This Privacy Policy explains how Chronicle collects, uses, stores, and shares information when You use the Chronicle mobile application and its supporting service (together, the “Service”). Chronicle is operated by Victor Xirau Guardans in Spain (“Chronicle,” “We,” “Us,” or “Our”).
Chronicle is a media-tracking application that connects to a Chronicle API and related media services. The Google Play build connects to Chronicle's hosted API. Separately built, self-hosted versions may connect to infrastructure operated by another person; that server operator is responsible for its own data-handling practices.
Information We Collect
Account and authentication information
Chronicle supports native accounts using a username, email address, and password. Sign-in credentials are sent to Chronicle's API over HTTPS. Native account passwords are stored on the server as salted password hashes, rather than readable passwords. If You use the optional Jellyfin sign-in connection, its credentials are passed to the configured Jellyfin server for authentication.
To keep You signed in, the app stores Your username and Chronicle session token in the operating system's secure storage on Your Device. The server maintains account and session records. Optional Jellyfin or Seerr connections may also require access tokens or connection credentials, which are used to provide the functionality You request. Signing out clears account-linked data cached by the app, including its stored session token.
Profile and social information
Depending on the features You use, We may process:
- Your Chronicle account ID, email address, username, display name, and account role.
- Your media-server identity where You choose to connect a Jellyfin account.
- Your chosen display name, avatar, banner, and notification preferences.
- Friend requests, accepted connections, and related social notifications.
- Activity You choose to make visible through Chronicle's social features, including recent watch activity and non-private ratings, reviews, or comments.
Usernames, display names, avatars, friendship status, public comments, non-private reviews, and media activity may be visible to other authenticated users of the same Chronicle service where the relevant social feature displays them. Ratings marked private are not published as social comments.
User-generated content and reports
Chronicle may host user-generated content such as profile information, ratings, reviews, and comments. If You report abusive, illegal, or inappropriate content by emailing theprojektk@gmail.com, We may process Your account identifier, the reported user or content, the reason for the report, and any supporting information You provide. We use that information to investigate the report, protect users, and enforce Service rules. Content may be reviewed, restricted, or removed where appropriate.
Media activity and preferences
Chronicle processes the information needed to provide media-tracking features, including:
- Watchlists, watched status, series progress, episode counts, watch status, and activity timestamps.
- Ratings, reviews, comments, and watch-time statistics.
- Searches, discovery filters, media requests, and related request status.
- App preferences and notification-read state.
TV Time imports
If You choose to import a TV Time data-export ZIP, the archive is uploaded to Chronicle's API and processed to extract followed titles, watch history, ratings, comments, and watch-time statistics. The raw ZIP is processed in memory and is not stored as a permanent file. A preview of the extracted import is held temporarily for up to 30 minutes. When You confirm the import, the relevant extracted records are stored in Chronicle until You delete them or request deletion.
Avatar uploads
If You choose to upload a custom avatar, Chronicle stores the image and may also synchronize it to Your Jellyfin profile. Chronicle makes the avatar available to other users of the same Service as part of Your profile. Replacing or deleting the avatar removes the active Chronicle copy, subject to routine backups.
Technical and diagnostic information
When the app communicates with Chronicle's API, the server necessarily receives network and request information such as Your IP address, request time, requested endpoint, response status, and basic device-network information contained in standard HTTP requests. Limited operational logs may also contain a Chronicle user ID, import filename and size, media ID, or error details when needed to secure, operate, and troubleshoot the Service.
Chronicle does not use advertising identifiers, does not request location, contacts, microphone, SMS, or call-log access, and does not include third-party advertising SDKs. Optional usage analytics can derive approximate location from network information without requesting location access; it is described below.
Information stored on Your Device
To support sign-in, offline use, and faster loading, Chronicle stores secure local copies of Your session, profile, statistics, feed, activity, watch history, discovery results, requests, notifications, media details, pending offline changes, and user-interface preferences. Account-linked local data is cleared when You sign out. Cosmetic interface preferences may remain on the Device after sign-out and can be removed by clearing the app's storage or uninstalling it.
Optional Usage Analytics
If You choose Allow analytics during onboarding, Chronicle uses Google Analytics for Firebase to understand how the app is used and improve it. Choosing No thanks has no effect on access to any feature. Analytics collection remains off unless You consent; activity before consent is not sent later.
Google receives generic screen names and feature actions, such as marking an episode watched or posting a review, along with a random app-instance identifier, app and device information, session information, and approximate location derived from network information. This is pseudonymous usage information. We do not send Your Chronicle account identifier, name, email, search terms, review text, rating values, watched titles, or imported files to Google Analytics. Advertising features, Google Signals, and advertising identifier collection are disabled.
Google processes analytics information on Our behalf under its applicable Data Processing Terms. Processing can involve international transfers under the safeguards in those terms. See Google's privacy information and Data Processing Terms.
We configure Google Analytics user and event retention to two months, without resetting the retention period when You return. Standard aggregated reports are outside that retention setting and may be retained longer.
Analytics preferences
You can grant or withdraw consent at any time by opening Analytics preferences in Chronicle on a device with a version of Chronicle that supports analytics installed. Choose Stop sharing to withdraw consent. Withdrawal stops future collection and resets the local analytics identifier; it does not erase information already received by Google. Your choice is stored on Your Device separately from Your login and watch history. Signing out does not change that choice. If the app link does not open or You wish to exercise data protection rights, contact theprojektk@gmail.com.
How We Use Information
We use the information described above to:
- Authenticate You and maintain Your session.
- Provide, synchronize, and personalize Chronicle's media-tracking features.
- Display profiles, social activity, comments, ratings, and friend connections.
- Review content reports and address abuse, safety, or legal concerns.
- Process imports, media requests, searches, and optional avatar uploads.
- Keep the Service secure, prevent abuse, diagnose failures, and improve reliability.
- Understand general app usage and improve features when You consent to usage analytics.
- Comply with legal obligations and respond to valid legal requests.
We do not use Personal Data for targeted advertising, do not send marketing messages, and do not sell Personal Data.
Legal Bases for Processing
Where the European Economic Area, United Kingdom, or similar law applies, We process Personal Data on the following bases:
- Performance of the Service: to authenticate You and provide the features You request.
- Legitimate interests: to secure, maintain, troubleshoot, and improve the Service, provided those interests are not overridden by Your rights.
- Your consent or affirmative request: for optional actions such as importing a TV Time archive, uploading an avatar, or posting social content.
- Consent for usage analytics: to collect optional analytics information as described above. You can withdraw this consent at any time.
- Legal obligations: where processing is required by applicable law.
Services Chronicle Connects To
Chronicle uses or may use the following services to provide requested functionality. The particular services used depend on server configuration:
- Google Analytics for Firebase: optional, consented app usage analytics as described in the Optional Usage Analytics section.
- Jellyfin: authentication, user profiles, library information, playback status, watch progress, and optional avatar synchronization.
- Seerr, Sonarr, and Radarr: media discovery, user lookup, availability, and media requests.
- Jellystat: optional playback history and watch-time statistics.
- TMDB, TVmaze, OMDb, Fanart.tv, and TheTVDB: media metadata, artwork, release information, external identifiers, ratings, and availability information.
Chronicle sends these services only the information needed for the relevant request. For example, Jellyfin receives authentication credentials and account-specific media actions; Jellystat may receive Your media-server user ID; and metadata providers generally receive search terms or media identifiers rather than Your Chronicle identity. These services process information under their own privacy terms or under the terms of the server operator that configured them.
When We Share Information
We may disclose information only in the following circumstances:
- To provide the Service: with the integrated services described above and infrastructure providers that process data on Our behalf.
- With other Chronicle users: when a social or public feature described in this Policy displays the information.
- For legal and safety reasons: when reasonably necessary to comply with law, a valid legal process, protect rights or safety, investigate abuse, or defend legal claims.
- In a business transfer: as part of a merger, acquisition, reorganization, or transfer of the Service, with appropriate notice and safeguards.
- With Your direction or consent.
We do not sell or rent Personal Data to third parties.
Data Retention
Chronicle retains different categories of information for different periods:
- Chronicle and Jellyfin session records normally expire after 30 days, unless the server operator configures a different session duration or You sign in again.
- TV Time import previews expire after 30 minutes.
- Rebuildable provider-enrichment data is normally pruned after 90 days, and unreferenced catalog results after 180 days.
- Profile data, watch activity, preferences, friendships, ratings, comments, content reports, requests, confirmed imports, and avatars are retained while needed to provide the Service, until You delete them where that function is available, request deletion, or the Service is discontinued.
- Google Analytics user and event retention is configured to two months without resetting on new activity. Standard aggregated reports may be retained longer.
- Operational logs are retained only for as long as reasonably needed for security, troubleshooting, and service integrity.
Residual copies may remain in restricted backups until the backups are overwritten in the ordinary course. We may retain limited information longer when required by law, necessary to resolve disputes, prevent abuse, or establish or defend legal claims.
Your Choices, Rights, and Data Deletion
You may request access to, correction of, export of, restriction of, or deletion of Your Chronicle Personal Data. You may also object to certain processing or withdraw consent for optional processing. These rights may depend on Your location and applicable law.
To request deletion of Your Chronicle account data and associated Personal Data, email theprojektk@gmail.com with the subject “Chronicle data deletion request” and include Your Chronicle or Jellyfin username. We may ask for limited information to verify that You control the relevant account. We will respond without undue delay and normally complete a verified request within 30 days.
A Chronicle deletion request covers data controlled by Chronicle. It does not delete Your underlying Jellyfin, Seerr, TV Time, or other third-party account or the source data held by those services. You must contact the relevant service or server operator to delete that separate data. Where Chronicle synchronized an avatar or watch action to Jellyfin, the corresponding Jellyfin copy may also need to be removed through Jellyfin.
Signing out removes account-linked data stored by Chronicle on that Device but does not delete server-side data. Uninstalling the app removes its local data but does not by itself delete server-side data.
If You are in the EEA, You may also lodge a complaint with the data-protection authority in Your country. We encourage You to contact Us first so We can address Your concern.
Security
The production app communicates with Chronicle's API over HTTPS. Chronicle uses authenticated API sessions, access controls, input limits, and operating-system secure storage for credentials and local account caches. No system can guarantee absolute security, and You are responsible for protecting access to Your Device and media-server account.
International Data Transfers
Chronicle is operated from Spain. Depending on where integrated service and infrastructure providers operate, information may be processed in other countries whose laws differ from those in Your country. Where required, We use appropriate safeguards for such transfers. Self-hosted deployments process data in locations chosen by their server operator.
Children's Privacy
Chronicle is not directed to children under 16, and We do not knowingly collect Personal Data from children under 16. If You believe a child has provided Personal Data, contact Us so We can investigate and delete it where appropriate.
Changes to this Privacy Policy
We may update this Privacy Policy when Chronicle's features or data practices change. We will post the updated version on this page and revise the “Last updated” date. Material changes may also be communicated through the Service where appropriate.
Contact
For privacy questions, data-deletion requests, or user-content reports, contact Victor Xirau Guardans at theprojektk@gmail.com.