← Back to cronolog.

Privacy Policy

Last updated: August 5, 2026

cronolog. is a time-tracking app. This page says exactly what we collect, the legal ground we rely on for each thing, how long we keep it, who else sees it, and what you can demand from us. It is written to satisfy the Brazilian LGPD (Lei 13.709/2018) and the European GDPR, whichever applies to you.

1. Who is responsible

cronolog. is operated by an individual as a personal project — there is no separate company and no appointed Data Protection Officer. A dedicated contact address for privacy requests is being set up; until it is live, use the in-app channels for everything this policy describes (export, correction, deletion — see section 8), which don't require contacting anyone. We answer any request within 15 days (LGPD) or 30 days (GDPR).

2. What we collect, why, and on what legal basis

DataWhyLegal basisKept for
Account — email, display name, and the name/email Google shares if you use Google sign-inTo create and secure your account and sync your data between devicesPerformance of a contract (LGPD art. 7 V / GDPR art. 6(1)(b))Until you delete your account
Activity data — activities, sessions and their descriptions, to-dos, goals, layout and themeIt is the product. Stored on your device and, if signed in, in your accountPerformance of a contractUntil you delete it or your account
Group data — display name, your total tracked time for that group's activity, chat messagesTo rank a shared leaderboard you chose to joinConsent, given by joining the group (withdrawable by leaving it)Until you leave the group or delete your account
Device identifier — a random string generated in your browserTo tell your own devices apart when syncing a running timerLegitimate interest in a working sync (GDPR art. 6(1)(f))Until you clear the app's storage
Usage measurement — daily totals: visits, time in app, time per tab, device type, browser language, referring siteTo see which parts of the app are actually used and where to spend effortConsent — nothing is measured until you acceptAggregated daily; raw rows removed after 400 days
Advertising data — cookies and identifiers set by our ad partnerTo show and measure ads, which is what keeps the app freeConsent — no ad script loads until you acceptSet by the partner; see section 5

We do not profile you, and no decision affecting you is made automatically. We do not collect your precise location, your contacts, or anything from other apps.

If you use cronolog. as a guest without an account, your data stays in your browser and is never sent to us at all.

3. Storage on your device

We use your browser's local storage and a sign-in cookie. These are strictly necessary: they hold your sessions so the app works offline, and they remember your privacy choice so we don't ask again. They are not used for tracking and are not shared. Measurement and advertising storage is separate and only ever written after you consent.

4. Your consent, and taking it back

The banner on first visit is a real choice — declining costs you nothing and the app behaves identically. You can change or withdraw that choice at any time in Account → Data & privacy → Privacy choices. Withdrawal takes effect immediately and does not affect processing that already happened.

5. Advertising

When advertising is enabled, this site uses Google AdSense. Google's Consent Mode governs it: the AdSense library is present on every load, but by default it is told to store no ad cookie, collect no ad-related device data, and show only non-personalised ads. Personalised ads, and any ad cookie or identifier, only turn on the moment you accept ads in the banner — and turn back off the moment you withdraw that consent from Account → Data & privacy.

You can control the personalised ads Google shows you at adssettings.google.com, opt out of the industry-wide personalisation programmes Google participates in at optout.aboutads.info, and read how Google uses data from advertising. Your activity data — what you tracked, when, and for how long — is never shared with advertisers.

6. Who else processes your data

ProcessorRoleWhere
SupabaseDatabase and authenticationSão Paulo, Brazil
VercelHosting and content deliveryGlobal edge network
CloudflareDNS and network protectionGlobal edge network
GoogleSign-in (if you choose it) and advertising via AdSense (only with your consent)United States

We never sell your data, and we never share it for anyone else's marketing. Other members of a group see only your display name and your total time for that group's activity — never which specific activity or description you recorded.

7. International transfers

Your account and activity data are stored in Brazil. Hosting, DNS, sign-in and advertising providers may process data outside your country, including in the United States. Those transfers rely on the providers' Standard Contractual Clauses and equivalent safeguards under GDPR art. 46 and LGPD art. 33.

8. Your rights

Under the LGPD and GDPR you can, at any time and free of charge:

  • Access and export everything you've tracked — Account → Data & privacy → Export sessions gives you a CSV immediately, no request needed.
  • Correct anything wrong — every session, activity and profile field is editable in the app.
  • Delete your account and everything attached to it — Account → Data & privacy → Delete account. It is immediate and irreversible.
  • Withdraw consent for measurement and advertising — same screen, Privacy choices.
  • Object to or restrict processing based on legitimate interest, and port your data to another service (the CSV export is machine-readable for exactly this).
  • Complain to a regulator — the ANPD in Brazil, or your national data protection authority in the EU/UK.

A dedicated contact address for anything the app can't do for you directly is being set up — check this page again soon, or reach the ANPD/your national authority directly (link above) if it's urgent.

9. Security

Traffic is HTTPS-only and forced by HSTS. Every database table enforces row-level security, so one account's query cannot reach another's rows even if the client is tampered with. Passwords are hashed by Supabase Auth and never reach us. A Content-Security-Policy restricts where the page may load code from and where it may send data. No system is perfect; if you find a vulnerability, email the address above and we will credit you.

10. Children

cronolog. is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it. Under the LGPD, processing a child's data requires specific parental consent, which we do not collect and therefore do not rely on.

11. Changes

If this policy changes materially we update the date at the top and, where the change affects what you consented to, ask for your choice again the next time you open the app.

Privacy policyTerms of usecronolog.