Last updated: September 23, 2026
cronolog. is a time-tracking app. This page says exactly what we collect, the legal ground we rely on for each thing, how long we keep it, who else sees it, and what you can demand from us. It is written to satisfy the Brazilian LGPD (Lei 13.709/2018) and the European GDPR, whichever applies to you.
cronolog. is operated by an individual as a personal project — there is no separate company and no appointed Data Protection Officer. For privacy requests this page doesn't already handle in-app (export, correction, deletion — see section 10), write to contato@cronolog.net. We answer any request within 15 days (LGPD) or 30 days (GDPR).
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Account — email, display name, and the name/email Google shares if you use Google sign-in | To create and secure your account and sync your data between devices | Performance of a contract (LGPD art. 7 V / GDPR art. 6(1)(b)) | Until you delete your account |
| Activity data — activities, sessions and their descriptions, to-dos, goals and theme | It is the product. Stored on your device and, if signed in, in your account. Your island layout stays on this device only and is never uploaded | Performance of a contract | Until you delete it or your account |
| Group data — display name, your total tracked time for that group's activity, chat messages | To rank a shared leaderboard you chose to join | Consent, given by joining the group (withdrawable by leaving it) | Until you leave the group or delete your account |
| Device identifier — a random string generated in your browser | To tell your own devices apart when syncing a running timer | Legitimate interest in a working sync (GDPR art. 6(1)(f)) | Until you clear the app's storage |
| Usage measurement — daily totals: visits, time in app, time per tab, device type, browser language, referring site | To see which parts of the app are actually used and where to spend effort | Consent — nothing is measured until you accept | Aggregated daily; raw rows removed after 400 days |
| Advertising data — cookies and identifiers set by our ad partner | To show and measure ads, which is what keeps the app free | Consent — no ad script loads until you accept | Set by the partner; see section 5 |
| Subscription (AI Pro only): plan status, renewal date, and the customer and subscription ids Paddle gives us | To turn the plan on and off and let you manage it. Your card and billing address go to Paddle, never to us | Performance of a contract | While subscribed, then 5 years for tax records |
| Connected calendars (only if you connect one): event titles, times and the access tokens that let us read them | To draw your appointments in the Planner and, if you ask, add an event you created here | Consent, given when you connect (withdrawable by disconnecting) | Until you disconnect; events are deleted with the link |
| AI requests (AI Pro only): your question and a short summary of your tracked time built on your device | To answer the question | Performance of a contract | Not stored by us; only a daily count of requests is kept for cost limits |
We do not profile you, and no decision affecting you is made automatically. We do not collect your precise location, your contacts, or anything from other apps.
If you use cronolog. as a guest without an account, your data stays in your browser and is never sent to us at all.
We use your browser's local storage and a sign-in cookie. These are strictly necessary: they hold your sessions so the app works offline, and they remember your privacy choice so we don't ask again. They are not used for tracking and are not shared. Measurement and advertising storage is separate and only ever written after you consent.
The banner on first visit is a real choice — declining costs you nothing and the app behaves identically. You can change or withdraw that choice at any time in Account → Data & privacy → Privacy choices. Withdrawal takes effect immediately and does not affect processing that already happened.
Today ads appear only on the help pages (/ajuda), served by Google AdSense, and only after you accept ads in the banner. Before that, not even the AdSense script is fetched. The Free plan may later show ads beside the timer; AI Pro never shows ads.
If we move to Ezoic, it which places ads through its own network of demand partners (Google among them) and runs its own consent platform. No ad script of any kind is loaded until you accept ads in our banner — not Ezoic's, not any partner's — and every one of them stops loading the moment you withdraw that consent from Account → Data & privacy. Ads never appear on the timer screen, in full-screen focus mode, or in the mini-timer.
You can read Ezoic's privacy policy, opt out of the industry-wide personalisation programmes its partners take part in at optout.aboutads.info, and control the personalised ads Google shows you at adssettings.google.com. Your activity data — what you tracked, when, and for how long — is never shared with advertisers.
AI Pro is sold through Paddle (Paddle.com Market Ltd), which acts as our reseller and merchant of record: Paddle is the seller on your receipt, collects the payment and handles sales tax and VAT. Paddle receives your card, name, email, billing country and address directly on its own checkout page, under its privacy policy. We never see or store card numbers. What comes back to us is whether the subscription is active, when it renews or ends, and Paddle's ids for it, so you can open Paddle's portal from Account → AI plan to cancel, change the card or download receipts.
Connecting Google Calendar, Outlook or Apple Calendar is optional. We read events from a window of 7 days back to 60 days ahead, store their title, time and calendar so the Planner can draw them, and write to your calendar only when you create an event here and choose to add it there. Access tokens and the Apple app-specific password are stored encrypted on the server and are never sent back to your browser. Disconnecting deletes the tokens and every copied event.
cronolog's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to show your own schedule to you. It is not used for advertising, not sold, not read by people, and not used to train AI models.
| Processor | Role | Where |
|---|---|---|
| Supabase | Database and authentication | São Paulo, Brazil |
| Vercel | Hosting and content delivery | Global edge network |
| Cloudflare | DNS and network protection | Global edge network |
| Sign-in, if you choose it | United States | |
| Ezoic | Advertising, only with your consent and only once advertising is switched on | United States |
| Paddle | Payments for AI Pro, as reseller and merchant of record | United Kingdom and United States |
| Google, Microsoft, Apple | Your calendar, only if you connect it | United States |
| Alibaba Cloud | Runs the AI assistant, for subscribers to the AI plan only. It receives a short summary of your tracked time — never your account, your email, or the raw history | Singapore |
We never sell your data, and we never share it for anyone else's marketing. None of your data is used to train AI models. Other members of a group see only your display name and your total time for that group's activity — never which specific activity or description you recorded.
Your account and activity data are stored in Brazil. Hosting, DNS, sign-in and advertising providers may process data outside your country, including in the United States. If you subscribe to the AI plan, the summary the assistant needs is additionally processed in Singapore, by Alibaba Cloud. Those transfers rely on the providers' Standard Contractual Clauses and equivalent safeguards under GDPR art. 46 and LGPD art. 33; the AI transfer additionally rests on performance of the contract you entered into when subscribing (LGPD art. 33, V).
Under the LGPD and GDPR you can, at any time and free of charge:
For anything the app can't do for you directly, write to contato@cronolog.net, or reach the ANPD/your national authority directly (link above) if it's urgent.
Traffic is HTTPS-only and forced by HSTS. Every database table enforces row-level security, so one account's query cannot reach another's rows even if the client is tampered with. Passwords are hashed by Supabase Auth and never reach us. A Content-Security-Policy restricts where the page may load code from and where it may send data. No system is perfect; if you find a vulnerability, email contato@cronolog.net and we will credit you.
cronolog. is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email contato@cronolog.netand we will delete it. Under the LGPD, processing a child's data requires specific parental consent, which we do not collect and therefore do not rely on.
If this policy changes materially we update the date at the top and, where the change affects what you consented to, ask for your choice again the next time you open the app.