Privacy Policy

Last updated: 28 March 2026

1. Who we are

KuroCat is an educational investment information app. We are committed to protecting your privacy and handling your data responsibly.

2. What data we collect

Account information: If you create an account, we store your email address and a securely hashed version of your password. We never store your password in plain text.

Portfolio holdings: If you use the portfolio feature, the categories and amounts you enter are stored on our servers, linked to your account.

Usage data: We may collect anonymous, aggregated usage statistics (such as which screens are viewed) to improve the app. No personally identifiable information is included.

We do NOT collect your real name, phone number, location, contacts, photos, or any other sensitive personal data.

3. How we use your data

Your account data is used solely to authenticate you and provide personalised features (such as portfolio insights).

Portfolio data is used only to calculate insights within the app. It is not shared with third parties.

We do not sell, rent, or trade your personal data to anyone.

4. Third-party services

All scores, scenarios, and portfolio insights are generated from calculations based on market data. No user data is sent to AI services.

We use standard industry APIs (such as Yahoo Finance, FRED, and NewsAPI) to fetch publicly available market data and news. These services do not receive your personal data.

5. Data storage and security

Passwords are hashed using bcrypt before storage. We never store plain-text passwords.

All data is stored in encrypted databases with access controls.

We use secure token-based authentication (JWT) for all authenticated requests.

We recommend you use a strong, unique password for your KuroCat account.

6. Your rights

You can delete your account and all associated data at any time by contacting us.

You can request a copy of the data we hold about you.

If you are in the EU/EEA, you have rights under GDPR including the right to access, rectification, erasure, and data portability.

7. Data retention

We retain your data for as long as your account is active. If you delete your account, we remove your personal data within 30 days.

8. Children's privacy

KuroCat is not intended for children under 16. We do not knowingly collect data from children.

9. Changes to this policy

We may update this policy from time to time. Significant changes will be communicated within the app.

10. Contact

If you have questions about this privacy policy or your data, contact us at support@kurocat.app.