Data & Compliance
Last updated 5 August 2026
How Chrono Lens meets UK GDPR and EU GDPR obligations, what we store in your browser, and how you exercise your data rights.
Controller and lawful bases
Chrono Lens is the data controller for the personal data described in our Privacy Policy. We rely on:
- Contract — to create your account, run scans and manage your subscription.
- Legitimate interests — to keep the service secure, prevent abuse and improve accuracy using aggregated data.
- Consent — for optional marketing emails, which you can withdraw at any time.
- Legal obligation — to retain billing records where tax or accounting law requires it.
Your rights
- Access — request a copy of the personal data we hold about you.
- Export (portability) — receive your scans and collection in a machine-readable format.
- Rectification — correct inaccurate details, or edit entries directly in the app.
- Erasure — delete your account from Profile, or ask us to erase your data.
- Restriction and objection — object to processing based on legitimate interests.
- Withdraw consent — unsubscribe from marketing at any time.
Email privacy@chronolens.dev to make a request. We respond within 30 days and never charge for a first request. You may also complain to your supervisory authority (in the UK, the Information Commissioner's Office).
Cookies and local storage
Chrono Lens does not use advertising or cross-site tracking cookies. We store only what the app needs to function:
- Your authentication session, so you stay signed in.
- Small preference values such as whether you have completed the onboarding tour.
- A short-lived cache of recently viewed watches to make navigation instant.
- Payment-processor cookies during checkout, strictly to complete the transaction securely.
Clearing your browser storage signs you out and resets these preferences.
International transfers
Our infrastructure, AI and payment providers may process data outside the UK/EEA. Where they do, transfers are covered by adequacy decisions or Standard Contractual Clauses.
Retention
- Account, scan and collection data: kept while your account is active.
- Uploaded images: deleted when you delete the scan or your account.
- Cached recognitions: automatically expire after 30 days.
- Billing records: retained as long as required by tax law.
Security
- TLS encryption in transit and encryption at rest.
- Row-level security on every table so records are scoped to their owner.
- Private image storage accessed only via short-lived signed URLs.
- Server-side authorisation on every privileged operation, with admin functions restricted to a single verified account.
- Secrets held in a managed secret store, never in client code.
Breach notification
If a personal data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay.