Privacy Policy
Last updated: 7 July 2026
Chronio ("we", "us", "our") is a time-tracking and planning app operated from Ireland. This policy explains what personal data we collect, why, who we share it with, and the rights you have over it under the EU General Data Protection Regulation (GDPR) and Ireland's Data Protection Act 2018. It applies to chronioapp.com, the Chronio web app, and the Chronio browser extension.
Contents
1. Information we collect
Account information
When you register, we collect your email address and a hashed password (we never store your password in plain text). You can optionally add a name, avatar, bio, and timezone in your profile.
Content you create
Using Chronio necessarily involves storing the content you create: your Pillars, Goals, Activities, time entries, weekly plans, Library resources (including any notes, ratings, or reflections you write), and achievement/streak statistics. This is the core data the app exists to hold, and it's yours — see Your rights below for exporting or deleting it.
Optional AI features
If you use AI-assisted planning, the goal or focus-area text involved is sent to our AI provider (OpenAI) to generate suggestions. If you use the optional voice activity log, your voice recording is sent to OpenAI's transcription service to convert it to text, which is then used to draft time entries for you. We only use these recordings and transcripts to provide that feature.
Third-party connections you choose to enable
Chronio integrates with Notion and Trello, but only if you actively connect your account. If you do:
- We store an access token so we can act on your behalf, protected with access controls and, where technically applied, encryption at rest.
- For Notion, we store your workspace ID/name and the page you set as a default — content you explicitly link or create (e.g. a resource's notes) is sent to Notion.
- For Trello, when you push a weekly plan, we send board, list, and card content (goal/task names, descriptions, and checklist items drawn from your library) to Trello.
Disconnecting an integration in Settings removes the stored token.
Technical & usage data
We log IP address, browser/device type, and login timestamps for security and to keep you signed in (see Cookies). Session records expire automatically.
Messages you send us
If you contact us through the form on our site, we (and our form provider, Formspree) receive whatever you submit — typically your email address and message — so we can respond.
2. How we use your information
- To provide the core service: storing and displaying your tracked time, plans, and goals.
- To authenticate you and keep your account secure.
- To power optional features you turn on: AI planning assistance, voice-to-entry conversion, and Notion/Trello sync.
- To respond to support requests and messages you send us.
- With your consent, to understand aggregate product usage via analytics (see Cookies).
We do not sell your personal data, and we do not currently run advertising or send you marketing email. Chronio has no paid plan yet, so we don't collect any payment or billing information.
3. Our legal bases for processing
Under GDPR Article 6, we rely on:
- Contract — processing your account and content data is necessary to provide the service you signed up for.
- Consent — for analytics cookies, and for any optional AI feature you choose to use (voice logging, AI planning assistance).
- Legitimate interests — for basic security logging (e.g. detecting abuse) and improving the product, balanced against your right to privacy.
4. Who we share data with
We use a small number of vendors ("subprocessors") to run Chronio. We share only what's necessary for each to do its job:
| Vendor | Purpose | What they see |
|---|---|---|
| Amazon Web Services (Elastic Beanstalk) | Hosts our application servers (EU — Ireland region) | All data passing through the app, as our infrastructure provider |
| MongoDB Atlas | Database hosting (EU — Ireland region) | All stored account and content data |
| Google (Firebase Hosting) | Hosts the web app's static files | Standard web request/connection data |
| Google Analytics (GA4) | Product usage analytics — only after you accept analytics cookies | Page views and aggregate usage patterns |
| Google Custom Search | Powers learning-resource search suggestions | Your search query text (not your account identity) |
| OpenAI | AI planning assistance and voice-note transcription | Goal/planning text you submit, and voice recordings if you use that feature |
| Notion | Two-way library/notes sync — only if you connect it | Page titles/content you link or create via Chronio |
| Trello | Push weekly plans to a board — only if you connect it | Board/card/checklist content generated from your plan |
| Formspree | Delivers messages from our contact form | Your email address and message text |
We may also disclose information if required by law, or to protect the rights, property, or safety of Chronio, our users, or others.
5. International data transfers
Our application servers and database both run in the EU (Ireland). Some vendors we rely on — including OpenAI, Google, and Formspree — are based in or process data in the United States. Where data leaves the EEA, we rely on the safeguards those providers make available, such as the EU–U.S. Data Privacy Framework or Standard Contractual Clauses.
6. Cookies
We use two categories of cookies:
- Strictly necessary — a secure, HTTP-only session cookie that keeps you logged in. This can't be switched off, since the app can't function without it.
- Analytics (optional) — Google Analytics cookies, only set after you accept them in the cookie banner. You can change your mind at any time via the "Cookie settings" link in the footer.
7. How long we keep data
We keep your account and content data for as long as your account is active. Session records expire and are automatically deleted after 30 days (90 days if you chose "Remember me"). If you delete a Pillar, Goal, or Library resource yourself, its dependent data (time entries, tasks, etc.) is deleted along with it. If you request full account deletion (see below), we delete your account and associated content within one month.
8. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data — most profile and content fields can be edited directly in the app.
- Export your data — Chronio has a built-in Excel export for your time-tracking reports, available in the app.
- Erase your data ("right to be forgotten").
- Restrict or object to certain processing.
- Withdraw consent at any time (e.g. for analytics cookies or AI features), without affecting processing done before withdrawal.
- Lodge a complaint with Ireland's Data Protection Commission (DPC) at dataprotection.ie, or your local supervisory authority.
You can delete individual Pillars, Goals, time entries, and Library resources yourself at any time in the app. For full account deletion, or any other rights request, use the contact form linked in the footer — we'll act on it within one month, as required by law.
9. Children's privacy
Chronio is not directed at, and we do not knowingly collect data from, anyone under 16 years old — the age of digital consent under Ireland's Data Protection Act 2018. If you believe a child has provided us with personal data, please contact us and we'll delete it.
10. Security
We apply industry-standard measures to protect your data, including password hashing, encrypted credential storage for supported integrations, and encrypted (HTTPS) connections throughout. No system is 100% secure, but we take reasonable steps to protect your information and will notify you and the DPC of any breach as required by law.
11. Changes to this policy
We may update this policy as Chronio evolves — for example, if we introduce billing or new integrations. We'll update the "Last updated" date above, and for material changes we'll make a reasonable effort to let you know in the app.
12. Contact us
For any question about this policy, or to exercise your rights above, please use the contact form linked in the footer of this site.