Kurto
— Know what you own. See what’s coming.
How Kurto treats your data
July 2026 · Plain words, no legal fog · incorporated into
the
Terms of Use.
What we hold
The minimum the product needs: your email address (it is your
sign-in — there are no passwords), the name you gave when you asked
for an invitation, the names and time horizons of your goals, and
the funds you enter with a dollar amount or share count — plus
ordinary service records: which days you signed in and which features you
used (counts, not contents). That’s it. No bank links, no brokerage
credentials, no documents, no phone number.
Where it lives, and how
- On our own hardware. Kurto’s analysis runs on machines we own,
not in a rented cloud. The AI that writes your briefing runs locally on
that same hardware — your portfolio is never sent to any
third-party AI service. Your account itself (email, goals, positions)
is stored encrypted at our edge provider, separate from the analysis
machines, which never see who you are.
- Encrypted before it’s stored. Once you have an account, your
email, your name, goal names, and positions are encrypted by our
application before they ever reach the database. What sits on disk is
scrambled ciphertext — so a copy, a backup, or anyone browsing the
stored data sees nothing. The analysis happens in program memory, at the
moment you ask for it. The one readable exception: the invitation list
— the email address you give us to request access stays readable,
because it is how we send your one invitation and manage access. The name
you give with it is encrypted like everything else.
- The honest boundary, because you deserve the real sentence and not
a slogan: the system must decrypt your data to analyze it, so the operator
holds the application’s keys and could, deliberately, access it.
What the encryption guarantees is that no stored artifact leaks your data
and no casual access sees it. We won’t pretend otherwise —
companies that claim absolute “zero knowledge” while analyzing
your data are describing something mathematically impossible.
What we never do
- We never sell or share your data. There is no third party to share it
with: no analytics trackers on your pages, no ad tech, no data
partners.
- We never set tracking cookies. Kurto’s only cookie is your sign-in
session — nothing follows you around the web.
- We never send your portfolio to outside AI. (The one outside service in
the whole flow is the email carrier that delivers your six-digit sign-in
code and your invitation — it sees your address, your name and the
code, nothing else.)
- We never give investment advice, and we never will. Kurto tells you what
you own and what touched it, with sources.
Leaving
Two buttons on your account page, no process, no email to support:
- Export — everything we hold about you, downloaded as one
file, any time. It includes your record of the Terms versions you
accepted, and when.
- Delete — every goal, position, and briefing is erased
immediately and you are signed out everywhere. Encrypted platform-side
copies (short-lived backups and the database’s own recovery
window) age out on their own within about 30 days; the record that you
once accepted the Terms is retained, without your name or email, because
the law expects us to keep it. Kurto forgets you. Deleting your data
doesn’t revoke your invitation — you’re welcome back
anytime, starting fresh.
The early-days caveat
You’re using an early product. Two things follow: we may
occasionally reset or migrate data as we build (we’ll tell you first),
and features will change under your feet. In exchange you get a direct line
to the people building it — write to
hello@kurto.ai freely.