How we look after your story.
Chronicle holds something unusually personal – the story of your life, in your own words. This notice explains, in plain language, what we collect, why we collect it, who handles it on our behalf, how long we keep it, and the rights you have over it at every point.
The short version is at the top. The detail is below. If anything is unclear, write to dpo@withchronicle.ai and a person will answer.
At a glance
- Who we are. Chronicle AI Ltd, a private company based in England and Wales. We are the controller for the information you share with us.
- What we collect. The account details you give us, the interview answers you give the app, the drafts we produce from them, and a small amount of technical information so the service works.
- Why. To turn your conversations into a written life story. Some of what you tell us is health, belief, or relationship information – we treat that as special category data and only process it with your explicit consent.
- Who else sees it. A small set of service providers we use to run Chronicle – described below. We name the AI provider directly because it's the one most people want to know about; we describe the others by category and will name any of them on request. Nobody else, ever. We do not sell or share your story.
- Where it goes. Mostly the UK and EU. Our AI drafting partner, Anthropic, is based in the United States. That transfer is covered by an approved mechanism explained below. Two others – our payment provider and, on our marketing pages only, our advertising partners – also involve the US, under their own approved safeguards.
- Marketing vs the app. On our public marketing pages we now use advertising measurement tools, but only if you accept them in the cookie banner. They never run inside the app and never see your story.
- How long. Each type of data has its own retention period. You can ask us to delete your digital data at any time.
- Your rights. You have the full set of UK GDPR rights. There is one practical limit you should know about: once you print a copy of your life story and give it to someone, we cannot retrieve it.
1. Who we are
Chronicle is a service operated by Chronicle AI Ltd, a private limited company registered in England and Wales. For the purposes of UK data protection law, Chronicle AI Ltd is the data controller for the personal information you give us through this service.
You can write to us at dpo@withchronicle.ai about anything in this notice, including to exercise the rights set out below. The same address reaches our Data Protection Officer.
2. What we collect
We collect four kinds of information:
Account information
Your name, email address, a password (held only as a one-way hash – we never see the plain text), and the answers you give when you set up a two-factor login.
The story you tell us
Interview transcripts, the drafts we generate from them, the chapter structure you choose, the topics you tell us are off-limits, the editorial through-lines you agree on, and any notes or edits you make to a draft. This is the heart of the service. Some of it will be special category data – information about your health, your beliefs, your relationships, your political opinions, your ethnic background, or other deeply personal matters. We only process that information with your explicit consent (see section 3).
Where you choose to answer out loud, we record your voice and convert it to text so it can become part of your draft. Recording is your choice: the first time you use it we ask you to turn it on, and you can turn it off again at any time. If you keep it on, we store your recordings so you – and, if you wish, your family – can listen back to them, and you can delete any recording, or all of them, whenever you like in your settings. To turn your speech into text, the recording is sent to our speech-to-text provider (see section 5); they may only use it to do the transcription and are not allowed to use it to train their models. We do not use your voice to identify you and we do not create a synthetic ‘clone’ of your voice.
Information about people you mention
Your story will naturally include other people – family, friends, colleagues. We handle that information carefully. See section 4 for the detail.
Technical information
Standard server logs (the date and time you signed in, the type of device and browser, basic error information) so we can keep the service running and investigate problems if they happen. We do not use this information to profile you or to target advertising.
3. Why we use it
We use the information you give us to deliver the service you have asked us to deliver: to guide you through interview sessions, to draft chapters of your life story from those sessions, to let you edit and finalise the result, and to keep the service available, secure and accountable.
UK data protection law requires us to set out a lawful basis for each processing activity. Ours are:
| What we do | Why we are allowed to (lawful basis) |
|---|---|
| Running your account and delivering the life story service | Article 6(1)(b) UK GDPR – necessary for performance of our contract with you. |
| Processing any special category data you share about yourself | Article 9(2)(a) UK GDPR – your explicit consent, given at signup and recorded in our consent register. |
| AI drafting of chapters using your interview content | Article 6(1)(b) – contract. The AI provider acts as our processor. |
| Recording, transcribing and (if you choose) storing your voice answers | Article 6(1)(b) – contract; Article 9(2)(a) – your explicit consent, which you give when you first turn voice answers on and which covers the sensitive things you may say aloud. You can turn recording off and delete your recordings at any time. |
| Measuring how well our advertising campaigns work, using measurement tools on our public marketing pages | Article 6(1)(a) – your consent, given through the cookie banner. You can decline or withdraw at any time and the tools do not run. |
| Information about other people that appears incidentally in your life story | Article 6(1)(f) – legitimate interests in helping you record your life story, balanced against the rights of those individuals; supported by the literary exemption (DPA 2018, Sch. 2, Pt 5, Para. 26) where it applies. |
| Sending you transactional emails about your account | Article 6(1)(b) – contract. |
| Keeping billing records, when applicable | Article 6(1)(c) – legal obligation (UK tax and accounting rules). |
| Investigating misuse, fraud or security incidents | Article 6(1)(f) – legitimate interests in keeping Chronicle secure for everyone. |
About explicit consent for special category data
When you create your account, we ask you to give explicit consent to our processing of any special category data you share while telling your story. That consent is recorded in our consent register alongside the version of this privacy notice you saw at the time. You can withdraw it at any time (see section 8); withdrawal does not affect the lawfulness of processing carried out before you withdraw.
4. People mentioned in your story
A life story is, by its nature, about more than one person. The people you talk about – family members, friends, colleagues – may also be identifiable from your story, and some of what you say may be special category data about them too.
We rely on three things together to process that information lawfully:
- Our legitimate interests in helping you preserve and share your life story, balanced against the privacy rights of the people you mention. We have written that balancing exercise into a Legitimate Interests Assessment which we will share with the Information Commissioner's Office on request.
- The literary exemption in the Data Protection Act 2018 (Schedule 2, Part 5, paragraph 26), which applies to material processed with a view to publication of literary works in the public interest. A life story for family distribution falls within this. We have documented our reasonable belief in the literary and public-interest purpose, and we apply that belief case by case.
- Your own confirmation, given when you start your first interview, that you understand other people may appear in your story and that you are responsible for ensuring it is appropriate for you to share what you share. This is not a waiver of anyone else's rights – it is a record of your understanding that those rights exist.
If a person mentioned in a life story contacts us and asks us to remove information about them, we take that request seriously. We consider it against the literary exemption case by case, and we log our decision. Where the exemption does not apply, we will action the request.
5. Service providers we use
We use a small number of carefully chosen providers to run Chronicle. Each one acts as a processor – they handle data on our written instructions only, under a contract that meets UK GDPR Article 28 requirements.
| Provider | What they do for us | Where |
|---|---|---|
| Anthropic PBC | AI drafting via the Claude API. Bound by a written Data Processing Agreement and prohibited from using your data to train its models. | United States – transfer protected by Standard Contractual Clauses (see section 6). |
| Speech-to-text provider (OpenAI) | Converts your recorded voice answers into text. Receives the audio only to transcribe it; bound by a written Data Processing Agreement and prohibited from using your recordings to train its models. The stored recordings themselves are held securely by us in our own database (see the database-provider row), not by OpenAI. | United States, under Standard Contractual Clauses. |
| Database and authentication provider | Holds your account, your interview transcripts and your drafts. Operates under a written Data Processing Agreement with strict role-based access controls. | European Union. |
| Application hosting provider | Serves the Chronicle web app to your browser. Static assets are cached globally; life story content is not. | European Union. |
| Transactional email provider | Delivers the account and story-related emails we send you. | European Union. |
| Product analytics provider (PostHog) | Records anonymous, event-level usage data – which screens are visited and which features are used – so we can improve the product. Configured to never capture story content, transcripts, names, or anything you type into the app. Session recording and automatic event capture are disabled. No cookies or local storage are set. Bound by a written Data Processing Agreement. | European Union (PostHog EU Cloud). Requests are routed via a managed Cloudflare proxy on a Chronicle-owned subdomain – described in the next row and in section 6. |
| Edge proxy infrastructure (Cloudflare) | Routes analytics requests from your browser to our analytics provider via a Chronicle-owned subdomain. Because Cloudflare terminates the secure connection between your browser and our proxy, it is in the data path for the same event-level metadata our analytics provider receives – your IP address, your device and browser type, and the names of events such as 'page viewed' or 'export started'. It does not see story content, transcripts, names, or anything you type into Chronicle, because we never send that information to our analytics provider in the first place. This layer exists so analytics keeps working for users on networks or browsers that block direct connections to analytics services. | Global edge network (United States parent). Covered by the additional safeguards described in section 6. |
| Payment processor (Stripe) | Handles payment information directly for one-time purchases. We never see or store your full card number. Bound by a written Data Processing Agreement. | European Union and United States – Stripe operates under its own Standard Contractual Clauses and Data Privacy Framework certification. |
| Print partner (Mixam) | Prints and posts your book when you order one. Receives only the finalised manuscript and your delivery address. Bound by a written Data Processing Agreement. | United Kingdom. If any job is ever printed outside the UK or EEA we will update this and put an approved transfer safeguard in place first. |
We name the providers that handle the most sensitive parts of your story directly – our AI drafting and speech-to-text providers, our analytics setup, our payment processor and our print partner. The few remaining providers, which run our infrastructure and never see your story content, are described by category here – if you'd like to know exactly which provider sits behind each one, write to dpo@withchronicle.ai and we'll tell you. We keep the full list internally and make it available to the Information Commissioner's Office on request.
On our public marketing pages only, and only if you accept them in our cookie banner, we use advertising-measurement tools from Meta and Google so we can understand which adverts bring people to Chronicle. When you take an action such as joining the waitlist or making a purchase, we share a small, fixed set of technical details with them: a securely hashed (scrambled) version of your email address, an advertising click identifier from the advert you arrived through, your device’s IP address and browser type, the fact that the action happened, and – for a purchase – the amount and currency. We never share your story, your name in a life story, your recordings, or anything you type in the app. Meta and Google act as independent controllers for their own advertising purposes, so they also handle that information under their own privacy terms. Our cookie banner is built by us, not a third-party tool. If you decline, none of this runs.
We do not sell, rent, share or otherwise disclose your information to anyone else. We will only ever release information to a third party if we are legally required to (for example, in response to a court order) or if you have asked us to do so (for example, by using a share link to send a draft to a family member).
6. Transfers outside the UK
Most of your data is held in the UK or the European Economic Area by our hosting and email providers. There are a few transfers outside that area you should know about.
When Chronicle drafts a chapter of your life story using artificial intelligence, it sends the relevant parts of your interview content to Anthropic's Claude API. Anthropic is based in the United States. The transfer is protected by the Standard Contractual Clauses (Module 2, controller-to-processor) incorporated into our written Data Processing Agreement with Anthropic, including the UK jurisdictional addendum required for transfers from the UK. Anthropic is contractually prohibited from using your data to train its models.
Before we began transferring data to Anthropic, we completed a Transfer Risk Assessment focused on the protections that apply to special category biographical data in the United States. The assessment, and our underlying Data Processing Agreement, are available to the Information Commissioner's Office on request.
Where we convert your recorded voice to text, the audio is processed by OpenAI in the United States, under Standard Contractual Clauses, on the same footing as our AI drafting partner. Only your voice content is involved in this step; your account details are not.
Two further transfers to disclose, both under the providers’ own approved safeguards. Our payment provider, Stripe, processes payment and billing details partly in the United States under its Standard Contractual Clauses and Data Privacy Framework certification. On our marketing pages only, and only with your consent, Meta and Google receive the limited advertising-measurement data described in section 5 in the United States, as independent controllers under Standard Contractual Clauses and their own safeguards. Neither transfer involves your story content.
There is a further, narrower transfer to disclose. To keep our product analytics working for users whose browsers or networks block connections to analytics services, we route analytics requests through Cloudflare, an infrastructure provider headquartered in the United States. Cloudflare is in the path for the same event-level metadata our analytics provider receives – IP address, device and browser type, and the names of events such as "page viewed" or "export started". It is not in the path for story content, transcripts, names, or any of the information you type into Chronicle, because none of that is sent to our analytics provider in the first place. The transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, incorporated into our written agreement with our analytics provider.
7. How long we keep things
We hold each category of information only for as long as we need it for the purpose it was collected, and no longer.
| Information | How long we keep it |
|---|---|
| Account information (name, email, hashed password) | For as long as your account is active. Deleted within 30 days of account closure. |
| Interview transcripts | Held while you are actively using the service. Deleted 12 months after a life story is marked complete, unless you ask us to keep them. Before anything is deleted we email you first, so you can keep them for longer or download everything. |
| Voice recordings (audio of your spoken answers) | Only kept if you choose to store them. If you do, we keep them until you delete them or close your account – you can delete any recording, or turn recording off, at any time. If you choose not to store them, the recording is deleted as soon as it has been transcribed. Either way, the copy sent to our speech-to-text provider is retained by them only as long as needed to transcribe it. |
| AI processing logs (the request and response data sent to and from Anthropic and our speech-to-text provider) | Deleted within 30 days of each session. |
| Drafts and chapter versions | Held while you are working on the life story. Deleted on final life story delivery unless you ask us to keep them. |
| Final life story (digital copy on your account) | For as long as your account is active. You control export and deletion at any time. |
| Consent records (what you consented to and when) | Retained for as long as we may need to demonstrate consent, in a pseudonymised form not linked to life story content. |
| Billing records (where applicable) | Six years from the end of the tax year, as required by UK tax law. |
| Server and security logs | 30 days, unless retained longer to investigate a specific incident. |
If you stop using Chronicle
We do not want to hold a life story that nobody is looking at any more. If a storyteller's account has had no activity for six months, we email the person who set the account up to ask whether they would like to keep it active. If we do not hear back within thirty days, we delete the story data. A single click in the dashboard keeps the account active and stops the clock.
If your Chronicle is refunded
If a purchase is refunded, access to the life story ends that day. We keep the story for thirty days more so that you can sign in and download a copy of everything – the transcripts, the chapter drafts and any saved recordings – and so that you can buy a tier again and carry on where you left off if you change your mind. At the end of those thirty days we delete the story and its data. We keep only the record of the purchase and the refund itself, which we are required to hold for accounting and payment-dispute purposes.
8. Your rights
Under UK GDPR you have the following rights. To exercise any of them, write to dpo@withchronicle.ai or use the self-service controls in your account settings. We respond within one calendar month and we do not charge for any of these requests except in rare cases where a request is manifestly unfounded or excessive.
- Access (Article 15). Ask us for a copy of the information we hold about you, plus a description of what we do with it.
- Rectification (Article 16). Ask us to correct information that is inaccurate or incomplete.
- Erasure (Article 17). Ask us to delete your data. We will, subject to the practical limit on printed copies in section 9 and any narrow legal retention obligations (for example, billing records).
- Restriction (Article 18). Ask us to pause processing while a dispute is sorted out.
- Portability (Article 20). Ask us for a copy of your data in a machine-readable format, or ask us to send it directly to another service.
- Object (Article 21). Object to processing we are doing on the basis of legitimate interests, including any processing of third-party information in your life story.
- Withdraw consent (Article 7(3)). Withdraw the explicit consent you gave for special category data processing, whenever you like. Withdrawal does not affect the lawfulness of anything we did before you withdrew.
- Not be subject to automated decisions (Article 22). We do not take any automated decisions about you that produce legal or similarly significant effects. The AI we use is a writing assistant, not a decision-maker.
- Complain to the Information Commissioner's Office. If you are unhappy with how we have handled your data, you can complain to the UK's data protection regulator at any time. We would rather you came to us first, but it is your right.
ICO – Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. ico.org.uk/make-a-complaint. Helpline 0303 123 1113.
How withdrawal works in practice
You can begin a withdrawal in your account at any time. We will ask you, gently, why – the answer helps us improve, but you do not have to give one. We will offer the chance to export a copy first if you would like. Once you confirm, we delete your story data within thirty days, send you a confirmation email, and sign you out. If you change your mind during that thirty-day window, reply to the confirmation email and we can stop the deletion.
9. Printed copies
There is one practical limit on the right to erasure that we want to be honest about. Once you print a life story and a book has been delivered – to you, to a family member, to anyone – we have no way of recalling that physical copy. If you later ask us to erase your digital data, we will, but the printed copies remain wherever you sent them. We ask you to acknowledge this each time you generate a printable export, so that the limitation is in front of you at the moment it becomes relevant rather than buried in a notice.
10. How we keep it secure
We take security seriously because the information you give us is unusually personal. Our core measures are:
- Life story content, transcripts, drafts and account data are encrypted at rest using AES-256.
- All connections between your browser, our service and our providers use TLS 1.3.
- Chronicle staff cannot read your life story content by default – see “When someone on our team needs to look”, below.
- Database credentials and API keys are stored in a managed secrets service and rotated regularly. They are never embedded in code.
- We carry out independent security testing before launch and at least annually thereafter. Critical and high findings are resolved before any deployment that touches user data.
- We have a written breach response plan. If we ever discover a personal data breach that is likely to risk people's rights and freedoms, we notify the Information Commissioner's Office within 72 hours of becoming aware, and we notify affected users without undue delay where the risk is high.
When someone on our team needs to look
By default, nobody at Chronicle reads your story. There is one situation where a member of our team may need to: when you have asked us for help and we cannot solve it without looking. If you tell us a message has gone missing, that a chapter has come out wrong, or that something in your book needs fixing, the person helping you may open the relevant part of your account to understand what happened and put it right.
When that happens, it is only ever to support you with the issue you have raised. We do not browse your story out of curiosity, and we never use what we see for marketing, advertising, profiling, or any purpose other than helping you. Every such access requires the staff member to sign in, pass two-factor verification, and is recorded in an audit log that captures who looked, at what, when, and why. We look at the least we need to, and no more. If you would rather we did not look at a particular part of your story while helping you, tell us and we will do our best to work around it.
11. Cookies
Chronicle uses cookies only for things that are strictly necessary to run the service – keeping you signed in, remembering which session you are working on, and protecting against abuse.
On our public marketing pages, we now use advertising-measurement tools from Meta and Google to understand how well our advertising works. Most of this happens on our own servers rather than through browser tracking, and we do not use Meta’s browser pixel. These tools only run if you accept them. When you first visit you will see our cookie banner, which we built ourselves: nothing beyond the strictly necessary cookies runs until you choose. You can accept, reject, or change your mind at any time, and rejecting is as easy as accepting. These tools run only on our marketing pages – never inside the app, and never against your story.
Our product-improvement analytics (named in section 5) is separate from all of this: it uses no cookies or local storage, so it sits outside the banner, and it never sees your story. It captures only anonymous event-level data (which screens are visited, which features are used), and never records the contents of your story.
12. Children
Chronicle is intended for adults. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, please write to us and we will delete it. Life stories may mention childhoods – yours, or other people's – which is a different matter and is covered in section 4.
13. Changes to this notice
We review this notice at least once a year, and whenever we make a material change to how we process information. If a change affects your rights or how your data is handled, we will tell you directly (by email) and, where the law requires it, ask for fresh consent. We do not bury significant changes in a generic update.
The version and date of this notice are at the bottom of the page.
14. Contacting us
For anything privacy-related, write to dpo@withchronicle.ai. That inbox is monitored by our Data Protection Officer and is the right route for access requests, erasure requests, complaints, or general questions about this notice.
For everything else, including help using the product, hello@withchronicle.ai will reach us.