Last updated: October 8, 2026
1. In short
- KronX does not ask for your name, email address or phone number. The only key to your account is the sync code the app creates for you.
- Your portfolio ledger (transactions, assets, settings) is encrypted on your device and sent to the server encrypted. The decryption key never leaves your device, and the server cannot read your ledger.
- Exchange and wallet connections work differently: so that data can be fetched while the app is closed, your exchange API keys are stored encrypted on the server in a form the server can decrypt, and the trades and balances read from exchanges and blockchains are kept on the server temporarily in plain text. Details below.
- We use no ad networks, analytics or tracking tools. We do not sell your data or share it for marketing.
- You can delete all of your data on the server with a single tap inside the app.
2. Data controller
The data controller under the GDPR and KVKK is:
- Name: Kadriye Kara
- Address: Öğretmenler Mah. Şehit İsmet Akın Cad. No: 1, Tasgül Moment Ofis, Floor 1, Unit 2, Tarsus, Mersin, Türkiye
- Email: destek@kronx.co
In this policy, "KronX", "we" and "us" refer to the data controller.
3. Data that stays on your device
The following is kept in the app's storage on your device:
- Your transactions, asset list, ledgers, recent prices and preferences.
- Your sync code. On iPhone and iPad it is kept in the Keychain; on Android in storage encrypted with the Android Keystore.
- If you turn on the app lock, a value derived from your PIN, not the PIN itself. Biometric checks (Face ID, fingerprint) are done by the operating system; biometric data never reaches us.
- Exchange statements you import from a file are read on your device. The file itself is not uploaded; the transactions in it are added to your ledger and synced encrypted with it.
You can delete this data with Erase data on this device in the app, or by uninstalling the app.
4. Sync and encryption
The app creates a sync code for you the first time you open it. When you add your first record, your ledger is written to the server, so it is backed up and reaches your other devices that use the same code.
- On your device, the code is turned into two separate values: an access ID that is sent to the server and an encryption key that stays on your device. The encryption key cannot be derived from the access ID.
- Your ledger is compressed and encrypted with AES-GCM on your device. The server only sees the encrypted package, its size, a revision number and the time it was last updated.
- An encrypted backup is made automatically every month; the 24 most recent monthly backups are kept.
- Your sync code is the key to your ledger, so nobody, including us, can access your encrypted ledger on the server. If you lose your code and the records on your device are also deleted, you will need to reconnect your exchanges and wallets and re-enter any transactions you added manually. Keep your code somewhere safe and make regular file backups with Settings → Back up. Never share your code: anyone who has it can read and change your ledger.
5. Exchange connections
If you connect an exchange with an API key:
- Your API key and secret are stored on the server, encrypted with our server key (AES-GCM). Because scheduled fetching runs while you are not using the app, these keys can be decrypted by the server. So give your key read-only permission on the exchange, and never trading, transfer or withdrawal permission. Where the exchange allows it, the app checks whether withdrawals are enabled when you add a key and warns you.
- Requests to exchanges are forwarded through our own relay server, which has a fixed IP address. For some exchanges your key is used in this server's memory for the duration of the request; it is not written to disk.
- Trades (asset, amount, price, fee, time) and balances read from the exchange are stored on the server in plain text. Once your device has picked them up and written them to your ledger, they are deleted within 7 days (see Retention periods). Balances are replaced on every fetch.
- To manage the connection, we record fetch times, the last error or status note, the fetch interval you chose and when you last opened the app. If you do not open the app for more than 30 days, automatic fetching pauses; it resumes when you open the app again.
6. Wallet tracking
- You only enter a public wallet address. Your private key or recovery phrase is never requested or stored.
- The address, the networks you choose and any label you give it are stored on the server in plain text, so the wallet can be scanned while the app is closed.
- To read balances and movements, the address is sent to the blockchain node or block explorer for that network (see Service providers). Blockchain data is public, but linking an address to you can be personal data.
- Movements that are read wait on the server in plain text until you review them, then they are deleted (see Retention periods).
7. Price alerts and notifications
- For each alert, the asset, target price or percentage, direction and repeat setting are stored on the server in plain text, because the server watches the price.
- If you allow notifications, your device's push token, device language and unread notification count are stored.
- Notifications are sent through Google Firebase Cloud Messaging (FCM); on iPhone and iPad, FCM delivers them through the Apple Push Notification service (APNs). The notification text (for example the asset name and price) passes through these services.
- You can turn notifications off at any time in your device settings.
8. News and AI summaries
The news feed is collected by our server from public news sources; no data is taken from you for this. If you tap Summarize on a news item, that item's headline, source and short excerpt are sent to Anthropic to produce the summary. Your portfolio data, sync code and device details are not sent. The summary is stored and shown to other users who open the same item. The AI never runs on its own.
9. Abuse prevention and technical logs
- IP address: Your IP address is visible when the app's requests reach our server. It is used for short-lived request counters when a new account is created and on some endpoints; we do not store it separately.
- Cloudflare Turnstile: An invisible human check runs when a new account is created and before costly actions such as wallet scans. Technical signals about your device and your IP address are sent to Cloudflare. This is covered by the Cloudflare Turnstile Privacy Addendum.
- Rate limits: To prevent abuse, requests are counted per access ID. The counters are short-lived.
- Error logs: When something fails, technical details are written to the server log with a short error code. If you give us the code when asking for help, we can find the problem. Logs are kept briefly by our hosting provider.
10. Subscription and payment
KronX subscriptions are sold only through the App Store and Google Play. Apple or Google takes the payment; your card details and billing address never reach us. Subscription status information provided by the store (for example active, trial, expired) may be used to check whether your subscription is valid. Apple and Google process data under their own privacy policies. See the Subscription Terms for details.
11. Support emails
If you write to destek@kronx.co, we use your email address, your name (if it appears in your email) and your message only to reply and solve your issue. Incoming emails are forwarded by Cloudflare email routing to Google's email service (Gmail) and kept there. We will never ask for your sync code or API keys for support; do not send them by email.
12. Purposes and legal bases
Your data is collected automatically and electronically through the app. It is processed for the purposes below, on the legal bases in Article 6(1) GDPR (and Article 5(2) KVKK):
| Purpose | Data | Legal basis |
|---|---|---|
| Syncing and backing up your ledger | Access ID, encrypted ledger, encrypted monthly backups | Performance of a contract (GDPR 6(1)(b); KVKK 5(2)(c)) |
| Fetching exchange trades and balances | Exchange API keys, fetched trades and balances, connection status | Performance of a contract (GDPR 6(1)(b); KVKK 5(2)(c)) |
| Tracking your wallets | Wallet addresses, networks, movements read | Performance of a contract (GDPR 6(1)(b); KVKK 5(2)(c)) |
| Sending price alerts and notifications | Alert settings, push token, device language | Performance of a contract (GDPR 6(1)(b); KVKK 5(2)(c)) |
| Protecting the service against abuse, keeping it secure, fixing errors | IP address, Turnstile signals, request counters, error logs | Legitimate interests (GDPR 6(1)(f); KVKK 5(2)(f)) |
| Answering support requests | Email address, message content | Performance of a contract and legitimate interests (GDPR 6(1)(b), (f); KVKK 5(2)(c), (f)) |
| Meeting legal obligations, handling legal claims | Data as needed | Legal obligation; establishing, exercising or defending legal claims (GDPR 6(1)(c), (f); KVKK 5(2)(ç), (e)) |
We do not use your data for automated decision-making or profiling.
13. Service providers and international transfers
We use the service providers below to run KronX. Some of them process data outside Turkey and the European Economic Area, mainly in the United States.
| Provider | Purpose | Data sent |
|---|---|---|
| Cloudflare, Inc. (USA; global infrastructure) | Server, database, file storage, Turnstile, hosting of kronx.co, email routing | All data stored on the server, IP address, Turnstile signals |
| Hetzner Online GmbH (Germany; server in the European Union) | Relay server that forwards exchange and blockchain requests from a fixed IP | Exchange and blockchain requests; for some exchanges, the API key for the duration of the request |
| The exchanges you connect | Reading trades and balances | Your API key and the signed requests the exchange requires |
| Blockchain node and explorer providers (for example Alchemy, Etherscan, Blockscout, NodeReal, dRPC, PublicNode and the networks' own public nodes) | Reading wallet balances and movements | Wallet address |
| Aave | Reading Aave positions (if you use it) | Wallet address |
| CoinGecko and exchanges' public market endpoints | Price and chart data | No personal data; the server fetches shared lists |
| News sources (RSS feeds, CryptoCompare, Google News) | News feed | No personal data; the server fetches shared lists |
| Anthropic, PBC (USA) | Summarizing a news item you choose | Only the item's headline, source and excerpt |
| Google LLC (USA) — Firebase Cloud Messaging | Sending notifications | Push token, notification text |
| Apple Inc. (USA) — APNs | Delivering notifications to iPhone and iPad | Device token, notification text |
| Apple Inc. and Google LLC — App Store, Google Play | Selling subscriptions and taking payment | Data the stores collect themselves |
| Google LLC (USA) — Gmail | Support emails | Email content |
These transfers are necessary to provide the service. For users in the European Economic Area, transfers rely on safeguards provided by the GDPR, such as European Commission adequacy decisions (including the EU-U.S. Data Privacy Framework where the provider is certified) or Standard Contractual Clauses. Transfers from Turkey rely on the safeguards in Article 9 KVKK (such as the providers' standard contracts) and, where needed, the exceptions listed in that article. These providers' own privacy policies also apply.
14. Retention periods
| Data | How long |
|---|---|
| Encrypted ledger | Until you delete it |
| Encrypted monthly backups | The 24 most recent; older ones are deleted automatically |
| Exchange API keys, wallet addresses, price alerts | Until you remove the connection or alert, or delete your data on the server |
| Trades fetched from exchanges, wallet movements | 7 days after your device picks them up; at most 90 days if it does not (at most 10,000 pending records per account; beyond that the oldest are deleted) |
| Exchange balances | Replaced on every fetch; deleted when the connection is removed |
| Triggered price alert | Deleted 24 hours after it triggers |
| Notification registration | Deleted if you do not open the app for 90 days; created again when you open it |
| Request counters, Turnstile checks | A matter of minutes |
| Server error logs | For our hosting provider's short log retention period |
| Support emails | As long as needed to resolve your request; deleted when you ask (unless the law requires us to keep them) |
15. Deleting your data
In the app, go to Settings → Sync (Connect devices) → Delete all my data on the server. Your encrypted ledger, backups, exchange connections and keys, fetched trades and balances, wallet addresses and movements, price alerts and notification registrations are permanently deleted from the server. There is no waiting period, and deletion cannot be undone.
Data on your device is not affected. You can delete it with Erase data on this device or by uninstalling the app. If you cannot access the app, write to destek@kronx.co; because your account is identified only by your sync code, we may need to ask you for information to verify the data is yours.
Canceling your subscription or uninstalling the app does not delete your data on the server. You also need to cancel your subscription separately in your store settings.
16. Your rights
Under the GDPR you have the right to:
- access your personal data and get a copy of it,
- have inaccurate data corrected,
- have your data erased,
- restrict processing,
- data portability,
- object to processing based on legitimate interests,
- lodge a complaint with the data protection authority in the country where you live or work.
Under Article 11 KVKK you also have the right to learn whether your data is processed, which third parties in Turkey or abroad it is transferred to, to ask that corrections and deletions be notified to those third parties, to object to an outcome against you that results solely from automated analysis, and to claim compensation for damage caused by unlawful processing.
17. How to make a request
To use your rights, email destek@kronx.co or write to Öğretmenler Mah. Şehit İsmet Akın Cad. No: 1, Tasgül Moment Ofis, Floor 1, Unit 2, Tarsus, Mersin, Türkiye. Include your name, contact details and a clear description of your request. Because your account is identified by your sync code rather than a name or email, we may need to verify that the data belongs to you; do not email your sync code — we will suggest a safe way.
We respond free of charge within 30 days at the latest (within one month under the GDPR, which may be extended in complex cases as the law allows). If you are not satisfied with our response, you can complain to your local data protection authority or, in Turkey, to the Personal Data Protection Board (KVKK).
18. The kronx.co website
- The site is static; it has no forms, accounts or payments.
- It uses no cookies and no analytics, advertising or tracking tools.
- The site is hosted on Cloudflare. To deliver pages, your IP address and the standard information your browser sends (such as browser type) are technically processed by Cloudflare.
- Everything, including fonts, is served from our own server; the site does not connect to Google or any other third-party service while you visit. See the Cookie Policy.
19. Security and its limits
All communication with the server uses encrypted connections (HTTPS). Only our own server, holding a certificate, can connect to our relay server. Your ledger is encrypted on your device; your exchange keys are stored encrypted on the server.
No system is completely secure. Because exchange keys can be decrypted by the server and fetched trades are briefly stored in plain text, this data could be affected by a security breach. Use read-only keys to reduce this risk. If we become aware of a breach, we will notify the competent authority and affected users within the time limits set by law.
20. Children
KronX is not directed at children under 13 and does not knowingly collect their data. If you believe such data exists, contact us and we will delete it.
21. Changes
We may update this policy as the app or the law changes. The current version is always on this page, with the date at the top. We will also announce significant changes in the app.
22. Contact
For privacy questions and requests: destek@kronx.co