Privacy Policy

Last updated: 9/1/2026

TL;DR: We are GDPR compliant, aligning with one of the world's most protective data privacy laws. This ensures your data is handled with the highest standard of care, transparency, and security.

Information We Collect

Cronus collects information to provide better services to our users. This section describes the Cronus app for Mac; what the iPhone app collects is narrower and is set out in The iPhone App below. We collect information in the following ways:

  • Information You Provide: This includes your name and email address when you register for an account.
  • Activity and Usage Data: We collect data from your device to power our automatic time-tracking features. This includes metadata about the applications you use and the websites you visit, such as window titles and URLs.

    To categorize your activity accurately, Cronus also reads the text shown in your active window. This happens on your device, using the macOS on-device text recognition (OCR) and accessibility APIs; in a browser, it may read the text of the page you are viewing. The image that text is recognized from exists only in memory for the moment it takes to read it. It is never written to disk and is never sent to us.

    The recognized text itself is sent to our servers, where it is stored and used to categorize your activity, including by the AI provider listed under Third-Party Services below. Before it leaves your device it is scanned for secrets such as passwords, API keys and access tokens, which are replaced with [REDACTED], and it is truncated to 2,000 characters.

    This is what the “Screen Recording” permission is used for. macOS also requires that permission to read another application's window title on 10.15 and later. Granting it is optional: without it, Cronus sees little more than app names and tracks your time far less accurately.
  • Crash Diagnostics: If the app crashes or hits an unexpected error, a diagnostic report is sent to our error-tracking provider so we can fix it. These reports are generated only on a failure and can include the state the app was in at the time, which may contain a window title or URL. They are used solely for debugging.
  • Device Information: We collect basic information about your device, such as its operating system, to ensure our service is compatible and to improve functionality.

The iPhone App

Everything above describes the Cronus app for Mac, which is where automatic tracking happens. The iPhone app is different, and deliberately narrower: iOS does not let an app see which other apps you are using, so Cronus on your phone reads no window titles, no URLs and no on-screen text, and takes no screenshots. Most of what it shows you is the day your Mac recorded, displayed on a smaller screen.

Two things it does collect:

  • Entries you make yourself: the manual entries you start and stop, and the corrections you make to how an activity was categorized. These are the same records the Mac app creates, made from your phone instead.
  • Phone usage, only for apps you add: under Settings → Phone distractions you can name an app and pick it in the Screen Time picker iOS shows you. Cronus then learns how long you spend in that one app, and adds the time to your own timeline alongside what your Mac recorded. This is entirely optional and the rest of the app works without it.

The second one is worth being precise about, because “Screen Time access” sounds broader than it is. Cronus uses Apple's Family Controls and DeviceActivity frameworks, authorized by you for your own device. Those frameworks are built so that we cannot learn what is on your phone: iOS hands the app an opaque token for the app you picked, never its name or bundle identifier, and never a list of what you have installed. What reaches our servers is the label you typed, a duration, and a timestamp. We never receive the identity of any app on your phone, and we never receive anything at all about apps you have not added.

Cronus does not block, restrict or shield any app, and it is not a parental control app. It measures the device it is installed on, for the person who installed it.

The phone also stores your sign-in token in the iOS keychain, and registers a push notification token with Apple so the server can ask what you are working on after your Mac wakes.

Revoking it. Screen Time access can be withdrawn at any time in iOS Settings → Screen Time, or by removing individual apps under Settings → Phone distractions inside Cronus. Once withdrawn, no further usage is measured. Deleting the app removes the stored token from the keychain; to delete the data already collected, use Delete account inside the app, which removes your account and its history entirely.

Signing in with Apple. If you use Sign in with Apple, you may choose to hide your email address, in which case Apple gives us a forwarding address at privaterelay.appleid.com. We store it exactly as given and make no attempt to resolve it to your real address. Apple provides your name only on the first sign-in, so that is the only time we can record it.

How We Use Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Develop new features and functionality
  • Communicate with you about our services
  • Protect Cronus and our users

Third-Party Services

To provide our services, we work with the following trusted third-party providers:

  • OpenAI: We use OpenAI's services to process and analyze your activity data to provide AI-powered insights and categorization
  • Apple: if you use Sign in with Apple, Apple authenticates you and tells us the identifier, and the email address, you agreed to share. On iPhone, Apple's push notification service also delivers the notifications the app sends you.
  • Google OAuth: We use Google's authentication service for secure login and calendar integration (calendar integration is currently in development)
  • MongoDB: We use MongoDB as our database service to store your account and activity data
  • PostHog: We use PostHog for analytics, tracking clicks and views, which may include IP addresses, to improve our app. EU users can opt in; non-EU users are tracked by default with an opt-out option.

These services may have access to your data as necessary to provide their functionality. Each service operates under their own privacy policies and terms of service.

Google API Services and Limited Use Disclosure

The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Limited Use Disclosure: Our application's use of information received from Google Workspace APIs will adhere to Google's Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Limited Use requirements. Specifically, we affirm that:

  • We only use Google user data to provide and improve our time tracking and productivity analysis services.
  • We do not use Google user data for serving advertisements.
  • We do not allow humans to read Google user data unless:
    • We have your explicit consent
    • It is necessary for security purposes
    • It is required to comply with applicable laws
  • We do not sell Google user data or share it with third parties except as necessary to provide and improve our services.

Information Sharing

We share personal information with the third-party services listed above as necessary to provide our services. We do not sell or share your personal information for advertising or marketing purposes.

Data Security

We take reasonable measures to protect your information, though no method of transmission over the internet or electronic storage is 100% secure. We work with reputable third-party services that maintain their own security practices.

Data Retention

We retain personal information only for as long as necessary to provide our services and fulfill the purposes outlined in this privacy policy. When we no longer need personal information, we securely delete or anonymize it.

Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate personal information
  • Request deletion of your personal information — on iPhone you can do this yourself, without contacting us, under Settings → Delete account, which removes your account, your tracked history and any active subscription
  • Object to processing of your personal information
  • Request data portability

To exercise any of these rights, please contact us at the email address provided in the "Contact Us" section. We will process your request in accordance with applicable data protection laws. When you request data portability, we will provide your data in a structured and machine-readable format.

Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Email: wallawitsch@gmail.com

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.