Privacy Architecture

Your data is yours.
Not a commodity.

Chronis captures the deepest signals of a human life — voice, biometrics, behavioral patterns, decision rhythms. This document explains exactly what we collect, where it lives, who can access it, and what happens to it. No buried clauses.

DPDP Act 2023 Compliant AES-256 at Rest Zero Third-Party Data Sale
Last reviewed April 2026
Read below

What we collect

The signals that
make you, you.

Chronis is not a messaging app. It captures the depth of a human being — biometric, behavioral, environmental, structural. Every data type is listed here with full transparency. Nothing is collected that is not on this list.

Biometric

Voice & Acoustic Identity

Full-spectrum voice recordings processed into a neural vocal signature — pitch contours, prosody, micro-pauses, emotional inflection, accent drift over time.

  • Raw audio waveforms (locket microphone)
  • Extracted vocal embeddings (not reversible to audio)
  • Heart-rate variability from locket BPM sensor
  • Breathing rhythm patterns during conversation
Biometric

Facial & Visual Presence

Video frames captured by the locket camera when open. Facial geometry is processed locally on-device into embeddings for replica fidelity — raw frames are never permanently stored unless you elect Full Dataset mode.

  • Facial landmark geometry (468 points)
  • Micro-expression temporal sequences
  • Eye movement and gaze direction
  • Lighting-normalized skin tone reference
Behavioural

Motion & Somatic Patterns

The locket accelerometer and gyroscope record how you move through the world — walking cadence, gesture vocabulary, rest stillness, posture shifts during speech.

  • 6-axis IMU data (3-axis accel + 3-axis gyro)
  • Walking rhythm and cadence fingerprint
  • Gestural emphasis during conversation
  • Rest vs. active state classification
Ambient

Environmental Context

Where and when moments occur gives them meaning. Ambient audio, time-of-day, and location context (opt-in, coarse) tag your data with the texture of your life.

  • Ambient sound environment classification
  • Time-of-day and day-of-week metadata
  • Coarse location (city-level, opt-in only)
  • Social context detection (alone / group)
AI Model

Conversation & Linguistic DNA

Every session with your Chronis replica generates a conversation record — not just words, but the structure of how you think, argue, comfort, and question.

  • Full session transcripts (your words + replica's)
  • Topic and emotional arc metadata
  • Linguistic pattern vectors (vocabulary, syntax)
  • Decision and reasoning pattern signatures
Structural

Account & Operational Data

The administrative layer that makes Chronis function — identity, payment processing, support interactions, and minimal usage telemetry for product reliability.

  • Name, email, phone (account registration)
  • Payment tokens (Razorpay — never stored by us)
  • Device identifiers (locket serial + app UUID)
  • Anonymised crash and error telemetry

How data flows

From locket
to vault.

The journey of every signal captured by the Chronis locket — from sensor to encrypted storage to model training. Every step is described here, with the privacy control applied at each stage.

End-to-end data pipeline
Six stages from sensor capture to model inference. Your privacy mode governs what survives past stage three.
AES-256 · TLS 1.3
1
On-device
Sensor capture & local pre-processing
The locket's hardware sensors — microphone, camera, IMU, photoplethysmograph — capture raw signals. Initial feature extraction (vocal embeddings, facial landmarks, motion primitives) runs on the locket's secure enclave chip. Raw pixels and raw audio are not transmitted in this stage.
On-device only
2
Transmission
Encrypted transit over TLS 1.3
Extracted features (not raw data) are transmitted from locket to Chronis servers over TLS 1.3 with certificate pinning. Payload is additionally encrypted with your user-specific key before leaving the device. No plaintext data ever traverses the network.
TLS 1.3 + payload encryption
3
Privacy Gate
Mode-based routing — your choice governs what continues
At our ingestion layer, your elected privacy mode determines what happens next. Raw Vault: data is encrypted with your key and written to cold storage — no processing occurs. Skimmed Dataset: only sessions you've explicitly approved proceed to training. Full Dataset: all signals proceed to model training infrastructure.
Your mode controls this
4
Model Training
Isolated per-user model infrastructure
If your mode permits training, your data enters a federated training enclaveAn isolated compute environment where your model trains on only your data — no shared weights, no data leakage to other users' models. with zero shared weights across users. Your model architecture is dedicated to your account. Chronis staff have no access to model internals; only your account can trigger inference.
Isolated per-user compute
5
Encrypted Storage
AES-256 encrypted vault, key held by you
All stored data — raw signals (if applicable), feature vectors, conversation transcripts, and model weights — is encrypted at rest with AES-256-GCM. For Full Vault mode users, the master decryption key is derived from your credentials and never held by Chronis in plaintext. We are architecturally incapable of reading your vault without your active authentication.
AES-256-GCM at rest
6
Inference
Replica sessions run in ephemeral compute
When you open a session, your model is loaded into an ephemeral compute instance that terminates when the session ends. No session state persists between conversations unless you have enabled persistent memory. Conversation logs are written back to your encrypted vault only — never to shared infrastructure.
Ephemeral compute · no cross-session leak

Privacy modes

You choose the
depth of exposure.

Three modes — chosen at setup, changeable anytime. Your mode is not a setting buried in a menu. It is the foundation of what Chronis is allowed to do with your data. Changing it triggers a model rebuild from your approved dataset.

Skimmed Dataset

Your AI.
Only what you choose.

Granular session-level consent. Include Sunday mornings. Exclude the hospital room. The model learns only what you consciously let through — nothing is assumed included.

Signal-type toggles: voice, video, motion, BPM each independently includable
Session redaction — flag any window of time as off-record before it is processed
Re-scope training at any point; model rebuilds cleanly from the updated approved dataset
Voice and face reconstruction available even on minimal datasets
Behavioral patterns learn from approved sessions only — no inference across redacted gaps
Raw Vault

Sealed.
Nothing touches it.

End-to-end encrypted. Nothing is processed. No AI is trained. A sealed chronological record of your life — readable only by you, invisible to every system including ours.

Zero inference, zero processing — client-side encryption before data leaves the locket hardware
Chronis has no technical pathway to your vault contents — enforced by architecture, not policy
Upgrade to Full or Skimmed at any time; archived data becomes the training foundation immediately
Permanent deletion is cryptographically verifiable and physically irreversible — proof on request
Use as a personal archive of your life even with no intention of AI training

Hard limits

What Chronis will
never do.

We are building a system that holds the most intimate data that has ever been collected about a human being. That is either the most trustworthy thing ever built, or the most dangerous. The hard limits below are not policy — they are architectural constraints enforced in code.

Chronis Design Principle · Privacy-First Architecture
Action
Status
Enforcement
Sell or transfer personal data to any third party
Never · Ever
Contractual + architectural
Use your data to train any shared AI model
Prohibited
Isolated per-user infra
Allow advertisers access to your data or behavior
Prohibited
Zero ad infrastructure
Allow government access without valid legal process
Prohibited
Legal challenge + user notice*
Retain data after deletion request is confirmed
Prohibited
30-day purge window
Share voice or facial data with any third party
Prohibited
Vault isolation
Access your vault without active user authentication
Architecturally impossible
Key derivation from your credentials
Collect data from users under 18
Prohibited
Age verification at signup

* We will resist unlawful requests, notify affected users when legally permitted, and publish a transparency report annually.


Your rights

Data principal rights
under DPDP 2023.

India's Digital Personal Data Protection Act 2023 gives you specific rights over your personal data. Chronis is built to honour all of them — and in several cases, goes further than what the Act requires.

I

Right to Access & Summary

Request a complete summary of all personal data Chronis holds about you — including data types, processing purposes, third parties engaged, and the basis for processing. Delivered within 72 hours.

Request access
II

Right to Correction

Request correction of inaccurate or incomplete personal data. For biometric data, this means the ability to re-record voice or video to update the model's training foundation.

Request correction
III

Right to Erasure

Permanent deletion of your account, all stored signals, your trained model weights, and all associated metadata. Deletion is cryptographically verifiable and complete within 30 days with proof provided on request.

Initiate deletion
IV

Right to Data Portability

Export your full data vault in open formats — audio files, transcripts, motion logs, and model metadata — to take elsewhere. Your model belongs to you. We provide export tooling at any time.

Export data
V

Right to Withdraw Consent

Change your privacy mode at any time without consequence. Withdraw consent for AI training and your data immediately stops being processed. The model freezes at its last state until you re-consent or delete.

Manage consent
VI

Right to Grievance Redressal

Contact our Data Protection Officer with any privacy concern. We respond within 48 hours. You may also escalate to India's Data Protection Board if you believe your rights have been violated.

Contact DPO

Technical safeguards

The technical
architecture of trust.

Privacy is only as strong as the code that enforces it. Below is the technical implementation of our security posture — not marketing language, but the actual mechanisms.

Layer
Technology
Standard
Data at rest
AES-256-GCM
FIPS 140-2
Data in transit
TLS 1.3 + cert pinning
RFC 8446
Key derivation (vault)
Argon2id from user credentials
PHC winner
On-device processing
Secure Enclave (ARM TrustZone)
ISO/IEC 19790
Model training isolation
Per-user compute enclaves
Zero shared weights
Authentication
TOTP + device binding
RFC 6238
Deletion verification
Cryptographic proof of deletion
Merkle tree audit log
Penetration testing
Bi-annual third-party audit
OWASP ASVS L3

Legal framework

Compliance is the
floor, not the ceiling.

We comply with all applicable law. We also go further — because the sensitivity of what Chronis holds demands it.

India · DPDP 2023

Digital Personal Data Protection Act 2023

Chronis is registered as a Data Fiduciary under the DPDP Act. We maintain a Data Protection Officer, respond to Data Principal requests within statutory timelines, and have implemented all Significant Data Fiduciary obligations including impact assessments and algorithmic audits.

India · IT Act 2000

Information Technology Act & SPDI Rules

All Sensitive Personal Data and Information (SPDI) — including biometric and health data — is processed under our published Privacy Policy in accordance with the IT (Amendment) Act 2008 and the IT (SPDI) Rules 2011, with explicit written consent obtained before collection.

Global · EU Reference

GDPR-Aligned Practices (International)

Although India-incorporated, Chronis voluntarily aligns with GDPR Articles 9 (special category data) and 25 (data protection by design) given the biometric nature of our data. International users benefit from these protections as a baseline standard.

Global · Biometrics

Biometric Data Special Handling

Voice prints, facial geometry, and BPM patterns are classified as special category biometric data requiring explicit consent, purpose limitation, storage minimisation, and enhanced security measures. These are never used beyond replica construction without separate explicit consent.

Global · Children

Children's Data Protection

Chronis is not available to persons under 18 years of age anywhere. We verify age at registration using government-ID validation. Any account discovered to belong to a minor is immediately suspended and all associated data deleted without retention.

Cross-border

Data Localisation & Transfer

Personal data of Indian citizens is stored on servers located within India. Cross-border data transfers (if required for technical operations) occur only to countries with adequate protection frameworks, under Standard Contractual Clauses, and with user notification.


Deletion & exit

Deletion is
genuinely permanent.

Most companies say "we delete your data" and then keep backups for 90 days. That is not deletion. Chronis deletion is cryptographically enforced — when you delete, we destroy the encryption key. The ciphertext becomes permanently inaccessible, not just inaccessible to us.

Deletion request triggers immediate key destruction — vault content becomes permanently inaccessible
Backup copies (which hold only ciphertext) are purged within 30 days — a cryptographic proof of deletion is issued on request
Your trained model weights, conversation transcripts, signal data, and account metadata are all included in deletion scope
We send one confirmation email 7 days before permanent deletion is finalised — after which there is no technical path to recovery
To initiate: email privacy@chronis.in with subject line "Account Deletion Request" or use the in-app deletion option under Settings → Privacy → Delete everything

Third-party processors

Who else
touches your data.

We engage a small number of third-party processors. None of them receive personal data in identifiable form. All are bound by data processing agreements under DPDP 2023 and GDPR-aligned standards.

Processor
Purpose
Data Shared
Razorpay
Payment processing
Payment tokens only — no biometrics
AWS India (ap-south-1)
Encrypted vault storage & compute
AES-256 ciphertext only
Twilio (India)
SMS notifications (opt-in)
Phone number only
Mixpanel (anonymised)
Product analytics
Anonymous event metadata
Sentry
Error and crash reporting
Sanitised stack traces — no personal data

No personal data is shared with any AI model vendor, data broker, government entity (except under valid legal compulsion), advertiser, or analytics provider in identifiable form.


Cookies & tracking

Minimal. Declared.
No surveillance.

We use three categories of cookies. That is all. No advertising networks. No cross-site tracking. No behavioural fingerprinting.

Cookie Type
Purpose
Deletable?
Session authentication
Keep you logged in securely
Yes — logs you out
Privacy mode preference
Remember your elected data mode
Yes — resets to default
Anonymous analytics
Product improvement (opt-out available)
Yes — opt-out in settings

Contact & oversight

Questions about
your privacy?

Contact our Data Protection Officer directly. We respond within 48 hours. No automated replies, no ticket queues — a human helping you over your request.

privacy@chronis.in →
DPO

Data Protection Officer

Chronis
privacy@chronis.in · Response: 48 hours

Escalation

Data protection, mail to our CEO.

If you believe your rights under DPDP 2023 have been violated and we have not resolved your concern, or you find the issue wasn't addressed well mail us at. founders@chronis.in