Safety & account protection

Automation that behaves like you.

Every account you connect runs in its own cloud browser that matches your device, moves at human speed and stays inside the limits you set. You log in yourself, so your password never reaches us. Here's how the whole thing keeps your account safe.

A browser per accountHome-region IP matchPassword never stored
01Isolated sessions

A real browser.
One per account.

Every account you connect gets its own browser running in the cloud. It loads pages and runs their JavaScript just like the browser on your desk, so the activity looks like a person at a real computer rather than a script hitting an endpoint. Each one stays walled off and tied to that single account.

  • One browser per account, never shared between seats
  • Loads the real page and runs its JavaScript
  • Stays signed in, so a session reads like a returning visit
Connected accounts4 live
AccountStatusBrowser
JWJonas Weberacc_01HQ4TX8ZHActiveisolated
LHLena Hoffmannacc_01HQ7KM3PDActiveisolated
TBTim Braueracc_01HQ2VN9RCActiveisolated
ASAnna Sommeracc_01HQ9WD5KFActiveisolated
Every account runs in its own isolated browser
02Device match

A device profile that fits you.

Each account is paired with a steady home-region IP and a full device profile: the operating system, browser, screen, language and timezone. Nothing shifts around while a session runs, so every visit looks like the same person on the same machine.

  • A home-region residential IP for each account
  • OS, browser, screen, language and timezone all lined up
  • One steady profile per seat, no mid-session shuffle
Device profilematched
Your deviceCloud browser
RegionBerlin, DEBerlin, DE match
OSmacOS 14.4macOS 14.4 match
BrowserChrome 128Chrome 128 match
Screen2560×14402560×1440 match
Languageen-USen-US match
TimezoneCET (+01)CET (+01) match
+40 parameters matched, one persistent profile per seat
03Timing

Paced like a person,
not a script.

Nothing fires back to back. Actions wait, pause and vary the way real browsing does, with a different gap each time. That uneven rhythm is most of what separates a person using LinkedIn from a bot working through a list.

  • A different pause before every action, never fixed
  • Types and scrolls at a believable speed
  • Eases off the moment LinkedIn asks it to
Time between actionsscripted vs Curviate
Scripted botfixed
The same gap, over and over. Easy to spot.
Curviatevaried
Gaps run from a moment to several seconds, no two alike.
04Limits

Ceilings you set.
A ramp we run.

Every action has a ceiling, from invites and messages to profile visits, searches, reactions and comments. Reasonable defaults are in place from the start and you can lower any of them whenever you want. Fresh seats build up slowly over a warm-up window before they reach full pace. Reach a ceiling and the action stops with a clear error.

  • Daily, weekly and monthly ceilings for every action
  • Sensible defaults you can tighten at any point
  • New seats warm up slowly before full volume
Action ceilingsEditable
Invites sent7 / 25
Direct messages23 / 60
Profile visits58 / 120
Searches11 / 40
Post reactions19 / 50
Comments4 / 20
Warm-upNew seatday 3 / 10
05Sign-in

Your password never reaches us.

You log in yourself, right inside your own cloud browser. We don't see it, record it or keep it anywhere. What we hold is an encrypted session that only lets us act for you, and you can pull it whenever you like. There's no shared login and no way for us to carry on without you.

  • You type the password; it never comes to us
  • We keep only an encrypted, revocable session
  • Drop a seat and the access is gone at once
Credential flowno password stored
An encrypted session, held by you
the password never reaches Curviate
1
You log in yourself
Right inside your isolated cloud browser. The password stays in that session.
2
We hold an encrypted session
It only lets us act for you. Nothing about the password is kept.
3
Pull access whenever
Drop a seat and the session is gone, with nothing left behind.
Not even our own team can open an active session.
Why it stays safe

What flags accounts, and what we do instead.

Most restrictions trace back to the same few tells. Curviate is built to sidestep every one.

What gets accounts flagged
How Curviate prevents it
Datacenter or shared IPs that don't match the account
A home-region IP tied to each account
Robotic, evenly spaced actions firing back to back
Human timing with real gaps, pauses and typing speed
Headless drivers or raw HTTP dressed up as a browser
A real cloud browser that renders the page the way you do
Heavy volume from a brand-new account on day one
Ceilings you set, plus a warm-up ramp for new seats
One environment and profile shared across many accounts
A dedicated, isolated browser and profile per seat
Passwords sitting inside the automation tool
You log in yourself; the password never reaches us
?FAQ

Questions we get a lot

Compliance & data
EU-hosted
Built in Germany. Processed and stored in the EU.
Encrypted at rest
Sessions and credentials encrypted; keys rotated.
Hard-delete on disconnect
Drop a seat and its data is removed across systems.
DPA on request
Data Processing Agreement and sub-processor list.

GDPR requests (access, correction, deletion, portability) and a current DPA are handled at security@curviate.com.

Automate without the second-guessing.

Connect an account and run with isolation, human timing, limits you control and no stored password, right from the first request.

COMPANY · LEGAL

Privacy Policy

Redmer Holding GmbHLast updated July 25, 2026

Who we are

Curviate is operated by Redmer Holding GmbH ("Curviate", "we", "us"), a German GmbH registered at Amtsgericht Bonn, HRB 29957, registered address Hostertstraße 16, 53332 Bornheim, Germany. Full company details are on our Imprint. We haven't appointed a statutory Data Protection Officer, since our processing doesn't reach the scale or sensitivity that requires one. Privacy questions go to privacy@curviate.com.

The two roles we play

When you create an account and use Curviate, we process your own data (identity, billing, API keys, connector authorizations). For that data, we are the controller.

When you use Curviate to act on your own connected LinkedIn account, viewing profiles, sending messages, managing engagement, that content and those contacts belong to that account and its people. You are the controller of that data; we are the processor, acting only on your instructions, under the Data Processing Agreement between us. If one of your contacts has a question about being reached through Curviate, you're who they should contact first; email privacy@curviate.com if you need help routing it.

What we collect, and why

DataWhy
Account identity (name, email, sign-in method)Create and secure your account
Your LinkedIn credentialsOperate the actions you request
LinkedIn content returned by an API callFulfil that specific request, nothing more
API keys and connector (OAuth) authorizationsAuthenticate your API, CLI, MCP, or SDK requests
Billing detailsCharge you correctly and meet our tax obligations
Usage and security logsKeep the service reliable and abuse-free
Support messagesRespond to you
Website analytics, only if you opt inUnderstand how the site is used

We rely on our contract with you, our legitimate interest in running and securing the service, our legal obligations (tax law, for example), and, for analytics, your consent. We never sell your data or use it to train models.

Where it's processed, and who else touches it

Our infrastructure runs in the EU. Hosting: Railway. Database and auth: Supabase, Ireland. Email: Resend. Payments: Stripe. Network security: a DDoS-protection provider sits in front of our app and never sees or stores request content. LinkedIn connectivity: a third-party infrastructure provider that lets us execute LinkedIn actions on your behalf. Error tracking: Sentry, Frankfurt. Product analytics: PostHog, Frankfurt. Uptime monitoring: Better Stack.

We give the current, named list of every provider above, plus our Data Processing Agreement, to any customer who asks: security@curviate.com.

Outside the EU

All customer LinkedIn data, account data, and telemetry are processed and stored exclusively in EU regions of our sub-processors. A few providers we rely on (Stripe and Sentry, for example) are headquartered outside the EU/EEA; where that applies, it's covered by their own GDPR safeguards, typically the EU Standard Contractual Clauses.

How long we keep it

DataRetention
Account and workspace dataWhile your account is active
Closed accountRecoverable for 7 days, then deleted on day 8
LinkedIn credentialsUntil you disconnect that account
LinkedIn contentNot stored; any transient cache clears within 1 hour, never indexed, never used for training
API keysUntil you revoke or rotate them
Connector (OAuth) authorizationsAccess token ~1 hour; refresh token up to ~12 months, or until you revoke it, whichever comes first
Billing recordsAs required by German tax law, currently up to 10 years
LogsA short operational window; metadata only, never message content

The 12-month figure above is a server-side credential for a connected AI agent or app. It is not a cookie and doesn't touch your browser session; see Cookies below for that. You can see and revoke every connector from Authorized applications in your dashboard at any time.

Cookies

We keep cookies to a minimum, and ask before anything beyond the essentials runs.

Strictly necessary, no consent needed:

NamePurposeExpiry
cc_cookieRemembers your cookie choice12 months
curviate-themeRemembers light/dark mode (local storage, not a cookie)Persistent
sb-*-auth-tokenKeeps you signed inWhile active; cleared on sign-out

Analytics, only if you accept:

NamePurposeExpiry
_gaGoogle Analytics: distinguishes visitors2 years
_gidGoogle Analytics: distinguishes visitors24 hours
_ga_<container id>Google Analytics: persists session state2 years

No advertising cookies, ever. Accept and reject are equally easy, and you can change your mind any time via Cookie Preferences in the footer; we won't ask again for 12 months unless something material changes. Our LinkedIn connect flow and OAuth authorization screen never set anything beyond the essentials, so no banner appears there.

Connecting an AI agent or app

Curviate is built for AI agents and automated clients as much as for people. If you connect an app like Claude, or your own code, via an API key or an OAuth connector, it can act on your workspace within the access you gave it. What it does with anything it receives back, including what it sends to its own AI model, is between you and that provider; review its practices before connecting it. Review and revoke any connection any time from your dashboard.

Your rights

You can access, correct, delete, restrict, or object to your data, port it elsewhere, and withdraw consent at any time: email privacy@curviate.com. Closing your account starts the 7-day recoverable window above. We don't make automated decisions about you that have a legal or similarly significant effect. You can also complain to a supervisory authority; ours is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), www.ldi.nrw.de, though you're free to complain to the one in your own country instead.

Keeping it secure

Credentials are encrypted and never logged, returned, or shared. LinkedIn actions run through native, humanized flows; full detail is on our Security & Compliance page. If a breach puts your rights at risk, we'll notify the authorities and you, as GDPR requires. Curviate isn't directed at, or offered to, anyone under 16.

Changes

We'll update this page when our practices change, and reset the cookie prompt if the change is material.

Contact