Legal
Privacy Policy
Last updated: July 16, 2026. How Kura collects, uses, and protects information.
This Privacy Policy explains how Kura Finance LLC (“Kura,” “we,” “us,” or “our”) handles personal information when you use our websites, applications, and related services (the “Service”). It should be read with our Terms of Service and Trust & Security Center.
1. Who We Are
Controller: Kura Finance LLC, registered in Wyoming, USA. Mailing address: 1007 N Orange St. 4th Floor 5629, Wilmington, DE 19801. Privacy contact: privacy@kura-finance.com (or support@kura-finance.com).
2. Information We Collect
We follow a minimization-first policy and collect only what is needed to operate the Service:
- Account data — authentication identifiers from our login partner (such as email) and your public wallet addresses.
- Financial data you connect — balances, transactions, and holdings from banks, brokerages, read-only exchange API connections, and on-chain wallets you link in TrackFi. Sensitive TrackFi content uses zero-access encryption and is stored only as ciphertext on our servers.
- Verification data — when you use Card, fiat ramps, or securities features, identity (KYC) information is collected and processed by regulated partners (such as Bridge, Sumsub, or Dinari), not held in readable form by Kura.
- Subscription & billing data — plan tier, payment status, and billing identifiers processed by Stripe or app-store processors.
- Referral data — referral codes, referred-user relationships, payout status, and related identifiers needed to operate the referral program.
- Card display data — if a virtual card is shown in-app, we may temporarily receive masked or full card details from the card partner solely to display them to you. We do not store full PAN except as required to render the display session, and we do not use card numbers for marketing.
- Technical data — device, app version, diagnostics, IP address, approximate location derived from IP, crash logs, and security signals needed for reliability and fraud prevention.
- Communications — messages you send to support or legal inboxes, and related metadata.
3. How We Use Information
We use information to: provide and secure the Service; provision wallets; facilitate trading, transfers, earn/borrow, card, and ramp flows through partners; operate subscriptions and referrals; prevent fraud and abuse; comply with law; improve reliability; and communicate service notices. We do not sell your personal or financial data, and we do not use TrackFi financial records for advertising, ad targeting, or behavioral profiling.
4. Legal Bases (EEA / UK)
Where GDPR or UK GDPR applies, we process personal data on these bases as applicable: (a) performance of a contract (providing the Service you request); (b) legitimate interests (security, fraud prevention, product improvement, limited analytics) balanced against your rights; (c) legal obligation (tax, accounting, lawful requests); and (d) consent where required (for example certain cookies or optional communications). You may withdraw consent without affecting prior lawful processing.
5. Third-Party Processors and Partners
When you use a feature, the relevant partner processes data under its own privacy policy. Current categories include:
- Privy — authentication, OAuth, embedded wallet MPC key management.
- Bridge / MoonPay — fiat ramps and related KYC.
- Li.Fi — swaps and bridges.
- Morpho — DeFi vaults and borrow markets (on-chain).
- Dinari — tokenized assets / equities KYC and brokerage flows.
- Sumsub / card partners — card KYC, issuance, and processing.
- Stripe / app stores — subscription billing.
- Plaid / CEX APIs — read-only account connectivity for TrackFi.
- DeBank / CoinGecko / Pimlico / WalletConnect (Reown) — market data, on-chain data, AA infrastructure, wallet sessions.
- Infrastructure / analytics — hosting, CDN, error monitoring, and security tooling as needed to run the Service.
6. Zero-Access Security Model
Your wallet keys are controlled by you. TrackFi sensitive content is encrypted on-device with a key unlocked by your passkey; our servers hold ciphertext. Biometric unlock data stays on your device. Data in transit uses TLS. Because we do not maintain broad plaintext access to TrackFi ciphertext, we are structurally limited in what readable financial content we can produce — including after a breach or when responding to third-party requests.
7. Legal Requests and Disclosures
We may disclose information when we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request; to enforce our Terms; or to protect Kura, users, or the public. What we can disclose depends on what is technically accessible. Typically this may include account identifiers, wallet addresses, device/IP logs, billing and referral records, and support correspondence — not TrackFi ciphertext plaintext. Partners that hold KYC may respond separately under their own obligations. On-chain transactions are public.
8. Retention
We retain personal information only as long as needed for the purposes collected, including to provide the Service, resolve disputes, enforce agreements, and meet legal, tax, and accounting requirements. Typical periods (subject to longer legal holds):
- Account and authentication records — for the life of the account, then a reasonable wind-down period.
- Billing and subscription records — generally up to seven (7) years where tax/accounting rules require.
- Referral and payout records — for the program life plus a reasonable audit period.
- Security and access logs — generally 12–24 months unless needed longer for investigations.
- Support tickets — generally up to three (3) years after closure.
- TrackFi ciphertext — until you delete it or close your account, subject to backup rotation.
Partner-held KYC may be retained by those partners under AML rules beyond Kura’s control.
9. International Transfers
We are based in the United States and may process data in the U.S. and other countries where our providers operate. Where required, we use appropriate transfer mechanisms such as Standard Contractual Clauses or provider certifications. By using the Service from outside the U.S., you understand your information may be transferred to jurisdictions with different data-protection laws.
10. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of personal data, or to object to certain processing. You can disconnect accounts, delete encrypted TrackFi caches where the product allows, and request account deletion. Some records may be retained where legally required. To exercise rights, email privacy@kura-finance.com. We may need to verify your identity. You may lodge a complaint with your local supervisory authority.
11. U.S. State Privacy Notices (including CCPA)
If you are a California resident (or resident of a state with similar laws), you may have rights to know, delete, correct, and opt out of certain sharing. Categories of personal information we collect are described in Section 2. We do not sell personal information as “sale” is commonly defined, and we do not share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under CCPA beyond what is necessary to provide the Service. You may submit requests to privacy@kura-finance.com. Authorized agents may submit requests with proof of authority. We will not discriminate against you for exercising privacy rights.
12. Cookies, SDKs, and Analytics
Our websites and apps may use cookies, local storage, and mobile SDKs for authentication, security, preferences, performance, and limited product analytics. Essential cookies are required for the Service to function. Where required by law, we will request consent for non-essential cookies. You can control cookies through browser settings; blocking some cookies may break features. Mobile OS settings may limit ad or tracking identifiers; we do not use TrackFi data for ads.
13. Children
The Service is not directed to children under 18 (or under 13 where that higher protection standard applies). We do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it. Contact us if you believe a child has provided information.
14. Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction, subject to confidentiality and continuing privacy commitments consistent with this Policy.
15. Changes to This Policy
We may update this Policy from time to time. We will revise the “Last updated” date and may provide additional notice for material changes. Continued use after the effective date constitutes acceptance of the updated Policy where permitted by law.
16. Contact
Privacy requests: privacy@kura-finance.com · Support: support@kura-finance.com · Legal: legal@kura-finance.com.