Last updated: August 5, 2026
This Privacy Policy explains how KronosPay LLC ("Kronos," "we," "us," or "our") collects, uses, shares, and safeguards your personal information when you use the Kronos mobile application, website, and related services. By using Kronos, you consent to the practices described in this policy. This notice is provided in compliance with the Gramm-Leach-Bliley Act (GLBA), the California Consumer Privacy Act (CCPA/CPRA), the EU General Data Protection Regulation (GDPR) and UK GDPR where applicable, and other applicable privacy regulations.
Personal Information: When you create an account, we collect your full name, email address, phone number, date of birth, Social Security Number (for KYC verification), and mailing address.
Financial Information: When you link an external bank through Plaid, we receive the account identifiers, institution and account metadata, account/routing details, balances, ownership information, and transaction history you authorize. Plaid handles your bank login credentials; Kronos does not receive them. This connection is used for account insights, verification, gig-income detection and, for eligible users, creation of a HiFi outbound destination that can receive Kronos withdrawals. It is not an authorization to debit or pull money from the linked bank. Separately, if an eligible money-movement feature is available, we may collect partner-issued account and routing details, beneficiary information, transfer instructions, direct-deposit information, balances, and transfer records. Raw card numbers are handled by the disclosed payment processor rather than stored by Kronos.
Gig Platform, Mileage, and Tax Data: If you connect gig platform accounts or enter gig activity manually, we collect earnings data, work history, payout schedules, trip counts, hours, mileage logs, tax-reserve preferences, and related notes to provide earnings, tax, and income-management tools.
Biometric and Identity Data: If you enable Face ID, Touch ID, or fingerprint unlock, your device biometric template stays on your device and Kronos receives only a yes/no confirmation from your operating system. For account opening and later compliance checks, identity verification may require a government-ID image, a centered live frame, a short live-motion recording, and, only when a risk trigger requires it, audio of a server-generated spoken-number challenge. With your express consent, approved automated identity-verification systems compare the trusted ID portrait or prior approved reference with the live evidence, evaluate capture quality and replay risk, and return a limited verification result. A non-pass or inconclusive result is routed to restricted Kronos compliance staff for review and does not automatically decline your account or financial application. These records are used only for identity verification, fraud prevention, compliance review, and legally required recordkeeping.
Contacts, Location, Support, and Membership Data: If you choose to find friends on Kronos, we read phone numbers and email addresses from your device contacts, hash them on-device, send only hashes for matching, and do not store your contact list. If you use mileage tracking, we use precise or background location only to detect and calculate trips you choose to save. If you contact support, we collect support messages, attachments, call metadata, and call audio routed through support providers. If you subscribe or claim perks, we collect subscription status, purchase receipts, renewal state, shipping details for merch, and perk-claim records. For a direct membership purchase, Whop provides the customer identity, product, payment status, renewal, cancellation, and refund metadata needed to grant and maintain access. Kronos does not receive or store the full payment-card number entered at Whop checkout.
Device & Usage Data: We automatically collect device type, operating system, IP address, app usage patterns, session duration, diagnostics, and crash reports to secure the service, improve reliability, and detect fraud. TikTok App Events may receive limited app install, launch, and retention events so we can measure our TikTok advertising; if you allow Apple’s tracking permission on iOS, TikTok may also access your device advertising identifier. Kronos does not send TikTok financial, identity, contact, wallet, transaction, subscription-purchase, or support data; automatic payment and enhanced-data reporting are disabled. You can deny the request or change the permission later in iOS Settings.
Device Fingerprint & New-Login Verification: Each time you sign in, Kronos generates a one-way hash of your device's hardware signals (model, OS version, model year, total memory, and a stable installation identifier) and records the public IP address of the request. The hash and IP are written to a dedicated known_devices table and used only to detect new-device or new-location logins, in which case we may require additional verification (email OTP, SMS OTP, or biometric re-auth). The device hash and IP are retained for ninety (90) days from the most recent login and then automatically purged. Raw hardware signals are never transmitted to Kronos servers — only the resulting hash.
Third-Party Service Providers (data shared by category): To deliver money movement, digital-asset, identity-verification, support, subscription, yield, fulfillment, and analytics functions, Kronos shares the minimum data required with the following processors under the applicable service and data-protection terms: our money-movement partner (only for separately enabled partner accounts, on/off-ramp, transfer, and compliance services — identity, beneficiary, bank, KYC, and transaction data needed for the requested feature); Plaid (external-bank linking, authorized account and transaction data, account verification, and Plaid Identity Verification where used — Plaid handles bank credentials, and Kronos receives only the data and permissions the user authorizes); Google Gemini API (government-ID images, approved reference images, centered live frames, short live-motion recordings, and risk-triggered spoken-challenge audio used for document-capture quality, liveness, replay-risk, and identity-match assistance; Gemini does not make a final adverse account decision, and non-passes are reviewed by restricted Kronos compliance staff); an approved card processor (only when card funding or payouts are enabled — name, address, card source, and transaction amount); Apple App Store and Google Play (subscription purchases, receipts, renewals, cancellations, and refunds); licensed crypto exchange and liquidity partners (trade routing, quotes, fills, and settlement details); Turnkey, Inc. (non-custodial wallet-key infrastructure used to hold and sign Kronos's DeFi yield position on the Base network — pseudonymous user identifier + on-chain wallet address only; no PII); Alchemy (Base mainnet RPC provider used to read blockchain state and submit transactions — IP address + on-chain wallet address); Spark Savings / Sky Protocol (underlying DeFi yield protocol; interacted with via permissionless smart contracts — receives only on-chain wallet addresses and transaction amounts, no off-chain PII); Sentry (crash + error reporting — pseudonymous user ID and PII-scrubbed breadcrumbs only; sendDefaultPii: false); Supabase (Kronos-owned database and support workspace hosting — account identifiers and support-conversation content); Resend (transactional and support email — name, email address, and email content); Telnyx, Twilio, or similar communications providers (SMS, voice, support-call routing, and account-verification metadata); Printful or other fulfillment partners (merch-box order and shipping details); Google Places API (address autocomplete during signup, accessed via a Kronos server-side proxy so your IP is not exposed to Google); Meta, Reddit, TikTok, Google Ads, or similar web attribution tools on the website when enabled and permitted by consent settings; and TikTok App Events in the iOS app for the limited advertising-attribution data described above, with access to the device advertising identifier only after Apple tracking permission.
Direct membership processor: Whop processes direct membership checkout and billing. Whop receives the name, email address, selected membership, and payment details entered at checkout, and sends Kronos product, payment, renewal, cancellation, and refund status. Kronos does not receive the full payment-card number.
On-Chain Wallet Addresses. Kronos creates a Turnkey-managed wallet address on the Base network for each user to hold the DeFi yield position. The wallet address is pseudonymous (a 42-character hexadecimal string) and is recorded on a public blockchain. Any party can view transaction history associated with a wallet address; Kronos does not publish the mapping between wallet addresses and user identities. On-chain transaction history is permanent and publicly auditable. If a user shares their wallet address with a third party, that third party can view all transactions associated with the address. Kronos cannot delete or amend on-chain records — they are governed by the underlying blockchain protocol, not by Kronos.
We use your information to: provide, operate, and maintain banking, money movement, crypto, savings/yield, card, payout, international transfer, gig-income, mileage, tax, subscription, support, and perk features; verify your identity and comply with KYC/AML regulations; match contacts privately when you ask us to find Kronos users; process transactions and send notifications; calculate subscription billing and membership eligibility; ship eligible merch and other physical perks; detect, prevent, and investigate fraudulent or unauthorized activity; communicate important account updates and promotional offers; perform automated risk assessments for fraud prevention; and improve our products through aggregated analytics.
Kronos uses automated systems to assist with fraud-risk scoring, account-risk assessments, document-capture quality, liveness, replay-risk detection, and identity comparison. Automated identity systems may pass a check or route it to restricted Kronos compliance staff, but they do not issue a final adverse account or financial decision without human review. You may request an explanation or human review of an automated decision that significantly affects your account by contacting support@getkronos.io.
As a financial services provider, KronosPay LLC is subject to the GLBA. We collect nonpublic personal information (NPI) about you from account applications, transaction history, and third-party sources. We do not disclose NPI to non-affiliated third parties except as permitted by law, including: to process your transactions, to protect against fraud, to comply with legal requirements, and with service providers who are contractually obligated to keep your information confidential. You may opt out of certain information-sharing practices by contacting privacy@getkronos.io.
We do not sell your personal information. We share data only in the following circumstances: with our money-movement partner HiFi and applicable partner banks for separately enabled and eligible partner-account, USD↔stablecoin conversion, ACH, RTP where available, wire, local-payout, and related transfer features; a Plaid link alone does not instruct HiFi to move money; with payment processors and card networks (Visa, Mastercard) to facilitate transactions; with identity verification providers (for KYC/AML compliance); with App Store / Google Play for in-app subscriptions; with fulfillment providers for merch and physical perks; with on-device key derivation (BIP32/BIP39) for wallet and key management; with licensed cryptocurrency exchange and liquidity partners to facilitate trades; with cloud infrastructure providers (for hosting and data storage); with email, SMS, voice, and support providers (for transactional communications and customer support); with law enforcement or regulators when required by law, subpoena, or legal process; and with analytics or attribution providers using aggregated, de-identified, hashed, or consented website data or, after Apple tracking permission, limited iOS advertising-attribution data. All third-party service providers are bound by data processing agreements that require them to protect your information and use it only for the purposes we specify.
Sub-processors. Certain partners act as our sub-processors and may handle your data under their own privacy policies — including HiFi for banking, money-movement, KYC, and transaction processing. Where a partner processes your data as a controller for its own legal, compliance, or fraud-prevention obligations, that partner’s privacy policy also applies. You may direct requests relating to data held by HiFi to support@hifi.com, and we will assist where required.
International data transfers. Kronos and its service providers are based in the United States, and your information is processed in the U.S. Where data is transferred from the EEA, UK, or Switzerland, we and our sub-processors rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses (SCCs) and equivalent UK/Swiss mechanisms — to protect it.
We implement industry-leading security measures to protect your data, including: 256-bit SSL/TLS encryption for all data in transit and at rest; biometric and two-factor authentication; real-time transaction fraud monitoring; SOC 2-compliant cloud infrastructure; PCI DSS compliance for payment card data; regular third-party security audits and penetration testing; role-based access controls for internal data access; and encrypted database backups with geographic redundancy.
In the event of a data breach that compromises your personal information, we will notify affected users via email and in-app notification within 72 hours of confirming the breach, or as otherwise required by applicable state law. The notification will include: the nature of the breach, the types of data affected, the steps we are taking to address it, and recommended actions you can take to protect yourself. We will also notify applicable state attorneys general and regulatory authorities as required by law. Where appropriate, we will offer complimentary credit monitoring services to affected users.
We retain your personal information for as long as your account is active and for a period of five (5) years after account closure to comply with BSA/AML financial record-keeping regulations. Transaction records may be retained for up to seven (7) years as required by applicable tax and financial reporting laws. You may request deletion of your account data at any time, subject to regulatory retention requirements, by contacting privacy@getkronos.io.
Depending on your jurisdiction, you have the following rights regarding your personal data:
All Users: Right to access your data, correct inaccuracies, opt out of marketing communications, and request a portable copy of your information.
California Residents (CCPA/CPRA): Right to know what personal information is collected and disclosed; right to delete your data; right to correct inaccurate data; right to opt out of the sale or sharing of personal information (note: Kronos does not sell your data); right to limit the use of sensitive personal information; and right to non-discrimination for exercising your rights. To exercise your CCPA rights, contact privacy@getkronos.io or call our privacy line. We will respond within 45 days.
Virginia Residents (VCDPA): Right to access, correct, delete, and obtain a portable copy of your data; right to opt out of targeted advertising, profiling, and sale of personal data.
Colorado Residents (CPA): Right to access, correct, delete, and port your data; right to opt out of targeted advertising, sale of data, and profiling that produces legal effects.
Connecticut Residents (CTDPA): Right to access, correct, delete, and port your data; right to opt out of targeted advertising, sale of data, and profiling.
To exercise any of these rights, email privacy@getkronos.io with your request. We will verify your identity and respond within the timeframes required by applicable law.
Our website currently does not respond to "Do Not Track" (DNT) browser signals, as there is no industry-standard protocol for DNT compliance. However, you can control tracking through cookie preferences, browser settings, and the privacy controls offered by supported ad platforms.
Our website uses cookies and similar technologies to remember your preferences, protect forms from abuse, analyze traffic, attribute App Store download visits, and measure whether our own ads work. This may include Cloudflare, Turnstile, Google Ads, Meta, Reddit, TikTok, or similar attribution tools when enabled. You can manage cookie preferences through your browser settings. For detailed information about the cookies we use, their purposes, and how to control them, see our Cookie Policy.
The Kronos app and website may contain links to third-party websites, services, or applications that are not owned or controlled by KronosPay LLC. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.
We strongly advise you to read the terms and privacy policies of any third-party website you visit. KronosPay LLC shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any third-party content, goods, or services.
Legal bases. Where the GDPR or UK GDPR applies, we process your personal data on these legal bases: (a) performance of a contract — providing your Kronos account and the services you request; (b) legal obligation — identity verification, anti-money-laundering and sanctions screening, tax and record-keeping laws; (c) legitimate interests — securing our services, preventing fraud, and improving the product, balanced against your rights; and (d) consent, where we ask for it (for example marketing communications and optional analytics cookies), which you may withdraw at any time without affecting the lawfulness of prior processing.
Your additional rights. Beyond the rights listed above, you may: object to processing based on legitimate interests; restrict processing while a dispute about it is resolved; withdraw consent at any time; request human review of any decision based solely on automated processing that produces legal or similarly significant effects (including automated identity-verification outcomes); and lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner’s Office).
Exercising your rights. Contact privacy@getkronos.io. We respond within one month as required by law. Identity-verification records collected to satisfy anti-money-laundering obligations are retained for the statutory period even after an erasure request; we will tell you when this applies.
If you are located in the EU/EEA or the UK and have questions or concerns regarding your personal data, you may contact our appointed GDPR representatives:
EU Representative:
Euverify Ltd (Ireland)
Unit 3D North Point House, North Point Business Park
New Mallow Road, Cork, T23 AT2P, Ireland
Email: gdpr@euverify.com
UK Representative:
Euverify Ltd (UK)
3rd Floor, 86–90 Paul Street
London, EC2A 4NE, United Kingdom
Email: gdpr@euverify.com
To submit a Data Subject Access Request (DSAR), a deletion request, or any other GDPR inquiry, use our secure portal: verify our representative & submit a request. Requests submitted through this portal are logged and tracked to ensure timely response.
Verification: Certificate ID EV103301 · View our GDPR representation certificate (PDF) · Verify live with Euverify
Calls to and from Kronos support lines may be recorded and transcribed for quality, security, fraud prevention, and training. An automated notice at the start of each call informs you before recording begins; if you do not wish to be recorded, you may hang up and use in-app chat or email support instead. Recordings are stored securely, access is restricted and audited, and they are retained under the schedule in Section 9. Verification digits you enter on the keypad are captured before recording starts and are excluded from recordings and transcripts.
Kronos is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If we discover that a minor has created an account, we will promptly delete the account and associated data. If you believe a minor has provided us with personal information, contact privacy@getkronos.io.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before taking effect. Continued use of Kronos after updates constitutes acceptance of the revised policy. Prior versions of this policy are available upon request.
For privacy-related questions, data access requests, or concerns, contact our privacy team at privacy@getkronos.io. For general support, reach us at support@getkronos.io. To report fraud or unauthorized activity, email reportfraud@getkronos.io.