Private alpha · Version 2026-07-26

Privacy notice

ChronoZero uses the least information it can to keep your timeline, estimate your current state, and produce a recommendation. It does not sell personal data, does not use it for advertising, and does not build profiles for anyone other than you.

1 · Who is responsible

ChronoZero is an independent, non-commercial project operated by a private individual in Switzerland. There is no company, no commercial register entry, and no group of affiliates. The controller for the processing described here is:

Andreas Dersch
Independent operator of ChronoZero
Zurich, Switzerland

The dedicated email contact for privacy questions and data-rights requests is privacy@chronozero.app
Security incidents and vulnerability reports: security@chronozero.app

Because the operator is based in Switzerland, the Swiss Federal Act on Data Protection (FADP) applies. Where ChronoZero is used from the EU or EEA, the GDPR applies as well, and this notice is written to address both. No data protection officer has been appointed; for a project of this size and nature that is not expected to be required.

2 · What is processed

Waitlist

If you request alpha access, ChronoZero stores the email address you submit, an optional name, the version of this notice you accepted and when, and the status of the review (waitlisted, approved, accepted, declined, or revoked). Joining the waitlist does not create an account and does not guarantee access.

Account and identity

An approved address can create an account. ChronoZero then stores your email address, an optional display name, your timezone and interface language, authentication material (a hashed password, or the stable identifier your identity provider returns), and session records.

Google sign-in

If you choose to sign in with Google, Google returns your email address, whether it is verified, and a stable subject identifier for your account. ChronoZero stores those three things and nothing else from your Google account. It does not read your Google Calendar, contacts, Drive, or mail. Google's own processing of the sign-in is governed by Google's privacy policy, not by this notice.

Planning data

This is the substance of the product: the activities you define, the calendar context you enter, your behavior timeline (what you did and when), session outcomes, subjective energy and vitality reports, onboarding answers, and the recommendations you accept, correct, or ignore.

Optional readiness checks

If you opt in, short reaction-time exercises produce timing data used to sharpen the state estimate. They are optional, can be skipped, and are never used to assess health.

Two different things could be done with that data, and they are kept separate on purpose. Sharpening your own estimate is part of providing the product to you, and it is what happens today. Using readiness timings to improve the models that serve everyone is research, not service delivery, so it needs your separate and specific permission. The web app's Readiness research setting is therefore a distinct opt-in, off by default, refusable without losing any part of the product, and withdrawable in the same place at any time. Taking a readiness check does not grant that permission. Only future checks recorded after you opt in can be considered, and your permission must still be active when a research release is made. Withdrawing it excludes all of your identifiable checks that have not already been made anonymous.

Research releases are made only for a completed calendar month. They do not contain an individual row, account or session identifier, exact timestamp, or lookup table. Results are first summarized per contributor, then released only as cohort distributions and pooled timing histograms when at least 20 different contributors are present for the same game and protocol version. The purpose is to test and calibrate how the shared models respond, not to assess a person or infer a health condition.

Model-generated estimates

From the above, ChronoZero derives and stores a simulated internal state: estimates of fatigue, focus, drive and recovery, plus the plans and recommendations produced from it. These are outputs of a model, not measurements of your body or mind. They are stored so that today's plan stays continuous with yesterday's.

Assistant narration

A language model hosted on the same EU server may put bounded engine output into readable sentences. Its prompts do not leave that server and are not sent to any third-party model provider.

Operational logs and telemetry

Servers record request metadata, error traces, performance timings, and abuse-relevant signals such as IP address and user agent. Telemetry forwarded to the monitoring provider is scrubbed of message content.

Product analytics

Pseudonymous product analytics is off unless you explicitly enable and consent to it. When enabled, it records which parts of the product are used, and never free-text answers, activity or calendar titles, assistant prompts, or raw state vectors. It is disabled entirely in automated test environments.

This website

These marketing pages are static files. They set no cookies, embed no third-party scripts, and run no analytics or advertising trackers. The CDN serving them keeps short-lived request logs.

3 · Why, and on what basis

Under the GDPR the legal bases are set out below. Under the FADP the same processing is carried out to provide a service you asked for, with consent wherever this notice says consent is required.

PurposeBasis
Running the planner: timeline, state estimate, recommendations, continuity Performance of the agreement you enter into by using the alpha (Art. 6(1)(b) GDPR)
Reviewing and administering waitlist requests Steps taken at your request before that agreement (Art. 6(1)(b) GDPR)
Account security, abuse prevention, service integrity, backups Legitimate interests in operating the service securely (Art. 6(1)(f) GDPR)
Optional readiness checks and optional product analytics Your consent, withdrawable at any time (Art. 6(1)(a) GDPR)
Improving the underlying models from pooled readiness timings and the model's corresponding estimates Separate, specific consent, withdrawable at any time (Art. 6(1)(a) GDPR). Once records are aggregated into an anonymous research set they cease to be personal data and fall outside this notice
Handling data-rights requests and security reports Legal obligation, and legitimate interests in handling reports (Art. 6(1)(c) and (f) GDPR)

Withdrawing consent does not affect processing that already happened, and it never costs you access to the core product: readiness checks and analytics are optional by design.

Automated processing

Recommendations are produced automatically. They are suggestions about how to arrange your own day, they can always be overridden or ignored, and they have no legal or similarly significant effects. ChronoZero does not make decisions about you in the sense of Art. 22 GDPR, and it does not infer, record, or claim health data.

4 · Who else is involved

ChronoZero uses as few external services as it practically can. At category level:

Application data is stored in the EU. Using Google sign-in involves Google's own infrastructure and may involve transfers outside the EU under Google's terms. Subscription-billing and third-party product-analytics providers are not active for this alpha; if that changes, this notice is updated before it happens, not after.

5 · How long it is kept

These are the periods currently configured for the alpha. They describe operational practice rather than contractual commitments, and may be adjusted as the service matures. Material changes are published here first.

6 · Your rights

You can request access to your data, correction, deletion, restriction of processing, and a portable export, and you can object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time.

Export and deletion can be requested from Settings inside the application, so you do not have to write to anyone first. Requests are fulfilled by the operator and answered within one month, as the law requires. Deletion revokes your sessions and removes your account graph. A pseudonymous record that a request was made is kept as an audit trail, and deleted data expires from encrypted backups within the backup window above.

One limit is worth stating clearly. If you enable the model-improvement consent described in section 2, withdrawing it stops any further research contribution immediately; deleting your account also removes your identifiable records. Withdrawal does not delete readiness data still held for your own product use under the retention period above, but it excludes that data from future research releases. Neither action can reach aggregates that have already been stripped of identifiers, because at that point there is no longer anything in them that points to you. That is the honest trade in pooled research data, and it is why the permission will be asked for separately rather than folded into anything else.

For anything else, write to privacy@chronozero.app. If you are not satisfied with the response, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to your national supervisory authority if you are in the EU or EEA.

7 · Security and incidents

Traffic is encrypted in transit, production access is restricted and key-based, dependencies are scanned, backups are encrypted off-host and periodically restore-tested, and the service is monitored for availability and errors. No internet service can promise absolute security, and this one is an alpha run by one person. Please keep that in mind when deciding what to put into it.

To report a vulnerability, write to security@chronozero.app before disclosing it elsewhere. For non-security bugs, see support and bug reports.

8 · Age, and changes to this notice

ChronoZero is not intended for people under 16, and accounts are not knowingly created for them.

This notice is versioned. The version you accepted when joining the waitlist is stored with your request. Material changes are published on this page before they take effect, and where the change requires it you will be asked to accept the new version.

Version 2026-07-26 · effective 26 July 2026.
Questions about this notice: privacy@chronozero.app · product problems: support@chronozero.app