Effective 24 April 2026
Chronos Calendar (“Chronos”, “we”, “us”, “our”) is operated by Byte Size Labs(ABN 69 122 385 632), based in Australia. We are the entity responsible for personal information collected through the Chronos Calendar web application and related services (the “Service”).
This policy explains how we handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
AI-assisted scheduling currently runs on our own servers. Your task and calendar content is not sent to third-party large language model providers. If this changes in the future, we will update this policy and notify users before doing so.
When you connect Google Calendar or Microsoft Outlook, we use OAuth so that you grant access without sharing your password. Access tokens are encrypted at rest using AES-256 with a key stored separately from the database.
We only request scopes necessary to read and write calendar events on your behalf. You can revoke access at any time from your Chronos settings, or directly from your Google or Microsoft account security page. Revoking access stops further sync and deletes the stored tokens.
Google API Services User Data Policy.Chronos Calendar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use data obtained from Google APIs only to provide and improve the user-facing features of Chronos Calendar, we do not transfer this data to third parties except as necessary to provide and improve those features or to comply with applicable law, we do not use the data for advertising, and we do not allow humans to read the data unless we have your explicit consent, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and used for internal operations in line with the policy.
We do not sell your personal information. We use a small number of carefully chosen service providers (“processors”) to run the Service. They handle personal information only for purposes we have instructed and under contractual confidentiality and security obligations.
Some of these providers may store or process information in jurisdictions outside Australia (including the United States and the European Union). By using the Service you consent to such transfers, subject to APP 8.
We will only disclose your information outside this list where we are required to do so by law, to enforce our terms, or to protect the rights, property, or safety of Chronos, our users, or others.
Chronos uses a single essential, HTTP-only authentication cookie (auth-token) to keep you signed in. Disabling this cookie will prevent you from logging in.
We also use the Reddit Pixel, a third-party advertising cookie, to measure the performance of our Reddit ad campaigns. It does not receive your name, email, or other identifying information from Chronos. You can block it using your browser's tracking-protection or ad-blocking settings without affecting your ability to use Chronos.
If you opt in to browser push notifications, your browser stores a push subscription that we use only to deliver notifications you have configured.
We retain your personal information for as long as your account is active. If you delete your account or ask us to delete your data, we will permanently remove it from our production systems within 90 days. Encrypted backups containing deleted data are rotated out within the same period.
We may retain limited records (such as billing history) for longer where required by Australian taxation or other laws.
We use industry-standard measures to protect your information, including TLS in transit, encryption at rest for OAuth tokens, hashed passwords, restricted production access, and audit logging. No system is perfectly secure, and we cannot guarantee absolute security. If you become aware of a security issue, please contact us immediately.
Under the Privacy Act 1988 (Cth) you have the right to:
To exercise these rights, email us at [email protected]. We will respond within a reasonable time, normally within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Chronos is not intended for children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us and we will delete it.
We may update this Privacy Policy from time to time. When we do, we will revise the “Effective” date above and, for material changes, notify you in-app or by email. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
If you have questions about this policy or how we handle your information, contact us at [email protected].
See also our Terms & Conditions.