Legal
Back to Kuraa

Kuraa Method / Legal

Privacy Policy

How Kuraa Method handles information across the website, Discord bot, browser extension and backend API, including Community, purchases and optional integrations such as TikTok.

Last Updated: October 11, 2026

About 19 min read

The short version

A summary only. The full policy below governs.

Selling your data
Never

Not to advertisers and not to data brokers.

Standard optimization
Header only

Kuraa receives the file's technical header, not your video. Optional features that need the whole video are off unless you turn them on.

TikTok post records
90 days

Then removed. You can disconnect TikTok at any time.

Your rights
Copy, fix, delete

Email [email protected]. We won't penalize you for asking.

Overview

This policy explains how Kuraa Method ("Kuraa Method", "Kuraa", "we", "us"), the app operated at tikhd.kuraagabut.com, handles information when you use the Kuraa Method website, Discord bot, browser extension, and backend at api.tikhd.kuraagabut.com. It also covers Community, purchases and optional integrations such as TikTok. What the Kuraa Check Chrome extension does on your device is described in detail in the Kuraa Check Extension Privacy Policy.

Kuraa Method, operated from the Philippines, is the personal information controller responsible for the Kuraa processing described here. Our data protection contact handles privacy questions and requests at [email protected]. This notice explains our practices; it does not require you to waive privacy rights or provide blanket consent. Optional permissions and any consent required by law are handled separately.

Video processing at a glance

  • Some optimizations run entirely on your device.
  • For standard optimization, your browser sends only the file's technical header to Kuraa and builds the optimized video on your device; the video itself is not uploaded.
  • When you post to TikTok, your browser uploads the video directly to TikTok after you confirm.
  • If you turn on an optional feature that needs the whole video, such as re-encoding, your browser sends the video to a third-party processing provider and downloads the result before Kuraa optimizes it.

Information We Process

1. Discord account and server information

When you sign in with Discord or use the Kuraa bot, we may process your Discord user ID, username, avatar, server membership, and Haze-related roles. We use this information to authenticate you, provide bot commands, determine your tier, grant or remove roles, and keep the website and Discord server in sync. Kuraa's OAuth flow does not request your Discord email address.

1a. Google sign-in and your Kuraa account

You can sign in with Google instead of, or as well as, Discord. Google sign-in asks only for your basic profile (openid, email, profile): we store Google's account identifier, your name, your profile picture link and your email address when Google has verified it, and use them only to sign you in and to show your account. We do not receive your Google password or access your other Google data. Every Kuraa account has an account ID (for an account created with Discord, this is your Discord user ID) and a username you choose, which other people may see where Kuraa shows who did something, such as in Community. Your credits, purchases and settings belong to the Kuraa account, whichever sign-in method you use; you can connect or remove a sign-in method from the account menu as long as one remains.

2. Discord bot activity

The bot processes the commands, buttons, and other interactions you send to it. Depending on the feature used, it stores information needed for Kuraa Credits, XP and levels, moderation and anti-abuse controls, sticky messages, server statistics, donation roles, and feature settings. Chat activity may earn XP, but it does not earn Kuraa Credits. When a feature depends on a Discord message event, the bot processes the message and channel identifiers and the content needed to perform that feature.

3. Purchases, subscriptions, and older payment tickets

Every purchase, including subscriptions and free trials, goes through our checkout partner Whop, which collects your payment details directly; Kuraa never receives your full card number. From Whop we receive and store the membership and payment identifiers, the plan, amount, currency, payment status, and trial, renewal and cancellation dates, linked to your Kuraa account ID. We also record each purchase agreement: your Kuraa account ID, the Terms and Refund Policy version you accepted, which checkout it was for, and when. We use these records to grant and renew paid plans, stop renewals when you cancel, allow one free trial per person, answer refund requests, and respond to payment disputes.

Before September 28, 2026, some payments were made directly to Kuraa through Discord payment tickets. For those tickets, we keep the ticket number, Discord account, selected payment method and amount, ticket status, associated Discord channel, staff decision, rejection reason when provided, and role expiry. Payment services may have provided Kuraa with a transaction identifier, amount, and payment status so we could prevent duplicate processing and grant the correct role. Where the website shows an older ticket, it shows only its status (number, payment method, amount, months and creation date), never the messages in the Discord ticket channel.

Messages, attachments and proofs you choose to send in a Discord support or payment ticket are processed through Discord and can be viewed by the staff handling it. We may keep information necessary to resolve the request or payment claim. Discord's own retention and permissions apply; deleting a channel or message does not necessarily remove an independently retained transaction record. Do not send passwords, full card details, or unrelated sensitive information.

4. Credits, usage, and account status

We store records used to operate the service, including your weekly and purchased Kuraa Credits, temporary processing reservations, detected resolution, frame rate and file-size pricing data, upload count, approximate MB saved, account restrictions, warnings, and paid-plan and role expiry dates. Weekly balances reset on a weekly schedule; lifetime totals may remain on the account record.

5. Video and media files

  • On-device optimizationProcessing occurs on your device. These videos are not uploaded to Kuraa for that stage.
  • Optional full-video features (off by default)When you turn on an optional feature that needs the whole video, such as re-encoding, your browser uploads the selected video directly to a third-party processing provider, which processes it and returns the result to your browser for the normal Kuraa optimization. Kuraa itself receives only a job identifier and its status, not the video. The provider keeps the files it processes under its own retention rules.
  • Standard optimizationYour browser sends Kuraa's API only the file's technical header (track layout, timing and sample tables, with no picture or sound) and receives instructions it uses to build the optimized file on your device; the video itself is not uploaded. That header can also hold details your camera or editing app embedded in the file, such as the recording time, device model or location; Kuraa uses the header only to build those instructions and does not store it. Kuraa keeps a fingerprint (hash) of the header with the record of your credit reservation, so an answer lost within the hour can be re-sent without charging you twice.
  • Recent optimized videosOnly if you turn on "Keep videos on this device" (it is off by default), the website stores the output file, filename, size and related processing information in your browser's IndexedDB so you can download it again or select it for upload. Turning the setting off deletes those saved videos. Your choice is stored in your browser (localStorage key haze_keep_videos). Saved entries expire after 3 days and are removed during cache cleanup when the cache is used. The cache holds at most 20 files and 500 MiB; older entries may be evicted sooner and browser storage may be cleared. Signing out does not necessarily erase saved videos. Turn the setting off or clear site data to remove them, and keep your own backups.
  • Posting to TikTokAfter you confirm a post, your browser uploads the video directly to TikTok. Kuraa sends TikTok the caption, privacy and interaction settings you choose, and stores the publish ID, caption, privacy setting, status, failure reason and public post ID for status history. The retention window is 90 days; older records are removed during database cleanup when new post records are stored.
  • Video checkingIf you submit a TikTok URL for analysis, the backend processes the link, publicly available video and creator details, and technical measurements needed to return the result. These records are distinct from your optional TikTok OAuth connection. To show whether TikTok is limiting a video's reach (the "Shadowban" line), your browser also sends the TikTok link you entered directly to a third-party video information provider that reads public TikTok post data. That request carries no Kuraa account details or cookies; the provider receives the link and ordinary request data such as your IP address under its own terms.

We do not use submitted videos to train models, advertise to you, or build advertising profiles.

6. TikTok connection (Login Kit & Content Posting API)

Connecting TikTok is optional and uses its official OAuth Login Kit. With user.info.basic, we retrieve your display name and profile picture to identify the connected account. We store access and refresh tokens encrypted, associate them with your Kuraa account or a random anonymous ID stored in your browser, and refresh them as needed. When you confirm publishing, video.publish is used for the video and settings you select, with a direct upload to TikTok. These permissions are not used to publish without your action.

You can disconnect on the Upload page to delete the saved tokens from Kuraa, or revoke permissions in your TikTok account. Revoking at TikTok prevents further authorized use but does not itself guarantee immediate deletion of our stored record; contact us if you also need deletion. Clearing site data can lose access to an anonymous connection, so disconnect first or revoke at TikTok and contact us with enough information to identify it. Never send us a token as proof. Disconnecting does not delete an already published TikTok post or automatically erase status history; request eligible record deletion separately.

Connection and publishing data are processed only for the purposes described here and shared with TikTok and the infrastructure needed to provide the feature. TikTok applies its own privacy policy to information it receives.

7. Security, analytics and technical information

The website sends limited operational measurements to our hosting logs: app version, page category, operation category, duration, and success or failure. Performance measurements are sampled. These event payloads exclude account identifiers, tokens, video contents, filenames, captions, full URLs, and error messages. This reporting honors browser Do Not Track and Global Privacy Control signals and is capped per page session.

Separately, the website uses a privacy-focused web analytics service to measure traffic and page use. It uses request-derived anonymous visitor measurements without analytics cookies, and may process the page path, referring site, device or browser characteristics, and approximate region. Kuraa removes query strings, including query strings embedded in route hashes, before sending page URLs so sign-in callback tokens are not included. This analytics path is separate from the operational reporting above; the operational reporting's Do Not Track and Global Privacy Control gate should not be understood as a site-wide analytics opt-out. Where applicable law requires consent or an opt-out for particular processing, those requirements apply.

Kuraa does not place advertising cookies or advertising pixels on its pages, and does not share your activity on Kuraa with advertising networks.

When you use Kuraa, we process normal request information such as IP address, timestamps, request metadata, and rate-limit events. For multi-account and abuse detection, we may also store a browser-generated device identifier, hashed identifiers, linked account IDs, detection outcomes, warnings, and termination status. These checks can restrict an account automatically. If that happens to you, contact us and a person will review the decision.

8. Information stored on your device

The website and extension store session details, basic profile and tier data, credit balances, feature preferences, and interface settings using cookies, local storage, or extension storage. Signing out clears Kuraa authentication data from the active browser. The extension's optional TikTok repair action deletes the ttwid cookie when you ask it to; it does not transmit that cookie's value to Kuraa.

Local storage also supports language choice, onboarding preferences, anonymous TikTok ownership and recent optimized files. Some storage is necessary for the features you request; clearing it may sign you out, reset preferences or remove access to an anonymous connection. A cookie or local identifier is not proof that a particular individual authorized a payment.

9. Community

When you post in Community, your message, your username and your badge at that moment are shown publicly to anyone who visits the page, and stored with the time you sent it. If you share a Kuraa check, the result of that check (the TikTok handle, resolution, frame rate and verdict) is stored with your message. Moderators can delete messages and limit who can post. Deleted messages are hidden right away and kept for 30 days so reports can be reviewed, then removed. Anything you post publicly can be seen, and copied, by other visitors, so do not share private information there.

10. Partner offers

Some offers give extra credits for subscribing to a partner's Telegram channel. If you link a Telegram account for such an offer, we store the Telegram user ID you enter with your Kuraa account, whether the partner reports it as subscribed, and when it was linked and last checked. To confirm the offer, we send that ID to the partner to ask whether it is subscribed; the partner answers yes or no and receives no other Kuraa account information from us. You can unlink at any time where you linked it, or ask us to remove the link. The partner keeps its own subscriber records under its own policy.

Discord Privileged Intents and Your Controls

The Kuraa bot uses one Discord privileged gateway intent, Server Members. This section describes what it is used for and the controls available to you. Message-content features (such as info commands and link moderation) are provided by a separate companion bot.

Server Members

Used to welcome new members, log departures for moderators, and keep your Kuraa tier in sync when donation or booster roles change. As described above, we store your Discord user ID, assigned tier, and role expiry off-platform; this is required to grant your perks.

How We Use Information

  • Authenticate users and synchronize Discord roles and Kuraa tiers
  • Operate the website, Discord bot, optimizer, Community, ticket system, economy, and usage limits
  • Process payments and grant time-limited roles or bought credits
  • Carry out video processing and publishing actions you request
  • Measure site traffic and reliability in aggregate
  • Run promotions and partner offers you choose to take part in
  • Provide support, diagnose failures, secure the service, moderate Community, rate-limit requests, and prevent abuse

We do not sell personal information or share it with advertisers or data brokers.

Retention

Information Typical retention
On-device videos and recent-output cacheOriginal and downloaded files remain on your device. Optimized videos are kept on your device only if you turn on "Keep videos on this device" (off by default); turning it off deletes them. Saved outputs expire after 3 days and are removed during cache use/cleanup; browser storage can be cleared sooner.
Optional full-video processing jobsKuraa keeps a job identifier, your account ID, the job's status and its times for a short period, so each job runs once and usage limits can be applied, then removes them. The video itself is handled by the processing provider under its own retention.
Standard optimization headers and resultsKuraa uses the header only to build the instructions and does not store it; the credit/job record keeps a fingerprint (hash) of the header. Results are built on your device and never reach Kuraa's servers.
Older payment-ticket recordsAs long as needed for accounting, refund and dispute purposes, like other payment records
TikTok connection tokensUntil deleted through Kuraa disconnect or an applicable deletion request; expired or revoked permissions may prevent use before the stored record is deleted.
Community messagesShown publicly while they remain in the room. Deleted messages are hidden right away and kept for 30 days for report review, then removed.
TikTok post records90-day retention window, with older records removed during post-record storage cleanup.
Partner-offer linksUntil you unlink or ask us to remove the link, or the offer ends, plus any period needed to resolve a dispute about a bonus.
Payment, subscription, trial, and policy-acceptance recordsAs long as needed for accounting, tax, refund, and dispute purposes, and as the law requires, even after you stop using Kuraa
Account, credit, economy, role, and security recordsWhile needed to operate the account, enforce limits, resolve payments, secure Kuraa, or meet applicable obligations

We retain only what is reasonably necessary for the stated purpose or a legal obligation, and review retention when resolving deletion requests. Records needed for accounting, a pending dispute, fraud investigation or legal claim may remain restricted rather than immediately erased. Different records and backups may have different removal schedules; we do not promise every copy disappears instantly. We will explain a relevant retention exception when responding to your request.

When Information Is Shared

Information is shared only as needed to provide a feature you use. We name the services you choose or see; we describe other providers by their role, and may change them without changing this policy when the change does not reduce your protections.

  • Discordfor sign-in, server membership and roles, bot interactions, ticket channels, and related Discord features.
  • Googlewhen you sign in with Google, Google confirms your identity to us; we send Google nothing beyond the sign-in request.
  • TikTokonly when you connect or post to TikTok. TikTok's own terms and privacy policy apply to its processing.
  • Payment providers and storesWhop and the payment method selected at checkout process information you provide directly to them under their own notices. Checkout metadata includes your Kuraa account ID, purchase type, relevant plan or trial details, and accepted agreement version so payment and access can be attributed correctly. Providers return transaction and membership information to Kuraa. Records of payments made directly to Kuraa before September 28, 2026 remain subject to the retention rules above. For a dispute, we may provide proportionate agreement, payment, cancellation, entitlement and usage evidence to the provider or issuer; this does not mean sharing your video file.
  • Hosting, security and analytics providersreceive the data needed to host, secure, measure and operate the website and API. Hosting request logs may include ordinary network information even where a custom event payload excludes it.
  • Font providersome public pages load fonts from a third-party font service, which receives normal web-request information such as your IP address.
  • Processing providersonly when you turn on an optional feature that needs the whole video; your browser sends that video to the provider before Kuraa optimizes it.
  • Video information providerswhen you check a video, your browser sends the TikTok link you entered to a provider that reads public TikTok post data, to show whether TikTok is limiting that post's reach. The provider receives the link and normal web-request information such as your IP address, not your Kuraa account.
  • Partnersonly when you link an account for a partner offer: the linked ID, to confirm the offer (section 10).
  • The publicmessages you post in Community, with your username and badge, are visible to anyone who opens the page.

Authorized staff and the Community moderators we appoint may access information needed for support, moderation, payments and security. We may disclose relevant information for a lawful request or to establish, exercise or defend a legal claim, using only what is reasonably necessary. A business transfer may involve service records, subject to applicable safeguards and notice requirements. We do not publish private support or payment evidence as a response to a refund claim.

International Transfers

Kuraa is operated from the Philippines. Hosting, database, payment and connected-service providers may process information in the United States and other countries with different privacy laws. Where applicable law requires a transfer mechanism or safeguards, we must use the applicable protections, such as appropriate contractual safeguards or a recognized lawful transfer basis. Contact us for information about safeguards relevant to your data; this notice is not itself a claim that every destination has equivalent laws.

Your Rights

Depending on where you live, including under the Philippine Data Privacy Act of 2012, the GDPR in the EU and UK, and US state privacy laws, you may have the right to:

  • Know

    be told how your information is used (this policy);

  • Get a copy

    get a copy of the information we hold about you, in a portable format;

  • Correct

    correct information that is wrong or incomplete;

  • Delete or restrict

    have information deleted or blocked, or object to or restrict how we use it;

  • Withdraw consent

    withdraw consent you gave, without affecting what we did before; and

  • Complain

    complain to a data-protection authority — in the Philippines, the National Privacy Commission (privacy.gov.ph).

Email [email protected] or open an official Discord ticket. Identify the account and request, but do not send passwords, access tokens, or full card details. We may seek proportionate proof of ownership; if you have lost access to your sign-in method, contact us to discuss another way to verify the request. An authorized representative may act where the law permits. We aim to respond within 30 days and follow any shorter deadline or permitted extension under the applicable law, explaining an extension or refusal and available review or complaint routes.

We will not penalize you for using privacy rights. Deleting browser data or requesting account-data deletion does not by itself stop subscription billing. If you also want cancellation, clearly say so, use Cancel in the account menu where your subscription shows it, or cancel through Whop; a clear on-time request is treated under the Refund Policy. Necessary billing or dispute records may remain even after eligible account data is deleted.

Your Choices and Deletion Requests

  • Sign out to remove active Kuraa authentication data from that browser.
  • Clear the site's browser data or remove the extension to clear locally stored preferences.
  • Unlink a partner-offer account where you linked it.
  • Disconnect TikTok on the Upload page to delete the encrypted connection from Kuraa.
  • Delete ticket messages or attachments in Discord where Discord permits; the website neither stores nor displays ticket conversations.
  • Request deletion of eligible server-side account information, including your Community messages, using the contact details below. Some transaction, moderation, or security records may need to be retained where reasonably necessary.

A request to Kuraa can address data we control. It does not erase data independently held by Discord, Google, TikTok, Whop, other third-party providers or partners, your bank or your downloaded files; use those services' own controls where necessary. Withdrawing optional consent stops the corresponding future processing unless another lawful basis applies, without invalidating earlier lawful processing.

Security

Kuraa uses HTTPS for network communication, encrypted storage for TikTok tokens, signed sessions, access controls, rate limits, and other technical safeguards. No internet service can guarantee absolute security. If a breach affects your personal information, we will notify you and the authorities where the law requires it.

Children's Privacy

Kuraa is not intended for children under 13 or below a higher minimum age applicable to the service where they live. We do not knowingly collect their personal information. If we learn an ineligible child provided information, we will take steps to remove it, subject to any necessary legal or safety retention. Parents or guardians can contact us about a child's information. A minor's account does not prove valid parental permission or payment authorization.

Changes to This Policy

We update the date when this notice changes and provide appropriate notice of material changes. If a new use of information requires consent or another legal step, publishing an updated notice or continuing to use Kuraa does not substitute for that requirement. Changes do not retroactively authorize a use that was unlawful when it occurred.

Contact

Kuraa Method, operated from the Philippines, is the personal information controller for the information described in this policy. For privacy questions or data requests, email our data protection contact at [email protected] or contact staff through the official Discord community linked at tikhd.kuraagabut.com. General support stays at [email protected].

Make a privacy request

Tell us the account and what you need. Never send passwords, tokens or card details.

This policy applies to the Kuraa website, Discord bot, browser extension, and backend service. Third-party services maintain their own privacy practices.