Chrono Logo
Official Policy

Chrono Privacy Policy

Effective Date:August 21, 2026 • Chrono — Time Tracker Browser Extension (v1.9.0)

🔒 100% Offline & Local-First Privacy Commitment

Chrono is strictly engineered as an offline-first, zero-telemetry application. We do not operate user accounts, tracking servers, telemetry SDKs, or cloud databases. Your tracked hours, tasks, project names, labels, client details, and settings remain stored on your local device and are never transmitted to third parties.

1. Local Data Storage & IndexedDB (ChronoDB)

All tracking records, projects, tags, color configurations, and user preferences are stored exclusively on your device using:

  • Chrome Storage API (chrome.storage.local): For active timer states, regional options, and theme configurations.
  • IndexedDB Multi-Store Engine (ChronoDB): For high-volume, structured offline storage of time entries, projects, and labels.

Key Guarantees:

  • No personal identifiable information (PII) is collected or shared.
  • Data stays on your local disk until you uninstall the extension or clear browser storage.
  • You can export your raw data at any time in CSV, SheetJS Excel (.xlsx), JSON, or printable PDF formats.

2. Zero Third-Party Analytics & Telemetry

Chrono does not include any analytics packages (e.g., Google Analytics, Mixpanel), session replay tools, advertising SDKs, or tracking pixels. We do not collect or monitor:

  • Your browsing history or visited URLs.
  • Your IP address, device fingerprints, or location data.
  • Keystrokes outside the extension's own input fields.

3. Optional Integrations & Cloud Services

A. Google Calendar 1-Click Meeting Tracker (Optional)

If you connect Google Calendar to track meetings:

  • Direct OAuth 2.0: Authentication occurs directly with Google via chrome.identity.getAuthToken. No client secrets or intermediate proxy servers are used.
  • Read-Only Scopes: Chrono requests strictly read-only access (https://www.googleapis.com/auth/calendar.events.readonly and calendar.readonly).
  • Non-Destructive Tracking: Chrono reads meeting titles solely to auto-populate the timer description when you click "Start Timer" on an event popover. Chrono never creates, edits, deletes, or modifies any Google Calendar events.
  • Local Association: Event IDs and meeting descriptions are saved locally in your database and are never sent to external servers.

B. Google Drive Cloud Backups (Optional)

If you enable automated or manual Google Drive backups:

  • Backups are stored in Chrono's dedicated application folder (drive.file / drive.appdata) in your Google Drive.
  • Chrono cannot read, view, or modify any other files in your Google Drive.
  • Backup files are transmitted directly between your local browser and Google Drive servers.

C. Atlassian Jira Cloud Integration (Optional)

If you link your Jira workspace:

  • Connects directly using official Atlassian OAuth 2.0 PKCE flows.
  • Reads assigned ticket summaries, project keys, and issue statuses exclusively to populate worklogs and autocomplete suggestions.
  • All requests communicate directly between your browser and api.atlassian.com.

4. Google API Services User Data Policy (Limited Use)

Chrono's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • Google user data is accessed solely to provide and improve user-facing features (reading calendar event titles for time logging and uploading backup files to Drive).
  • We do not transfer Google user data to third parties, except as necessary to provide or improve these features, comply with applicable law, or as part of an acquisition.
  • We do not use Google user data for serving advertisements.
  • Humans are not permitted to read your Google user data unless you provide explicit consent for troubleshooting, it is necessary for security purposes, or required by law.

5. Extension Permissions & Justifications

Chrono requests only the minimal set of browser permissions strictly required to deliver its core tracking and optional integration features:

storageLocal API

Persists timer entries, projects, labels, and settings locally in chrome.storage.local and IndexedDB (ChronoDB).

alarmsBackground API

Manages periodic badge duration updates (30s), active session reminders, and scheduled Drive backups.

notificationsSystem API

Displays native notifications for idle prompts (after 60s inactivity) and long-running timer warnings.

idleSystem API

Detects system inactivity to prompt saving or discarding active timers with accurate idle time deduction.

activeTabTab API

Captures page titles when triggered via the global shortcut (Alt+T) to auto-populate task descriptions.

identityOAuth API

Provides single-click OAuth 2.0 authentication for Google Calendar, Google Drive, and Atlassian Jira.

https://calendar.google.com/*Host Permission

Injects an interactive Chrono timer button onto Google Calendar meeting popovers.

https://accounts.google.com/* & https://www.googleapis.com/*Host Permission

Communicates directly with Google for Calendar read-only access and Drive cloud backups.

https://auth.atlassian.com/* & https://api.atlassian.com/*Host Permission

Authenticates and synchronizes worklogs with Jira Cloud.

6. Policy Updates & Support Contact

Should our privacy practices update due to browser platform or API changes, revisions will be published on this page.

For inquiries or feedback regarding Chrono's privacy design, contact:

© 2026 Chrono — Time Tracker. All rights reserved.