Last updated: 15 July 2026 · Effective: 15 July 2026
Cronicular is an iOS calendar application. The app is operated by Luke Nelson (sole trader, United Kingdom). We are the data controller for personal information processed through Cronicular.
When you sign in we receive:
This data is stored in our backend (Supabase) and used to identify your account and sync your data across devices.
Cronicular stores the events, anchors, rings, themes, plans and preferences you create inside the app, on-device and synced to Supabase against your account. Photos you attach to anchors stay on your device on the free tier; on Pro they are uploaded to our storage (Supabase) so they sync across your devices. A note on anchor photos: to make cross-device sync work, uploaded anchor photos are stored at a long, random, unguessable web address. They are not listed or searchable anywhere, but anyone who has the exact link could view the photo — so a photo you attach to an anchor should not be something you'd be unwilling to share by link. Removing or replacing the photo in the anchor editor deletes the uploaded copy; you can also ask us to delete any stored photo at any time via [email protected]. If you use 'Import Contact Birthdays', your contacts' names and birth dates are read from your device and stored as anchors in Supabase against your account (only when you choose to run the import).
If you choose to import from Google Calendar, Cronicular uses the Google Calendar API to read your calendars and their events (titles, dates/times, locations and notes) only at the moment you run an import, and only for the calendars you select. Imported events are stored as Cronicular events in Supabase against your account so they appear on your dial. You can disconnect Google at any time in the app, and delete the imported events or your whole account. Cronicular's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we do not use Google Calendar data for advertising, do not sell it, do not transfer it to third parties except as needed to provide the import feature, and do not use it to train machine-learning or AI models. We only use it to provide the calendar-import feature you requested.
If you choose to import from your device's Apple Calendar, Cronicular uses Apple's EventKit framework to read the calendars and events you select — their titles, dates/times, locations and notes — only at the moment you run an import, and only for the calendars you choose. Imported events are stored as Cronicular events in Supabase against your account so they appear on your dial. This read happens on your device; Apple is not a third-party recipient of this data.
If you enable notifications, Cronicular registers a device push token so we can deliver the reminders and alerts you ask for. Tokens are issued by Apple's push service (APNs) and routed through Expo's push notification service (Expo provides our app framework). The token identifies your device, not you personally, and is used only to send notifications you've enabled. You can turn notifications off at any time in iOS Settings.
Cronicular can store a copy of your dial data in your personal iCloud account so it's available across your Apple devices and included in your own backups. This data lives in your iCloud under your Apple ID — we cannot see or access it — and is governed by Apple's iCloud terms and privacy policy.
If you grant permission, Cronicular reads sleep, workout and activity samples from Apple Health to display them on the dial. Apple Health (HealthKit) data never leaves your device — it is not sent to our servers. Any health details you enter manually (such as date of birth, biological sex, blood type, or manually-logged values) are, if you use 'Push to Cloud' (iCloud Sync), stored in your own personal iCloud under your Apple ID — not on our servers, and we cannot see or access them. Health data is never used for advertising or marketing, never shared with ad networks, and never sold — in line with Apple's HealthKit rules and our own policy.
If you enable the Nature ring's local daylight feature, Cronicular asks for your device location (while the app is in use) to calculate your local sunrise, sunset and daylight hours for that ring. Your location is used on your device to compute those times — it is not sent to our servers, stored against your account, sold, or shared. You can decline, or turn location off any time in iOS Settings; the ring then falls back to non-located astronomy.
Crash logs and performance traces are collected via Sentry, hosted in Sentry's EU (Germany) region. We configure Sentry not to collect default personal identifiers (such as your IP address): diagnostic events carry device model, OS version, app version and an opaque account ID (so we can trace a bug to a session) — never your name or email. This data is used only to fix bugs and improve reliability, and is deleted on Sentry's rolling retention (90 days).
The free tier of Cronicular shows banner ads supplied by Google AdMob. All ads are currently requested as non-personalised — the app asks Google for non-personalised ads for every user, regardless of your tracking choice, so AdMob does not build an advertising profile of you through Cronicular today. Serving any ad still involves Google receiving basic device information and your IP address to deliver it. iOS may show you the App Tracking Transparency prompt the first time an ad is about to appear; if we ever enable personalised ads in future, we will ask for your consent first (via Google's certified consent flow for UK/EEA users) and update this policy before doing so. Cronicular Pro removes ads entirely.
If you upgrade, Apple processes the payment. We receive a purchase receipt and entitlement state — we do not receive your payment card details.
Some features let you share your own data with others — always by your choice, and revocable at any time:
We process your data to:
We do not sell your data, build advertising profiles outside AdMob, or use your calendar content for machine-learning training.
We share data with a small number of processors:
| Processor | Purpose | Data |
|---|---|---|
| Supabase Inc. | Auth, database, file storage | Account ID, email, calendar data, imported contact birthdays, Pro anchor photos. (Manually-entered health details are not sent here — they stay in your own iCloud.) |
| Apple Inc. | Sign in with Apple, IAP, push delivery (APNs) | User ID, purchase receipts, device push token |
| Expo (650 Industries, Inc.) | Push-notification routing | Device push token |
| Google LLC (Calendar API) | Calendar import (optional, only when you run it) | Read access to the Google calendars you select |
| Google LLC (AdMob) | Ads (free tier) | IDFA (if you consent), coarse device info |
| Functional Software, Inc. (Sentry) | Crash reporting (EU/Germany region) | Crash & performance data, linked to your account ID; no IP or default PII collected |
| Cloudflare, Inc. | Hosting for this website and the web app (app.cronicular.com) | Standard connection data (IP address, request logs) processed to serve the pages |
We do not share data with anyone else except where required by law.
We keep your account data while your account is active. If you delete your account, we permanently delete it within 30 days. Crash logs are retained for 90 days. Backups roll over within 60 days.
You can:
To exercise rights, email [email protected]. We respond within 30 days.
Cronicular is rated 4+ but is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have, contact us and we will delete it.
Supabase processes data in the EU (Frankfurt region) and Sentry crash data is stored in Sentry's EU (Germany) region. Apple, Google, Expo and Cloudflare process data globally (including in the United States) under their published transfer mechanisms (Standard Contractual Clauses, the UK IDTA / Addendum, and — where applicable — the EU–US Data Privacy Framework).
Data is encrypted in transit (TLS 1.2+) and at rest. Supabase row-level security restricts each user's data to their own account. Auth tokens are stored on-device in the iOS Keychain via expo-secure-store.
This website (cronicular.com) does not use cookies. It sets no cookies, runs no analytics or tracking scripts, and loads nothing from advertising or social-media networks — which is why you don't see a cookie banner: there is nothing to consent to. Fonts are served from our own domain (we removed the Google Fonts CDN so your IP address is never sent to Google just for visiting this page).
The site is hosted on Cloudflare Pages. Like any web host, Cloudflare processes your IP address and standard request data transiently to deliver the pages and protect against abuse; we do not receive or keep visitor analytics from it.
The Cronicular web app at app.cronicular.com stores your sign-in session in your browser's session storage (cleared when you close your tabs) and your app preferences in local storage. Both are strictly necessary for the app to work — they are not used for tracking, and no advertising or analytics cookies are set there either.
If you are a resident of California or another US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Utah, Texas and others), you have rights over your personal information. These rights apply in addition to the rights described above.
Depending on your state, you may have the right to:
Do Not Sell or Share My Personal Information. We do not sell your personal information for money. While ads are shown on the free tier they are requested as non-personalised, so we do not "share" your personal information for cross-context behavioural advertising. If we ever enable personalised advertising in the future, we will provide a clear opt-out (and honour Global Privacy Control browser signals on our website) before doing so, and update this policy first.
The categories of personal information we collect are described in section 2, the purposes in section 3, and the third parties we disclose to (for business purposes only) in section 5. We do not knowingly process the personal information of anyone under 16 for sale or sharing.
To exercise any of these rights, email [email protected] or use the in-app tools (Settings → Account & Data). We will verify your request against your account and respond within the timeframe your state law requires (typically 45 days). You may use an authorised agent where your state allows it.
If we materially change this policy we will notify you in-app and update the date at the top of this page.
[email protected]
Luke Nelson · United Kingdom