Effective date: 18-07-2026
Kurio (“Kurio”, “we”, “us” or “our”) operates a financial insights application and website (the “Service”).
This Privacy Policy explains how we collect, use, store, and protect personal data when you use Kurio.Kurio is operated as a sole proprietorship (eenmanszaak) based in the Netherlands and complies with the General Data Protection Regulation (GDPR).
Contact:
info@kurio.finance
1. Data We Collect
We collect the following categories of personal data:
Account Information
- Full name
- Email address
- Authentication method (email/password, Google, or Apple sign-in); optional profile photo; phone number if you link WhatsApp
Financial Data (Read-Only)
- Bank account data via GoCardless
- Transaction data (amounts, dates, descriptions, categories)
- Crypto wallet addresses and balances (read-only)
- Kurio never stores bank login credentials, private keys, or recovery phrases.
- Kurio has read-only access and cannot initiate payments or transactions.
Technical & Usage Data
- IP addressDevice type
- App usage data, crash reports and performance diagnostics
- Firebase Analytics data (including your device advertising ID, used for analytics only - never for advertising)
2. How We Use Your Data
We use your data to:
- Provide financial overviews and insights
- Aggregate and display bank and crypto information. To do this, your transaction data is processed by Google's Gemini AI models within the EU to categorise transactions, generate your daily briefing and answer your questions. This happens only after you give explicit AI-processing consent in the app, which you can withdraw at any time.
- Improve app functionality and performance
- Provide customer support
- Comply with legal obligations
- Kurio does not sell personal data to third parties.
3. Legal Basis for Processing (GDPR)
We process personal data based on:
- Consent (e.g., linking bank accounts)
- Performance of a contract (providing the Service)
- Legal obligations
- Legitimate interests (security, analytics, service improvement)
4. Third-Party Services
Kurio uses third-party providers including:
- GoCardless – bank data aggregation
- Firebase – authentication, database, analytics
- RevenueCat – subscription management
- Apple App Store & Google Play – payments and distribution
- Google Gemini - AI processing of your financial data, in the EU; Meta Platforms - only if you link WhatsApp, to deliver the messages you send and receive; Sentry - crash and error monitoring; Resend - delivery of support emails. All of these act as our processors under data processing agreements and strict GDPR safeguards.
5. Data Storage & Security
We implement technical and organizational measures including:
- Encrypted data transmission
- Secure cloud infrastructure hosted in the European Union (Google Cloud, europe-west3)
- Restricted internal access
- No storage of sensitive credentials
6. Data Retention
We retain personal data only as long as necessary to provide the Service or comply with legal requirements. You can delete your account and all associated data in the app (Accounts, then Delete account) or via kurio-prod.web.app/data-deletion. Data is removed from our live systems immediately; residual copies may remain in encrypted backups for up to 30 days.
7. Your Rights (GDPR)
You have the right to:
- Access your data
- Correct inaccurate data
- Request deletion
- Restrict processing
- Data portability
-Withdraw consent at any time
-Requests can be sent to info@kurio.finance.
8. Marketing & Communication
Kurio may send:
-Transactional emails (account, security)
-Optional marketing communications (opt-out available)
9. Age Requirement
Kurio is intended for users 18 years or older.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be published on this page.
11. Contact
For privacy-related questions: info@kurio.finance