1. Data controller
The controller of your personal data is Artur Przybyło, ul. Spółdzielców 11/195, 30-682 Kraków, Poland, tax ID (NIP): 9452153899. Privacy contact: kontakt@chronicos.app.
ChronicOS (“the app”) helps people with Crohn’s disease or ulcerative colitis organize their own records and prepare for a doctor visit. We are not a medical facility or a medical-device manufacturer. The app does not diagnose or recommend treatment.
2. What data we process
Special-category health data (GDPR Art. 9), if you enter it:
- day summaries: pain, energy, stool, blood, urgency, sleep, stress, mood, notes,
- meals and tags, “I suspect” flags,
- medications, doses, and “taken” marks,
- lab results entered manually and PDF attachment metadata,
- profile: nickname, condition (Crohn/UC), diagnosis year, doctor and clinic,
- calendar: visits, planned labs, and other dates (day, time, place, note).
2b. Account and consent data
Email address (passwordless sign-in), user id, timestamps, versioned sync consents (consent log).
2c. Analytics, diagnostics, and dictation
App (optional): PostHog (usage events without diary contents) and Sentry (crashes/stack traces without notes, med names, or lab values). We don’t require a national ID or payment details in the current version.
Website chronicos.app: PostHog (EU) measures page visits (URL/path, referrer, device/browser type). We do not collect diary contents or health data from the app. We do not use session replay. Session identifiers stay in browser memory (no persistent marketing cookie).
Meal dictation: on-device speech recognition. We do not send recordings to ChronicOS servers. If the phone has no on-device recognition, type the meal. We do not store and we do not retain audio.
2d. Location (toilet map)
If you use the toilet map, the app first shows an in-app explanation, then asks the system for location while in use (when-in-use). We need it to show nearby toilets from OpenStreetMap.
An approximate search area (coordinates in the query, not a location history) is sent to the public Overpass API (OpenStreetMap, overpass-api.de). If you tap navigation, we open Apple or Google Maps with the destination. We do not save location to your ChronicOS account or our cloud. You can deny permission; the toilet map then won’t work.
3. Purposes and legal bases
You may withdraw consent to processing health data in the cloud and to sync at any time (More → Account). Withdrawal does not affect processing before withdrawal.
- Keeping a diary and local pattern analysis — explicit consent (Art. 9(2)(a)).
- Account and cross-device sync (cloud) — explicit consent (Art. 9(2)(a)) and performance of a contract (Art. 6(1)(b)).
- Sending sign-in link/code — performance of a contract (Art. 6(1)(b)).
- Security and abuse prevention — legitimate interest (Art. 6(1)(f)).
4. Where data is stored
Primary store: locally on your device.
Cloud: only if you create an account and enable sync. Data goes to Supabase in the European Union (Frankfurt). Cloud data is identified (tied to your account) — your private store, not anonymization.
Without sync enabled, the diary, Analysis, and PDF report work locally.
5. Recipients / processors
We use providers under data-processing agreements (DPAs) where required:
- Supabase — database, auth, storage (EU / Frankfurt; some subprocessors outside the EEA under SCCs).
- Resend — sign-in emails.
- PostHog / Sentry — product and website analytics and diagnostics without diary contents (if enabled).
- OpenStreetMap / Overpass (overpass-api.de) — public toilet-map API; receives an approximate search area, not health diary data.
- Apple / Google — app distribution; Maps if you start navigation to a toilet.
- Vercel (or another site host) — delivery of chronicos.app.
5b. No sale of data and sharing with third parties
We don’t sell data. We don’t share the diary or health data with advertisers. You generate the PDF report and share it (e.g. with your doctor) yourself.
We share with third parties:
- location (toilet map only): an approximate area to Overpass / OpenStreetMap to fetch toilet points,
- analytics and crash logs (PostHog, Sentry), without diary contents, if enabled in that build,
- navigation: if you tap navigate, we open Apple or Google Maps (your choice at that moment).
- Processors acting on our behalf: Supabase, Resend, Vercel. Cloud health data goes only to Supabase in the EU, and only after your sync consent.
6. Transfers outside the EEA
Primary cloud storage of health data is in the EU. If a subprocessor processes data outside the EEA, we rely on Standard Contractual Clauses (SCCs) and additional safeguards.
7. Data retention policy
This section is our data retention policy. We retain personal data only for as long as needed to provide the app or as required by law. Where we do not collect a category of data, we state it clearly: we do not store and we do not retain that data.
- Diary and health data on the device: stored only locally until you uninstall the app or use More → Delete local data. After that we do not retain a copy on the phone.
- Diary and health data in the cloud (only after an account and sync consent): retained until you delete your account or withdraw sync consent. We then delete it from the database without delay (usually within 24 hours). Infrastructure backups are deleted within 30 days. We do not retain health data after that.
- Account data (email, user id, consent log): retained for the life of the account. After account deletion we delete it with the account; backups for up to 30 days.
- Email sign-in codes: one-time and short-lived (minutes). We do not store them as a password — the app does not use passwords.
- Location (toilet map): we do not save coordinates to your account or our cloud. We do not store and we do not retain a location history. Permission is only while the map is in use. The Overpass query includes an approximate area and is not archived by us.
- Audio (dictation): we do not send recordings to ChronicOS servers. We do not store and we do not retain audio.
- Payment data: the current version does not collect card numbers or payment details. We do not store and we do not retain payment-card data.
- Product and website analytics (PostHog, no diary contents): retained for up to 24 months, then deleted or anonymized.
- Crash logs (Sentry, without notes, medication names, or lab values): retained for up to 90 days, then deleted.
- JSON backup you export yourself: stays with you (on the device or wherever you save the file). We do not retain it unless you send it to us.
8. Your rights
You have rights of access, rectification, erasure, portability (JSON export in the app), restriction, objection, and withdrawal of consent. Use the app (More → Account → Delete cloud account), https://chronicos.app/en/delete-account, or write to kontakt@chronicos.app (postal: Artur Przybyło, ul. Spółdzielców 11/195, 30-682 Kraków, Poland). You may also lodge a complaint with UODO (Poland) or your local supervisory authority.
9. Security
Encryption in transit: TLS. Cloud data is encrypted at rest at the provider. We use row-level isolation (RLS — you only see your own rows), SecureStore for session tokens, and minimization in analytics. A phone screen lock still matters for local data.
10. No automated decisions
We don’t make automated decisions with legal effects. Patterns in “Analysis” are observations from your logs — not a diagnosis or recommendation.
This is not medical advice. To nie jest porada medyczna.
11. Age
The app is not intended for people under 16. We don’t knowingly collect such data.
12. Changes
Material changes will be announced in the app and we will bump the policy/consent version (currently 2026-08-28); we may ask for consent again when needed.
ChronicOS does not provide medical advice. This is not medical advice. Informational document — not legal advice.