//Kronolog

Privacy Policy

Last updated: June 2026

1. Controller

The controller responsible for processing your personal data under the GDPR is Asli S. You can reach us at support@kronolog.com. Full contact and address details are available in our Imprint.

We do not sell your personal data. We do not use your content to train AI models.

2. Data We Collect and Why

Account data (GitHub OAuth)

When you sign in with GitHub, we receive your GitHub username, display name, email address, and avatar URL. We use this to create and identify your account. We do not request access to your repositories, organisations, or any other GitHub data. Legal basis: Art. 6(1)(b) GDPR — necessary for the performance of the service contract.

Content data

Posts, drafts, tags, profile bio, and other content you create are stored in your account. Private posts are visible only to you and are never shared with other users or indexed by search engines. Published posts are publicly accessible. Legal basis: Art. 6(1)(b) GDPR.

Usage analytics

We use Umami Cloud, a cookie-free analytics tool, to understand how the site is used in aggregate. Umami does not set cookies, does not track you across sites, and does not collect personal data. The data it processes (page views, referrers, browser type) is anonymised and aggregated. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in understanding and improving site usage.

Infrastructure logs

Our hosting provider (Vercel) automatically records standard server logs including IP addresses, request timestamps, and user-agent strings. IP addresses are used transiently for rate limiting and security purposes and are not stored or linked to individual accounts beyond the log retention period. Logs are retained for up to 30 days. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in operating a secure service.

Session cookie

We set a single, essential session cookie (managed by Supabase Auth) to keep you signed in. This cookie contains a session token only — no personal data, no tracking, no advertising. It is automatically deleted when you sign out or your session expires. Essential cookies do not require consent under GDPR or the ePrivacy Directive.

3. Sub-Processors

We share data with the following service providers who process it on our behalf:

  • Supabase, Inc. (San Francisco, US) — database, authentication, and file storage. Your account data and content are stored on Supabase infrastructure.
  • Vercel, Inc. (San Francisco, US) — hosting and global content delivery. All web requests are processed through Vercel, which may log IP addresses and request metadata.
  • Umami Software, Inc. (US) — cookie-free, anonymised analytics. No personal data is transferred.
  • GitHub, Inc. / Microsoft Corporation (US) — OAuth authentication only. We receive a minimal profile payload at sign-in; no ongoing data sharing occurs.

Transfers to US-based providers are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission, which provide appropriate safeguards for international data transfers under Art. 46 GDPR.

4. Retention

Account and content data is retained for as long as your account is active. If you delete your account, your data is permanently removed from our systems within 30 days, except where retention is required by law. Infrastructure logs are retained for up to 30 days. Umami analytics data is aggregated and contains no personal data.

5. Your Rights

Under the GDPR, you have the following rights:

  • Access (Art. 15) — request a copy of the data we hold about you.
  • Rectification (Art. 16) — correct inaccurate personal data.
  • Erasure (Art. 17) — request deletion of your personal data.
  • Restriction (Art. 18) — restrict how we process your data in certain circumstances.
  • Portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interests.

To exercise any of these rights or to submit a data deletion or access request, contact us at support@kronolog.com. We will respond within 30 days.

6. Right to Lodge a Complaint

You have the right to lodge a complaint with the data protection supervisory authority competent for your place of residence or the location of the alleged infringement. In Germany, this is the supervisory authority of the federal state in which the controller is established.

7. Changes to This Policy

We may update this policy from time to time. Material changes will be announced on the platform at least 14 days before taking effect. The date at the top of this page always reflects the most recent revision.

Last updated: June 2026

© 2026 Kronolog·Privacy·Terms·Imprint