Skip to content
Kuro

Privacy policy

Draft pending legal review. Values in [brackets] are being finalised.

Kuro VPN is a VPN. The point of it is privacy, so this policy is short on purpose: we collect as little as we can, and we explain the little we do keep. "We" means [COMPANY_LEGAL_NAME], [COMPANY_ADDRESS], the operator of Kuro VPN and the controller of the data described here.

The short version

  • We do not log your traffic, the sites you visit, your DNS queries, when you connect, or your IP address.
  • You sign in with a 16-digit account number. We don't need your name or email.
  • We keep what we need to run the service: your account, your devices' public keys, your subscription status, and (on the free plan only) how many bytes you used this month.
  • Partner sites in our Perks program only ever learn whether you're a Kuro Black subscriber, under an anonymous ID that is different for every partner.

What we collect

| Data | Why | |---|---| | Account ID and account number | To identify your account and let you sign in | | Recovery email, if you add one (stored encrypted) | To send you your account number if you lose it | | Country at sign-up (from your IP address at that moment; the IP itself is not stored) | Sanctions compliance and aggregate statistics | | Device name, platform, app and OS version, WireGuard public key, and the date (not time) the device was last used | Enforcing the device limit, showing you your devices, and support | | The server your device is currently registered on and its tunnel address | Routing your traffic; deleted after 24 hours without use or when you disconnect | | Free plan only: total bytes used this month | Enforcing the free data allowance | | If you arrived through a partner's referral link: which partner referred you (stored on your account and first subscription) | Crediting the partner. Partners receive only monthly totals, never which accounts they referred | | Subscription status, store country and price from Google Play, the App Store or Paddle | Billing | | Emails you send to support or abuse | Answering you |

When you connect, our API sees your IP address for a moment, to protect against abuse (rate limiting) and to pick a nearby server. It is not written to any database or log.

What we don't collect

Your browsing history, traffic contents or destinations, DNS queries, connection times or durations, your IP address, and which server you used at a given time. Our apps contain no analytics SDKs. More detail on how this is enforced is on our no-logs page.

How long we keep it

| Data | Kept for | |---|---| | Account ID, account number, referring partner | Until you delete your account, then 30 days | | Recovery email (encrypted) | Until you remove it or delete your account | | Country at sign-up | Until you delete your account | | Device name, platform, public key, app version, last-used date | Until you remove the device or delete your account | | Sign-in sessions (stored as hashes) | Up to 90 days, removed 30 days after they expire | | Server registration and tunnel address | Until 24 hours without use, or until you disconnect | | Free-plan monthly byte totals | 2 months | | Subscription status, store country, price, referring partner | 7 years (tax and accounting), unlinked from your account when you delete it | | Billing notifications from the stores | 90 days, then reduced to the event type only | | Perk links and codes | Links until revoked; codes 24 hours after they expire; partner delivery records 30 days | | Administrator audit log (with a hashed IP) | 365 days | | Aggregate server metrics (no per-user data) | 30 days | | Abuse reports | 2 years | | Crash reports, if you turn them on | 90 days |

Who we share data with

We don't sell data, and we don't share it for advertising. We use these service providers, who process data on our behalf:

  • Payments: Google Play and the Apple App Store for in-app subscriptions; Paddle (our merchant of record for web purchases, who handles payment details and taxes); RevenueCat, which tells us your subscription status. They receive your account ID, never your account number.
  • Email: our email provider sends recovery and verification messages, if you add an email.
  • Hosting: the data centres that run our servers.
  • Free-plan ads: the free mobile app shows a banner ad from Google AdMob. AdMob runs only inside the app's interface, never sees your VPN traffic, and is governed by Google's privacy policy. Kuro Black has no ads.
  • Crash reporting: off by default. If you turn it on, crash reports go to Sentry after we strip IP addresses, keys, account numbers and URLs.

Referral links. If you arrived through a partner's link, the website stores a kuro_ref cookie in your browser for 30 days naming that partner. When you create an account, we record the partner on it. The partner never learns who you are; they only see how many sign-ups and subscriptions came through their link each month.

Partner perks. If you redeem a perk code on a partner site, that partner receives an anonymous ID unique to that partner, your plan, and when it renews. Nothing else: no email, account number, device information, IP or activity. You can unlink a partner at any time.

Legal requests. If we receive a valid legal request, we can only provide the data listed above. We cannot provide what we don't have.

Your rights

You can see your account details and devices in the app or on your account page, remove devices, remove your recovery email, and delete your account at any time (Settings → Account → Delete account). Depending on where you live you may also have rights to access, correct, port or object to processing of your data. Email [email protected] and we'll respond within 30 days. You can also complain to your local data protection authority.

Deleting your account does not cancel a subscription bought through Google Play or the App Store; cancel it in the store as well.

International transfers

Our servers are in several countries. Where we transfer personal data out of the EEA or UK, we use appropriate safeguards such as standard contractual clauses.

Children

Kuro VPN is not intended for anyone under 18.

Changes

If we change this policy in a way that matters, we'll update the date above and tell you in the app.

Contact

[COMPANY_LEGAL_NAME], [COMPANY_ADDRESS]. Email: [email protected].