Last updated 14 August 2026
Privacy policy
This page explains what data Kronoz collects, why, and how you can control it. In short: we collect only what's needed to run your shared calendar with your provider or clients, we don't run analytics or advertising, and we don't sell your data.
Who we are
Kronoz is developed and operated by an individual developer based in the United Kingdom, who acts as the data controller for the purposes of UK GDPR. You can reach us at support@kronoz.co.uk for any question about this policy or your data.
What data we collect, and why
Account data — your email address and password, handled by our authentication provider, Supabase Auth. Used to create and secure your account.
Profile data — your name, your role (provider or customer), and, for providers, business or session-type details you enter. Used to operate your calendar and show you correctly to the people you book with.
Booking data — session times, provider-customer relationships, and join codes. This is the core data the app runs on.
Push notification tokens — a device identifier used to deliver notifications (e.g. a client joins your code, a booking is confirmed).
Biometric data — never collected. If you enable Face ID, Touch ID, or fingerprint app-lock, that processing happens entirely on your device. Kronoz never receives, transmits, or stores any biometric data.
Who we share data with
We use a small number of processors to run the app, and share only what each needs to do its job:
- Supabase — our database, authentication, and realtime infrastructure. Your account, profile, and booking data is stored on Supabase's UK (London) infrastructure.
- Apple — to deliver push notifications to iOS devices (APNs).
- Google / Firebase — to deliver push notifications to Android devices (Firebase Cloud Messaging).
- Expo — the push notification relay and app build infrastructure Kronoz is built on.
- Vercel — hosts this website only (not the app itself), and sees standard web server request logs when you visit it.
We do not use analytics or advertising SDKs of any kind, and we do not sell your data to anyone.
International transfers
Your account, profile, and booking data is stored in the United Kingdom (Supabase's London region). Apple, Google, Expo, and Vercel are US-based companies; where they process data on our behalf, they do so under their own standard contractual safeguards for international transfers.
Data retention & account deletion
You can delete your account at any time from within the app (Settings → Delete account). This is immediate and permanent: your profile, bookings, availability, session types, and customer links are deleted straight away, and your login credentials are removed at the same time. We don't hold a recovery window or retain a copy afterward.
If you'd rather not use the in-app flow, email support@kronoz.co.uk from your account's email address and we'll delete your account for you.
Your rights under UK GDPR
You have the right to access, correct, erase, restrict, or receive a copy of your personal data, and to object to how it's processed. To exercise any of these rights, email support@kronoz.co.uk. You also have the right to lodge a complaint with the UK's Information Commissioner's Office (ICO) at ico.org.uk.
Children's privacy
Kronoz is not directed at, and is not knowingly used by, children under 13. If you believe a child has provided us with personal data, contact us and we'll remove it.
Security
Data is encrypted in transit and at rest through our infrastructure provider, Supabase. No method of transmission or storage is 100% secure, but we take reasonable, industry-standard steps to protect your data.
Changes to this policy
If this policy changes, we'll update the “last updated” date at the top of this page. Material changes will be communicated in the app where practical.
Contact
Questions about this policy or your data: support@kronoz.co.uk.