Last updated: 21 April 2026
All traffic to and from Chronos Calendar is encrypted using TLS 1.2 or higher. Data at rest is encrypted on disk by our infrastructure provider. OAuth access and refresh tokens for connected calendars are encrypted with AES-256 before being stored.
Chronos Calendar is hosted on Railway, which runs on audited cloud infrastructure. Our databases are isolated per environment, backed up regularly, and access-controlled. Production access is restricted to authorised engineers and logged.
If you believe you've found a security vulnerability, please email [email protected] with details. We aim to acknowledge reports within two business days and will keep you updated as we investigate. Please do not publicly disclose issues before we've had a chance to respond.
See our Privacy Policy for how we handle personal information, and our Terms of Service for the full agreement.