← Chronos
Privacy Policy
Effective September 3, 2026
Chronos is a calendar application for iPhone and Mac, built and operated by
Glenn Joseph ("we", "us"). Chronos is designed so that your data stays with
you: the app has no backend servers of its own, no user accounts of its own,
no advertising, and no analytics about how you use it. The one thing we hold
about you is the record of an optional Chronos Pro subscription, described
below.
What Chronos accesses
- Calendar data. With your permission, Chronos connects
directly from your device to the calendar services you choose — Google
Calendar, iCloud (CalDAV), and Microsoft 365 (Microsoft Graph) — to read
and write your calendars and events, and to send responses to invitations
you act on. This data flows directly between your device and the provider.
- Contacts. With your permission, Chronos reads your
device's contacts locally to suggest attendees while you type. Contact data
never leaves your device except as attendee email addresses you explicitly
add to an event, which are sent to your calendar provider to deliver
invitations.
- Location. With your permission, Chronos uses your
approximate location to show local weather. Coordinates are sent only to
the weather services below and are not stored by us.
Chronos Pro subscriptions
Chronos Pro is an optional subscription sold through Apple's App Store.
Apple processes the payment; we never see your payment details. To unlock Pro
features, restore your purchase on your other devices, and keep subscription
records straight, Chronos uses
RevenueCat, a subscription-management
service. RevenueCat receives:
- An anonymous customer ID. A random identifier created
the first time Chronos runs and kept in the device Keychain. It is not
derived from your name, Apple ID, or email address.
- Your purchase history. The App Store record for Chronos
Pro: which plan you chose, when it started, when it renews or expires, and
whether a free trial is active. It contains no payment details.
- Your email address. When you connect a calendar account,
Chronos attaches that account's email address to your subscription record
so that, if you contact us for help, we can find your subscription. Only the
first account you connected is used, and the address is removed from the
record when you remove your last calendar account from Chronos.
- Basic device details. The app version, device model and
operating system version, and the country the request comes from.
We use these records to unlock what you paid for and to see aggregate
subscription figures, such as how many free trials convert. They are never
used for advertising and never shared with anyone else. RevenueCat processes
them on our behalf under its own
privacy policy.
Where your data lives
- Sign-in credentials (OAuth tokens, app-specific passwords) are stored in
the device Keychain, on your device only.
- Calendar and event data is cached on your device so the app opens
instantly. Removing an account, or deleting the app, removes this data.
- We operate no servers. We cannot see your calendars, events, contacts,
credentials, or location — architecturally, they never reach us.
- The only data about you held outside your device and your calendar
providers is the Chronos Pro subscription record at RevenueCat described
above.
Google user data
Chronos's use and transfer of information received from Google APIs adheres
to the Google
API Services User Data Policy, including the Limited Use requirements.
Specifically: Google Calendar data is used only to display and manage your
calendar inside the app at your direction; it is not transferred to anyone
other than Google, not used for advertising, and not read by humans.
How we protect your data
Chronos protects sensitive data — including Google user data — with the
following mechanisms:
- Encryption in transit. All communication with Google,
Apple, and Microsoft calendar services, and with RevenueCat, uses TLS
(HTTPS) encryption. Chronos never transmits calendar data over unencrypted
connections.
- Encryption at rest. OAuth tokens and app-specific
passwords are stored exclusively in the Apple Keychain, which encrypts them
at rest using hardware-backed keys on your device. Cached calendar data is
stored inside the app's sandboxed container, protected by Apple's built-in
Data Protection (file-level encryption tied to your device passcode).
- OS sandboxing. Chronos runs in Apple's app sandbox, so
other apps cannot read its data.
- Least-privilege access. Chronos requests only the OAuth
scopes it needs to display and manage your calendars, and you can revoke
that access at any time (see below).
- No server-side copies. We operate no backend servers,
so no copy of your calendar data exists outside your device and your
calendar provider — there is no server of ours for anyone to breach. The
subscription record at RevenueCat contains no calendar data.
Data retention and deletion
Because Chronos stores your calendar data only on your own device,
retention and deletion are in your control:
- Retention. Google user data (your calendar and event
data) is cached on your device only for as long as the associated Google
account remains connected in Chronos. We retain no copies of Google user
data on any server, and we retain nothing after you disconnect an
account.
- Deletion. To delete Google user data from Chronos,
remove the account in Chronos → Settings, which immediately deletes its
cached calendar data and stored credentials from your device — or simply
delete the app, which removes all data it stored. You can additionally
revoke Chronos's access at
myaccount.google.com/permissions,
after which Chronos can no longer access your Google data.
- Provider copies. Deleting data from Chronos does not
affect the data held by your calendar provider (e.g., events in Google
Calendar itself), which remains governed by that provider's own policies
and controls.
- Subscription records. RevenueCat keeps your Chronos
Pro record for as long as it is needed to honor your purchase, including
restoring it on a new device. Removing your last calendar account removes
your email address from it. To have the whole record deleted, email us at
chronosappsupport@gmail.com.
Deleting it does not cancel a subscription — you manage that in your Apple
ID settings — and Apple keeps its own purchase records under your Apple
ID.
Third-party services
- Your calendar providers (Google, Apple, Microsoft)
receive the calendar operations you perform and are governed by their own
privacy policies.
- Apple Weather (WeatherKit) and
Open-Meteo receive approximate coordinates to return
forecasts.
- U.S. EPA AirNow receives approximate coordinates to
return air-quality observations.
- Apple Maps is used to display event locations and
suggest addresses as you type.
- Apple's App Store processes Chronos Pro payments and
holds the purchase records under your Apple ID.
- RevenueCat stores the subscription records described
above.
What we don't do
- No advertising, ad tracking, or cross-app tracking of any kind.
- No analytics or telemetry about how you use the app. The only usage
figures we see are aggregate subscription numbers from RevenueCat.
- No selling, sharing, or transferring of your data.
- No collection of your calendar, contact, credential, or location data
— none of it ever reaches us, so there is nothing of that kind for us to
retain or delete.
Revoking access
You can disconnect an account in Chronos's Settings at any time, which
deletes its credentials and cached data from your device. You can also revoke
Chronos's access from your provider:
Google,
Apple ID (app-specific passwords), or
Microsoft.
Children
Chronos is not directed at children under 13 and does not knowingly
collect personal information from them.
Changes
If this policy changes, the updated version will be posted at this address
with a new effective date.
- September 3, 2026. Added the Chronos Pro subscription
section: what RevenueCat receives, including the email address of your
first connected calendar account, and how to have that record deleted.
- July 30, 2026. First published.
Contact
Questions? Email chronosappsupport@gmail.com.