Developer Agreement

Effective date: September 30, 2026

This Developer Agreement ("Agreement") is between CuraeAI Inc., a Delaware corporation ("CuraeAI," "we" or "us"), and the organization that creates a CuraeAI developer account ("Developer" or "you"). It governs your use of the CuraeAI developer platform: the developer console, the Platform and SDK application programming interfaces, the software development kits, Curae Connect, webhooks and developer documentation (together, the "Platform").

The person who accepts this Agreement confirms that they have authority to bind the Developer. You accept it by ticking the box that says you agree to it when you create your developer account or when we ask you to review a new version; we record which version was accepted, by whom and when. Our Privacy Policy explains how we handle the personal information of the people who use your developer account.

1. Definitions

  • "App" means each application or service you build that uses the Platform.
  • "End User" means an individual who uses your App and connects their CuraeAI health record to it.
  • "Connection" means an End User's authorization, given on the CuraeAI-hosted authorization screen, for your App to access their information within the scope, period of records and duration shown there.
  • "Curae Data" means all information about an End User that your App receives through the Platform, including health information, identifiers and anything derived from them. Curae Data is also the End User's personal and consumer health data under the laws that apply to you.
  • "Live Access" means the ability to use cae_live_ API keys and to start Curae Connect for real people.

2. Access to the Platform

2.1. License. Subject to this Agreement, CuraeAI grants you a limited, non-exclusive, non-transferable, non-sublicensable and revocable license during the term to use the Platform to develop, test and operate your Apps, and to use our software development kits and documentation for that purpose.

2.2. Test keys. You can create cae_test_ keys yourself. There is no separate sandbox environment: test keys run against CuraeAI's production service. On the Platform API a test key has every health-data permission removed, and through the SDK it can read only through a Connection. Until your App is approved under Section 2.3, no Connection can be started, so a test key cannot read anyone's health information. After approval, information your App receives through a Connection is Curae Data under this Agreement whichever kind of key read it.

2.3. Live Access is reviewed. CuraeAI grants Live Access only after it reviews and approves your App. Before approval you must prove that you control your App's website domain by publishing the TXT record the developer console gives you at _curae-challenge. followed by your domain; CuraeAI checks it again before each approval. The review records, among other things, the version of this Agreement you accepted, your legal entity, the proven domain, the identity requirements your App declares, your confirmation that your App is intended only for adults 18 and older, whether your App has an active webhook endpoint, and the App name and support link that End Users see on the authorization screen. CuraeAI shows that support link only while your App still proves its domain. CuraeAI may approve or refuse Live Access at its sole discretion, may impose conditions, and may revoke an approval at any time under Section 11. When an approval is revoked, every live key of the App stops working on its next request.

2.4. Accurate information. You must keep your account details, your App's name, support link, website domain and return addresses, and your contact email address accurate and current. Curae Connect returns a person only to a return address you registered on your proven domain or one of its subdomains, or to your App's scheme formed from that domain reversed, and it stops returning people to your App while the domain no longer proves. You agree that CuraeAI may show End Users your App's reviewed name and support link, and may give End Users your contact email address as the way to contact you about the Curae Data you received, as the consumer-health-data laws require.

2.5. Credentials. API keys and webhook signing secrets are confidential. Keep them only on servers you control — never in a browser, mobile app, source code repository, log or screenshot — and give them only to personnel who need them. You are responsible for all use of your keys. Rotate a key immediately if you believe it has been exposed, and tell us under Section 7.

2.6. Your developer account. Your personnel sign in to the developer console with strong authentication: a passkey, or a password plus a code from an authenticator app.

3. How your App may obtain and use Curae Data

3.1. Only through a Connection. Your App may access an End User's information only through a Connection that End User authorized, only within the scope, period of records and duration of that Connection, and only while it is active. Request only the scopes your App needs.

3.2. Only for the End User. You may use Curae Data only to provide your App's features to the End User the data is about, as you described them to that End User and to CuraeAI in the review, and to meet your legal obligations.

3.3. Never sold or monetized. You must not sell, rent, license, lease or otherwise monetize Curae Data or any individual's data derived from it, whether identified or pseudonymized, and you must not use or disclose it for advertising or marketing, insurance underwriting, employment, credit, housing or other eligibility decisions, or data brokerage.

3.4. No onward disclosure without the End User. You must not disclose Curae Data to anyone except (a) service providers that process it only on your behalf, under a written contract at least as protective as this Agreement, (b) another person or organization the End User specifically directs, with the End User's consent, or (c) as the law requires. You are responsible for your service providers.

3.5. No re-identification, profiling or tracking. You must not attempt to re-identify de-identified or pseudonymized data, combine Curae Data with other data to identify or profile an End User beyond what your App's features need, or use Curae Data to track End Users across other services.

3.6. Adults only. Your App must be intended only for adults 18 and older, and you must not knowingly connect a person under 18 through the Platform.

3.7. Your own privacy obligations. You must publish an accurate privacy policy for your App that tells End Users what you collect through CuraeAI and why, obtain every consent the law requires of you (including any consent consumer-health-data laws require for your collection and sharing), and honor End Users' requests to access, correct and delete their data and to withdraw consent. You are responsible for your own compliance with the laws that apply to you, including the FTC Act, the FTC Health Breach Notification Rule, state consumer-health-data and privacy laws, and, if you are a HIPAA covered entity or business associate, HIPAA. CuraeAI discloses Curae Data to your App at the End User's direction; CuraeAI is not your business associate, and you are not CuraeAI's.

3.8. Records protected by 42 C.F.R. Part 2. A resource CuraeAI marks as protected by 42 C.F.R. Part 2 carries the notice "42 CFR part 2 prohibits unauthorized use or disclosure of these records." You must not use or disclose such a record except as that Part permits, and you must keep the notice with the record wherever you store or show it.

3.9. The FTC Health Breach Notification Rule. Before you receive Live Access, you must tell CuraeAI whether your App is a vendor of personal health records or a PHR related entity under 16 C.F.R. Part 318, and you must tell us if that changes. Where CuraeAI holds information for your App as a third party service provider under that rule, your account's contact email address is the official designated to receive CuraeAI's breach notices unless you name another in writing, and you must acknowledge each notice when you receive it.

3.10. A way to stop sharing. Your App must give every End User who has a Connection a control that stops the sharing: easy to find in your App, free to use, and no harder to use than connecting was. When an End User uses it, your App must revoke that Connection through the Platform at that moment; Section 4.2 then applies. Your App must also open Curae Connect whenever an End User asks to manage their sharing, so that the End User can use its Manage sharing screen. You must keep both available for as long as that End User has an active Connection. An End User whose CuraeAI account was made through your App, and who has not finished setting up a full account, has no other way to stop sharing, so CuraeAI may suspend Live Access under Section 11.1 while either is missing.

4. Retention and deletion

4.1. Keep only what you need. Keep Curae Data only as long as you need it to provide your App's features to the End User.

4.2. Delete within 24 hours after a Connection ends. When CuraeAI sends your App a connection.revoked or connection.expired event, or a Connection otherwise ends, you must delete all Curae Data you received through that Connection, including any cached copies, from your systems and your service providers' systems within 24 hours, except for data the End User has separately and expressly asked you to keep in your App and that the law allows you to keep. CuraeAI ends a Connection, and sends connection.revoked, when the End User stops sharing — in CuraeAI, in Curae Connect's Manage sharing screen, or with your App's control under Section 3.10 — or deletes their CuraeAI account; that event is CuraeAI's notice to you of the End User's withdrawal of consent and, where applicable, of their deletion request, and you must honor it as such. When records your App received through a Connection are deleted in CuraeAI — because the End User used Delete Records, or deleted their CuraeAI account after that Connection ended — CuraeAI sends a records.deleted event naming each of those records by resource type and identifier, whatever the Connection's status. It is sent after the records are erased in CuraeAI, and it may arrive in more than one part. You must delete those records, and anything you derived from them, within 24 hours after you receive it, and that event is CuraeAI's notice to you of the End User's deletion request. CuraeAI delivers connection.revoked and records.deleted to every active webhook endpoint of your developer account, whether or not it subscribes to them, and, if you have none, by email to your account's contact address.

4.3. On termination. When this Agreement ends, you must stop using the Platform and delete all Curae Data within 24 hours, except data an End User has separately and expressly asked you to keep and that the law allows you to keep.

4.4. Certification. On request, you must certify in writing that you have deleted Curae Data as this Section requires.

5. Security

5.1. You must protect Curae Data with administrative, technical and physical safeguards appropriate to health information, including at least: encryption in transit (TLS 1.2 or higher) and at rest; access limited to personnel who need it, with strong authentication for them; secure storage of API keys and signing secrets; verification of the signature on every webhook delivery before acting on it; logging of access to Curae Data; timely patching and vulnerability management; and a written incident-response plan.

5.2. Your webhook endpoints must use HTTPS on a public host. CuraeAI may pause deliveries to an endpoint that keeps failing.

5.3. You must not attempt to access information your Connections do not authorize, probe or test the security of the Platform, or get around its rate limits, permission checks or other controls. If you find a vulnerability in the Platform, report it to us under Section 7 and do not exploit or disclose it.

6. Acceptable use

You must not, and must not let anyone else: (a) use the Platform to build a product that competes with CuraeAI's personal health record by copying Curae Data or the Platform; (b) scrape, harvest or bulk-download data beyond what your Connections authorize; (c) misrepresent your identity, your App or its relationship with CuraeAI, or suggest CuraeAI endorses your App beyond the "Verified by Curae" label we show for reviewed Apps; (d) use the Platform in violation of any law, including privacy, health-information, consumer-protection, anti-discrimination, export-control and sanctions laws; (e) exceed or evade rate limits; (f) reverse engineer the Platform, except where the law expressly allows it despite this restriction; (g) use the Platform to send malware or unlawful content; or (h) use Curae Data to train or improve artificial-intelligence models, except models used solely to provide your App's features to the End User the data is about and not shared with anyone else.

7. Incidents and breach notice

7.1. You must notify CuraeAI at privacy@curaeai.com without undue delay, and in any event within 72 hours after you discover it, of any actual or reasonably suspected unauthorized access to, acquisition, use or disclosure of Curae Data, or any compromise of your API keys or signing secrets. Don't include health information in an email to us.

7.2. Your notice must describe what happened, the Curae Data and End Users affected, and what you are doing about it, and you must update it as you learn more. You must cooperate with CuraeAI's investigation, and you must not name CuraeAI in any public statement about the incident without our consent, except as the law requires.

7.3. You are responsible for giving any notice the law requires of you to End Users, regulators and others, and for its cost, to the extent the incident arose in your systems or your service providers' systems.

7.4. Notices CuraeAI gives through your App. An End User whose CuraeAI account was made through your App and who has not finished setting up a full account has given CuraeAI no email address. When CuraeAI must notify such End Users, including of a breach of security under 16 C.F.R. Part 318 or state law, CuraeAI sends its notice, and the list of the End Users it concerns by the identifier your App uses for them, to your account's contact email address. You must deliver that notice on CuraeAI's behalf, without changing it, to each of those End Users by email together with a message inside your App, within 5 business days after you receive it and at your own cost; confirm to CuraeAI in writing when you have done so; and tell CuraeAI, within the same 5 business days, which End Users you could not reach. Delivering CuraeAI's notice does not replace any notice the law requires of you under Section 7.3.

8. Audits and cooperation

8.1. On request, you must answer CuraeAI's reasonable written questions about your compliance with this Agreement and give us reasonable evidence of it, such as your App's privacy policy, your security practices and records of deletion.

8.2. If CuraeAI has reasonable grounds to believe you are not complying with this Agreement, or after an incident under Section 7, CuraeAI or an independent auditor bound by confidentiality may audit your compliance, on reasonable notice, during business hours and in a way that does not unreasonably disrupt your business. Unless an audit is prompted by an incident or finds a material breach, CuraeAI does not audit more than once in any 12 months and bears its own costs of the audit.

8.3. You must cooperate with CuraeAI to respond to End Users' requests and to inquiries from regulators about Curae Data you received.

9. Intellectual property and branding

9.1. CuraeAI and its licensors own the Platform and all rights in it. You own your App. Except for the license in Section 2.1, nothing in this Agreement transfers any rights to you.

9.2. You may say that your App uses CuraeAI, and use CuraeAI's name for that purpose, in the way our documentation describes. Any other use of our names and logos needs our written permission.

9.3. You grant CuraeAI a limited license to show End Users your App's name, logo and support link and your contact email address — on the authorization screen, in their CuraeAI record and in our answers to their requests.

9.4. If you give us feedback about the Platform, we may use it without restriction or payment to you.

10. Fees

Using the Platform does not cost anything today. If CuraeAI sets a fee for the Platform, it gives you at least 30 days' notice by email, and the fee applies only if you keep using the Platform after it takes effect.

11. Suspension and termination

11.1. Suspension. CuraeAI may suspend or limit your access to the Platform, revoke Live Access or disable your keys, in whole or in part, immediately and without prior notice, if CuraeAI in its discretion believes it is necessary to protect End Users, their data, the Platform or CuraeAI — for example, because of a security or privacy risk, a suspected breach of this Agreement, a complaint from an End User or a regulator, or a legal requirement. Where it is safe and lawful to do so, we tell you why and what you can do to have access restored.

11.2. Termination. You may end this Agreement at any time by telling us at privacy@curaeai.com, from your account's contact email address, that you are ending it; we then close your developer account and disable its keys. CuraeAI may end it for convenience on 30 days' notice, or immediately if you breach it, if CuraeAI stops offering the Platform, or if the law requires it.

11.3. Effect. When this Agreement ends, your license and your keys end, and Section 4.3 applies. Sections 3, 4, 5, 7, 8 (for 12 months), 9.1, 9.4 and 12 through 17 continue to apply.

11.4. When your last administrator leaves. CuraeAI does not let the last administrator of an App that is not retired be removed. If the CuraeAI account of the only person who administers your App is deleted, CuraeAI retires the App: its keys stop working, its Connections end, and each End User is told in their CuraeAI record. CuraeAI keeps your App's name, business contact and support link with the App's record, and keeps sending deletion notices to that contact, while a deletion notice about the App can still be owed; then it erases them.

12. Confidentiality

Non-public information that either party discloses to the other in connection with this Agreement, including API keys, non-public documentation and the details of an App review, is confidential. The receiving party must use it only for this Agreement and protect it with reasonable care, except information that is or becomes public through no fault of the receiving party, that the receiving party already had or independently developed, or that the law requires to be disclosed (after notice to the disclosing party where lawful). Curae Data is governed by Sections 3 to 5, not this Section.

13. Disclaimer of warranties

THE PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE." TO THE FULLEST EXTENT THE LAW ALLOWS, CURAEAI DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AND ANY WARRANTY THAT THE PLATFORM IS UNINTERRUPTED, ERROR-FREE OR SECURE, OR THAT ANY HEALTH INFORMATION IS COMPLETE OR ACCURATE. CuraeAI does not provide medical advice, and health information delivered through the Platform comes from health systems and End Users, not from CuraeAI. CuraeAI offers no service-level commitment for the Platform.

14. Limitation of liability

14.1. TO THE FULLEST EXTENT THE LAW ALLOWS, NEITHER PARTY IS LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL OR DATA, ARISING OUT OF OR RELATING TO THIS AGREEMENT, EVEN IF TOLD THEY WERE POSSIBLE.

14.2. TO THE FULLEST EXTENT THE LAW ALLOWS, CURAEAI'S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT DOES NOT EXCEED THE GREATER OF (A) THE FEES YOU PAID CURAEAI UNDER THIS AGREEMENT IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE LIABILITY AND (B) US$100.

14.3. THE EXCLUSIONS AND LIMITS IN THIS SECTION DO NOT APPLY TO YOUR OBLIGATIONS UNDER SECTIONS 3 TO 7 AND 15, TO YOUR INFRINGEMENT OR MISAPPROPRIATION OF CURAEAI'S INTELLECTUAL PROPERTY, OR TO EITHER PARTY'S FRAUD, GROSS NEGLIGENCE OR WILLFUL MISCONDUCT.

15. Indemnity

You must defend CuraeAI and its officers, directors, employees and agents against any claim, demand, investigation or proceeding brought by a third party (including an End User or a regulator) arising out of or relating to your App, your use of the Platform, your handling of Curae Data, your breach of this Agreement or your violation of the law, and you must pay the damages, fines, penalties, settlements, costs and reasonable attorneys' fees that result. CuraeAI notifies you promptly of the claim, lets you control its defense (except that you may not settle a claim in a way that admits fault by CuraeAI or imposes an obligation on it without its written consent), and cooperates at your expense. CuraeAI may take part in the defense with counsel of its choosing at its own expense.

16. Changes to this Agreement

CuraeAI may update this Agreement. Each version is published with its effective date, and earlier versions remain available. We give you at least 30 days' notice of a material change by email to your account's contact address and in the developer console, unless a shorter period is needed to comply with the law or to protect End Users or the Platform. When a new version takes effect, your developer console asks you to review and accept it before you make further changes in the console; if you do not accept it, you must stop using the Platform and Section 4.3 applies.

17. General

17.1. Governing law and courts. This Agreement is governed by the laws of the State of Delaware, without regard to its conflict-of-law rules. The state and federal courts located in the State of Delaware have exclusive jurisdiction over any dispute arising out of or relating to this Agreement, and each party consents to their jurisdiction, except that CuraeAI may seek an injunction in any court to protect End Users, Curae Data or its intellectual property.

17.2. Notices. Notices to CuraeAI must be sent by email to privacy@curaeai.com. Notices to you are sent to your account's contact email address and are effective when sent.

17.3. Relationship. The parties are independent contractors. This Agreement creates no partnership, joint venture, agency or employment relationship, and no End User or other third party has rights under it, except that CuraeAI may enforce Sections 3 and 4 for the benefit of End Users.

17.4. Assignment. You may not assign this Agreement without CuraeAI's written consent. CuraeAI may assign it in connection with a merger, acquisition, reorganization or sale of all or part of its business.

17.5. Entire agreement; order of precedence. This Agreement, together with any written terms of your App's approval, is the entire agreement about the Platform and replaces any earlier agreement about it, including any consumer terms you accepted for a developer account. If a developer-documentation page conflicts with this Agreement, this Agreement controls.

17.6. Other terms. If any part of this Agreement cannot be enforced, it is changed only as much as needed to make it enforceable, and the rest stays in effect. A failure to enforce a part of this Agreement is not a waiver. Neither party is liable for delay or failure caused by events beyond its reasonable control, except for your obligations under Sections 3 to 5 and 7. You must comply with United States export-control and sanctions laws in using the Platform.

17.7. Where the Platform is offered. CuraeAI offers the Platform for Apps whose End Users are in the United States. Terms for Apps whose End Users are elsewhere are published as regional supplements to this Agreement. No regional supplement is in effect.