Privacy Policy

Last updated September 5, 2026
Chronicle is made by XYZ Agent LLC. It records audio you choose to record, stores it for you, and — only when you explicitly ask — transcribes and summarizes it. This page explains exactly what that means for your data.

What we collect

Your email address, so you have an account. The audio you record or import, and the transcripts and summaries produced from it. Your subscription status. How many transcription minutes you have used this month, which is what your plan is measured against. On the mobile apps, crash reports and basic device information when something goes wrong.
Nothing is recorded in the background and nothing is captured without an explicit tap. We do not collect your location, contacts, calendar, photos, health data, messages, or browsing history, and we do not use advertising identifiers.

Transcription is a separate step you choose

Recording and transcribing are different acts. On the mobile apps a recording stays on your device until you upload it; transcribing is something you ask for, per recording or by a default you set.

You choose where your recordings are kept and processed

Under Settings → Preferences → Privacy there are two independent choices, and they decide everything on this page.
Where recordings are kept. On your device only, in our cloud storage, or on a server you run yourself. With your own server, the audio, transcript and summary live there and never reach our storage — we keep only each recording's title, status and timing, which is what makes it appear in your library.
Where they are transcribed. By our cloud provider, by your own server, or on your phone. Transcribing on your phone or your own server means the audio reaches no third party at all; with a local AI model on your server, the summary does not either.
The section below describes the default: our cloud storage and our cloud providers.

Who else processes your data

On the default settings, when you ask for a transcript the audio is processed by Google's Cloud Speech-to-Text service. The resulting transcript text — never the audio — is sent to Google's Gemini model to produce the summary, key points and action items. Google Firebase hosts the app and stores your account, audio and transcripts. RevenueCat handles subscriptions and receives an account identifier and your subscription status, never a card number.
Payment itself is taken by the store you subscribe through: Apple for the App Store, Google for Google Play, or Stripe for web subscriptions, which run through RevenueCat's web billing. They receive your payment details under their own privacy policies; we never see a card number.
If you transcribe on your own server or on your phone, the speech service is not involved and never receives your audio. If your server also runs its own AI model, Gemini is not involved either. If you keep recordings on your own server, Firebase stores no audio, transcript or summary for them. RevenueCat is the one processor every configuration uses, because it is what tells us your plan — and it never sees a recording.
All of these act only on our instructions. We do not sell your data, we do not share it with data brokers, we do not track you across other apps or websites, and there are no advertising SDKs in the app.
We record counts about how the app is used — how many recordings were transcribed, how long they were, which of the options above you are using — so we can plan capacity. These carry no titles, no filenames, no transcript text and no server addresses, and they are collected in every mode, including the private ones. They sit in our operational logs, tagged with your account and recording identifiers but never content, for up to 400 days.

AI agents you connect yourself

You can connect an AI assistant of your choice (Claude, or any agent that speaks the open MCP standard) to your own account. This never happens on its own: a connection exists only after you sign in and approve it on our consent screen, where you also choose what it may do — read your library and transcripts, add and transcribe recordings, or (only if you tick it) delete content.
A connected agent acts with exactly the access you approved and spends your own transcription minutes. What it reads is between you and your agent's provider under their privacy terms — connecting an agent is your decision to share with it. You can see every connected agent in Settings → Preferences → Connected agents and disconnect any of them at any time; disconnection takes effect on the agent's very next request.

Your recordings are not used to train AI models

Google's speech service does not log or retain your audio or transcript beyond producing your result, and does not use them to train or improve its models — that is its default behavior, and we have not changed it. Google does not use the transcript text sent for summarization to train its models either.

Security

Everything travels over encrypted connections and is encrypted at rest. Your recordings and transcripts are readable only by your own account; our access rules deny every other account by default. A server you run yourself is reached over an encrypted connection and requires both its own key and proof of your sign-in — that proof is your sign-in token, which is a credential for your account rather than for one file, and it is why this feature is for a machine you control. Point it only at your own server, never at one someone else runs for you. What happens on that machine is then yours to secure.

Deleting your data

You can delete an individual recording at any time, which removes its audio, transcript and summary — immediately and permanently, with no recovery window on our side. You can also delete just the audio and keep the transcript, or delete the transcript and keep the audio, per recording or for several at once. You can erase all of your data from Settings, and you can delete your account entirely, which removes your recordings along with it. Recordings kept on a server you run are the one exception: deleting a single recording removes its files from that server too, but erasing your whole account does not reach it — those files stay on your machine, where only you can remove them. If you cannot sign in, the Delete Account and Delete Data pages explain how to ask us to do it for you.

Website analytics

On the public web pages at chronicle.xyzagent.ai — this welcome page, sign-in and these policy pages, never the app screens — we count visits with Google Analytics. Analytics cookies are set only if you accept them in the banner; otherwise the measurement is cookieless and aggregate: the page, referrer, country and device type, with no personal identifiers.

Children

Chronicle is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will delete it.

Where your data lives, and your rights

Unless you have chosen a private server or on-device processing, your data is stored and processed in the United States by the providers named above. If you use Chronicle from elsewhere, your data is transferred to the United States to provide the service.
You can see everything Chronicle holds about you in the app: your recordings, transcripts and summaries in the library, your usage in Settings → Billing, and your profile in Settings → Account. You can export transcripts and download audio from each recording, and you can delete a recording, your data, or your whole account yourself from Settings at any time. Depending on where you live you may also have the right to access, correct or delete personal information, to object to or restrict its processing, or to complain to a supervisory authority; email us and we will act on the request within the time the applicable law allows. We do not sell personal information and we do not share it for advertising, so there is nothing to opt out of on that front. Do Not Track signals are not treated differently from the choices described on this page.

Changes and contact

If we change what we collect or who processes it, we will update this page and the date at the top. For any privacy question, or to request deletion, contact XYZ Agent LLC at chronicle@xyzagent.ai — the same address the Delete Account and Delete Data pages use.