Back to home

Privacy Policy

Effective 24 April 2026

1. Who we are

Chronos Calendar (“Chronos”, “we”, “us”, “our”) is operated by Byte Size Labs(ABN 69 122 385 632), based in Australia. We are the entity responsible for personal information collected through the Chronos Calendar web application and related services (the “Service”).

This policy explains how we handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. Information we collect

  • Account information — name, email address, hashed password, timezone, and account preferences you provide when you sign up or update your profile.
  • Calendar and task content — tasks, events, projects, availability windows, notes, and any attachments you create or upload to organise your work.
  • Connected calendar data — if you authorise Google Calendar or Microsoft Outlook integrations, we receive event metadata (titles, times, attendees, locations) so we can sync your schedule, plus the encrypted OAuth tokens you grant.
  • Usage and device data — basic technical information such as IP address, browser type, device, pages visited, and timestamps, used for security and to operate the Service.
  • Support and feedback — the contents of any feedback, bug report, or message you send us, including limited app context (page URL, app version) captured by our in-app feedback tool.
  • Billing information — if you subscribe to a paid plan, our payment processor handles your card details. We receive a customer reference, plan, and payment status; we do not store full card numbers.

3. How we use your information

  • To provide and maintain the Service, including AI-assisted scheduling, calendar sync, notifications, and reporting.
  • To authenticate you and keep your account secure.
  • To send transactional communications only — account verification, password resets, billing receipts, security alerts, and notifications you have configured. We do not currently send marketing emails.
  • To respond to support requests and investigate feedback you submit.
  • To diagnose problems, prevent abuse, and improve the reliability of the Service.
  • To comply with our legal obligations.

AI-assisted scheduling currently runs on our own servers. Your task and calendar content is not sent to third-party large language model providers. If this changes in the future, we will update this policy and notify users before doing so.

4. Calendar integrations and OAuth

When you connect Google Calendar or Microsoft Outlook, we use OAuth so that you grant access without sharing your password. Access tokens are encrypted at rest using AES-256 with a key stored separately from the database.

We only request scopes necessary to read and write calendar events on your behalf. You can revoke access at any time from your Chronos settings, or directly from your Google or Microsoft account security page. Revoking access stops further sync and deletes the stored tokens.

Google API Services User Data Policy.Chronos Calendar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use data obtained from Google APIs only to provide and improve the user-facing features of Chronos Calendar, we do not transfer this data to third parties except as necessary to provide and improve those features or to comply with applicable law, we do not use the data for advertising, and we do not allow humans to read the data unless we have your explicit consent, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and used for internal operations in line with the policy.

5. Third parties we share information with

We do not sell your personal information. We use a small number of carefully chosen service providers (“processors”) to run the Service. They handle personal information only for purposes we have instructed and under contractual confidentiality and security obligations.

  • Railway — cloud hosting provider for our application servers and managed MySQL database. Data may be stored on infrastructure located outside Australia.
  • Google — for users who connect Google Calendar via OAuth, we exchange calendar data with Google to keep your schedule in sync.
  • Microsoft — for users who connect Outlook Calendar via OAuth, we exchange calendar data with Microsoft to keep your schedule in sync.
  • Atlassian (Jira) — when you submit feedback through the in-app feedback widget, the contents of your message, your email, and limited app context are sent to our private Jira project to track and respond to the report. Please do not include sensitive personal information in feedback messages.
  • Reddit — we use the Reddit Pixel to measure the performance of our Reddit advertising campaigns. It records page visits and, where applicable, conversion events on our site. We do not send your name, email, or other identifying information to Reddit through this pixel.

Some of these providers may store or process information in jurisdictions outside Australia (including the United States and the European Union). By using the Service you consent to such transfers, subject to APP 8.

We will only disclose your information outside this list where we are required to do so by law, to enforce our terms, or to protect the rights, property, or safety of Chronos, our users, or others.

6. Cookies and similar technologies

Chronos uses a single essential, HTTP-only authentication cookie (auth-token) to keep you signed in. Disabling this cookie will prevent you from logging in.

We also use the Reddit Pixel, a third-party advertising cookie, to measure the performance of our Reddit ad campaigns. It does not receive your name, email, or other identifying information from Chronos. You can block it using your browser's tracking-protection or ad-blocking settings without affecting your ability to use Chronos.

If you opt in to browser push notifications, your browser stores a push subscription that we use only to deliver notifications you have configured.

7. Data retention

We retain your personal information for as long as your account is active. If you delete your account or ask us to delete your data, we will permanently remove it from our production systems within 90 days. Encrypted backups containing deleted data are rotated out within the same period.

We may retain limited records (such as billing history) for longer where required by Australian taxation or other laws.

8. Security

We use industry-standard measures to protect your information, including TLS in transit, encryption at rest for OAuth tokens, hashed passwords, restricted production access, and audit logging. No system is perfectly secure, and we cannot guarantee absolute security. If you become aware of a security issue, please contact us immediately.

9. Your rights

Under the Privacy Act 1988 (Cth) you have the right to:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate, out of date, incomplete, or misleading.
  • Delete your account and the personal information we hold (subject to lawful retention exceptions).
  • Withdraw consent for optional integrations or notifications at any time.
  • Complain about how we have handled your personal information.

To exercise these rights, email us at [email protected]. We will respond within a reasonable time, normally within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Children

Chronos is not intended for children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Effective” date above and, for material changes, notify you in-app or by email. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact us

If you have questions about this policy or how we handle your information, contact us at [email protected].

See also our Terms & Conditions.