Privacy Policy

Effective date: September 22, 2025

Welcome to Kurato! Your privacy is important to us, and we want you to feel comfortable using our personalized content recommendation app. This Privacy Policy explains how Kurato collects, uses, and protects your information when you use our services. It applies to all users of Kurato – whether you’re exploring anonymously, signed up for a free account, or using a paid subscription.

By using or accessing our Services in any manner, you acknowledge that you accept the practices and policies outlined below, and you hereby consent that we will collect, use and disclose your information as described in this Privacy Policy.

Remember that your use of Kurato’s Services is at all times subject to our Terms of Use at kurato.com/terms, which incorporates this Privacy Policy. Any terms we use in this Policy without defining them have the definitions given to them in the Terms of Use.

If you have a disability, you may access this Privacy Policy in an alternative format by contacting [email protected].

As we continually work to improve our Services, we may need to change this Privacy Policy from time to time. We will alert you of material changes by placing a notice on the Kurato website, by sending you an email and/or by some other means. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes.

Privacy Policy Table of Contents

What This Privacy Policy Covers

Personal Data

How We Disclose Your Personal Data

Cookies and Other Tracking Technologies

Data Security

Data Retention

Personal Data of Children

Other State Law Privacy Rights

European Union, United Kingdom, Swiss Data Subject Rights

Contact Information

What This Privacy Policy Covers

This Privacy Policy covers how we treat Personal Data that we gather when you access or use our Services. “Personal Data” means any information that identifies or relates to a particular individual and also includes information referred to as “personally identifiable information” or “personal information” or “sensitive personal information” under applicable data privacy laws, rules or regulations. This Privacy Policy does not cover the practices of companies we don’t own or control or people we don’t manage.

Personal Data

Categories of Personal Data We Collect

This chart details the categories of Personal Data that we collect and have collected over the past 12 months through your use of the Services:

Category of Personal Data (and Examples)

Business or Commercial Purpose(s) for Collections

Categories of Third Parties With Whom We Disclose this Personal Data

Profile or Contact Data such as first and last name, email, username, password.

This helps identify you on the platform and allows you to create an Account.

  • Providing, Customizing and Improving the Services
  • Corresponding with You

  • Service Providers
  • Business Partners

Payment Data via Mobile App
payment processing is handled by the app store provider. We do not receive or store your full payment card information.  We may receive limited transaction details such as confirmation of payment, purchase amount, and country of purchase to fulifll your order and maintain your account.


Payment Data via Website or Desktop App payment data such as payment card type, last 4 digits of payment card number, billing address, email.

  • Providing, Customizing and Improving the Services
  • Corresponding with You
  • Service Providers (specifically our payment processing partners)

Inference Data
such as your content preferences and interests generated from your activity on our Services.

We use inferences to provide you with personalized recommendations and to improve our content suggestions.

  • Providing, Customizing and Improving the Services
  • Corresponding with You
  • Service Providers
  • Business Partners
  • Parties you Authorize, Access, or Authenticate

User Generated Content
such as ratings or reviews of music, movies, books, or other media and uploaded profile images.

Your user feedback and preferences help us improve our recommendations.

  • Providing, Customizing and Improving the Services
  • Corresponding with You
  • Service Providers
  • Business Partners
  • Parties you Authorize, Access, or Authenticate

Device/IP Data such as IP address and type of device/operating system.

This helps us ensure the Service works correctly on different devices.

  • Providing, Customizing and Improving the Services
  • Corresponding with You
  • Service Providers
  • Business Partners

App Analytics such as app interactions, screen views, crash logs, and statistics associated with the interactions between device and the Services.

This data helps us understand user engagement and improve our offerings.

  • Providing, Customizing and Improving the Services
  • Corresponding with You
  • Service Providers
  • Business Partners

Web Analytics such as app interactions, screen views, crash logs, and statistics associated with the interactions between device and the Services.

This data helps us understand user engagement and improve our offerings.

  • Providing, Customizing and Improving the Services
  • Corresponding with You
  • Service Providers
  • Business Partners

Geolocation Data such as IP-address-based location information.

This helps us ensure the Service works correctly on different devices and aids in security. We may also derive the approximate location from your IP address for analytics.

  • Providing, Customizing and Improving the Services
  • Corresponding with You
  • Service Providers
  • Business Partners

Other Identifying Information that You Voluntarily Choose to Provide such as emails, letters, and text you send us.

  • Providing, Customizing and Improving the Services
  • Corresponding with You
  • Service Providers
  • Parties you Authorize, Access or Authenticate

Our Commercial or Business Purposes for Collecting Personal Data

Kurato uses the collected data to personalize and improve your experience, as well as to maintain a reliable and secure service. Here are the purposes for collecting your personal data:

For example, if you highly rate science fiction movies or popular podcasts, we use that history to suggest similar movies or the latest sci-fi podcast you might love.

Other Permitted Purposes for Processing Personal Data

In addition, each of the above referenced categories of Personal Data may be collected, used, and disclosed with the government, including law enforcement, or other parties to meet certain legal requirements and enforcing legal terms including: fulfilling our legal obligations under applicable law, regulation, court order or other legal process, such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities; protecting the rights, property or safety of you, Kurato or another party; enforcing any agreements with you; responding to claims that any posting or other content violates third-party rights; and resolving disputes.

We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated or incompatible purposes without providing you notice or obtaining your consent.

Categories of Sources of Personal Data

We collect Personal Data about you from the following categories of sources:

Collecting this information helps us understand your preferences so we can personalize your recommendations.

How We Disclose Your Personal Data

We disclose your Personal Data to the categories of service providers and other parties listed in this section. Depending on state laws that may be applicable to you, some of these disclosures may constitute a “sale” of your Personal Data. For more information, please refer to the state-specific sections below.

Please note that:

Legal Obligations

We may disclose any Personal Data that we collect with third parties in conjunction with any of the activities set forth under “Other Permitted Purposes for Processing Personal Data” section above.

Business Transfers

All of your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part).

Data that is Not Personal Data

We may create aggregated, de-identified or anonymized data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and share it with third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business, provided that we will not share such data in a manner that could identify you.

Cookies and Other Tracking Technologies

The Services use cookies and similar technologies such as pixel tags, web beacons, clear GIFs and JavaScript (collectively, “Cookies”) to enable our servers to recognize your web browser, tell us how and when you visit and use our Services, analyze trends, learn about our user base and operate and improve our Services. Cookies are small pieces of data – usually text files – placed on your computer, tablet, phone or similar device when you use that device to access our Services. We may also supplement the information we collect from you with information received from third parties, including third parties that have placed their own Cookies on your device(s).

Please note that because of our use of Cookies, the Services do not support “Do Not Track” requests sent from a browser at this time.

We use the following types of Cookies:

You can decide whether or not to accept Cookies through your internet browser’s settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your device. If you do this, however, you may have to manually adjust some preferences every time you visit our website and some of the Services and functionalities may not work.

To explore what Cookie settings are available to you or to modify your preferences with respect to Cookies, you can access your Cookie management settings by accessing your user profile settings. To find out more information about Cookies generally, including information about how to manage and delete Cookies, please visit http://www.allaboutcookies.org/ or https://ico.org.uk/for-the-public/online/cookies/ if you are located in the European Union.

Session Replay Technology

We may use session replay technology in order to identify and resolve customer issues, to monitor and analyze how you use our Services, to better understand user behavior, and to improve our Services. Use of session replay technology is optional. You will be given the opportunity to provide your consent and opt in before any session replay data is collected. If you do not opt in, session replay technology will not be enabled for your use of the Services. You may change your preferences at any time by adjusting your session replay settings in your user profile.

Data Security

We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting data over the internet or storing data is completely secure.

Data Retention

We retain Personal Data about you for as long as necessary to provide our Services or to perform our business or commercial purposes for collecting your Personal Data, as is the case with Web-Based Personal Data. When establishing a retention period for specific categories of data, we consider who we collected the data from, our need for the Personal Data, why we collected the Personal Data, and the sensitivity of the Personal Data In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.

For example:

Personal Data of Children

We do not knowingly collect or solicit Personal Data from children under the age of 13 (or the minimum age required by law in your jurisdiction) without verifiable parental consent. If you are under the required minimum age, please do not attempt to register for or use our Services or send us any Personal Data. If we learn that we have inadvertently collected Personal Data from a child without appropriate consent, we will take prompt steps to delete that information. If you believe a child under the required age may have provided us with Personal Data, please contact us at [email protected].

If a child between the ages of 13 and 17 uses the Services, they may do so only with the consent and supervision of a parent or legal guardian, who must accept our Terms of Use and this Privacy Policy on their behalf. Parents and guardians have the right to:

Other State Law Privacy Rights

California Resident Rights

Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to contact us to prevent disclosure of Personal Data to third parties for such third parties’ direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes.

Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications and services that you do not wish such operators to track certain of your online activities over time and across different websites. Our Services do not support Do Not Track requests at this time. To find out more about “Do Not Track,” you can visit http://www.allaboutdnt.com/.

European Union and United Kingdom Data Subject Rights

EU and UK Residents

If you are a resident of the European Union (“EU”), United Kingdom, Lichtenstein, Norway or Iceland, you may have additional rights under the EU General Data Protection Regulation (the “GDPR”) with respect to your Personal Data, as outlined below.

For this section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR, but “Personal Data” generally means information that can be used to individually identify a person, and “processing” generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. Kurato will be the controller of your Personal Data processed in connection with the Services.

If there are any conflicts between this section and any other provision of this Privacy Policy, the policy or portion that is more protective of Personal Data shall control to the extent of such conflict. If you have any questions about this section or whether any of the following applies to you, please contact us at [email protected]. Note that we may also process Personal Data of our customers’ end users or employees in connection with our provision of certain services to customers, in which case we are the processor of Personal Data. If we are the processor of your Personal Data (i.e., not the controller), please contact the controller party in the first instance to address your rights with respect to such data.

Personal Data We Collect

The “Categories of Personal Data We Collect” section above details the Personal Data that we collect from you.

Personal Data Use and Processing Grounds[a]

The “Our Commercial or Business Purposes for Collecting Personal Data” section above explains how we use your Personal Data.

We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.

Examples of these legitimate interests include (as described in more detail above):

Disclosing Personal Data

The “How We Disclose Your Personal Data” section above details how we share your Personal Data with third parties.

EU, UK, and Swiss Data Subject Rights

You have certain rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email us at [email protected]. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.

Transfers of Personal Data

The Services are hosted and operated in the United States (“U.S.”) through Kurato and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Kurato in the U.S. and will be hosted on U.S. servers, and you authorize Kurato to transfer, store and process your information to and in the U.S., and possibly other countries. In some circumstances, your Personal Data may be transferred to the U.S. pursuant to a data processing agreement incorporating standard data protection clauses.

Contact Information

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:

[a]Please confirm grouping of personal data is in the correct categories...Contractual vs Interest.