Privacy Policy
Last updated: 21 August 2026
ChronoLens is a small father-and-son project. This policy explains — in plain language — what data we collect, why, who else touches it, and the rights you have. If anything is unclear, email us at privacy@chronolens.app.
What we collect
In the app
- Your photo. When you snap or pick a photo, it's sent to our AI provider to identify the place and imagine it across history. The photo is used only to generate your result — we don't store it on our servers.
- Your location (optional). If you allow it, your rough GPS position is sent with the photo to help the AI pinpoint the place. It's never stored.
- Your account. If you sign in, we store your email and a user ID (via Supabase Auth) so your journeys can sync.
- Your journeys. Saved places, era images, and the photo you took are stored on your device. If sync is enabled, they're also stored in our Supabase database, linked to your account.
On the support page
- Your email and message. When you report an issue, we store your email, the message, the platform and app version you tell us, and an AI-generated summary of your report.
Who processes your data
We use a small number of third-party processors. Each only gets the data it needs to do its job:
- Supabase (database, authentication, edge functions) — hosts your account and journeys. Data is stored in the EU region.
- Fuel1 / Kimi (AI) — receives your photo and location to identify the place and generate era images, and receives your support message to help us triage it. Fuel1 processes data on our instructions and doesn't use it to train models.
- Resend (email) — receives your email address to send the acknowledgement when you submit a support report.
Why we process it (lawful bases)
- Contract — processing your photo and location is what the app does; without it there's no service.
- Legitimate interest — storing your support report and replying to it; keeping the service secure and rate-limited.
- Consent — optional location access (you can say no and the app still works).
How long we keep it
- Photos and locations — processed transiently, not stored on our servers.
- Account and journeys — kept until you delete them or delete your account.
- Support reports — kept for 12 months, then deleted.
Your rights
Under the GDPR you can ask us to access, correct, export, or delete your personal data, and to object to or restrict how we process it. Email privacy@chronolens.app and we'll sort it out within 30 days. You can also delete your journeys directly in the app.
If you're in the EU/EEA and think we've mishandled your data, you can complain to your local data protection authority.
Children
ChronoLens is a family project and is designed to be safe for younger users, but accounts require an email address. If you're under 16, please get a parent's permission before signing up.
Changes
If we change this policy we'll update the date at the top. Big changes will be announced in the app.
Contact
Data controller: Dali Kilani, privacy@chronolens.app.