Legal

Privacy Policy

Effective Date: August 8, 2026  ·  Last Updated: August 8, 2026

GURZ LTD ("we," "us," or "our") operates the CryptoScanner mobile application (the "App"). This Privacy Policy explains what information we collect, how we use it, the legal bases on which we rely, and your rights regarding that information.

Data controller: GURZ LTD, Rue Gallait 22, 1030 Schaerbeek, Brussels, Belgium
Privacy contact: support@gurz.com

§1. Information We Collect

Account information — When you register, we collect your name, email address, and password. Passwords are stored by our backend in hashed form; we never store your password in plain text.

Verification data — We send a one-time passcode (OTP) to your email to verify your identity during sign-up and for certain security-sensitive actions. We retain a record of verification attempts for a limited period for security and abuse-prevention purposes.

Push notification tokens — If you enable price alerts or other notifications, we collect and store a device push token (issued by Apple Push Notification service or Firebase Cloud Messaging) so that we can deliver alerts to your device. This token is tied to your account and is deleted when you disable notifications, sign out, or delete your account.

App usage data — Information about the features you use, such as price alerts you create, watchlists you maintain, assets you track, and general navigation within the App, in order to operate and improve the service.

Device and technical data — Basic technical information such as device type, operating system version, app version, and crash or error diagnostics, primarily for diagnosing issues and ensuring compatibility.

We do not collect: your device's camera, photo library, microphone, precise location, health data, or contacts. The App does not request these permissions. We do not collect cryptocurrency wallet addresses, private keys, seed phrases, or exchange API keys, and you should never send them to us.

§2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account.
  • Authenticate you and keep your account secure.
  • Deliver core features, including price tracking, market comparisons, historical charts, and price alerts.
  • Send push notifications you have requested, such as triggered price alerts.
  • Send transactional emails (for example, OTP codes or account notices).
  • Monitor, maintain, and improve the App's performance and reliability.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your data to make automated decisions that produce legal or similarly significant effects.

§3. Legal Bases for Processing (EEA/UK Users)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Creating and operating your account; delivering the App's featuresPerformance of a contract
Sending push notifications you enabledConsent (withdrawable at any time in device or app settings)
Security, fraud prevention, service improvementLegitimate interests
Retaining records for tax, accounting, or legal purposesLegal obligation

§4. Third-Party Services

We rely on the following categories of third-party service providers, each of which processes data under its own privacy policy:

  • Cryptocurrency exchange and market-data providers — supply the public price, market, and historical data displayed in the App. We do not share your personal account information with these providers; we query public market data on your behalf, and these queries do not carry identifiers that link them to you.
  • Push notification providers — Apple Push Notification service and/or Firebase Cloud Messaging, used solely to deliver notifications to your device.
  • Backend hosting provider — operates the servers that store your account data.
  • Email delivery provider — delivers transactional email such as OTP codes.

§5. Data Storage and Security

  • Your account data is stored on our backend servers and protected using industry-standard security measures, including encrypted (HTTPS/TLS) communication between the App and our servers.
  • Your authentication session token is stored locally and securely on your device to keep you signed in; it is removed when you sign out or when your session expires.
  • Access to production data is limited to personnel who need it to operate the service.
  • While we take reasonable steps to protect your information, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by applicable law.

§6. Data Retention

We retain your account information for as long as your account is active. If you delete your account, we will delete or anonymise your personal information within 30 days, except where we are required to retain certain data to comply with legal or accounting obligations, or to resolve disputes and enforce our agreements. Backup copies are purged on our regular backup rotation cycle.

§7. Your Rights and Account Deletion

Deleting your account. You can delete your account and all associated personal data directly in the App at any time: open Settings → Account → Delete Account. You do not need to contact us or reinstall the App to do this. Deletion is permanent and cannot be undone.

Depending on your jurisdiction, you may also have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of your account and associated personal data.
  • Object to or restrict certain processing of your data.
  • Withdraw consent where processing is based on consent (this does not affect processing carried out before withdrawal).
  • Request a copy of your data in a portable, machine-readable format.
  • Lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact us at the address in Section 11. We will respond within the timeframe required by applicable law, and we will not discriminate against you for exercising them.

§8. Children's Privacy

The App is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from someone under 18, we will delete it promptly. If you believe a child has provided us with personal information, please contact us.

§9. International Data Transfers

Your information may be processed and stored in countries other than your own, including countries that may not provide the same level of data protection as your jurisdiction. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, and we take steps to ensure your data receives an adequate level of protection regardless of where it is processed.

§10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the App or by email, and will update the "Last Updated" date above. Continued use of the App after changes take effect constitutes acceptance of the revised policy.

§11. Contact Us

If you have questions about this Privacy Policy or how your data is handled, contact us at:

General support: support@gurz.com

Postal address: Rue Gallait 22, 1030 Schaerbeek, Brussels, Belgium