01–12Document index12 sections
This register explains the data Chronicle needs to operate a native AI operator, where that data moves, and where Chronicle's responsibility ends and your business's responsibility begins.
Who handles what
Chronicle ("Chronicle", "we", "us") provides an AI operations service for businesses. We act as a controller for account, commercial, security, and support data we use for our own operations. When a business sends us customer conversations and instructions to operate the service, the business generally acts as controller and Chronicle acts as its processor or service provider. The exact legal role can depend on the data and applicable law.
Your business decides why customer data is collected and what Chronicle may do with it. Chronicle must process that customer data only to provide and secure the service, support you, meet law, and follow your documented instructions.
Data we collect
Account data includes your name, work email, business name, Clerk authentication identifier, and support communications.
Business and configuration data includes playbooks, hours, escalation contacts, autonomy settings, rules, connected channels, workflow definitions, and Calendar authorizations.
Conversation and operations data includes inbound and outbound message content, sender or recipient identifiers, channel, timestamps, provider identifiers, classifications, summaries, drafts, confidence and model-route metadata, policy decisions, approvals, corrections, delivery outcomes, and activity-log entries.
Integration data can include connection identifiers, status, encrypted customer-owned connector credentials, and tenant-scoped OAuth tokens. Billing data includes plan, allowance and usage counts, subscription status, provider customer or subscription identifiers, and charge context. Chronicle does not store full payment-card numbers; card processing is handled by the applicable payment processor under a signed order form or commercial arrangement.
Technical and security data can include request and webhook metadata, IP address, user agent, error details, and diagnostic logs needed to prevent abuse and operate the service.
How we use data
We use data to authenticate operators; route and triage inbound work; draft, approve, deliver, and record actions; connect calendars and messaging providers; apply your rules; meter plan usage; operate billing; provide support; protect the service; and meet legal obligations.
Corrections can be stored as active rules for the same business. They are not pooled into another customer's rules.
Chronicle does not sell customer conversation content. We do not use one business's messages or corrections to build a shared training corpus for other businesses.
AI and model processing
Chronicle sends the message content and business context needed to generate classifications or drafts to the configured OpenAI-compatible inference gateway. The current application supports OpenRouter and configured underlying model providers. The selected route and provider can change with configuration, availability, and product updates.
Those providers process prompts and outputs under their API terms and data-handling commitments. Chronicle does not promise that every provider has the same retention or residency terms; customers with contractual model-routing requirements should confirm them before deployment.
A model output is a proposal, not an authority. Chronicle records the action intent and policy result before automated delivery. Urgent, low-confidence, fallback, regulated-channel, unconfirmed-booking, draft-only, and other non-approved cases remain for human action.
Providers and sub-processors
Depending on the features and channels you use, service providers can include Supabase for database services, Clerk for authentication, Vercel for hosting, OpenRouter and underlying model providers for inference, Resend for email, Google for Calendar, Twilio for messaging and voice transport, Vapi for optional voice-agent handoff, Meta as an optional WhatsApp route, and payment processors or billing platforms as applicable to the commercial arrangement.
A provider receives only the categories needed for its function, but its own terms, infrastructure, availability, and legal obligations also apply. The list can change as the service changes; a material change will be reflected in this policy.
Credentials, OAuth, and webhooks
Customer-owned connector credentials are size-validated and encrypted with AES-256-GCM before database storage. The control surface treats submitted values as write-only and does not display them again. Deployment-level provider secrets are supplied through server environment variables. Google OAuth tokens are stored per business and are removed from Chronicle when the connection is disconnected; provider revocation is also requested where available.
Configured webhook routes verify the provider signature or shared secret for Twilio, Meta, Resend, and Vapi before accepting events. Some routes also enforce payload-size and content-type boundaries. A valid signature proves the configured provider sent the request; it does not make message content accurate or lawful.
Security and tenant boundaries
Chronicle uses authenticated control-plane routes, business ownership checks, tenant identifiers on operational records, row-level security with no public database policies, encrypted customer-owned connector credentials, signed webhook verification, and TLS-capable provider endpoints. Privileged server components can access multiple tenants to operate the service and must enforce business scope on every request.
No online service is perfectly secure. This policy describes implemented controls; it is not a claim of a third-party security certification, independent audit, or fitness for a regulated workload unless a signed agreement says otherwise.
Retention and deletion
Chronicle keeps account, conversation, configuration, activity, and subscription records while an account is active and for as long as reasonably needed to operate the service, resolve disputes, prevent abuse, maintain financial records, and meet law. The standard service does not promise a fixed automatic deletion schedule.
You can request access, correction, export, or deletion by emailing support@chronicles.systems from your account email. We will verify authority and act as required by applicable law and our processor obligations. We may retain records that law requires, security records needed to prevent abuse, and de-identified data that no longer identifies a person.
Enterprise retention or region controls are deployment-specific and apply only when agreed during deployment design; they are not a default promise for every plan. Provider copies and logs follow provider retention terms and may not be deleted on Chronicle's exact schedule.
Closing an account or disconnecting a channel does not itself prove that every historical record has been erased. Send a deletion request if deletion is required, and identify any customer records that must be located.
Your data responsibilities
Your business is responsible for the lawful basis, notices, consents, contact lists, suppression lists, and instructions associated with customer data it sends to Chronicle. This includes honoring opt-outs and channel rules and limiting sensitive data to what the workflow genuinely needs.
Do not submit credentials in message text or use Chronicle for data you are not authorized to control. Human approval does not replace customer consent or make an unlawful message lawful.
Rights and international transfers
Depending on location and applicable law, people may have rights to access, correct, delete, export, object to, or restrict use of personal data. A customer should normally contact the business they dealt with; that business can send Chronicle an authenticated processor request. Account holders can contact us directly at support@chronicles.systems.
Chronicle and its providers can process data in the United States and other countries where they operate. Where legally required, the responsible party must use an appropriate transfer mechanism. Contact us before deployment if your organization requires a specific region or contractual transfer safeguard.
Changes and contact
We can update this policy as the product, providers, or law changes. Material changes will be presented through an appropriate service or account notice when required. Privacy questions, rights requests, processor requests, and complaints can be sent to support@chronicles.systems.
Questions / rights requests / billing
Reach our team directly for legal or account inquiries.