Skip to content
KronX
FeaturesExchanges & NetworksSecurityPricingHow to UseFAQ
TREN
Download the app
Legal

Privacy Policy

This policy explains what data the KronX mobile app and the kronx.co website process and why. It is also our privacy notice under the EU General Data Protection Regulation (GDPR) and Turkey's Personal Data Protection Law No. 6698 (KVKK).

Last updated: October 8, 2026

1. In short

2. Data controller

The data controller under the GDPR and KVKK is:

In this policy, "KronX", "we" and "us" refer to the data controller.

3. Data that stays on your device

The following is kept in the app's storage on your device:

You can delete this data with Erase data on this device in the app, or by uninstalling the app.

4. Sync and encryption

The app creates a sync code for you the first time you open it. When you add your first record, your ledger is written to the server, so it is backed up and reaches your other devices that use the same code.

5. Exchange connections

If you connect an exchange with an API key:

6. Wallet tracking

7. Price alerts and notifications

8. News and AI summaries

The news feed is collected by our server from public news sources; no data is taken from you for this. If you tap Summarize on a news item, that item's headline, source and short excerpt are sent to Anthropic to produce the summary. Your portfolio data, sync code and device details are not sent. The summary is stored and shown to other users who open the same item. The AI never runs on its own.

9. Abuse prevention and technical logs

10. Subscription and payment

KronX subscriptions are sold only through the App Store and Google Play. Apple or Google takes the payment; your card details and billing address never reach us. Subscription status information provided by the store (for example active, trial, expired) may be used to check whether your subscription is valid. Apple and Google process data under their own privacy policies. See the Subscription Terms for details.

11. Support emails

If you write to destek@kronx.co, we use your email address, your name (if it appears in your email) and your message only to reply and solve your issue. Incoming emails are forwarded by Cloudflare email routing to Google's email service (Gmail) and kept there. We will never ask for your sync code or API keys for support; do not send them by email.

12. Purposes and legal bases

Your data is collected automatically and electronically through the app. It is processed for the purposes below, on the legal bases in Article 6(1) GDPR (and Article 5(2) KVKK):

PurposeDataLegal basis
Syncing and backing up your ledgerAccess ID, encrypted ledger, encrypted monthly backupsPerformance of a contract (GDPR 6(1)(b); KVKK 5(2)(c))
Fetching exchange trades and balancesExchange API keys, fetched trades and balances, connection statusPerformance of a contract (GDPR 6(1)(b); KVKK 5(2)(c))
Tracking your walletsWallet addresses, networks, movements readPerformance of a contract (GDPR 6(1)(b); KVKK 5(2)(c))
Sending price alerts and notificationsAlert settings, push token, device languagePerformance of a contract (GDPR 6(1)(b); KVKK 5(2)(c))
Protecting the service against abuse, keeping it secure, fixing errorsIP address, Turnstile signals, request counters, error logsLegitimate interests (GDPR 6(1)(f); KVKK 5(2)(f))
Answering support requestsEmail address, message contentPerformance of a contract and legitimate interests (GDPR 6(1)(b), (f); KVKK 5(2)(c), (f))
Meeting legal obligations, handling legal claimsData as neededLegal obligation; establishing, exercising or defending legal claims (GDPR 6(1)(c), (f); KVKK 5(2)(ç), (e))

We do not use your data for automated decision-making or profiling.

13. Service providers and international transfers

We use the service providers below to run KronX. Some of them process data outside Turkey and the European Economic Area, mainly in the United States.

ProviderPurposeData sent
Cloudflare, Inc. (USA; global infrastructure)Server, database, file storage, Turnstile, hosting of kronx.co, email routingAll data stored on the server, IP address, Turnstile signals
Hetzner Online GmbH (Germany; server in the European Union)Relay server that forwards exchange and blockchain requests from a fixed IPExchange and blockchain requests; for some exchanges, the API key for the duration of the request
The exchanges you connectReading trades and balancesYour API key and the signed requests the exchange requires
Blockchain node and explorer providers (for example Alchemy, Etherscan, Blockscout, NodeReal, dRPC, PublicNode and the networks' own public nodes)Reading wallet balances and movementsWallet address
AaveReading Aave positions (if you use it)Wallet address
CoinGecko and exchanges' public market endpointsPrice and chart dataNo personal data; the server fetches shared lists
News sources (RSS feeds, CryptoCompare, Google News)News feedNo personal data; the server fetches shared lists
Anthropic, PBC (USA)Summarizing a news item you chooseOnly the item's headline, source and excerpt
Google LLC (USA) — Firebase Cloud MessagingSending notificationsPush token, notification text
Apple Inc. (USA) — APNsDelivering notifications to iPhone and iPadDevice token, notification text
Apple Inc. and Google LLC — App Store, Google PlaySelling subscriptions and taking paymentData the stores collect themselves
Google LLC (USA) — GmailSupport emailsEmail content

These transfers are necessary to provide the service. For users in the European Economic Area, transfers rely on safeguards provided by the GDPR, such as European Commission adequacy decisions (including the EU-U.S. Data Privacy Framework where the provider is certified) or Standard Contractual Clauses. Transfers from Turkey rely on the safeguards in Article 9 KVKK (such as the providers' standard contracts) and, where needed, the exceptions listed in that article. These providers' own privacy policies also apply.

14. Retention periods

DataHow long
Encrypted ledgerUntil you delete it
Encrypted monthly backupsThe 24 most recent; older ones are deleted automatically
Exchange API keys, wallet addresses, price alertsUntil you remove the connection or alert, or delete your data on the server
Trades fetched from exchanges, wallet movements7 days after your device picks them up; at most 90 days if it does not (at most 10,000 pending records per account; beyond that the oldest are deleted)
Exchange balancesReplaced on every fetch; deleted when the connection is removed
Triggered price alertDeleted 24 hours after it triggers
Notification registrationDeleted if you do not open the app for 90 days; created again when you open it
Request counters, Turnstile checksA matter of minutes
Server error logsFor our hosting provider's short log retention period
Support emailsAs long as needed to resolve your request; deleted when you ask (unless the law requires us to keep them)

15. Deleting your data

In the app, go to Settings → Sync (Connect devices) → Delete all my data on the server. Your encrypted ledger, backups, exchange connections and keys, fetched trades and balances, wallet addresses and movements, price alerts and notification registrations are permanently deleted from the server. There is no waiting period, and deletion cannot be undone.

Data on your device is not affected. You can delete it with Erase data on this device or by uninstalling the app. If you cannot access the app, write to destek@kronx.co; because your account is identified only by your sync code, we may need to ask you for information to verify the data is yours.

Canceling your subscription or uninstalling the app does not delete your data on the server. You also need to cancel your subscription separately in your store settings.

16. Your rights

Under the GDPR you have the right to:

Under Article 11 KVKK you also have the right to learn whether your data is processed, which third parties in Turkey or abroad it is transferred to, to ask that corrections and deletions be notified to those third parties, to object to an outcome against you that results solely from automated analysis, and to claim compensation for damage caused by unlawful processing.

17. How to make a request

To use your rights, email destek@kronx.co or write to Öğretmenler Mah. Şehit İsmet Akın Cad. No: 1, Tasgül Moment Ofis, Floor 1, Unit 2, Tarsus, Mersin, Türkiye. Include your name, contact details and a clear description of your request. Because your account is identified by your sync code rather than a name or email, we may need to verify that the data belongs to you; do not email your sync code — we will suggest a safe way.

We respond free of charge within 30 days at the latest (within one month under the GDPR, which may be extended in complex cases as the law allows). If you are not satisfied with our response, you can complain to your local data protection authority or, in Turkey, to the Personal Data Protection Board (KVKK).

18. The kronx.co website

19. Security and its limits

All communication with the server uses encrypted connections (HTTPS). Only our own server, holding a certificate, can connect to our relay server. Your ledger is encrypted on your device; your exchange keys are stored encrypted on the server.

No system is completely secure. Because exchange keys can be decrypted by the server and fetched trades are briefly stored in plain text, this data could be affected by a security breach. Use read-only keys to reduce this risk. If we become aware of a breach, we will notify the competent authority and affected users within the time limits set by law.

20. Children

KronX is not directed at children under 13 and does not knowingly collect their data. If you believe such data exists, contact us and we will delete it.

21. Changes

We may update this policy as the app or the law changes. The current version is always on this page, with the date at the top. We will also announce significant changes in the app.

22. Contact

For privacy questions and requests: destek@kronx.co