Skip to content
KronX
FeaturesExchanges & NetworksSecurityPricingHow to UseFAQ
TREN
Download the app
Security

Your report is ready, your data is protected.

KronX only reads. It never trades or withdraws on your behalf. This page explains where your data lives and how it is protected, limits included.

Locked glass shield

Read-only exchange connections

To connect an exchange, an API key with read permission is all you need. No trading, transfer or withdrawal permission is required. KronX never sends order or withdrawal requests; it only reads balances and executed trades.

  • On Binance, Bybit, Bybit TR, OKX, OKX TR and Coinbase, the key's permissions are checked with the exchange when you connect, and again once a day.
  • If withdrawal, trading or transfer permission is turned on, the app warns you and suggests switching it off at the exchange.
  • On exchanges that don't report key permissions, the app tells you so and asks you to confirm in the exchange's settings that withdrawals are disabled.

Give your key read-only permission; KronX sees your balances and trade history but cannot make any transactions.

KronX can't touch your assets. It just keeps the books.

How are your API keys protected?

Your API keys are stored with several layers of protection and used only to read data from your exchange. Even when the app is closed, your trades are fetched from the exchange automatically every 2, 4 or 12 hours.

  • Encrypted storage: Your key is encrypted with AES-GCM on our servers. The encrypted record is bound to your account, ledger and exchange; even if it were copied elsewhere, it could not be opened.
  • Never shown again: Once saved, your key is never sent back in any response; the app only shows a masked version.
  • Permission check: When you add a key, its permissions are checked with the exchange. If withdrawal or trading is enabled, the app warns you, and the check repeats every day.
  • Protected connection server: Exchange requests go out from our own server with a fixed IP address. Only KronX can connect to it, using an encrypted certificate. The server only contacts approved exchange addresses and does not log request contents.
  • Secure IP addresses: KronX gives you secure, fixed IP addresses for exchange connections. If you restrict your API key to these addresses on your exchange, it cannot be used from anywhere else. The addresses are shown in the "Trusted IP" field on the app's add-key screen.
  • Abuse protection: Each account's exchange requests are rate-limited.
  • One ledger per key: The same API key cannot be linked to two different ledgers.
  • You stay in control: You can revoke a key on your exchange or remove it from the app at any time. If you delete your account, your keys are deleted from the server too.

No wallet permissions needed

You don't need to connect your wallet, sign a transaction or grant any permission. Just enter your public address; KronX reads your balances and activity directly from the blockchain.

  • Never asks for private keys or recovery phrases: KronX never asks for your private key, recovery phrase (seed phrase) or password.
  • No connection, no signatures: No wallet-connect window opens and nothing is signed, so not a single transaction can be started from your wallet.
  • Public information only: A wallet address is already public on the blockchain. KronX only reads the balances and activity anyone can see.
  • Network detected automatically: When you paste an address, its network is recognized from its format, so you never pick the wrong one.
  • Spam token filter: Worthless or look-alike tokens sent to your wallet are filtered out automatically and don't inflate your portfolio.
  • You stay in control: You can remove a wallet at any time. If you delete your account, your addresses are deleted from the server too.

End-to-end encrypted ledger sync

Instead of an account or email, your devices are linked with a 25-character sync code. Two separate values are derived from it:

Encryption key

Stays on your device. Your ledger is encrypted with it using AES-GCM before it goes to the server.

Access ID

Sent to the server and used only to find your encrypted package. The decryption key cannot be derived from it.

The sync code is kept in the Keychain on iPhone and iPad, and in Keystore-protected storage on Android.

Your sync code is the key to your ledger, so nobody, including us, can access your encrypted ledger on the server. If you lose your code and the records on your device are also deleted, you will need to reconnect your exchanges and wallets and re-enter any transactions you added manually. Keep your code somewhere safe and make regular file backups with Settings → Back up.

Where your data lives

In short: Your ledger is synced with end-to-end encryption. The information needed to read your exchange and wallet data is processed securely on our servers; it is not end-to-end encrypted.

  • On your device: your ledger (transactions and asset list), recent prices and preferences.
  • On the server, end-to-end encrypted: your synced ledger and its monthly backups. The server cannot open this package.
  • On the server, encrypted with a server key: your exchange API keys.
  • Processed on the server, unencrypted: trades and balances pulled from exchanges, your wallet addresses and their activity, your price alerts and your notification registration are not end-to-end encrypted. These are needed for calculations, scheduled reads and alerts.

We don't collect your name, email, phone number, location, contacts or advertising ID. The app contains no advertising, analytics or crash-reporting tools. Your IP address is used only to prevent abuse and enforce request limits.

Wallet balances are looked up with data providers for the relevant network. Notifications are delivered through Firebase on Android and Apple's notification service on iPhone.

You can delete everything on the server from inside the app: Settings → Sync (Connect devices) → Delete all my data on the server. Deletion is permanent and immediate. Details are in the Privacy Policy.

App lock

You can lock the app with a 6-digit code, and use fingerprint or face unlock where your device supports it. The code is never stored as plain text.

The app lock stops someone from seeing your portfolio if you leave your phone unlocked. It does not encrypt data on the device and is not a substitute for your device's own lock.

Payment security

Subscriptions are sold only through the App Store and Google Play. Your payment and card details stay with Apple or Google and never reach KronX. This website takes no payments and never asks for card details.

KronX will never ask you by email for an API secret, a wallet private key, a recovery phrase or card details.

Start with a read-only connection.

Free for 7 days.

Download the app