Privacy Policy
Draft last updated: August 10, 2026
1. Controller and contact details
The data controller for Chronify is TODO: legal entity name, of TODO: registered address. Contact: TODO: privacy contact email or postal address. Data protection officer: TODO: state whether a DPO is appointed and provide contact details, if applicable.
2. Information we collect
Chronify collects information you provide or choose to capture when you use the website and browser extension, including:
- Account information: name, email address, password hash, account preferences, verification status, and subscription status.
- Captured content: text conversations and transcripts from AI platforms (such as ChatGPT, Gemini, and Claude) that you explicitly choose to capture and save.
- Case content: case details, messages, documents, folders, tags, events, deadlines, and document metadata.
- Integration and storage settings: connected service configuration, calendar data selected for synchronisation, and user-selected storage-provider configuration.
- Authentication information: the browser extension stores its API-key copy locally in your browser's secure storage; the service keeps the corresponding account credential to authenticate requests to your Chronify account.
- Billing identifiers supplied by Stripe when you subscribe.
3. How we use information and our lawful bases
- Provide the account, Case Manager, capture, storage, export, and support features: performance of a contract with you (or steps at your request before entering one).
- Process subscriptions, invoices, and billing support: performance of a contract and compliance with applicable legal obligations.
- Protect the service, authenticate requests, prevent misuse, and maintain security: our legitimate interests in operating a secure and reliable service.
- Optional AI summaries, deadline extraction, and connected-service features: performance of the feature you request; where consent is required by applicable law, your consent.
- Respond to legal claims or mandatory retention requirements: compliance with a legal obligation and/or our legitimate interests in establishing, exercising, or defending legal claims.
4. Recipients and processors
We do not sell your personal data. The code can send data to the following recipients when the related feature is enabled or used:
- Google: Google Cloud hosts the configured application, Firestore database, and managed Cloud Storage. Google OAuth, Drive, Calendar, and Gemini may also receive the data necessary for a feature you connect or request.
- Cloudflare: Cloudflare R2 may store files, and Cloudflare's AI Gateway/Workers AI may receive prompts and content for a requested AI feature.
- Stripe: subscription and billing identifiers needed to provide paid services.
- Resend: email address and email content for verification, account, and deadline-alert messages.
- Microsoft: selected Microsoft Calendar data where you connect and synchronise that calendar.
- Notion and Google Drive: content you explicitly export to those services.
- Configured AI provider: depending on configuration, Gemini, Cloudflare Workers AI, OpenAI-compatible providers (including OpenAI, Qwen, OpenRouter, or a custom endpoint), or Anthropic may receive the prompt and content required to generate a requested result.
- User-selected storage: a Cloudflare R2, S3-compatible, or local-vault provider that you configure may receive stored files.
TODO: legal review must confirm the production processor list, contracts, and data-processing terms before publication.
5. International transfers
The deployment configuration in this codebase places Google Cloud Run, Firestore, and the managed Google Cloud Storage bucket in us-central1. Other configured providers may process data in locations they select or you configure. TODO: confirm every transfer destination and the applicable UK GDPR transfer safeguard (for example, an adequacy regulation, the UK International Data Transfer Agreement, or the UK Addendum) before publication.
6. Retention
The application code does not define a general retention schedule. Account, case, conversation, document, and related data remain available until you delete them or we need to retain limited information for a legal obligation or legal claim. TODO: define and approve specific retention periods, backup deletion timing, and any exceptions before publication.
7. Your UK GDPR rights
Subject to the conditions and limits in UK GDPR, you may have rights to:
- be informed about processing and request access to your personal data;
- request correction of inaccurate personal data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests or direct marketing;
- receive portable personal data and ask us to transmit it where technically feasible;
- withdraw consent where processing relies on consent; and
- not be subject to a solely automated decision with legal or similarly significant effects, where applicable.
You can download your data from Account Settings or delete your account from Account Settings. For other requests, use TODO: privacy contact method. We may need to verify your identity before responding.
8. Complaints
You may complain to the UK supervisory authority, the Information Commissioner's Office (ICO), via the ICO complaint route. We would also welcome the opportunity to address your concern first using the contact details above.