Sub-processors
Last updated: August 2026
Chrono relies on a small number of third-party service providers ("sub-processors") to operate the Service. Each sub-processor listed below has access to personal data strictly as needed to provide its part of the Service.
Where a sub-processor is based outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs) as the transfer mechanism, supplemented by the provider's own safeguards. We will update this page and notify existing customers by email if we add or change a sub-processor.
Current Sub-processors
| Provider | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Anthropic | AI Planner — generates scheduling suggestions via the Claude API | Task titles and descriptions, goals, schedule context shared at request time | United States | SCCs (Anthropic Commercial Terms & DPA) |
| Stripe | Processes web subscription payments | Email, customer ID, subscription status (no card details ever reach Chrono) | United States / Ireland | SCCs (Stripe DPA) |
| Apple | Sign in with Apple, In-App Purchases on iOS | Apple ID identifier, transaction identifiers | Global (Apple data centers) | Apple Developer Program DPA |
| Google Sign-In and two-way Google Calendar sync | Email, profile name, calendar event data for connected calendars | United States | SCCs (Google Cloud / Workspace DPA) | |
| Microsoft | Two-way Outlook Calendar sync via Microsoft Graph | Mailbox identifier, calendar event data for connected calendars | United States / EU (when EU Data Boundary applies) | SCCs (Microsoft Online Services DPA) |
| Neon | Managed PostgreSQL hosting for application data | All user data stored by the Service (account, tasks, goals, audit log) | United States | SCCs (Neon DPA) |
| Render | Application hosting and deployment infrastructure | All request traffic and application logs | United States | SCCs (Render DPA) |
| Resend | Transactional email (email verification, password reset, account notifications) | Recipient email address, email contents generated by the Service | United States | SCCs (Resend DPA) |
| Sentry | Server-side error tracking and performance monitoring | Exception stack traces and request metadata; some error reports include an account identifier and excerpts of AI output | United States | SCCs (Sentry DPA) |
| GitHub | Private issue tracker mirroring in-app feedback (feature requests and bug reports) for triage | Feedback title and description; for bug reports also app version, platform, and device/browser info. No account identifier. Content is removed when the feedback is deleted in Chrono | United States | SCCs (GitHub Data Protection Agreement) |
Changes
If we add a new sub-processor or replace an existing one, we will update this page. Customers with an active account will receive reasonable advance notice by email and have an opportunity to object before the change takes effect.
Questions
For questions about our sub-processors or to request a copy of our Data Processing Agreement, email privacy@getchrono.app.