Last updated: August 5, 2026
cronolog. is a time-tracking app. This page says exactly what we collect, the legal ground we rely on for each thing, how long we keep it, who else sees it, and what you can demand from us. It is written to satisfy the Brazilian LGPD (Lei 13.709/2018) and the European GDPR, whichever applies to you.
cronolog. is operated by an individual as a personal project — there is no separate company and no appointed Data Protection Officer. A dedicated contact address for privacy requests is being set up; until it is live, use the in-app channels for everything this policy describes (export, correction, deletion — see section 8), which don't require contacting anyone. We answer any request within 15 days (LGPD) or 30 days (GDPR).
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Account — email, display name, and the name/email Google shares if you use Google sign-in | To create and secure your account and sync your data between devices | Performance of a contract (LGPD art. 7 V / GDPR art. 6(1)(b)) | Until you delete your account |
| Activity data — activities, sessions and their descriptions, to-dos, goals, layout and theme | It is the product. Stored on your device and, if signed in, in your account | Performance of a contract | Until you delete it or your account |
| Group data — display name, your total tracked time for that group's activity, chat messages | To rank a shared leaderboard you chose to join | Consent, given by joining the group (withdrawable by leaving it) | Until you leave the group or delete your account |
| Device identifier — a random string generated in your browser | To tell your own devices apart when syncing a running timer | Legitimate interest in a working sync (GDPR art. 6(1)(f)) | Until you clear the app's storage |
| Usage measurement — daily totals: visits, time in app, time per tab, device type, browser language, referring site | To see which parts of the app are actually used and where to spend effort | Consent — nothing is measured until you accept | Aggregated daily; raw rows removed after 400 days |
| Advertising data — cookies and identifiers set by our ad partner | To show and measure ads, which is what keeps the app free | Consent — no ad script loads until you accept | Set by the partner; see section 5 |
We do not profile you, and no decision affecting you is made automatically. We do not collect your precise location, your contacts, or anything from other apps.
If you use cronolog. as a guest without an account, your data stays in your browser and is never sent to us at all.
We use your browser's local storage and a sign-in cookie. These are strictly necessary: they hold your sessions so the app works offline, and they remember your privacy choice so we don't ask again. They are not used for tracking and are not shared. Measurement and advertising storage is separate and only ever written after you consent.
The banner on first visit is a real choice — declining costs you nothing and the app behaves identically. You can change or withdraw that choice at any time in Account → Data & privacy → Privacy choices. Withdrawal takes effect immediately and does not affect processing that already happened.
When advertising is enabled, this site uses Google AdSense. Google's Consent Mode governs it: the AdSense library is present on every load, but by default it is told to store no ad cookie, collect no ad-related device data, and show only non-personalised ads. Personalised ads, and any ad cookie or identifier, only turn on the moment you accept ads in the banner — and turn back off the moment you withdraw that consent from Account → Data & privacy.
You can control the personalised ads Google shows you at adssettings.google.com, opt out of the industry-wide personalisation programmes Google participates in at optout.aboutads.info, and read how Google uses data from advertising. Your activity data — what you tracked, when, and for how long — is never shared with advertisers.
| Processor | Role | Where |
|---|---|---|
| Supabase | Database and authentication | São Paulo, Brazil |
| Vercel | Hosting and content delivery | Global edge network |
| Cloudflare | DNS and network protection | Global edge network |
| Sign-in (if you choose it) and advertising via AdSense (only with your consent) | United States |
We never sell your data, and we never share it for anyone else's marketing. Other members of a group see only your display name and your total time for that group's activity — never which specific activity or description you recorded.
Your account and activity data are stored in Brazil. Hosting, DNS, sign-in and advertising providers may process data outside your country, including in the United States. Those transfers rely on the providers' Standard Contractual Clauses and equivalent safeguards under GDPR art. 46 and LGPD art. 33.
Under the LGPD and GDPR you can, at any time and free of charge:
A dedicated contact address for anything the app can't do for you directly is being set up — check this page again soon, or reach the ANPD/your national authority directly (link above) if it's urgent.
Traffic is HTTPS-only and forced by HSTS. Every database table enforces row-level security, so one account's query cannot reach another's rows even if the client is tampered with. Passwords are hashed by Supabase Auth and never reach us. A Content-Security-Policy restricts where the page may load code from and where it may send data. No system is perfect; if you find a vulnerability, email the address above and we will credit you.
cronolog. is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it. Under the LGPD, processing a child's data requires specific parental consent, which we do not collect and therefore do not rely on.
If this policy changes materially we update the date at the top and, where the change affects what you consented to, ask for your choice again the next time you open the app.