Privacy Policy

Effective Date: August 6, 2026
Operator: Chronospace Pte. Ltd. (UEN 201603233N)

Chronospace Pte. Ltd. ("Chronickel," "we," "us," or "our") is committed to protecting your privacy and ensuring transparency in how we handle personal data. This Privacy Policy applies to all users of our services located at chronickel.com and related applications.

1. Data Controller & Data Protection Officer (DPO)

Chronospace Pte. Ltd. is the data controller responsible for your personal data. In compliance with the Singapore Personal Data Protection Act 2012 (PDPA) and international regulations, we have appointed a Data Protection Officer.

  • Entity: Chronospace Pte. Ltd. (UEN 201603233N)
  • Registered Address: Singapore
  • DPO Contact: dpo@chronickel.com

2. Personal Data We Collect

We collect data necessary to provide, maintain, and secure our family archive platform:

  • Account Data: name, email address, and hashed/salted authentication credentials.
  • User-Generated Content: family stories, uploaded photos, family tree entries, portraits, digital time capsule messages, attachments, and encrypted documents stored in the Vault (Family and Legacy plans).
  • Space Activity & Audit Logs: system logs recording invitations, revocations, permission role assignments, visibility modifications, billing adjustments, and media management.
  • Technical Data: essential session identifiers (cookies) used strictly to maintain secure user login sessions.

3. Purpose and Legal Basis for Processing

We process personal data based on contractual necessity, legal obligations, and legitimate interests:

Data CategoryPurposeLegal Basis (PDPA / GDPR)
Account & ContentOperating family spaces, secure vault storage, rendering family treesPerformance of Contract
Transactional EmailSending system notifications, invitations, password resetsPerformance of Contract
Payment DetailsProcessing subscriptions and billing operationsPerformance of Contract / Legal Obligation
Audit LogsPlatform security, abuse prevention, transaction auditingLegitimate Interests / PDPA Compliance
Automated ScreeningModerating illegal or harmful uploaded mediaLegitimate Interests / Legal Compliance

4. Data Sharing and Sub-Processors

We do not sell, rent, or trade your personal data. We disclose data only to trusted sub-processors acting on our explicit instructions under signed data processing agreements:

  • Payment Processing: Stripe, to process billing and subscriptions.
  • Email Delivery: Resend, to send transactional email such as invitations and password resets.
  • Automated Moderation: OpenAI's Moderation API, to detect prohibited material in uploaded text and images.
  • Object Storage: Cloudflare R2, to store your photos, documents, and encrypted Vault files.
  • Database Hosting: Neon, to host our production database.
  • Application Hosting: Vercel, to run and serve the application itself.
  • Conversational AI Assistant: Anthropic, to power the optional in-app chat assistant that answers general questions about the product. This assistant never receives your stories, photos, family-tree records, Time Capsule contents, or Vault documents/metadata — only your typed question, the current page, and (if signed in) your account's role and plan name.

A full, current list of our infrastructure providers is also published on our Security page.

5. International Data Transfers

Where personal data is transferred across international borders, we ensure compliance with PDPA Transfer Limitation Principles and GDPR Chapter V through Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms ensuring legal safeguards.

6. Data Rights and User Control

Subject to applicable law (PDPA, GDPR, APPR), you possess the following rights:

  • Access & Correction: request a copy of your personal data or correct inaccuracies.
  • Data Portability: export your entire family space archive in an offline, self-contained format at any time — see how exports work.

7. Retention and Security

  • Retention: data is retained for as long as your family space is active, except where retention is legally mandated.
  • Security Controls: the site is served over HTTPS. Vault documents (Family and Legacy plans) are encrypted with AES-256-GCM, with the encryption key derived from a separate vault passphrase rather than your account password. We use role-based access limits and salted password hashing throughout. Details are available on our Security page.

8. Data Breach Notification

If we become aware of a data breach involving your personal data, we will assess it in accordance with the Singapore Personal Data Protection Act 2012 (PDPA) and its Notification of Data Breaches Regulations. Where the breach is assessed to be notifiable, we will notify the Personal Data Protection Commission (PDPC) within the timeframe required by law, and notify affected individuals where the breach is likely to result in significant harm.

9. Minors and Children's Data

Chronickel allows families to document their personal histories. However, account creation is restricted to individuals aged 18 or older (or the age of legal majority). Parents or legal guardians uploading content regarding minors warrant that they hold the legal authority or parental consent to process such data.

10. Updates to Policy

We may update this policy periodically. Material changes will be communicated via email or prominent platform banners prior to taking effect.