CurbWorth Privacy Policy

Effective date: 2026-09-09

CurbWorth has no accounts and asks for no names or email addresses. It never uses your device's location to build your feed. This page describes the little it does store, and every place your data can reach someone else.

Who operates CurbWorth

CurbWorth is operated by Heathrow Andrews, an individual, in Portland, Oregon, USA ("we," "us," "CurbWorth"). Contact: [email protected].

What CurbWorth does

CurbWorth watches publicly visible listings on public marketplaces including Craigslist, Facebook Marketplace, OfferUp, and Nextdoor for genuinely free ($0) items in one watched metro area, ranks them by freshness, approximate distance, and estimated resale value, and links out to the original listing. Version 1 covers the Portland, Oregon metro only. CurbWorth does not sell items, does not process payments, and does not create accounts.

Information we collect

We collect the minimum needed to run the app without requiring a login.

Device identity. The first time you open CurbWorth, we issue your app or browser a random, cryptographically signed device identifier stored as a cookie (cw_device). It is not tied to your name, email address, phone number, Apple ID, or advertising identifier — we never ask for any of those. This identifier lets us remember your saved listings, alert keywords, and which items you have already seen, on that one device. If you delete the app, clear its data, or reinstall, the identifier is lost and your saves and alerts start over.

Product usage events. We record a small, fixed set of in-app actions so we can tell whether the product works end to end: opening the feed, tapping a card, opening a listing, following a link out to the original listing, saving, passing, and tapping an alert. Each event stores the event name, the anonymous device identifier, a timestamp, and — where it applies — the listing id and its source marketplace. No other event names are accepted or stored. An event row also has a small technical detail field. The app fills it in one case only: a feed view records how many listings came back and which view you were looking at. Nothing you type — search text or alert keywords — is ever put there. These events are self-hosted on the same server that runs CurbWorth, are never sent to a third party, and are deleted automatically after 90 days. We read them only in aggregate.

Alert settings. If you set keyword alerts, a minimum value threshold, or an alert mode, we store those settings against your device identifier so we know what to notify you about. The mode is either "Only my words" or "Everything new"; on "Everything new" your keywords do not narrow what the server sends.

Location. CurbWorth does not use your device's location to build your feed. Each CurbWorth instance serves one metro area, set as server-side configuration by us — not by your device. Distances shown next to a listing are approximate locality signals computed from the listing's own stated area, never an exact pickup location and never your position. The iOS app contains no location code: no CoreLocation, and no location permission text, so iOS never prompts you for location on CurbWorth's behalf.

One narrow exception is worth naming exactly, because the code settles it. The web settings include an operator-only "Home" control that sets the instance's own home base — the single point miles and drive times are measured from. It takes a typed address. The page also carries one navigator.geolocation call behind that control, and that call cannot succeed for anyone, the operator included: every CurbWorth response is sent with the header Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=(), which switches the browser's Geolocation API off for every CurbWorth page. On top of the header, both directions of the control require an admin token that is handed out only to a direct local request on the computer running the server, so on a phone, or in any browser reaching CurbWorth over the internet, the control stays hidden as well. Ordinary users are never prompted for location, and the feed, the ranking, and the distances never use device location.

Notifications. The CurbWorth iOS app posts local notifications. It asks the CurbWorth feed for listings posted since its last check and raises the banner on your device itself; there is no Apple Push Notification service token and no remote push payload. Those local banners are not filtered by your keywords or your minimum value: the app alerts you about every new free listing it has not already shown you, up to eight per check. Your keywords and minimum value filter the feed you browse and the Web Push alerts the server sends — not the iPhone app's own banners. The app's web view cannot use Web Push at all. If you instead install the CurbWorth web app to your Home Screen through Safari and enable notifications there, your browser gives us a Web Push subscription (an endpoint URL and keys); we store it against your device identifier and use it only to deliver the alerts you asked for.

Web Push has one hop worth naming: to deliver an alert, our server hands the encrypted message to the push service your browser named in that subscription — Apple's for Safari, the browser vendor's own for other browsers. That service is a third party we do not control. It sees that a message was delivered to your subscription and holds it until your device collects it; the message body is encrypted to keys only your browser holds, so the service cannot read the listing or the keyword that matched.

Optional ntfy backup. Alert settings have an Advanced section with an optional ntfy topic. It is empty, and this channel is off, unless you paste a topic there yourself. If you do, every alert we send you is also posted to that topic on https://ntfy.sh. A self-hosted HTTPS ntfy server can be configured on the instance itself, but the app ships no control that sets one, so in practice the destination is ntfy.sh. What leaves our server is the alert itself: its title (the item's title, with the estimated value when we have one), its body (the keyword it matched, the listing's stated area or an address the post itself published, an approximate distance and drive time, the source marketplace, and a short excerpt of the listing text), and the link to the original listing. Your device identifier is not sent. ntfy is a third party we do not control, and a topic on a public ntfy server can be read by anyone who knows the topic name, so choose an unguessable one — or leave the field empty. Clearing the field switches the channel off.

The iOS app's own two stored keys. The native app keeps two things in its own local storage (UserDefaults) on your phone: whether alerts are switched on, and the ids of listings it has already alerted you about, so it does not alert you twice. That data stays on the device and is not sent to us.

The web layer's browser storage. CurbWorth's web content — the same pages whether you meet them inside the iOS app or in a browser — keeps its own small conveniences in that browser's storage: when you last opened CurbWorth, which one-time tips it has already shown you, any map stops you selected, recently used ZIP codes, a short-lived cache of market data, and whether you dismissed the "Add to Home Screen" prompt. These stay in the browser, are not sent to us, and go away when you clear the site's data.

Server logs. Like any web service, the CurbWorth server writes ordinary request logs that include the requesting IP address, the path requested, and a timestamp. A logged path can include what you typed into search: the web app sends your search text as a query parameter on the feed request (/api/feed?q=…), and the log records the whole request line. We use these logs only to keep the service running and to rate-limit abuse. They rotate on a fixed size budget (5 MB, three older files kept) and are overwritten, we do not join them to your device identifier, and we do not use them for analytics or advertising.

Hosting and tunnel provider. The public CurbWorth instance is reachable only through a fronting Cloudflare Tunnel, so Cloudflare necessarily processes every request to CurbWorth — including your IP address and the requested path — as it carries that request to our server. Cloudflare acts as our infrastructure provider under its own terms and privacy policy.

What we do not collect. No accounts, no names, no email addresses, no phone numbers, no payment information, no contacts, no photos, no health data, no advertising identifier. We do not use third-party analytics or advertising SDKs. We do not track you across other companies' apps or websites.

How we use information

We use device identifiers, alert settings, and usage events solely to run and improve CurbWorth for you: showing your saved items, sending the alerts you configured, not re-showing items you dismissed, and measuring in aggregate whether people are finding usable listings. We do not sell your information, and we do not use it for advertising.

Third-party listing sources

CurbWorth aggregates publicly visible listings from third-party marketplaces, including Craigslist, Facebook Marketplace, OfferUp, and Nextdoor. We always identify a listing's source and link back to the original. We do not control those third parties' data practices — read their privacy policies for how they handle your interactions with them once you leave CurbWorth. CurbWorth does not resell listing data; the product is the alerting, ranking, and valuation layer on top of public listings.

Listing photos load from the source marketplace. We do not copy listing photos onto our server. Every thumbnail and full-size photo you see is loaded by your device straight from the marketplace's own image servers (images.craigslist.org, for example). That means those companies can see your IP address, and the fact that a photo was requested, each time one renders — the same as if you opened the original post. CurbWorth sends them nothing else about you: no device identifier, no keywords, and no saves. The page you were on is not passed along either: every CurbWorth response is sent with the header Referrer-Policy: same-origin, so no CurbWorth URL travels with an off-site image request.

Directions open in Apple Maps or Google Maps. When a listing carries a street address the poster published themselves, CurbWorth offers a one-tap directions link. Tapping it hands that destination address — and, on a multi-stop route, the other stops you picked — to Apple Maps or Google Maps, whichever you chose, and that company handles it under its own privacy policy. Nothing about you is attached: no device identifier, no keywords, no saves. CurbWorth never builds a directions link from an approximate or inferred location.

Resale value estimates come from live eBay asking prices for comparable items. They are informational only and are not sold-price data or appraisals.

Data retention and deletion

CurbWorth has no account to close and nothing to log out of. The only link between you and the rows on our server is the random cw_device cookie, which the server signs and sets. You cannot read it, and we cannot look you up without it. There is no delete button inside the app today, so these are the two routes that actually work:

Product usage events already recorded carry only the random device identifier they were stamped with; that delete does not remove them, and they age out automatically 90 days after they were recorded. Shared listing data — the public feed itself — is not personal to you and is unaffected.

Children's privacy

CurbWorth is not directed at children, and we do not knowingly collect information from children under 13.

Changes to this policy

We may update this policy as CurbWorth changes. When we do, we update the effective date at the top of this page.

Contact

Questions about this policy: [email protected].