Privacy Policy
Legal · last updated 22 August 2026
The short version: CurioFeed is a free, ad-supported set of calculators and reference data. You do not need an account and we do not ask you for anything to use it. The only personal data involved comes from advertising and from running the website — and advertising data only if you agree to it.
Last updated: 22 August 2026.
1. Who is responsible for your data
The controller of the personal data described in this policy is the owner of this website:

- Trading name: TEKY
- Legal form: sole trader (natural person), established in Spain
- Contact: contact form
There is no Data Protection Officer: this is a one-person operation and the law does not require one here (Art. 37 GDPR).
2. Who this policy applies to
CurioFeed is written for readers in the United States, but it is reachable from anywhere — and the person who runs it is established in Spain. That second fact matters: because the controller is established in the European Union, the GDPR governs everything described here, wherever you happen to be reading from. So this policy covers both:
- Visitors in the European Economic Area, the United Kingdom and Switzerland — the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR and the Swiss FADP apply to you, and this policy is our Article 13 information notice.
- Visitors in the United States — see section 11, “Your US privacy rights”.
3. What data we process, and why
We have no user accounts, no login, no newsletter and no shopping cart. Nothing on this site requires you to identify yourself.
| Data | Where it comes from | What it is used for | Legal basis (GDPR) |
|---|---|---|---|
| Advertising data: cookie and device identifiers, IP address, browser and device type, pages viewed, interaction with ads | Collected by Google when ads are served on this site | Funding the site through advertising: serving ads, measuring them, capping how often you see the same one, and preventing ad fraud | Your consent — Art. 6(1)(a) GDPR, together with Art. 5(3) of the ePrivacy Directive 2002/58/EC (in Spain, Art. 22.2 of Law 34/2002). You can withdraw it at any time. |
| Server log data: IP address, date and time, page requested, status code, user agent | Our hosting provider and our CDN, automatically | Keeping the site up, diagnosing errors, blocking abuse and attacks | Legitimate interest — Art. 6(1)(f) GDPR, in operating and securing the site |
| Message data: the name or alias, email address and message text you type into the contact form | You, voluntarily | Reading and answering your message | Your consent — Art. 6(1)(a) GDPR, given by ticking the box and sending the form |
| Your consent choice itself (what you accepted or refused, and when) | The consent tool, stored on your device | Remembering your decision so we do not ask again on every page, and being able to prove it | Legal obligation / strictly necessary — Art. 7(1) GDPR requires us to be able to demonstrate consent |
You are not obliged to give us anything. No law or contract requires you to provide personal data to use this site. The contact form is the only place where you can, and the only consequence of leaving it alone is that we cannot reply to a message you did not send.
What we do not do: we do not use Google Analytics or any other audience measurement tool; we do not run a newsletter; we do not profile you ourselves; we do not make automated decisions with legal effects about you (Art. 22 GDPR); and we do not sell your data.
The calculators run in your browser. The numbers you type into the gold, silver and coin calculators — weights, purities, how many coins you own — are processed on your own device and are never sent to us or to anyone else. The metal prices they use are downloaded from this website as a small file; your browser does not contact any price provider, so no third party learns that you used a calculator. If you tick “Remember this on my device”, the coin calculator saves your counts in your own browser’s local storage; see the Cookie Policy.
4. Who we share data with
| Recipient | Role | What for | Their terms |
|---|---|---|---|
| Google Ireland Limited — Gordon House, Barrow Street, Dublin 4, Ireland (registration number 368047). Controller for users in the European Economic Area and Switzerland. Google LLC — 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. Controller for users in the United Kingdom and elsewhere. | Independent controller — not our processor. See the note below. | Google AdSense advertising and the consent tool that asks for your choice | Google Privacy Policy · How Google uses data from sites that use its services · Google’s privacy commitments for business · Google Ads Controller-Controller Data Protection Terms |
| BanaHosting | Processor (Art. 28 GDPR) | Hosting the website and its email | BanaHosting Privacy Policy |
| Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) | Processor (Art. 28 GDPR) | DNS, content delivery and protection against attacks; your request passes through its network | Cloudflare Privacy Policy |
Why Google is described as an “independent controller” and not as our processor. When Google serves ads through AdSense it decides for itself, under its own privacy policy, what it does with the data it collects — we do not instruct it and we have no access to it. In data protection language that makes Google a separate controller in its own right, and what happens between us is a disclosure of data to a third party, not outsourced processing on our behalf. Practically, it means two things for you: your rights over the advertising data held by Google are exercised with Google, using the links in the table above; and the choice you make in the consent banner is the choice that governs it.
Google’s advertising partners. Google works with other advertising companies that may also receive data when ads are served. The complete, current list — with what each one does and what it stores — is inside the consent banner: open it from “Privacy & cookie settings” in the footer and go to the vendor list. It lives there rather than here because that list changes, and a copy pasted into this page would be out of date within weeks.
5. Transfers outside the EEA
Google LLC and Cloudflare, Inc. are established in the United States, so some of the data described above is processed there.
Those transfers rely on the EU-US Data Privacy Framework, which the European Commission has recognized as providing an adequate level of protection by Implementing Decision (EU) 2023/1795 of 10 July 2023, adopted under Art. 45 GDPR. An adequacy decision means that transfers to a certified organization need no further authorization or safeguard. Both Google LLC and Cloudflare, Inc. are certified under the Framework; you can check their current status yourself on the official list at dataprivacyframework.gov.
Where that Decision does not apply, or ceases to apply, these recipients rely on the Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR). You can ask us through the contact form for the published version of the clauses a given provider uses.
For visitors in the United Kingdom, the equivalent route is the UK Extension to the EU-US Data Privacy Framework, and for Switzerland the Swiss-US Data Privacy Framework.
6. How long we keep it
- Your consent choice: for the period set in the consent tool, after which you are asked again. You can change or withdraw it before that at any time.
- Advertising data: held by Google under its own retention rules — see the links in section 4. We hold none of it.
- Contact form messages: kept while we deal with your enquiry and for a short period afterwards for follow-up, then deleted.
- Server logs: kept for a limited period by our host and CDN for security and diagnostics, then rotated out.
7. Your rights under the GDPR
If the GDPR or the UK GDPR applies to you, you have the right to:
- Access your data and get a copy of it (Art. 15)
- Rectify data that is wrong or incomplete (Art. 16)
- Erasure, the “right to be forgotten” (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw your consent at any time (Art. 7(3)). Withdrawing does not make what we did before it unlawful.
How to use them: send us a message through the contact form saying which right you want to exercise. It is free and we answer within one month (Art. 12(3) GDPR). We will not ask you for a copy of your ID; we only ask for extra detail if we genuinely cannot tell who you are, and only as much as we need.
For advertising data, the fastest route is Google itself: your Google Ad Settings and the links in section 4.
8. Complaining to a supervisory authority
You can lodge a complaint with a data protection supervisory authority (Art. 77(1) GDPR).
- The owner of this site has a single establishment, and it is in Spain. Under Art. 56(1) GDPR — which points to the supervisory authority of the controller’s main or single establishment — that makes the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) the lead supervisory authority: Edificio Cuzco IV, Paseo de la Castellana 141, planta 9, 28046 Madrid, Spain · www.aepd.es · electronic office: sedeaepd.gob.es.
- You do not have to complain in Spain. Art. 77(1) GDPR lets you go to the authority of the Member State where you live, where you work, or where you believe the infringement happened, in your own language. That authority will deal with your complaint and coordinate with the AEPD.
- In the United Kingdom: the Information Commissioner’s Office — ico.org.uk.
9. Children
This site is for adults. It is not directed to children, we do not knowingly collect personal information from children under 13, and the advertising on it is not tagged as child-directed. If you believe a child has sent us personal information through the contact form, write to us and we will delete it.
10. Security
Traffic to this site is encrypted (HTTPS), the site sits behind a content delivery network with attack protection, software is kept updated and administrative access is restricted and protected with strong authentication.
11. Your US privacy rights
This section applies to visitors in the United States and supplements the rest of this policy. It uses the vocabulary of the California Consumer Privacy Act as amended by the CPRA and of the comparable state laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others).
Categories of personal information involved: identifiers (cookie and device IDs, IP address), internet activity (pages viewed, interaction with ads), approximate location derived from IP address, and — only if you write to us — the contact details you choose to give. We ourselves collect none of it: we hold no Social Security numbers, no financial account numbers, no biometric data, and we never ask for your age, race, health or political views. One thing to be aware of: the consent banner asks, for Google’s advertising partners, for permission to use precise geolocation data, which US state laws treat as sensitive. It is off unless you agree to it, and you can refuse it on its own under “Manage options”.
“Sale” and “sharing”. We do not sell personal information for money. However, when personalized advertising is switched on, information about your visit is made available to Google and its advertising partners for cross-context behavioral advertising — which several US state laws treat as a “sale” or a “share” whether or not money changes hands. You can turn that off:
- Refuse in the consent banner. The banner on this site is shown to every reader, not only to visitors in Europe, and “Do not consent” sits next to “Consent” as an equally prominent button. Refusing stops personalized advertising, and with it the cross-context behavioral advertising described above.
- Turn it off at Google, for every site at once: Google Ad Settings, and the industry opt-out pages YourAdChoices and NAI.
- Ask us directly through the contact form, and we will tell you what we can do and what has to be done with Google.
What we do not have yet, stated plainly: this site does not currently publish a dedicated US state opt-out message, and it does not emit the IAB Global Privacy Platform (GPP) signal. That means a Global Privacy Control signal sent by your browser is not converted by this site into a US state opt-out. The controls listed above are the ones that work today, and the consent banner — which does apply to you — is the most direct of them.
Your rights, depending on where you live: to know what personal information is collected and how it is used; to a copy of it; to correct it; to delete it; to opt out of sale, sharing and targeted advertising; to limit the use of sensitive information (we hold none ourselves, and precise geolocation is used by Google’s partners only if you agree to it in the banner); and to not be discriminated against for exercising any of these. We do not offer financial incentives for personal information. Some states also give you the right to appeal a refusal — if we ever refuse a request, we will tell you how to appeal in the same reply.
How to use them: through the contact form. You may use an authorized agent. We reply within 45 days and may extend once, as the state laws allow. Because we do not hold accounts, in most cases the only data tied to you is held by Google — refusing in the consent banner and Google Ad Settings are the effective controls.
Notice of collection: the personal information described above is collected for advertising, security and communication, is retained as described in section 6, and the categories disclosed for cross-context behavioral advertising are identifiers and internet activity.
12. Changes to this policy
We update this page when the site or the law changes. The version published here is the one in force, and the date at the top tells you when it last changed.