Kura

Privacy policy

Last updated 14 August 2026

Kura is a personal finance tracker, which means the records you keep in it are among the most revealing data anyone could hold about you. This page describes exactly what is stored, where, who can reach it, and how to take it back or destroy it.

Who is responsible for your data

The controller of the personal data described here is Kura, Zurich, Switzerland. You can reach us about anything on this page at privacy@kura.green.

What Kura stores

  • Your account. An email address, and a display name if you provide one. If you sign in with Google, we receive the email address, name and profile picture associated with that Google account — nothing else, and no access to any other Google service.
  • What you enter. Accounts, balances, transactions, categories, dates and notes. Kura does not derive, infer or enrich this with anything from outside.
  • Preferences. Your base currency, chosen language and light/dark theme.
  • Ordinary server logs. Our hosting provider records request metadata including IP address, in the normal course of serving a website.

What Kura does not do

  • No advertising network and no advertising SDK.
  • No analytics, no product telemetry, no session recording, no heatmaps.
  • No third-party trackers or advertising cookies of any kind. Kura loads no scripts from other companies’ servers.
  • Your financial records are never sold, rented, brokered or shared — including in aggregated or “anonymised” form. Kura sends them to nobody. The one way anything leaves is a connection you set up yourself, described under connections you authorise below.
  • Kura never asks for your online banking password and has no bank connection feature at this time.

Who else processes it

Kura is a small product built on infrastructure it does not own. These providers process data on our instructions as sub-processors:

  • Google (Firebase Authentication, Cloud Firestore). Stores your account credentials and all records you enter, encrypted in transit and at rest. Data is held in Zurich, Switzerland (Google Cloud region europe-west6).
  • Vercel. Serves the application and processes request metadata, including IP addresses, in its server logs.

Exchange rates come from European Central Bank reference data. That request is made by our server, not your browser, so the rates provider never sees your IP address, your currencies or how often you use Kura.

Connections you authorise

Kura has an API and an MCP server, so your own scripts, a spreadsheet, or an AI assistant can read and write your vault. This is the only mechanism by which your records leave Kura, and it is worth describing precisely rather than burying.

Nothing exists until you create it. A vault with no API token and no approved connection behaves exactly as it did before this feature existed. There is no default, no pre-enabled integration and no partner with standing access.

What can leave is everything a scope allows. A read token exposes your accounts, balances, every transaction, budgets, goals, labels, household profiles and reports. A write token can also create, change and delete records, which moves your balances. Tokens do not expire; the ones an application obtains by asking you expire and renew until you disconnect it.

Where it goes is wherever you pointed it. If you connect an AI assistant, your records are sent to whichever company operates that assistant. They are not a sub-processor of ours: we have no contract with them covering your data, we give them no instructions, and what they do with what you send is governed by their terms and not by this policy. You are asking them directly, through software we built to make that possible.

We cannot see it, and we cannot take it back. Kura does not receive a copy of what passes through a connection you authorise and keeps no log of it beyond the ordinary request metadata described above. That also means we have no way to recall anything already sent. Ending a connection stops further access; it does not undo access already used.

How to see and end them. Every token and every approved application is listed under Settings → API tokens, with what it may do and when it was last used. Revoking a token or disconnecting an application takes effect immediately. Deleting your account removes all of them.

Where the GDPR applies, this processing rests on your consent (Article 6(1)(a)), which you give by creating a token or approving a connection and withdraw by removing it. The API reference describes exactly what each scope reaches.

Market prices

If you give a holding a symbol and a quantity, its value can be refreshed from a market data provider. That happens when you press refresh, and when you change something that moves the position — adding or editing a holding, or recording a buy or a sell. Kura does not poll prices in the background: nothing is fetched on a timer, and closing the page stops it entirely.

  • CoinGecko for cryptocurrencies. For shares, funds and bonds, Twelve Data where configured, falling back to Yahoo Finance for symbols it cannot resolve.
  • The request is made by our server, not your browser. Neither provider receives your IP address, a cookie, or anything identifying you.
  • Only the symbol is sent. Your quantities, values, contributions and returns are never transmitted — a provider cannot tell whether you hold one share or ten thousand, and cannot link two symbols to the same person.
  • Holdings without a symbol and quantity are never included in a price request at all.

Searching for an instrument by name or ticker is separate, and worth stating plainly because it is the one place Kura sends something you have not saved. When you type into the search box while adding a holding, that text is sent to Yahoo Finance so it can offer matches — so a search reveals what you are considering, before you own any of it. As with prices, the request goes through our server rather than your browser, so Yahoo receives the words you typed and nothing that identifies you. The search is optional: the name, symbol and type can all be typed in directly instead, and nothing leaves if you do.

These providers have their own terms and privacy policies. If you would rather nothing at all left the service, simply do not add a symbol — every value can be entered by hand, and a holding without one is never included in a request.

Legal basis

Where the GDPR applies, we process your account details and the records you enter because they are necessary to provide the service you asked for (Article 6(1)(b), performance of a contract). Server logs are kept on the basis of our legitimate interest in operating and securing the service (Article 6(1)(f)).

Cookies and what is stored on your device

Kura sets no advertising or analytics cookies. What it does set:

  • KURA_SESSION — an essential, httpOnly session cookie that keeps you signed in. It cannot be read by JavaScript. Expires after five days.
  • KURA_LOCALE — remembers your chosen language.
  • Local storage — your theme preference, and the Firebase sign-in token.
  • IndexedDB — a local copy of your records, so Kura opens instantly and works offline.

Because that local copy contains financial data, signing out deletes it. Kura also wipes it automatically if a different account signs in on the same browser. On a shared or public device, sign out when you are finished.

Your rights

You can exercise most of these yourself, immediately, without contacting us:

  • Access and portability. Settings → Export downloads everything Kura holds about you as a single JSON file.
  • Erasure. Settings → Delete account removes your records and your sign-in credentials. This is a deletion, not an archive, and it cannot be undone.
  • Rectification. Every record can be edited or deleted from within the app.

You also have the right to object to processing, to restrict it, and to lodge a complaint with your local data protection authority. For anything not covered by the buttons above, write to privacy@kura.green.

How long it is kept

Your records are kept until you delete them or delete your account. There is no retention period beyond that and no archived copy held back. Provider backups may persist for a short period after deletion as part of normal disaster-recovery practice, after which they expire.

Security

Data is encrypted in transit and at rest. For anything you do in the browser, access rules are enforced by the database itself and scoped to a single account, so one user’s records are unreachable from another user’s session. Requests made with an API token are checked by our server instead, which derives which vault to read from the token presented — there is no account identifier in an API request for a caller to change. Session cookies are httpOnly, so a scripting vulnerability cannot be used to steal one; API tokens are stored only as a hash, so a copy of our database yields none that work. No system is perfectly secure, and we do not claim otherwise.

Children

Kura is not directed at children and should not be used by anyone under 16 without the consent of a parent or guardian.

Changes

If this policy changes in a way that materially affects you, we will say so in the app before the change takes effect. The date at the top always reflects the current version.

This document is written in English, which is the authoritative version. Kura’s interface is available in several languages; these terms are not.