Your data is yours.
Not a commodity.
Chronis captures the deepest signals of a human life — voice, biometrics, behavioral patterns, decision rhythms. This document explains exactly what we collect, where it lives, who can access it, and what happens to it. No buried clauses.
The signals that
make you, you.
Chronis is not a messaging app. It captures the depth of a human being — biometric, behavioral, environmental, structural. Every data type is listed here with full transparency. Nothing is collected that is not on this list.
Voice & Acoustic Identity
Full-spectrum voice recordings processed into a neural vocal signature — pitch contours, prosody, micro-pauses, emotional inflection, accent drift over time.
- Raw audio waveforms (locket microphone)
- Extracted vocal embeddings (not reversible to audio)
- Heart-rate variability from locket BPM sensor
- Breathing rhythm patterns during conversation
Facial & Visual Presence
Video frames captured by the locket camera when open. Facial geometry is processed locally on-device into embeddings for replica fidelity — raw frames are never permanently stored unless you elect Full Dataset mode.
- Facial landmark geometry (468 points)
- Micro-expression temporal sequences
- Eye movement and gaze direction
- Lighting-normalized skin tone reference
Motion & Somatic Patterns
The locket accelerometer and gyroscope record how you move through the world — walking cadence, gesture vocabulary, rest stillness, posture shifts during speech.
- 6-axis IMU data (3-axis accel + 3-axis gyro)
- Walking rhythm and cadence fingerprint
- Gestural emphasis during conversation
- Rest vs. active state classification
Environmental Context
Where and when moments occur gives them meaning. Ambient audio, time-of-day, and location context (opt-in, coarse) tag your data with the texture of your life.
- Ambient sound environment classification
- Time-of-day and day-of-week metadata
- Coarse location (city-level, opt-in only)
- Social context detection (alone / group)
Conversation & Linguistic DNA
Every session with your Chronis replica generates a conversation record — not just words, but the structure of how you think, argue, comfort, and question.
- Full session transcripts (your words + replica's)
- Topic and emotional arc metadata
- Linguistic pattern vectors (vocabulary, syntax)
- Decision and reasoning pattern signatures
Account & Operational Data
The administrative layer that makes Chronis function — identity, payment processing, support interactions, and minimal usage telemetry for product reliability.
- Name, email, phone (account registration)
- Payment tokens (Razorpay — never stored by us)
- Device identifiers (locket serial + app UUID)
- Anonymised crash and error telemetry
From locket
to vault.
The journey of every signal captured by the Chronis locket — from sensor to encrypted storage to model training. Every step is described here, with the privacy control applied at each stage.
You choose the
depth of exposure.
Three modes — chosen at setup, changeable anytime. Your mode is not a setting buried in a menu. It is the foundation of what Chronis is allowed to do with your data. Changing it triggers a model rebuild from your approved dataset.
Train your own AI.
On everything.
Every signal the locket captures builds a model that has only ever seen you. Not fine-tuned. Not a persona layer. Built from scratch on your data alone. The richest self-quantification possible.
Your AI.
Only what you choose.
Granular session-level consent. Include Sunday mornings. Exclude the hospital room. The model learns only what you consciously let through — nothing is assumed included.
Sealed.
Nothing touches it.
End-to-end encrypted. Nothing is processed. No AI is trained. A sealed chronological record of your life — readable only by you, invisible to every system including ours.
What Chronis will
never do.
We are building a system that holds the most intimate data that has ever been collected about a human being. That is either the most trustworthy thing ever built, or the most dangerous. The hard limits below are not policy — they are architectural constraints enforced in code.
* We will resist unlawful requests, notify affected users when legally permitted, and publish a transparency report annually.
Data principal rights
under DPDP 2023.
India's Digital Personal Data Protection Act 2023 gives you specific rights over your personal data. Chronis is built to honour all of them — and in several cases, goes further than what the Act requires.
Right to Access & Summary
Request a complete summary of all personal data Chronis holds about you — including data types, processing purposes, third parties engaged, and the basis for processing. Delivered within 72 hours.
Right to Correction
Request correction of inaccurate or incomplete personal data. For biometric data, this means the ability to re-record voice or video to update the model's training foundation.
Right to Erasure
Permanent deletion of your account, all stored signals, your trained model weights, and all associated metadata. Deletion is cryptographically verifiable and complete within 30 days with proof provided on request.
Right to Data Portability
Export your full data vault in open formats — audio files, transcripts, motion logs, and model metadata — to take elsewhere. Your model belongs to you. We provide export tooling at any time.
Right to Withdraw Consent
Change your privacy mode at any time without consequence. Withdraw consent for AI training and your data immediately stops being processed. The model freezes at its last state until you re-consent or delete.
Right to Grievance Redressal
Contact our Data Protection Officer with any privacy concern. We respond within 48 hours. You may also escalate to India's Data Protection Board if you believe your rights have been violated.
The technical
architecture of trust.
Privacy is only as strong as the code that enforces it. Below is the technical implementation of our security posture — not marketing language, but the actual mechanisms.
Compliance is the
floor, not the ceiling.
We comply with all applicable law. We also go further — because the sensitivity of what Chronis holds demands it.
Digital Personal Data Protection Act 2023
Chronis is registered as a Data Fiduciary under the DPDP Act. We maintain a Data Protection Officer, respond to Data Principal requests within statutory timelines, and have implemented all Significant Data Fiduciary obligations including impact assessments and algorithmic audits.
Information Technology Act & SPDI Rules
All Sensitive Personal Data and Information (SPDI) — including biometric and health data — is processed under our published Privacy Policy in accordance with the IT (Amendment) Act 2008 and the IT (SPDI) Rules 2011, with explicit written consent obtained before collection.
GDPR-Aligned Practices (International)
Although India-incorporated, Chronis voluntarily aligns with GDPR Articles 9 (special category data) and 25 (data protection by design) given the biometric nature of our data. International users benefit from these protections as a baseline standard.
Biometric Data Special Handling
Voice prints, facial geometry, and BPM patterns are classified as special category biometric data requiring explicit consent, purpose limitation, storage minimisation, and enhanced security measures. These are never used beyond replica construction without separate explicit consent.
Children's Data Protection
Chronis is not available to persons under 18 years of age anywhere. We verify age at registration using government-ID validation. Any account discovered to belong to a minor is immediately suspended and all associated data deleted without retention.
Data Localisation & Transfer
Personal data of Indian citizens is stored on servers located within India. Cross-border data transfers (if required for technical operations) occur only to countries with adequate protection frameworks, under Standard Contractual Clauses, and with user notification.
Deletion is
genuinely permanent.
Most companies say "we delete your data" and then keep backups for 90 days. That is not deletion. Chronis deletion is cryptographically enforced — when you delete, we destroy the encryption key. The ciphertext becomes permanently inaccessible, not just inaccessible to us.
Who else
touches your data.
We engage a small number of third-party processors. None of them receive personal data in identifiable form. All are bound by data processing agreements under DPDP 2023 and GDPR-aligned standards.
No personal data is shared with any AI model vendor, data broker, government entity (except under valid legal compulsion), advertiser, or analytics provider in identifiable form.
Minimal. Declared.
No surveillance.
We use three categories of cookies. That is all. No advertising networks. No cross-site tracking. No behavioural fingerprinting.
Questions about
your privacy?
Contact our Data Protection Officer directly. We respond within 48 hours. No automated replies, no ticket queues — a human helping you over your request.
Data Protection Officer
Chronis
privacy@chronis.in · Response: 48 hours
Data protection, mail to our CEO.
If you believe your rights under DPDP 2023 have been violated and we have not resolved your concern, or you find the issue wasn't addressed well mail us at. founders@chronis.in