Kruna
Privacy policy

What we hold, and why.

The full list of what Kruna collects, who it goes to and what you can ask us to do with it. No dark patterns, no ad tracking.

Last updated 4 September 2026

This policy covers kruna.gg. If you want any of it acted on — a copy of your data, a correction, a deletion — email support@kruna.gg and it goes to a person, not a queue.

What we collect

Four kinds of data, and nothing beyond them.

Account data. Whatever your sign-in method hands us: an email address, a Google account identifier, a wallet address, or a Telegram account. Authentication runs through our sign-in provider, so we receive an identifier and the contact detail attached to it — we never see a password, a seed phrase or a private key.

Purchase and order data. Top-ups, withdrawals, balance changes, every pack you open, the seeds and nonce behind each open, and the items in your inventory. This is the ledger; it is the record that lets you verify your own results.

Technical data. IP address, approximate country, browser and device type, and server logs of the requests you make. Errors are recorded through our monitoring provider so we can fix them.

Correspondence. Anything you send us in a support email, and our replies.

Why we use it

Every use maps to something you asked for or something we must do.

  • To run your account and show your balance, inventory and history.
  • To move money — crediting deposits and paying out withdrawals through our payment partners.
  • To keep the provably-fair record intact, so any open can be checked afterwards.
  • To detect and stop fraud, multi-accounting, chargeback abuse and money laundering, and to meet the legal obligations that come with handling payments.
  • To answer your support messages.
  • To keep the site working and to see, in aggregate, which parts of it are used. We do not build advertising profiles and we do not sell data.

Our legal basis

For anyone covered by the GDPR or a law modelled on it.

  • Performance of a contract — running your account, fulfilling your orders, and paying out withdrawals.
  • Legal obligation — financial records, anti-money-laundering and age checks.
  • Legitimate interests — security, fraud prevention, and keeping the service stable. We weigh these against your interests, and you can object.
  • Consent — for anything optional, which you can withdraw at any time.

Who else sees it

Only the services that make the shop work.

We use outside companies for the parts of Kruna we do not build ourselves: signing you in, processing payments, hosting the site and its database, sending your receipts, and monitoring errors. Each receives only the data it needs for that job, is bound by contract to use it for nothing else, and cannot pass it on.

We do not sell your data. We do not share it with advertisers or data brokers, and we do not use it to build a profile for anyone but you.

We will disclose data where a law, a court or a regulator requires it. If the business is ever sold, this policy travels with it.

Want the current list of companies by name? Email support@kruna.gg and we will send it.

Where it is held

In Europe, by default.

Our database, cache and application run in EU regions. Some of the companies we use process data outside the EU; where they do, transfers rely on the European Commission’s standard contractual clauses or an adequacy decision.

How long we keep it

As long as your account, plus what the law demands after.

Account, inventory and order data lives as long as your account does.

Transaction records — deposits, withdrawals, and the checks around them — are kept for the period financial and anti-money-laundering law requires after your account closes, typically five years. We cannot delete these earlier, even on request.

Server and error logs are kept for a short operational window and then discarded.

Provably-fair records are kept for as long as your account exists, because deleting them would destroy your ability to verify past opens.

Your rights

Email support@kruna.gg and we will action any of these.

  • Get a copy of the data we hold about you, in a portable format.
  • Correct anything that is wrong.
  • Have your data deleted, except the records we are legally required to keep.
  • Object to, or ask us to restrict, a use based on legitimate interests.
  • Withdraw a consent you gave, without that affecting what was done before.
  • Complain to your national data protection authority. We would rather you came to us first, but the right is yours either way.

Cookies

Essential only.

We set the cookies needed to keep you signed in and to remember a small number of interface preferences. That is the whole list — there are no advertising cookies, no third-party trackers and no cross-site pixels, which is also why you are not being asked to dismiss a consent banner.

Security

What we do, and what is on you.

Traffic is encrypted in transit. Card details never touch our servers — card payments run on our provider’s hosted checkout. We never hold private keys or seed phrases, and we will never ask for one.

No system is perfect. If a breach ever affects your data, we will tell you and the relevant authority within the time the law sets.

On your side: keep control of the inbox, wallet or Telegram account you sign in with. Whoever holds that holds the account.

Under-18s

Kruna is for adults.

We do not knowingly collect data from anyone under 18. If we find an underage account we close it and delete the data, keeping only what we must to record that we did so. If you believe a minor is using Kruna, email support@kruna.gg.

Anything unclear?

These pages are meant to be read, not survived. If a clause is confusing, tell us and we will rewrite it.

Email us

Questions & answers