Built with
eyes wide open.
Capturing the full depth of a human being — voice, pattern, decision, rhythm — raises real ethical questions. We will not deflect them with corporate language. Here is exactly how we think.
This is not a simple
product category.
Chronis sits at an intersection that has never existed before: continuous biometric capture, private AI trained from scratch on a single person, and the possibility of preserved presence that outlasts a life. Each of those things alone is ethically complex. Together, they require us to think carefully.
We built Chronis because we believe, in the right hands with the right constraints, this technology does genuine good. It helps people know themselves better. It helps families preserve what matters before it's gone. It may, in time, help solve one of the deepest problems in human experience — the fragmentation that happens when a person dies. But that belief carries obligations.
Grief is one use case. Self-quantification — understanding your own patterns, your own decision architecture, your own emotional baseline — is another, and perhaps the one with the most profound long-term implications. Both require the same ethical seriousness. This page is that seriousness, written down.
Six principles.
Not aspirations.
These are not marketing commitments. They are architectural decisions built into how the product works — constraints we cannot override even if we wanted to.
Informed consent, before anything
No data is captured, no model is trained, no replica exists without explicit, informed consent. Not checkbox consent — documented consent with a clear explanation of what the technology does and does not do. We explain the hard parts first, not in footnotes.
You own the model, not us
The AI that Chronis trains on your data is not an asset on our balance sheet. It lives in your private vault. Chronis staff cannot access it without your explicit permission. If you delete it, it is gone — from our infrastructure, not just our database. We have no shadow copy.
Zero training bleed between users
Your data trains only your model. It never improves a shared foundation model, never improves another user's experience, never leaves your vault in a form that carries your identity. This is not the default in AI — it is a deliberate, expensive departure from industry norm.
Honest framing, always
Chronis is an AI. A sophisticated, personality-grounded, emotionally resonant AI — but an AI. We never describe it as bringing someone back. We never obscure the synthetic nature of what the user is experiencing. Clarity about what this is protects the people using it.
Psychological safety is a design requirement
We include grief resource referrals throughout the product. We build in session pacing features to avoid dependence patterns. We actively study the psychological literature on grief technology and adjust accordingly. Wellbeing is a product metric, not an afterthought.
Permanent deletion is unconditional
If you request deletion — of your data, your model, your replica, or your account — it happens immediately and completely. No retention period for "service improvement." No anonymisation that preserves anything identifiable. Deletion means gone.
Three modes.
Total control.
You decide what Chronis does with your signal. Nothing is assumed. Nothing is defaulted. These are not settings in a menu — they are distinct architectures with different data flows and different promises. You choose once; you can change any time.
Your complete AI. Built entirely from you.
Every signal the Locket captures — voice, video, motion, biological rhythm — is used to train a private AI that represents only you. The most complete model of a human being that technology has made possible. And the most private.
- Full voice, video, gyroscope, and BPM dataset used
- Dedicated model trained on your signal exclusively
- Real-time conversation capability fully activated
- Legacy access for designated family members
- Model lives in your private vault, not Chronis servers
Curated intelligence. Only what you choose.
You select which categories of your signal are used in training. Leave out what feels too raw. Include what matters most. The AI reflects the version of you that you are willing to share — no more.
- Choose which signal types are included
- Granular session-level consent controls
- AI trained only on your approved categories
- Expand or restrict scope at any time
- Voice and face reconstruction still available
No AI. Just the archive, untouched.
Zero processing. Zero training. Your recordings are sealed in end-to-end encrypted storage — accessible only to you, processed by nothing, opened only when you choose. A time capsule, not a model.
- Zero AI processing of any kind
- All raw recordings stored encrypted at rest
- Viewable only by vault owner
- Upgrade to Full or Skimmed at any time
- Permanent deletion on request, immediately
The three modes exist because control is not a feature — it is a right. The most ethical thing we can do is build a system where the default is restraint, not extraction.
The questions
we can't fully answer yet.
Intellectual honesty requires acknowledging where we don't have clean answers. These are the hard questions in our space — and our current best thinking on each.
We are building towards a future where wisdom doesn't vanish where we remember everything we evolve from. While this is a step towards generative interface we stay grounded for now not in generic AI, but in the memory, voice, and patterns stored privately and personally.
Almost certainly, yes — and this is not a trivial concern. Seeing your own patterns made explicit (your decision latency, your emotional baseline, your speech rhythm) changes your relationship to those patterns. In some cases this is exactly the point. In others, it may be unwanted.
We believe most people who choose to use Chronis want that self-knowledge. But we build in the ability to stop, to step back, and to never look at your own data if you prefer it as a sealed archive. The Raw Vault mode exists partly for this reason: preservation without observation.
It could — for some people, in some circumstances. Grief is one of the most vulnerable states a human being can be in. Research on grief technology is early, and the evidence is mixed: some people report genuine comfort from continued interaction with a deceased person's digital presence; others report it complicating or prolonging the grief process.
While chronis is capable to make interaction with a deceased person but we only offer it as a complimentary feature. What we do: include grief resource referrals in every session, build session pacing features, avoid features that blur the reality of loss, and make it easy to step away or close the replica permanently. We are not a grief therapy product. We say this clearly, always, without hiding it.
This is a question every long-term data steward must answer honestly, and most don't. Our commitment: in the event Chronis ceases to operate, users receive 180 days notice to export or delete their full dataset and trained model. We are required by our own terms to provide export tools that give users their data in portable formats. No sale of user data to a successor is permitted without opt-in consent per user.
We are also exploring a third-party escrow model for trained models — where the model is held by a neutral party and accessible only to the user — as the most robust version of this commitment. We will publish our progress.
The model is trained on observed behaviour, not described character — which is the most direct guard against this. It not just knows what you said to yourself; it knows how you actually spoke, reasoned, and moved. Fabrication risk is lower when training data is behavioural rather than declarative.
We also build in epistemic transparency: the AI is trained to signal uncertainty, to mention "Data insufficient" and to resist confident responses in areas where training data is thin. A Chronis replica should be recognised as a reconstruction, not a simulation of omniscience. We build that humility into the model architecture.
Yes — significantly. A photograph is passive. It captures a moment and offers no response. A Chronis model captures a pattern and continues to apply it. It can respond to new situations the person never encountered. That is categorically different: it is a form of ongoing agency, however bounded.
This distinction means the ethical stakes are higher, the consent requirements are stricter, and the honesty requirements about what the technology is and is not are non-negotiable. We don't think this means the technology shouldn't exist. We think it means the people building it have a higher obligation to think carefully. We are trying to live up to that obligation.
Not policies.
Architecture.
The commitments below are not just stated in a legal document and never violated by how the product actually works. These commitments are the product. The architecture enforces them.
These are not aspirations. They are
how the code is written.
Chronis based on privacy first architecture
Your data is stored in world's leading databases with advanced private architecture protection.
No cross-user weight sharing
Models trained on one user's data never improve another user's model. No shared foundation model is fine-tuned on your signal. Each model is built from scratch, for one person, isolated completely.
Deletion is total and immediate
When you delete, every record is removed — training data, trained weights, conversation history. Deletion takes effect within 24 hours. We retain no backup beyond a 30-day disaster recovery window, after which even that is purged.
Consent before every data category
Before each new signal type is activated — voice, video, biometric — explicit, documented consent is required. Consent is granular, not blanket. You can grant and revoke per category, per session, at any time.
Epistemic transparency in the model
The AI is trained to signal uncertainty, to acknowledge the limits of its reconstruction, and to resist confident responses where training data is thin. It is honest about what it is — a model, not a person — by design.
Annual privacy audit
Our data handling, model architecture, and deletion processes are audited annually. Audit results are published in summary form.
Satisfied with
where we stand?
If you have questions our ethics framework doesn't address, email us directly. We read every message. We reply to every serious question.