Last updated: 14 August 2026 · Effective: 14 August 2026
Cronicular is an iOS calendar application. The app is operated by Luke Nelson (sole trader, United Kingdom). We are the data controller for personal information processed through Cronicular.
When you sign in we receive:
This data is stored in our backend (Supabase) and used to identify your account and sync your data across devices.
The app also generates a random device identifier (a UUID created on install — not Apple's advertising identifier) and stores it against your account. It is used solely to enforce the free tier's one-device policy (Cronicular Pro removes the limit) and is never used for advertising or shared with third parties.
Cronicular stores the events, anchors, rings, themes, plans and preferences you create inside the app, on-device and synced to Supabase against your account. Photos you attach to anchors stay on your device on the free tier; on Pro they are uploaded to our storage (Supabase) so they sync across your devices. A note on anchor photos: to make cross-device sync work, uploaded anchor photos are stored at a long, random, unguessable web address. They are not listed or searchable anywhere, but anyone who has the exact link could view the photo — so a photo you attach to an anchor should not be something you'd be unwilling to share by link. Removing or replacing the photo in the anchor editor deletes the uploaded copy; you can also ask us to delete any stored photo at any time via [email protected]. If you use 'Import Contact Birthdays', your contacts' names and birth dates are read from your device and stored as anchors in Supabase against your account (only when you choose to run the import).
If you choose to import from Google Calendar, Cronicular uses the Google Calendar API to read your calendars and their events (titles, dates/times, locations and notes) only at the moment you run an import, and only for the calendars you select. Imported events are stored as Cronicular events in Supabase against your account so they appear on your dial. You can disconnect Google at any time in the app, and delete the imported events or your whole account. Cronicular's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we do not use Google Calendar data for advertising, do not sell it, do not transfer it to third parties except as needed to provide the import feature, and do not use it to train machine-learning or AI models. We only use it to provide the calendar-import feature you requested.
If you choose to import from your device's Apple Calendar, Cronicular uses Apple's EventKit framework to read the calendars and events you select — their titles, dates/times, locations and notes — only at the moment you run an import, and only for the calendars you choose. Imported events are stored as Cronicular events in Supabase against your account so they appear on your dial. This read happens on your device; Apple is not a third-party recipient of this data.
If you enable notifications, Cronicular registers a device push token so we can deliver the reminders and alerts you ask for. Tokens are issued by Apple's push service (APNs) and routed through Expo's push notification service (Expo provides our app framework). The token identifies your device, not you personally, and is used only to send notifications you've enabled. You can turn notifications off at any time in iOS Settings.
Cronicular can store a copy of your dial data in your personal iCloud account so it's available across your Apple devices and included in your own backups. This data lives in your iCloud under your Apple ID — we cannot see or access it — and is governed by Apple's iCloud terms and privacy policy.
If you grant permission, Cronicular reads sleep, workout and activity samples from Apple Health to display them on the dial. Apple Health (HealthKit) data never leaves your device — it is not sent to our servers. Any health details you enter manually (such as date of birth, biological sex, blood type, or manually-logged values) are, if you use 'Push to Cloud' (iCloud Sync), stored in your own personal iCloud under your Apple ID — not on our servers, and we cannot see or access them. Health data is never used for advertising or marketing, never shared with ad networks, and never sold — in line with Apple's HealthKit rules and our own policy.
If you enable the Nature ring's local daylight feature, Cronicular asks for your device location (while the app is in use) to calculate your local sunrise, sunset and daylight hours for that ring. Your location is used on your device to compute those times — it is not sent to our servers, stored against your account, sold, or shared. You can decline, or turn location off any time in iOS Settings; the ring then falls back to non-located astronomy.
Crash logs and performance traces are collected via Sentry, hosted in Sentry's EU (Germany) region. We configure Sentry not to collect default personal identifiers (such as your IP address): diagnostic events carry device model, OS version, app version and an opaque account ID (so we can trace a bug to a session) — never your name or email. This data is used only to fix bugs and improve reliability, and is deleted on Sentry's rolling retention (90 days).
To understand which features people actually use, Cronicular records a small set of usage events — for example that a ring was created, a theme was changed, or the paywall was shown. These are first-party: they are written to our own Supabase database in the EU (Frankfurt), and are not sent to any third-party analytics company. We use no analytics SDK.
What an event records is deliberately narrow: the event name, a few low-cardinality descriptors (such as the ring type, or which view you switched to), your account ID, the app version and platform, and a timestamp. It never includes the content of your calendar — no event titles, notes, dates, anchor labels, photos, contacts or health data — and never any free text you have typed. This is enforced in the app's code and by constraints on the database table, not just by policy.
You can turn this off at any time in Settings → Account & Data → Data & Privacy → “Share usage analytics”. Turning it off stops collection immediately and discards anything not yet sent. Usage events are deleted after 400 days.
The free tier of Cronicular shows banner ads supplied by Google AdMob. All ads are currently requested as non-personalised — the app asks Google for non-personalised ads for every user, regardless of your tracking choice, so AdMob does not build an advertising profile of you through Cronicular today. Serving any ad still involves Google receiving basic device information and your IP address to deliver it. Because we never request personalised ads, Cronicular does not show the iOS App Tracking Transparency prompt and does not use your device's advertising identifier to track you. If you are in the UK or EEA, ads are only requested after you have answered Google's certified consent message. If we ever enable personalised ads in future, we will ask for your consent first and update this policy before doing so. Cronicular Pro removes ads entirely.
If you upgrade, Apple processes the payment. We receive a purchase receipt and entitlement state — we do not receive your payment card details.
Some features let you share your own data with others — always by your choice, and revocable at any time:
We process your data to:
We do not sell your data, build advertising profiles outside AdMob, or use your calendar content for machine-learning training.
We share data with a small number of processors:
| Processor | Purpose | Data |
|---|---|---|
| Supabase Inc. | Auth, database, file storage | Account ID, email, calendar data, imported contact birthdays, Pro anchor photos, usage-analytics events (event names + descriptors only). (Manually-entered health details are not sent here — they stay in your own iCloud.) |
| Apple Inc. | Sign in with Apple, IAP, push delivery (APNs) | User ID, purchase receipts, device push token |
| Expo (650 Industries, Inc.) | Push-notification routing | Device push token |
| Google LLC (Calendar API) | Calendar import (optional, only when you run it) | Read access to the Google calendars you select |
| Google LLC (AdMob) | Ads (free tier, non-personalised only) | Coarse device info and IP address needed to deliver an ad. No advertising identifier is used for tracking. |
| Functional Software, Inc. (Sentry) | Crash reporting (EU/Germany region) | Crash & performance data, linked to your account ID; no IP or default PII collected |
| Cloudflare, Inc. | Hosting for this website and the web app (app.cronicular.com) | Standard connection data (IP address, request logs) processed to serve the pages |
We do not share data with anyone else except where required by law.
We keep your account data while your account is active. If you delete your account, we permanently delete it within 30 days. Crash logs are retained for 90 days. Usage-analytics events are retained for 400 days. Backups roll over within 60 days.
You can:
To exercise rights, email [email protected]. We respond within 30 days.
Cronicular is rated 4+ but is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have, contact us and we will delete it.
Supabase processes data in the EU (Frankfurt region) and Sentry crash data is stored in Sentry's EU (Germany) region. Apple, Google, Expo and Cloudflare process data globally (including in the United States) under their published transfer mechanisms (Standard Contractual Clauses, the UK IDTA / Addendum, and — where applicable — the EU–US Data Privacy Framework).
Data is encrypted in transit (TLS 1.2+) and at rest. Supabase row-level security restricts each user's data to their own account. Auth tokens are stored on-device in the iOS Keychain via expo-secure-store.
This website (cronicular.com) does not use cookies. It sets no cookies, runs no analytics or tracking scripts, and loads nothing from advertising or social-media networks — which is why you don't see a cookie banner: there is nothing to consent to. Fonts are served from our own domain (we removed the Google Fonts CDN so your IP address is never sent to Google just for visiting this page).
The site is hosted on Cloudflare Pages. Like any web host, Cloudflare processes your IP address and standard request data transiently to deliver the pages and protect against abuse; we do not receive or keep visitor analytics from it.
The Cronicular web app at app.cronicular.com stores your sign-in session in your browser's session storage (cleared when you close your tabs) and your app preferences in local storage. Both are strictly necessary for the app to work — they are not used for tracking, and no advertising or analytics cookies are set there either.
If you are a resident of California or another US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Utah, Texas and others), you have rights over your personal information. These rights apply in addition to the rights described above.
Depending on your state, you may have the right to:
Do Not Sell or Share My Personal Information. We do not sell your personal information for money. While ads are shown on the free tier they are requested as non-personalised, so we do not "share" your personal information for cross-context behavioural advertising. If we ever enable personalised advertising in the future, we will provide a clear opt-out (and honour Global Privacy Control browser signals on our website) before doing so, and update this policy first.
The categories of personal information we collect are described in section 2, the purposes in section 3, and the third parties we disclose to (for business purposes only) in section 5. We do not knowingly process the personal information of anyone under 16 for sale or sharing.
To exercise any of these rights, email [email protected] or use the in-app tools (Settings → Account & Data). We will verify your request against your account and respond within the timeframe your state law requires (typically 45 days). You may use an authorised agent where your state allows it.
If we materially change this policy we will notify you in-app and update the date at the top of this page.
[email protected]
Luke Nelson · United Kingdom