Effective August 14, 2026

Privacy Policy

How DevChrono handles the private engineering context you choose to keep in the product.

1. What this policy covers

This Privacy Policy explains how DevChrono handles information connected to the public website, private workspace, account access, API routes, support forms, generated summaries, attachments, and exports.

For self-hosted or private deployments, the organization operating that deployment controls its database, storage, email, AI provider settings, retention, backups, access logs, and support process.

2. Information DevChrono stores

Workspace content may include daily logs, entries, projects, tasks, snippets, documents, tags, focus items, attachment metadata, generated summaries, support messages, and exported content.

Account and security records may include your name, email address, password authentication data, password reset records, membership status, storage limit, API token metadata, active sessions, invitation records, and administrator role information.

Attachment storage may include uploaded files, object keys, file names, content types, sizes, public or private storage URLs, and the records that link those attachments back to workspace content.

3. How information is used

DevChrono uses workspace data to operate the private journal: saving records, linking work back to projects, searching your archive, rendering documents, managing attachments, generating editable daily summaries, exporting logs, and providing support.

Account and security data is used to authenticate users, keep sessions active, protect administrator functions, process invitations, manage API tokens, apply storage limits, and help recover access.

DevChrono is designed around private work context. Product data should not be sold, used for public social profiles, or turned into activity feeds.

4. Cookies and local storage

DevChrono uses strictly necessary cookies for account sessions and security. The current session cookie is devchrono_session, which keeps signed-in users authenticated.

DevChrono may set a short-lived devchrono-toast cookie to show service messages after redirects, such as successful saves or updates.

The cookie banner stores your preference in local browser storage under devchrono-cookie-consent. This preference records whether you accepted all cookies or chose essential-only mode.

DevChrono does not currently set optional analytics, advertising, cross-site tracking, or personalization cookies. If optional cookies are added later, they should remain off unless you choose to accept them.

NamePurposeType
devchrono_sessionKeeps signed-in users authenticated.Strictly necessary
devchrono-toastShows short-lived service messages after redirects.Strictly necessary
devchrono-cookie-consentStores your cookie banner choice in local browser storage.Preference storage

5. AI, email, storage, billing, and other providers

When generated summaries are configured, relevant workspace context may be sent to the configured AI provider. Review generated output before relying on it.

When attachment storage is configured, selected files may be uploaded to the configured S3-compatible storage provider and linked back to DevChrono records through stored metadata.

When email is configured, DevChrono may use the configured SMTP or email provider to send password reset messages, invitations, support notifications, billing reminders, retention warnings, and account-related messages.

Paid subscriptions are processed by Paddle, which acts as merchant of record. Paddle may collect billing contact details, payment method information, tax identifiers, and transaction records needed to process subscriptions, refunds, and invoices.

DevChrono stores subscription status, Paddle customer and transaction references, refund request records, and minimal account tombstone data needed to enforce trial eligibility and retention policies.

6. Abuse protection and security services

DevChrono may use Cloudflare or similar edge protection to filter abusive traffic, apply rate limits, and protect public forms and APIs.

Public contact and feedback forms may use Google reCAPTCHA Enterprise to detect automated abuse. Google may process technical signals such as IP address, browser metadata, and interaction patterns when those forms are submitted.

Application-level rate limits and security headers are also used to reduce spam, credential stuffing, and automated abuse.

7. Sharing and disclosure

DevChrono may share information with configured service providers only as needed to operate hosting, storage, email, database access, support, security, or infrastructure.

Shared document links, exports, API tokens, screenshots, and copied content can disclose workspace information outside DevChrono. You are responsible for deciding what to share and with whom.

Information may be disclosed if required to comply with applicable law, protect rights and safety, enforce terms, investigate abuse, or secure the service.

8. Retention, deletion, and exports

You can export daily logs to Markdown so your engineering memory is not locked inside the application.

If your trial or paid subscription ends and the account becomes read-only, DevChrono may retain workspace data for up to 90 days while sending reminder emails before automatic deletion.

When you delete your account, DevChrono removes workspace content and stores only a minimal tombstone needed to prevent repeat free-trial abuse and preserve billing or audit references.

Deleting content from the live application may not immediately remove it from backups, logs, provider systems, exported files, or copies already shared outside the workspace.

9. Security expectations

DevChrono is built for private engineering notes, but you should not intentionally store production secrets, private keys, passwords, access tokens, or credentials in journal content, snippets, documents, exports, or attachments.

Protect deployment environment variables, object storage buckets, database credentials, SMTP credentials, administrator accounts, API tokens, and backup files.

Use least-privilege access, rotate credentials when users leave, revoke unused API tokens, and test restore procedures for deployments you operate.

10. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information.

You can manage account data through the product where supported, export daily logs, revoke API tokens, sign out of sessions, and use browser controls to clear cookies or local storage.

For requests about a hosted or organization-operated deployment, contact the operator responsible for that deployment.

11. Changes to this policy

This Privacy Policy may be updated as DevChrono changes. The effective date at the top of this page shows when the current version was published.

If optional analytics, advertising, or tracking cookies are introduced later, this policy and the consent banner should be updated before those cookies are enabled.

This page is production-oriented starter copy for DevChrono deployments. It should be reviewed by qualified counsel for your specific legal, hosting, data-processing, and regulatory needs.