Security at Chrono
We take the security of your data seriously. Here's how we protect your information at every level.
Encryption
All traffic encrypted in transit via TLS. Calendar OAuth tokens are additionally encrypted at rest with AES-256-GCM; data is stored on managed infrastructure with disk-level encryption.
Authentication
JWT-based auth with bcrypt password hashing, OAuth 2.0 for third-party login.
Infrastructure
Hosted on Render with automatic SSL, PostgreSQL on Neon with encrypted connections.
Data Privacy
Your data is yours. We never sell or share personal information with advertisers.
Calendar Sync
OAuth 2.0 scopes limited to minimum required. Tokens stored encrypted, revocable anytime.
AI Features
Task data sent to our AI provider (Anthropic) is never used to train AI models. It's processed to generate your suggestions and retained only briefly under the provider's API data-retention policy.
Responsible Disclosure
If you discover a security vulnerability, we appreciate your help in disclosing it responsibly. Please email security@getchrono.app with details and we'll respond within 48 hours.
Contact Us
For any security-related questions or concerns, reach out to us at security@getchrono.app.