable service. Where we rely on legitimate interests, we consider the impact on the people concerned.
Supporting account and data deletion: compliance with a legal obligation, and performance of our contract with you.
Meeting legal, regulatory, accounting, or dispute-resolution obligations: compliance with a legal obligation, and our legitimate interests in establishing or defending legal claims.
Where a studio enters client, supplier or project information into its workspace, that studio decides why the information is used and is responsible for the lawful basis for it. We process that information on the studio’s instructions.
12. Retention
- Workspace content remains while the workspace is active and until someone with the relevant permission deletes it.
- Soft-deleted records remain in Recently Deleted until restored or permanently removed; ProcureCore does not promise an automatic 30-day purge.
When a record is permanently deleted it is removed from our servers, and the deletion is applied to your other devices the next time each one connects. A device that is offline keeps its local copy until it reconnects.
Deleting a workspace removes its records and the files uploaded to it — product images, project covers, attachments and the workspace logo — from our servers.
- ProcureCore does not persist AI message content. AI quota and audit records remain until the studio is deleted.
- Under the standard commercial API terms assumed here, Anthropic may retain API inputs and outputs for up to 30 days, subject to its legal, safety, and usage-policy exceptions.
Limited billing and security records may remain for as long as reasonably needed for their purpose, or for as long as the law requires. See “Billing records” below.
Billing records. When a workspace is deleted we keep its billing and subscription history — purchases, renewals, cancellations, and any payment issues we had to investigate. These records identify the workspace by an internal identifier and an opaque billing reference. They do not contain your name or email address. We keep them for six years from the end of the accounting period they relate to, because tax and accounting rules require it, and because they are what allows a later payment or refund question to be answered. Your account, your workspace content and your uploaded files are still deleted.
Support correspondence is kept only as long as needed to deal with your enquiry and any follow-up. Security and operational records are kept only as long as needed to investigate and protect the service.
13. User controls, account deletion, and subscriptions
You can edit workspace information and use the export tools available in the app. Roles with the appropriate permission can move records to Recently Deleted, restore them, or remove them permanently.
You can delete your account from Settings, then Delete Account. Deletion removes your account, the workspaces you solely own and their records, and the working copy held on your device. Where you signed in with Apple, it also revokes that credential. Deletion is permanent and cannot be undone.
If you own a workspace that has other members, you will be asked to transfer it to another owner or delete it before your account can be removed.
Deleting your account does not cancel an Apple subscription. Cancel that separately in your Apple account settings.
If you need help, contact info@curateddesign.studio from the email address associated with the account.
14. Your privacy rights
Depending on the circumstances, UK data-protection law may give you rights to access personal data, correct it, ask for erasure or restriction, object to certain processing, receive portable data, and withdraw consent where processing depends on consent. These rights can be limited by law and by other people’s rights.
Email info@curateddesign.studio to exercise a right. For account, billing, support, and service-operation data controlled by Curated Design, we will respond directly. If your request concerns client or project information controlled by your employer or studio, we may direct you to that organisation or assist it in responding.
Data-protection complaints. If you think we have handled personal data in a way that breaks UK data-protection law, you can complain to us. Email info@curateddesign.studio with “Data protection complaint” in the subject line, or write to Curated Design Limited, Floor 1, 8 Park Crescent, London W1B 1PG. Tell us what happened, and what you would like us to put right.
We will acknowledge your complaint within 30 days of receiving it. We will then make appropriate enquiries into what you have raised, keep you informed of progress, and tell you the outcome without undue delay. If your complaint concerns client or project information controlled by your employer or studio, we will tell you, refer it to that organisation, and assist it in responding.
You may also complain to the UK Information Commissioner’s Office. Complaining to us does not affect that right. See the ICO’s guidance on making a complaint.
15. International processing
Some of our service providers process information outside the United Kingdom. Where UK data-protection law treats that as a restricted international transfer, these are the safeguards we rely on.
Supabase (Supabase Pte. Ltd, Singapore) provides hosting, database, file storage and authentication. We rely on the EU Standard Contractual Clauses, Modules Two and Three, together with the UK Addendum version B.1.0, incorporated into Supabase’s data processing addendum.
Anthropic (Anthropic Ireland, Limited) processes requests to the optional AI assistant. We rely on the UK International Data Transfer Addendum, version B.1.0, incorporated into Anthropic’s data processing addendum.
RevenueCat (RevenueCat, Inc., United States) manages subscription status and entitlements. We rely on the EU Standard Contractual Clauses as amended by the UK International Data Transfer Addendum.
Apple provides the device platform and App Store billing and acts as its own controller for that processing, under its own privacy policy.
Provider locations and transfer arrangements can change. You may ask us for more information about the safeguards relevant to a particular request by emailing info@curateddesign.studio. Commercially sensitive parts may be redacted.
16. Security
ProcureCore uses encrypted network connections, account authentication, private file storage, role-based workspace permissions, database row-level access controls, and restricted operational access. Users should protect their devices and credentials. No service can guarantee complete security.
17. Children
ProcureCore is a professional business tool for interior-design studios. It is not directed at children.
18. Changes and contact
We may update this policy when the app, providers, or legal requirements change. Material changes will be reflected on this page with a revised effective date and communicated where required.
Privacy and support enquiries: info@curateddesign.studio.
You can also read the ProcureCore Terms of Use and the ProcureCore Data Processing Schedule, or visit ProcureCore Support.
Curated Design Limited
Company number 16720521
Registered office: Floor 1, 8 Park Crescent, London W1B 1PG