Skip to content
CURSARIS
  • Features
  • Pricing
  • Support
Download

PRIVACY POLICY — CURSARIS

Last updated: 2026-04-22

  • All data is stored only on your device.
  • We do not collect analytics.
  • API keys are encrypted in the Keychain.
  • Background notifications — only with your consent.

Contents

  • 1. WHO WE ARE
  • 2. WHAT DATA WE PROCESS
  • 3. WHY WE PROCESS DATA
  • 4. WHERE YOUR DATA GOES
  • 5. HOW WE PROTECT YOUR DATA
  • 6. HOW LONG WE RETAIN DATA
  • 7. YOUR RIGHTS
  • 8. AUTOMATED DECISION-MAKING
  • 9. CHILDREN’S PRIVACY
  • 10. POLICY CHANGES
  • 11. CONTACT US
  • APPENDIX A: EU/EEA RESIDENTS (GDPR)
  • APPENDIX B: CALIFORNIA RESIDENTS (CCPA/CPRA)
  • APPENDIX C: BRAZIL RESIDENTS (LGPD)

1. WHO WE ARE

Cursaris is developed by Alexander Uskov (individual developer). For the purposes of the General Data Protection Regulation (GDPR), we are the “data controller” with respect to the limited data described below.

Contact: support@cursaris.app or via the App Store.

2. WHAT DATA WE PROCESS

Cursaris is a local-first application. The vast majority of data never leaves your device.

Your exchange credentials — API keys are stored exclusively in the device Keychain (hardware encryption). We never access your keys.

Your portfolio data — positions, trades, balances, calculations. Stored only on your device in SwiftData.

Your wallet addresses — if you add on-chain wallets, the addresses are sent to public blockchain nodes to query balances.

Device identifier (APNs token) — if you enable background notifications, an anonymous device identifier is sent to our notification server (api.cursaris.app) to deliver alerts about market events. We do NOT link this token to any personal data, portfolio data, or exchange credentials.

Your webhook URLs — if you configure trading-plan webhooks, the URL and plan context are sent to the address you specified when the conditions are triggered.

Reference data — the app may download updated reference data (Smart Money filter) from our CDN. No personal data is transmitted; however, your IP address may be visible to the hosting provider (GitHub/Microsoft) as part of standard HTTPS connections.

3. WHY WE PROCESS DATA

Performance of a contract (Art. 6(1)(b) GDPR) — portfolio storage, exchange synchronization, PnL calculation, notifications, backups, widgets. These features are necessary for the operation of the app you downloaded.

Explicit consent (Art. 6(1)(a) GDPR) — APNs token registration with api.cursaris.app (background notifications), OTA filter download (Smart Money Radar). Each of these features requires your explicit consent before activation.

Legitimate interest (Art. 6(1)(f) GDPR) — webhook URL validation (SSRF protection), log sanitization (credential protection), automatic backup (data-loss prevention).

4. WHERE YOUR DATA GOES

api.cursaris.app — our notification server (APNs token only, upon explicit consent).

Exchange APIs — Binance, Bitget, Bybit, OKX, MEXC, Coinbase, Gate.io, KuCoin, BingX, Kraken, Bitfinex, Deribit — requests with your authentication, initiated by you. We are not an intermediary — this is your direct relationship with the exchanges.

Blockchain RPC nodes (5 EVM networks) — public infrastructure, wallet addresses used to query balances.

Public market-data APIs — Binance, Deribit, Yahoo Finance, CoinGecko, Alternative.me, CoinMarketCap — unauthenticated public requests.

oleksandruskov.github.io — Smart Money label updates (a static file; no user data is sent).

Apple Push Notification Service — delivery of push notifications.

User webhooks — your own infrastructure; data is sent only when your trading plans are triggered.

We do NOT sell, rent, or share your data with advertisers. The app does NOT use third-party analytics SDKs.

5. HOW WE PROTECT YOUR DATA

API keys: iOS Keychain (kSecAttrAccessibleWhenUnlockedThisDeviceOnly) — hardware encryption.

Portfolio data: SwiftData with device-level encryption (iOS Data Protection).

Network connections: all connections use TLS 1.2+ (HTTPS).

Logs: sensitive data is sanitized before writing (API keys, secrets, passwords are masked).

Backups: JSON export is not encrypted — you control the export location.

6. HOW LONG WE RETAIN DATA

Portfolio data — until you delete it or remove the app.

Balance snapshots — automatically deleted after 30 days.

Debug logs — rotating buffer, max ~6 MB, automatic rotation.

Automatic backups — the 3 most recent are kept; older ones are deleted.

APNs token on the server — deleted after 90 days of inactivity, or immediately upon disabling background notifications.

7. YOUR RIGHTS

Regardless of your location, you have the following rights:

Access — export all data via Settings → Data → Export.

Rectification — edit any position, trade, or wallet within the app.

Erasure — delete individual items, entire portfolios, or all data.

Portability — export in machine-readable JSON format.

Restriction of processing — disable any exchange, wallet, or automated feature.

Withdrawal of consent — disable background notifications or synchronization at any time.

8. AUTOMATED DECISION-MAKING

Cursaris includes automatic monitoring features (Trading Plans, Alert System) that may generate notifications and invoke webhooks based on rules you define.

These automated systems:

  • Process only data already on your device.
  • Perform only the actions you configure.
  • Alerts can be turned off in Settings → Monitoring, and webhook delivery in Settings → Data → Manage Data → Consent Management; an individual plan is switched off in the plan itself.
  • Do NOT make financial decisions — they notify YOU for decision-making.

You have the right to disable any automated feature at any time.

9. CHILDREN’S PRIVACY

Cursaris is not intended for use by persons under 16 years of age. We do not knowingly collect personal data from children.

10. POLICY CHANGES

We may update this policy. The current version is always available in the app and on our website. Continued use of the app after an update constitutes acceptance of the changes.

11. CONTACT US

For privacy-related questions, contact us at support@cursaris.app or via the App Store.

APPENDIX A: EU/EEA RESIDENTS (GDPR)

Additional rights under Articles 15–22 GDPR:

  • The right to lodge a complaint with a supervisory authority (EDPB list: edpb.europa.eu).
  • The right to object to processing based on legitimate interest (Art. 21).
  • Appointment of a DPO is not required (data processing is not on a large scale).
  • International transfers: your data remains on your device; the APNs token is processed in accordance with Apple’s DPA.

APPENDIX B: CALIFORNIA RESIDENTS (CCPA/CPRA)

  • Categories of PI collected: device identifiers (APNs token). Financial information is processed locally.
  • Sale of PI: we do NOT sell your personal information.
  • Right to know: data export feature.
  • Right to delete: data deletion feature.
  • Right to opt out of sale: not applicable (no sale takes place).
  • Non-discrimination: we do not discriminate against users exercising their privacy rights.

APPENDIX C: BRAZIL RESIDENTS (LGPD)

  • Legal basis (Art. 7): consent + performance of a contract.
  • DPO (Encarregado): contact via the App Store.
  • Complaints to ANPD: users may file complaints with Brazil’s National Data Protection Authority.
  • International transfers (Art. 33): data remains on the device.
CURSARIS
PrivacyTermsDisclaimerSupport

Cursaris is a portfolio tracker, not a broker or an exchange. It connects to exchanges with read-only API keys, never requests trade or withdrawal permissions, and holds no custody of funds. Nothing here is investment advice.

© 2026 Cursaris