Privacy Policy

Last updated: June 2026

1. Information We Collect

We follow a minimization-first policy and collect only what is needed to operate the Service:

  • Account data — authentication identifiers from our login partner (such as email) and your public wallet addresses.
  • Financial data you connect — balances, transactions, and holdings from banks, brokerages, read-only exchange API connections, and on-chain wallets you link in TrackFi. This sensitive content uses zero access encryption and is stored only as ciphertext on our servers.
  • Verification data — when you use the Kura Card, fiat ramps, or securities features, identity (KYC) information is collected and processed directly by our regulated partners (such as Bridge, Sumsub, or Dinari), not held in readable form by Kura.
  • Subscription & billing data — plan tier, payment status, and billing identifiers processed by Stripe or applicable app-store payment processors.
  • Referral data — referral codes, reward status, and related account identifiers needed to operate the referral program.
  • Technical data — limited device, app, and diagnostic information needed for security and reliability.

2. How We Use Your Information

We use data solely to provide and secure the Service — including wallet provisioning, trading and transfers, yield vault facilitation, card and fiat ramp facilitation, account aggregation, subscriptions, referrals, and analytics you request. We do not sell your personal or financial data, and we do not use your financial records for advertising, ad targeting, or behavioral profiling.

3. Third-Party Data Processors & Partners

Kura integrates independent providers to deliver specific features. When you use a feature, the relevant partner processes the data needed for that function under its own privacy policy:

  • Privy — authentication, OAuth sign-in, and embedded wallet key management (MPC).
  • Bridge — fiat on/off ramp, virtual accounts, and related identity verification.
  • MoonPay — card-based purchases of crypto.
  • Li.Fi — same-chain swaps and cross-chain bridges.
  • Morpho — DeFi yield vaults and related on-chain data.
  • Dinari — tokenized real-world assets and US equities access, including separate KYC.
  • Sumsub — identity verification for card partner onboarding.
  • Card partners — issuance and processing of the non-custodial debit card.
  • Stripe — subscription billing and payment processing.
  • Plaid — read-only connections to your bank and investment accounts.
  • CEX partners — read-only API connections to supported exchanges (including Binance, Coinbase, Kraken, OKX, Bybit, and others) for balance tracking only; Kura cannot trade on your behalf.
  • DeBank — on-chain token and DeFi position data for addresses you add.
  • CoinGecko — cryptocurrency market and price data.
  • Pimlico — smart-account transaction bundling and gas sponsorship on Base.
  • WalletConnect (Reown) — secure pairing between your wallet and external dApps or tracked wallets.

These integrations are scoped to the minimum data required and are designed to avoid unnecessary exposure of readable sensitive content to Kura.

4. Zero-Access Security Model

Kura follows a Zero-Access, non-custodial architecture. Your wallet keys are controlled by you, and we cannot move funds from your wallet or connected accounts. Financial data you store in TrackFi uses zero access encryption with a key unlocked by your device passkey, so our servers hold only ciphertext. Biometric data used to unlock your passkey stays on your device and is not transmitted to Kura. Data in transit is protected with TLS. Because we do not maintain broad plaintext access to your sensitive data, we are structurally limited in what readable data can be produced — including if our systems are breached or when responding to third-party or government requests.

5. Your Rights and Control

You can disconnect accounts, delete your encrypted data cache, and request access to, correction of, or deletion of your personal data at any time. Some verification records held by regulated partners may be retained by those partners to meet their own legal obligations. To exercise your rights, contact us at support@kura-finance.com.