Legal
Privacy Policy
Effective date: 28 July 2026
Last updated: 28 July 2026
This Privacy Policy explains how Chronalio (“Chronalio”, “we”, “us”, “our”) collects, uses, discloses, stores, and protects information when you use the Chronalio mobile applications (iOS and Android), progressive web app, websites (including https://chronalio.com and https://app.chronalio.com), and related support channels (collectively, the “Services”).
Chronalio is a family-centric emergency alert and journey safety product. We process personal data to help you notify trusted contacts, operate a reliable service, and meet legal obligations. We do not sell your personal data.
1. Who we are / controller
Data controller: Chronalio
Privacy contact: support@chronalio.com
Support: chronalio.com/support
Operating location: Worldwide
2. Personal information we collect
2.1 Account and identity
- Email address and display name
- Authentication metadata (session identifiers, sign-in timestamps)
- Optional phone number if you provide it for profile, recovery, or support
- Optional profile photo you upload
2.2 Family and circle data
- Circle / family membership, roles, and invitation status
- Relationships you define within a circle (for example admin vs member)
- Presence status you share with your circle (online, away, offline)
2.3 Emergency, incident, and journey data
- Panic / HELP and check-in events, timestamps, and status
- Location data shared during alerts, journeys, or deliberate sharing (precise GPS when permitted)
- Optional ambient audio recorded in short chunks during an active emergency
- Optional camera / surrounding video recorded in short chunks during an active emergency (when enabled and permitted)
- Notes, acknowledgements, and messages within an incident timeline
- Journey schedules, ETA, check-ins, breadcrumbs, and related safety status
2.4 Sensitive / special-category information (if you choose to provide it)
- Emergency profile fields such as medical notes, blood type, allergies, and ICE contacts. These fields are optional. Where implemented, sensitive profile fields are protected with device-bound or application-level encryption in addition to transport security.
- Emergency audio and video may incidentally capture sensitive surroundings. Capture is limited to active emergency contexts you initiate (or that your settings allow).
2.5 Device, diagnostics, and identifiers
- Device type, operating system, app version, build, language
- Push notification tokens
- IP address, approximate region, connectivity diagnostics, and crash / error logs
- Battery level or availability signals when the platform exposes them (for example during journeys); some browsers (notably iOS Safari) do not provide battery APIs
2.6 Notifications
- Permission state for push / browser notifications and delivery metadata needed to send alerts to you or your circle
2.7 Photos and media
- Profile photos selected from your library (with your permission)
- Emergency evidence media (audio / video chunks) uploaded to secure storage associated with an incident
2.8 Contacts
Chronalio does not require access to your full device address book. Trusted contacts are those you invite into a Chronalio family circle using email or invite links you control.
2.9 Support communications
- Name, email, phone (if provided), ticket content, attachments, and correspondence when you contact support via the website or email
2.10 Cookies and similar technologies (web / PWA)
- Essential cookies or local storage for authentication sessions, preferences (for example theme), and security
- We do not use third-party advertising cookies. Optional product analytics, if enabled, load only after you consent via our cookie banner or Cookie settings (footer). See our Cookie Policy for categories and how to change your choice.
2.11 Chronalio Intelligence (AI companion)
- Chat messages and prompts you send to Chronalio Intelligence (text or transcribed speech), plus limited session context we attach so replies stay relevant (for example active journey or incident status, not your full history by default)
- Optional speech-to-text transcripts when you press to talk (we do not run an always-on wake phrase in current releases)
- Optional text-to-speech playback on your device when you enable spoken replies
- Companion-initiated safety actions you confirm (for example mark arrived, pause/stop a journey, check-in, all clear, or trigger HELP) use the same account APIs as the on-screen controls
Model inference may be performed by our servers or contracted LLM processors (see Sharing below). Heuristic / on-device fallbacks may be used when the model service is unavailable. Chronalio Intelligence is assistive only — it is not medical, legal, or emergency advice.
3. Location, camera, microphone, speech, and notifications — how we use them
- Location: used to help your trusted circle locate you during emergencies and (when enabled) during active journeys or presence sharing. Background location is used only for safety features that require ongoing updates while an alert or journey is active, subject to OS permissions. Approximate location may also be used for journey ETA / map context via routing providers.
- Microphone: (1) short ambient audio chunks during an active emergency so trusted contacts can hear context; and (2) optional Chronalio Intelligence voice prompts when you choose to speak (push-to-talk). Microphone is not used for continuous background listening for a wake phrase in current releases.
- Speech recognition: converts your spoken prompts to text for Chronalio Intelligence when you use voice input, subject to OS permission.
- Camera: used to record short surrounding video chunks during an active emergency when video capture is enabled in settings and permitted by the OS.
- Photos / media library: used only when you choose a profile photo or similar user-initiated upload.
- Notifications: used to deliver emergency alerts, journey updates, and service notices you enable.
- Biometrics (Face ID / fingerprint): processed on device by the OS to cancel an alert when you enable that protection; we do not receive biometric templates.
4. How we process and use information
- Provide, maintain, and improve emergency alert and journey features
- Power Chronalio Intelligence (companion chat, optional voice, and confirmed safety actions)
- Authenticate users and secure accounts
- Deliver notifications and alert emails / SMS to your trusted circle (where those channels are configured)
- Detect abuse, debug failures, and improve reliability
- Respond to support requests and safety escalations
- Comply with legal obligations and enforce our Terms
- Communicate service updates; marketing only with appropriate consent or as permitted by law
5. Analytics and crash reporting
We may collect limited diagnostic and usage data (for example crash logs, performance metrics, and feature reliability signals) to keep the Services stable. This data is used for security and product improvement, not for advertising profiling. Where a third-party crash or analytics provider is used, it acts as a processor under contract.
6. Legal bases (GDPR / UK GDPR where applicable)
Depending on your location, we may process data based on:
- Contract — providing the Services you request
- Legitimate interests — security, fraud prevention, product reliability, and service improvement (balanced against your rights)
- Consent — optional features such as certain notifications, marketing, or optional sensors where required
- Vital interests — limited processing necessary to protect life or safety in genuine emergencies
- Legal obligation — compliance with applicable law
7. How data is stored and protected
- In transit: traffic to our backends uses HTTPS / TLS
- At rest: cloud databases and object storage use provider-managed encryption at rest; sensitive emergency-profile fields may use additional application-level encryption
- Access controls, Row Level Security (RLS) for family-scoped data, rate limiting on public APIs, and operational monitoring
No method of transmission or storage is 100% secure. See our Security page for more detail.
8. Sharing and third parties
We may share information with:
- Your circle members — incident and journey context you enable (location, media, profile fields shared during an alert)
- Service providers (processors) — carefully selected companies that process data on our behalf under contractual confidentiality and data-protection terms, including categories such as:
- Cloud hosting, authentication, database, and file storage
- Transactional email delivery for alerts, account, and service messages
- SMS delivery where you or your circle have that channel enabled
- Push notification networks (device and browser push services)
- Artificial intelligence / language-model inference used for Chronalio Intelligence. Limited prompts and session context may be sent solely to generate companion replies; provider API keys remain on our servers
- Maps, geocoding, routing, and weather services used for Journey Intelligence (typically location queries or coordinates you initiate for place or ETA context)
- Optional diagnostics and crash-reporting services
- Authorities — when required by law or to protect vital interests, rights, or safety
- Business transfers — in connection with a merger, acquisition, or asset sale, subject to appropriate protections
We do not sell personal data and we do not share personal data for cross-context behavioural advertising.
9. International data transfers
We may process data in regions where our infrastructure and cloud providers operate. Where required (for example transfers from the EEA / UK), we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms offered by our providers.
10. Retention
- Account data: retained while your account is active
- Incident / evidence records: retained for a period necessary for safety, dispute resolution, and legal compliance, then deleted or anonymised (typical operational window: up to 24 months unless a longer period is required by law or an active investigation)
- Journey breadcrumbs: retained while needed for the journey and short-term safety history, then purged or aggregated
- Support tickets and attachments: retained according to operational needs, then removed or archived
- Diagnostics: retained for shorter operational windows unless needed to investigate a security incident
- Intelligence prompts / transcripts: retained only as needed to provide the companion experience, debug reliability, and meet security or legal obligations; not used to train public advertising models
You may request deletion as described below. Some residual logs may remain for legal or security purposes for a limited time.
11. Your rights (GDPR, CCPA/CPRA, and similar laws)
Subject to applicable law, you may have rights to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete personal information
- Restrict or object to certain processing
- Data portability
- Withdraw consent where processing is consent-based
- Opt out of “sale” or “sharing” of personal information (Chronalio does not sell or share for cross-context advertising)
- Limit use of sensitive personal information (where you provided it optionally)
- Lodge a complaint with a supervisory authority
California residents may designate an authorised agent to make requests. We will not discriminate against you for exercising privacy rights. We may need to verify your identity before fulfilling requests.
Contact support@chronalio.com or use our Support form. You can also start an account deletion request from the Chronalio app under Settings → About & Legal.
12. Account deletion and data deletion requests
- In the Chronalio app, open Settings → About & Legal → Delete account, confirm, and submit the request; or
- Email support@chronalio.com from your account email with subject “Account deletion”, or use the Support form.
After verification we delete or anonymise account data and associated personal content within 30 days, except where retention is required by law, safety investigations, or dispute resolution. Active emergency evidence may be retained for the retention period above before purge.
13. Children
Chronalio is not directed at children under 13 (or the minimum age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under that age. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
14. Emergency services disclaimer
Chronalio does not replace police, ambulance, or fire services. In a life-threatening emergency, contact local emergency numbers first.
15. Changes to this Policy
We may update this Policy from time to time. We will post the revised version on this page and update the effective / last-updated dates. Material changes may be communicated in-app or by email where appropriate. Continued use after the effective date constitutes acknowledgement of the updated Policy where permitted by law.
16. Policy revision history
- 28 July 2026 — Sharing section updated to category-based processor disclosures (vendor names removed from the public policy); subprocessors available on request; aligned with cookie consent controls on the marketing site.
- 25 July 2026— Moved to /legal/privacy/ as part of the site's information architecture update; added cross-links to the new Cookie Policy and Data Processing Addendum.
- 23 July 2026 — Chronalio Intelligence (chat, optional STT/TTS, confirmed companion actions), speech recognition, AI processors, map/weather/routing helpers, and alert email/SMS processor categories disclosed; microphone uses clarified (emergency evidence and push-to-talk voice).
- 20 July 2026 — Comprehensive update for App Store / Play Store readiness: expanded sensor and media disclosures, encryption, retention, CCPA/CPRA rights, subprocessors overview, account deletion path, and cookies / PWA section.
17. Contact
Privacy questions: support@chronalio.com
Address: Worldwide