Privacy, without the fine-print fog.
Chronicle is a local-first desktop application for versioning creative files. Core features, including capture, history, restore, and keyword search, work without a Chronicle account. Your watched files, stored versions, local database, AI summaries, tags, and search index remain on your device unless a feature described below requires you to send specific data elsewhere.
Your version library is not uploaded to Chronicle. Online accounts, sync, and AI features are separate from local versioning.
Information Chronicle handles
Data stored on your device
Chronicle stores watched-folder paths, copies of captured file versions, file metadata, thumbnails, version history, AI-generated annotations, embeddings, app settings, and queued work in its local app data. Chronicle reads the folders you choose and writes to an original path only when you restore a version. Removing Chronicle does not delete your original working files.
Account information
If you choose Google Sign-In, we receive your Google account's stable identifier, verified email address, given name, and family name. We use these details to create or identify your Chronicle account, secure sign-in, and prevent accounts from being merged by email alone.
Installation and settings information
In the current desktop build, when the Chronicle service is configured and reachable, the app makes a best-effort registration of a random installation identifier together with the app version, operating-system family, and first- and last-seen timestamps. This can occur in local mode and does not create an account. The identifier is not a hardware ID and does not include your hostname, paths, project names, or creative data.
If you choose to sign in, Chronicle can store portable preferences such as appearance, selected AI providers and models, and sync or reporting choices. Local paths, project metadata, files, and version history are excluded. The current desktop control for portable settings sync starts enabled, but it has no effect until you sign in and can be switched off in Settings. Encrypted provider-key sync is a separate control and stays off until you enable it and save an encrypted copy.
Optional usage reporting
The current build includes a usage-reporting preference that starts enabled and can be switched off, but usage-event delivery is not implemented in the current release. Chronicle therefore does not currently send the planned usage events or provide the planned analytics dashboard. Before such reporting is released, this policy and the in-product notice will be updated to match the final data, retention period, and user choice.
The planned reporting contract is restricted to operational information such as random telemetry IDs, app version, operating-system family, coarse counts and size ranges, supported file types, timings, provider and model identifiers, outcomes, and whether a search occurred. It excludes file contents, file names, paths, project names, previews, version identifiers, hashes, AI summaries, tags, embeddings, and search queries. Planned events may queue locally while offline only when reporting is active.
Google Sign-In and Google user data
Google Sign-In is optional. Chronicle requests only the openid, email, andprofile scopes to authenticate you and create your Chronicle account. Authentication opens in your system browser. Chronicle sends the resulting short-lived Google ID token to its service for verification, then issues a Chronicle session. Chronicle stores the identity details described above and the Google account's stable subject identifier. Chronicle does not store Google access tokens or refresh tokens, does not access Google Drive, Gmail, Calendar, contacts, or other Google services, and does not use Google account data for advertising.
Chronicle's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI features and third-party providers
AI summaries and semantic search are optional and require a provider connection. When you configure your own provider key, Chronicle's local AI service sends only the inputs required for the task, such as the relevant current and previous images, filename, or annotation text, directly to the provider you selected. Your provider's privacy policy, retention rules, and terms apply to that processing.
Provider keys are encrypted on your device. Optional key sync is off by default and, if you enable it, uploads only an envelope encrypted on your device with your passphrase. Chronicle does not receive that passphrase or the plaintext key. A future Chronicle-hosted AI gateway, if offered, will be identified in the app before use and this policy will be updated to describe it.
Security and international processing
Chronicle uses safeguards appropriate to the data it handles, including external-browser OAuth with PKCE, server-side Google token verification, short-lived Chronicle access tokens, revocable sessions, encrypted local credential storage, and authenticated encryption for optional key sync. No system is perfectly secure, and we cannot guarantee absolute security.
The Chronicle service and third-party providers may process information in countries other than the one where you live. Where applicable, we rely on lawful transfer mechanisms and provider safeguards.
Retention and your controls
Local creative history remains on your device until you remove it using Chronicle or delete the app's local data. Cloud account records and synced settings are kept while your account is active and as needed to operate, secure, and comply with legal obligations. Short-lived session records expire or are revoked. Disabling encrypted-key sync removes the server copy of the encrypted envelope while keeping your local keys. The current release does not send usage events. If reporting is released, turning it off will stop new events, clear its local upload queue, and request deletion of covered raw installation and project telemetry. Minimal installation registration is a separate operation.
You may stop using Google Sign-In by signing out and revoking Chronicle's access from your Google Account. A self-service account-deletion control is not implemented in the current release. To request account deactivation, deletion, access, export, or correction, contact us using the channel below. Deleting a Chronicle account is separate from deleting local version history on your device. Some limited records may be retained when required for security, fraud prevention, or legal compliance.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent where consent is the legal basis. You may also complain to your local data-protection authority. We may need to verify your identity before completing a request. Chronicle is not directed to children under 13, or the higher minimum age required in their country, and we do not knowingly collect their personal information.
Changes to this policy
We may update this policy as Chronicle evolves. We will publish the revised version here, change the effective date, and provide additional notice when a change is material. Your continued use after an update is subject to the revised policy, where permitted by law.
Contact
Chronicle is maintained by the Chronicle project team. For privacy questions or requests, contact us at chronicle.support@gmial.com or through the Chronicle project issue tracker. Do not include passwords, provider keys, ID tokens, file contents, or other sensitive information in a public issue.