Overview
This policy explains how Kuraa Method ("Kuraa Method", "Kuraa", "we", "us"), the app operated at tikhd.kuraagabut.com, handles information when you use the Kuraa Method website, Discord bot, browser extension, and backend at api.tikhd.kuraagabut.com. It also covers Community, purchases and optional integrations such as TikTok. What the Kuraa Check Chrome extension does on your device is described in detail in the Kuraa Check Extension Privacy Policy.
Kuraa Method, operated from the Philippines, is the personal information controller responsible for the Kuraa processing described here. Our data protection contact handles privacy questions and requests at [email protected]. This notice explains our practices; it does not require you to waive privacy rights or provide blanket consent. Optional permissions and any consent required by law are handled separately.
Video processing at a glance
- Some optimizations run entirely on your device.
- For standard optimization, your browser sends only the file's technical header to Kuraa and builds the optimized video on your device; the video itself is not uploaded.
- When you post to TikTok, your browser uploads the video directly to TikTok after you confirm.
- If you turn on an optional feature that needs the whole video, such as re-encoding, your browser sends the video to a third-party processing provider and downloads the result before Kuraa optimizes it.
Information We Process
1. Discord account and server information
When you sign in with Discord or use the Kuraa bot, we may process your Discord user ID, username, avatar, server membership, and Haze-related roles. We use this information to authenticate you, provide bot commands, determine your tier, grant or remove roles, and keep the website and Discord server in sync. Kuraa's OAuth flow does not request your Discord email address.
1a. Google sign-in and your Kuraa account
You can sign in with Google instead of, or as well as, Discord. Google sign-in asks only for your basic profile (openid, email, profile): we store Google's account identifier, your name, your profile picture link and your email address when Google has verified it, and use them only to sign you in and to show your account. We do not receive your Google password or access your other Google data. Every Kuraa account has an account ID (for an account created with Discord, this is your Discord user ID) and a username you choose, which other people may see where Kuraa shows who did something, such as in Community. Your credits, purchases and settings belong to the Kuraa account, whichever sign-in method you use; you can connect or remove a sign-in method from the account menu as long as one remains.
2. Discord bot activity
The bot processes the commands, buttons, and other interactions you send to it. Depending on the feature used, it stores information needed for Kuraa Credits, XP and levels, moderation and anti-abuse controls, sticky messages, server statistics, donation roles, and feature settings. Chat activity may earn XP, but it does not earn Kuraa Credits. When a feature depends on a Discord message event, the bot processes the message and channel identifiers and the content needed to perform that feature.
3. Purchases, subscriptions, and older payment tickets
Every purchase, including subscriptions and free trials, goes through our checkout partner Whop, which collects your payment details directly; Kuraa never receives your full card number. From Whop we receive and store the membership and payment identifiers, the plan, amount, currency, payment status, and trial, renewal and cancellation dates, linked to your Kuraa account ID. We also record each purchase agreement: your Kuraa account ID, the Terms and Refund Policy version you accepted, which checkout it was for, and when. We use these records to grant and renew paid plans, stop renewals when you cancel, allow one free trial per person, answer refund requests, and respond to payment disputes.
Before September 28, 2026, some payments were made directly to Kuraa through Discord payment tickets. For those tickets, we keep the ticket number, Discord account, selected payment method and amount, ticket status, associated Discord channel, staff decision, rejection reason when provided, and role expiry. Payment services may have provided Kuraa with a transaction identifier, amount, and payment status so we could prevent duplicate processing and grant the correct role. Where the website shows an older ticket, it shows only its status (number, payment method, amount, months and creation date), never the messages in the Discord ticket channel.
Messages, attachments and proofs you choose to send in a Discord support or payment ticket are processed through Discord and can be viewed by the staff handling it. We may keep information necessary to resolve the request or payment claim. Discord's own retention and permissions apply; deleting a channel or message does not necessarily remove an independently retained transaction record. Do not send passwords, full card details, or unrelated sensitive information.
4. Credits, usage, and account status
We store records used to operate the service, including your weekly and purchased Kuraa Credits, temporary processing reservations, detected resolution, frame rate and file-size pricing data, upload count, approximate MB saved, account restrictions, warnings, and paid-plan and role expiry dates. Weekly balances reset on a weekly schedule; lifetime totals may remain on the account record.
5. Video and media files
- On-device optimizationProcessing occurs on your device. These videos are not uploaded to Kuraa for that stage.
- Optional full-video features (off by default)When you turn on an optional feature that needs the whole video, such as re-encoding, your browser uploads the selected video directly to a third-party processing provider, which processes it and returns the result to your browser for the normal Kuraa optimization. Kuraa itself receives only a job identifier and its status, not the video. The provider keeps the files it processes under its own retention rules.
- Standard optimizationYour browser sends Kuraa's API only the file's technical header (track layout, timing and sample tables, with no picture or sound) and receives instructions it uses to build the optimized file on your device; the video itself is not uploaded. That header can also hold details your camera or editing app embedded in the file, such as the recording time, device model or location; Kuraa uses the header only to build those instructions and does not store it. Kuraa keeps a fingerprint (hash) of the header with the record of your credit reservation, so an answer lost within the hour can be re-sent without charging you twice.
- Recent optimized videosOnly if you turn on "Keep videos on this device" (it is off by default), the website stores the output file, filename, size and related processing information in your browser's IndexedDB so you can download it again or select it for upload. Turning the setting off deletes those saved videos. Your choice is stored in your browser (localStorage key
haze_keep_videos). Saved entries expire after 3 days and are removed during cache cleanup when the cache is used. The cache holds at most 20 files and 500 MiB; older entries may be evicted sooner and browser storage may be cleared. Signing out does not necessarily erase saved videos. Turn the setting off or clear site data to remove them, and keep your own backups. - Posting to TikTokAfter you confirm a post, your browser uploads the video directly to TikTok. Kuraa sends TikTok the caption, privacy and interaction settings you choose, and stores the publish ID, caption, privacy setting, status, failure reason and public post ID for status history. The retention window is 90 days; older records are removed during database cleanup when new post records are stored.
- Video checkingIf you submit a TikTok URL for analysis, the backend processes the link, publicly available video and creator details, and technical measurements needed to return the result. These records are distinct from your optional TikTok OAuth connection. To show whether TikTok is limiting a video's reach (the "Shadowban" line), your browser also sends the TikTok link you entered directly to a third-party video information provider that reads public TikTok post data. That request carries no Kuraa account details or cookies; the provider receives the link and ordinary request data such as your IP address under its own terms.
We do not use submitted videos to train models, advertise to you, or build advertising profiles.
6. TikTok connection (Login Kit & Content Posting API)
Connecting TikTok is optional and uses its official OAuth Login Kit. With user.info.basic, we retrieve your display name and profile picture to identify the connected account. We store access and refresh tokens encrypted, associate them with your Kuraa account or a random anonymous ID stored in your browser, and refresh them as needed. When you confirm publishing, video.publish is used for the video and settings you select, with a direct upload to TikTok. These permissions are not used to publish without your action.
You can disconnect on the Upload page to delete the saved tokens from Kuraa, or revoke permissions in your TikTok account. Revoking at TikTok prevents further authorized use but does not itself guarantee immediate deletion of our stored record; contact us if you also need deletion. Clearing site data can lose access to an anonymous connection, so disconnect first or revoke at TikTok and contact us with enough information to identify it. Never send us a token as proof. Disconnecting does not delete an already published TikTok post or automatically erase status history; request eligible record deletion separately.
Connection and publishing data are processed only for the purposes described here and shared with TikTok and the infrastructure needed to provide the feature. TikTok applies its own privacy policy to information it receives.
7. Security, analytics and technical information
The website sends limited operational measurements to our hosting logs: app version, page category, operation category, duration, and success or failure. Performance measurements are sampled. These event payloads exclude account identifiers, tokens, video contents, filenames, captions, full URLs, and error messages. This reporting honors browser Do Not Track and Global Privacy Control signals and is capped per page session.
Separately, the website uses a privacy-focused web analytics service to measure traffic and page use. It uses request-derived anonymous visitor measurements without analytics cookies, and may process the page path, referring site, device or browser characteristics, and approximate region. Kuraa removes query strings, including query strings embedded in route hashes, before sending page URLs so sign-in callback tokens are not included. This analytics path is separate from the operational reporting above; the operational reporting's Do Not Track and Global Privacy Control gate should not be understood as a site-wide analytics opt-out. Where applicable law requires consent or an opt-out for particular processing, those requirements apply.
Kuraa does not place advertising cookies or advertising pixels on its pages, and does not share your activity on Kuraa with advertising networks.
When you use Kuraa, we process normal request information such as IP address, timestamps, request metadata, and rate-limit events. For multi-account and abuse detection, we may also store a browser-generated device identifier, hashed identifiers, linked account IDs, detection outcomes, warnings, and termination status. These checks can restrict an account automatically. If that happens to you, contact us and a person will review the decision.
8. Information stored on your device
The website and extension store session details, basic profile and tier data, credit balances, feature preferences, and interface settings using cookies, local storage, or extension storage. Signing out clears Kuraa authentication data from the active browser. The extension's optional TikTok repair action deletes the ttwid cookie when you ask it to; it does not transmit that cookie's value to Kuraa.
Local storage also supports language choice, onboarding preferences, anonymous TikTok ownership and recent optimized files. Some storage is necessary for the features you request; clearing it may sign you out, reset preferences or remove access to an anonymous connection. A cookie or local identifier is not proof that a particular individual authorized a payment.
9. Community
When you post in Community, your message, your username and your badge at that moment are shown publicly to anyone who visits the page, and stored with the time you sent it. If you share a Kuraa check, the result of that check (the TikTok handle, resolution, frame rate and verdict) is stored with your message. Moderators can delete messages and limit who can post. Deleted messages are hidden right away and kept for 30 days so reports can be reviewed, then removed. Anything you post publicly can be seen, and copied, by other visitors, so do not share private information there.
10. Partner offers
Some offers give extra credits for subscribing to a partner's Telegram channel. If you link a Telegram account for such an offer, we store the Telegram user ID you enter with your Kuraa account, whether the partner reports it as subscribed, and when it was linked and last checked. To confirm the offer, we send that ID to the partner to ask whether it is subscribed; the partner answers yes or no and receives no other Kuraa account information from us. You can unlink at any time where you linked it, or ask us to remove the link. The partner keeps its own subscriber records under its own policy.
Discord Privileged Intents and Your Controls
The Kuraa bot uses one Discord privileged gateway intent, Server Members. This section describes what it is used for and the controls available to you. Message-content features (such as info commands and link moderation) are provided by a separate companion bot.
Server Members
Used to welcome new members, log departures for moderators, and keep your Kuraa tier in sync when donation or booster roles change. As described above, we store your Discord user ID, assigned tier, and role expiry off-platform; this is required to grant your perks.
How We Use Information
- Authenticate users and synchronize Discord roles and Kuraa tiers
- Operate the website, Discord bot, optimizer, Community, ticket system, economy, and usage limits
- Process payments and grant time-limited roles or bought credits
- Carry out video processing and publishing actions you request
- Measure site traffic and reliability in aggregate
- Run promotions and partner offers you choose to take part in
- Provide support, diagnose failures, secure the service, moderate Community, rate-limit requests, and prevent abuse
We do not sell personal information or share it with advertisers or data brokers.
Why We Are Allowed to Use It
Where data-protection law (such as the Philippine Data Privacy Act of 2012 or the GDPR) asks for a legal basis, we rely on:
- Contractto provide the features, purchases and subscriptions you ask for;
- Legitimate intereststo secure Kuraa, investigate suspected fraud and multi-account abuse, moderate Community, measure site traffic, resolve disputes, and improve reliability, where that basis is available and our purpose and necessity are balanced against your rights;
- Consentfor optional connections such as TikTok or a partner-offer link, which you can withdraw by disconnecting or unlinking;
- Legal obligationto keep payment records and answer lawful requests.
Retention
| Information | Typical retention |
|---|---|
| On-device videos and recent-output cache | Original and downloaded files remain on your device. Optimized videos are kept on your device only if you turn on "Keep videos on this device" (off by default); turning it off deletes them. Saved outputs expire after 3 days and are removed during cache use/cleanup; browser storage can be cleared sooner. |
| Optional full-video processing jobs | Kuraa keeps a job identifier, your account ID, the job's status and its times for a short period, so each job runs once and usage limits can be applied, then removes them. The video itself is handled by the processing provider under its own retention. |
| Standard optimization headers and results | Kuraa uses the header only to build the instructions and does not store it; the credit/job record keeps a fingerprint (hash) of the header. Results are built on your device and never reach Kuraa's servers. |
| Older payment-ticket records | As long as needed for accounting, refund and dispute purposes, like other payment records |
| TikTok connection tokens | Until deleted through Kuraa disconnect or an applicable deletion request; expired or revoked permissions may prevent use before the stored record is deleted. |
| Community messages | Shown publicly while they remain in the room. Deleted messages are hidden right away and kept for 30 days for report review, then removed. |
| TikTok post records | 90-day retention window, with older records removed during post-record storage cleanup. |
| Partner-offer links | Until you unlink or ask us to remove the link, or the offer ends, plus any period needed to resolve a dispute about a bonus. |
| Payment, subscription, trial, and policy-acceptance records | As long as needed for accounting, tax, refund, and dispute purposes, and as the law requires, even after you stop using Kuraa |
| Account, credit, economy, role, and security records | While needed to operate the account, enforce limits, resolve payments, secure Kuraa, or meet applicable obligations |
We retain only what is reasonably necessary for the stated purpose or a legal obligation, and review retention when resolving deletion requests. Records needed for accounting, a pending dispute, fraud investigation or legal claim may remain restricted rather than immediately erased. Different records and backups may have different removal schedules; we do not promise every copy disappears instantly. We will explain a relevant retention exception when responding to your request.
International Transfers
Kuraa is operated from the Philippines. Hosting, database, payment and connected-service providers may process information in the United States and other countries with different privacy laws. Where applicable law requires a transfer mechanism or safeguards, we must use the applicable protections, such as appropriate contractual safeguards or a recognized lawful transfer basis. Contact us for information about safeguards relevant to your data; this notice is not itself a claim that every destination has equivalent laws.
Your Rights
Depending on where you live, including under the Philippine Data Privacy Act of 2012, the GDPR in the EU and UK, and US state privacy laws, you may have the right to:
- Know
be told how your information is used (this policy);
- Get a copy
get a copy of the information we hold about you, in a portable format;
- Correct
correct information that is wrong or incomplete;
- Delete or restrict
have information deleted or blocked, or object to or restrict how we use it;
- Withdraw consent
withdraw consent you gave, without affecting what we did before; and
- Complain
complain to a data-protection authority — in the Philippines, the National Privacy Commission (privacy.gov.ph).
Email [email protected] or open an official Discord ticket. Identify the account and request, but do not send passwords, access tokens, or full card details. We may seek proportionate proof of ownership; if you have lost access to your sign-in method, contact us to discuss another way to verify the request. An authorized representative may act where the law permits. We aim to respond within 30 days and follow any shorter deadline or permitted extension under the applicable law, explaining an extension or refusal and available review or complaint routes.
We will not penalize you for using privacy rights. Deleting browser data or requesting account-data deletion does not by itself stop subscription billing. If you also want cancellation, clearly say so, use Cancel in the account menu where your subscription shows it, or cancel through Whop; a clear on-time request is treated under the Refund Policy. Necessary billing or dispute records may remain even after eligible account data is deleted.
Your Choices and Deletion Requests
- Sign out to remove active Kuraa authentication data from that browser.
- Clear the site's browser data or remove the extension to clear locally stored preferences.
- Unlink a partner-offer account where you linked it.
- Disconnect TikTok on the Upload page to delete the encrypted connection from Kuraa.
- Delete ticket messages or attachments in Discord where Discord permits; the website neither stores nor displays ticket conversations.
- Request deletion of eligible server-side account information, including your Community messages, using the contact details below. Some transaction, moderation, or security records may need to be retained where reasonably necessary.
A request to Kuraa can address data we control. It does not erase data independently held by Discord, Google, TikTok, Whop, other third-party providers or partners, your bank or your downloaded files; use those services' own controls where necessary. Withdrawing optional consent stops the corresponding future processing unless another lawful basis applies, without invalidating earlier lawful processing.
Security
Kuraa uses HTTPS for network communication, encrypted storage for TikTok tokens, signed sessions, access controls, rate limits, and other technical safeguards. No internet service can guarantee absolute security. If a breach affects your personal information, we will notify you and the authorities where the law requires it.
Children's Privacy
Kuraa is not intended for children under 13 or below a higher minimum age applicable to the service where they live. We do not knowingly collect their personal information. If we learn an ineligible child provided information, we will take steps to remove it, subject to any necessary legal or safety retention. Parents or guardians can contact us about a child's information. A minor's account does not prove valid parental permission or payment authorization.
Changes to This Policy
We update the date when this notice changes and provide appropriate notice of material changes. If a new use of information requires consent or another legal step, publishing an updated notice or continuing to use Kuraa does not substitute for that requirement. Changes do not retroactively authorize a use that was unlawful when it occurred.
Contact
Kuraa Method, operated from the Philippines, is the personal information controller for the information described in this policy. For privacy questions or data requests, email our data protection contact at [email protected] or contact staff through the official Discord community linked at tikhd.kuraagabut.com. General support stays at [email protected].
Tell us the account and what you need. Never send passwords, tokens or card details.
This policy applies to the Kuraa website, Discord bot, browser extension, and backend service. Third-party services maintain their own privacy practices.