Privacy, without the fine-print fog.
Chronicle is a local-first desktop application for versioning creative files. Core features, including capture, history, restore, and keyword search, work without a Chronicle account. Your watched files, stored versions, local database, AI summaries, tags, and search index remain on your device unless a feature described below requires you to send specific data elsewhere.
Your version library is not uploaded to Chronicle. Online accounts, sync, and AI features are separate from local versioning.
Information Chronicle handles
Data stored on your device
Chronicle stores watched-folder paths, copies of captured file versions, file metadata, thumbnails, version history, AI-generated annotations, embeddings, app settings, and queued work in its local app data. Chronicle reads the folders you choose and writes to an original path only when you restore a version. Removing Chronicle does not delete your original working files.
Account information
If you choose Google Sign-In, we receive your Google account's stable identifier, verified email address, given name, and family name. We use these details to create or identify your Chronicle account, secure sign-in, and prevent accounts from being merged by email alone.
Installation and settings information
In the current desktop build, when the Chronicle service is configured and reachable, the app makes a best-effort registration of a random installation identifier together with the app version, operating-system family, and first- and last-seen timestamps. This can occur in local mode and does not create an account. The identifier is not a hardware ID and does not include your hostname, paths, project names, or creative data.
If you choose to sign in, Chronicle can store portable preferences such as appearance, selected AI providers and models, and sync or reporting choices. Local paths, project metadata, files, and version history are excluded. The current desktop control for portable settings sync starts enabled, but it has no effect until you sign in and can be switched off in Settings. Encrypted provider-key sync is a separate control and stays off until you enable it and save an encrypted copy.
Optional usage reporting
Usage reporting starts enabled and can be switched off at any time. While enabled, Chronicle sends app opens, project-removal records, hourly search and provider/model AI totals, current project/asset/version count snapshots, and sanitized unexpected application failures. Chronicle records the preference, this notice version, its timestamp, the random installation, and the linked account when present.
The reporting contract is restricted to operational information such as random telemetry IDs, app version, operating-system family, coarse counts and size ranges, supported file types, timings, provider and model identifiers, outcomes, and whether a search occurred. It excludes file contents, file names, paths, project names, previews, version identifiers, hashes, AI summaries, tags, embeddings, and search queries. Events may queue locally while offline only when reporting is active.
Google Sign-In and Google user data
Google Sign-In is optional. Chronicle requests only the openid, email, andprofile scopes to authenticate you and create your Chronicle account. Authentication opens in your system browser. Chronicle sends the resulting short-lived Google ID token to its service for verification, then issues a Chronicle session. Chronicle stores the identity details described above and the Google account's stable subject identifier. Chronicle does not store Google access tokens or refresh tokens, does not access Google Drive, Gmail, Calendar, contacts, or other Google services, and does not use Google account data for advertising.
Chronicle's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI features and third-party providers
AI summaries and semantic search are optional and require a provider connection. When you configure your own provider key, Chronicle's local AI service sends only the inputs required for the task, such as the relevant current and previous images, filename, or annotation text, directly to the provider you selected. Your provider's privacy policy, retention rules, and terms apply to that processing.
Provider keys are encrypted on your device. Optional key sync is off by default and, if you enable it, uploads only an envelope encrypted on your device with your passphrase. Chronicle does not receive that passphrase or the plaintext key. A future Chronicle-hosted AI gateway, if offered, will be identified in the app before use and this policy will be updated to describe it.
Security and international processing
Chronicle uses safeguards appropriate to the data it handles, including external-browser OAuth with PKCE, server-side Google token verification, short-lived Chronicle access tokens, revocable sessions, encrypted local credential storage, and authenticated encryption for optional key sync. No system is perfectly secure, and we cannot guarantee absolute security.
The Chronicle service and third-party providers may process information in countries other than the one where you live. Where applicable, we rely on lawful transfer mechanisms and provider safeguards.
Retention and your controls
Local creative history remains on your device until you remove it using Chronicle or delete the app's local data, with one exception: when a watched file is no longer on disk, Chronicle keeps its stored version history under Removed files for 30 days and then deletes it permanently from your device. You can delete that history sooner from the same place. Raw session, project-removal, and sanitized-error records are kept for up to 90 days; hourly usage rollups for up to 400 days; and current inventory snapshots for up to 30 days. Anonymous installation registrations and preference records expire after 400 inactive days. Cloud account records, identities, linked installations, and synced settings are kept while your account is active. Chronicle access and refresh sessions expire after 30 minutes and 7 days respectively, or are revoked earlier. Disabling encrypted-key sync removes the server envelope while keeping local keys. Turning reporting off stops new events and clears the local upload queue. Minimal installation registration is separate and can be erased from Settings.
You may stop using Google Sign-In by signing out and revoking Chronicle's access from your Google Account. Settings can export machine-readable account or anonymous-installation cloud data. A signed-in user can permanently delete the account, Google identity link, settings, encrypted envelope, linked installations, usage statistics, and Chronicle sessions. A local-mode user can erase the random installation and its usage data. These actions do not delete local version history, originals, or local provider keys.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent where consent is the legal basis. You may also complain to your local data-protection authority. We may need to verify your identity before completing a request. Chronicle is not directed to children under 13, or the higher minimum age required in their country, and we do not knowingly collect their personal information.
Changes to this policy
We may update this policy as Chronicle evolves. We will publish the revised version here, change the effective date, and provide additional notice when a change is material. Your continued use after an update is subject to the revised policy, where permitted by law.
Contact
Chronicle is maintained by the Chronicle project team. For privacy questions or requests, contact us at [email protected] or through the Chronicle project issue tracker. Do not include passwords, provider keys, ID tokens, file contents, or other sensitive information in a public issue.