Skip to content

Legal

Privacy policy

Last updated: 4 October 2026

What personal data Chronika handles, why, and what you can do about it. A recording shows what was on your screen, so we say plainly how it is treated.

Who is responsible

The controller of your personal data is Its Hive, Inc., a company based in Houston, Texas, which runs Chronika at chronika.io. You can reach us through the contact page.

If your employer or school gave you access to a team workspace, they decide what goes into it. For what is in that workspace they are the controller, and we act for them.

What we handle

Account data. Your name, your email address, and either a password (stored only as a hash) or the identity your sign-in provider gives us (Microsoft Entra ID, Google or another OIDC provider). Your workspaces, roles and invitations.

Email codes. To confirm your address and to reset a password we send a six-digit code. We store only a keyed hash of it, for 10 minutes at most, and delete it once it is used or expires. We also email you a welcome message and a notice when your password changes. We send service emails only, and no marketing unless you ask for it.

Billing data. If you buy a plan, Stripe collects your payment details and billing address. We receive your plan, the status and dates of your subscription, and the last four digits and brand of the card, not the full card number.

Messages. What you write to us, and our replies.

Recordings and guides. Each step holds a screenshot, where you clicked, the page address and title (or the Windows program and control name), text you typed, and any narration. A recording shows whatever was on your screen, so it can include personal data about you and about other people.

Recorder tokens. A personal token is created when you connect a recorder. It is shown once, and we keep only a SHA-256 hash of it.

Technical data. The server logs requests so it can run and be kept safe, and the browser sends the cookies listed in the cookie notice.

What is not kept

Password fields are detected and blurred in the screenshot on your computer before it is uploaded, and the text typed into them is not recorded. When a recorder cannot be sure a picture is clean, it leaves the picture out. A recorder does not run unless you start a recording.

That safeguard covers password fields. Other fields can still show on screen, so look over a recording before you share it, and blur anything that should not be seen.

Why we use it

  • to run your account, workspaces and guides, and to make screenshots available to the people you chose (our contract with you);
  • to keep the service secure and to prevent abuse, including limiting repeated sign-in attempts (our legitimate interest);
  • to answer you when you write to us (our legitimate interest, or steps you asked for before a contract);
  • to meet legal duties.

We do not sell personal data, and we do not use your recordings to advertise to you or to train AI models. Where data protection law such as the GDPR applies, the bases above are the ones we rely on: contract, legitimate interests, and legal obligation.

Who can see your guides

Screenshots and narration are served only to signed-in members of the guide’s workspace, or through a guide’s public link when its author has turned one on. Anyone with a public link can read that guide and the screenshots it uses, without an account.

Members with the editor role and above can record and edit. Admins manage members and invitations. Viewers can read.

AI processing

AI is off unless we switch the write-up on. When it is on, the text of a finished recording (page addresses and titles, the names of what was clicked, text typed outside password fields, and your narration) is sent to our AI provider, to write a title, an introduction and step text. Narration audio may be sent for transcription when the browser could not transcribe it live. Screenshots are not part of that request.

That provider acts as a processor for us, under business terms that limit it to providing the service, and we do not allow it to use your data to train its models. Which provider is in use is shown in our list of providers, available on request.

Who else handles it

We use a small number of service providers, each only for the job named here: hosting for the application, the database and stored files; Resend to send our emails; Stripe to take payments; and, when switched on, an AI provider for the write-up described above. They are processors for us (Stripe is also a controller of the payment data it collects), and we ask each to keep data secure and use it only for us. We keep a current list with their locations, which we will send on request.

We are based in the United States, so your data is processed there, and our providers may process it in other countries too. If you are in the EEA, the UK or Switzerland, we rely on standard contractual clauses or an equivalent safeguard for those transfers. We share data with authorities only where the law requires it.

How long we keep it

We keep account data while your account exists. A guide you delete goes to Trash and is removed for good when it is deleted from Trash. When an account is closed we delete its data within 30 days, except what we must keep by law (such as invoices, usually for several years). Backups are overwritten within 35 days, and server logs are kept for no more than 90 days.

Your choices and rights

Depending on where you live, you can ask for a copy of your data, to correct it, to delete it, to restrict or object to some uses, and to move it. Guides can be exported to PDF, Word, HTML and Markdown at any time. To use a right, write to us through the contact page. We answer within 30 days, and we may need to check it is really you. If you are in a team workspace, we may need to pass your request to the workspace’s owner.

US state privacy laws. If you live in a US state with a privacy law, such as Texas or California, you can ask to know what personal data we hold about you, to get a copy, to correct it, to delete it, and to opt out of sale, targeted advertising and profiling that has legal effects. We do none of those, and we do not discriminate against anyone who uses these rights. If we refuse a request you may appeal by writing back to us, and then complain to your state’s attorney general.

Businesses. If your organization uses Chronika for work and needs a data processing agreement, ask us through the contact page.

If you think we have mishandled your data you can also complain to your data protection authority. We would like the chance to put it right first, so please write to us.

Security

We protect data with access checks on every guide and file, hashed tokens and passwords, and blurred password fields. No system is perfectly safe. Read more on the security page, and report a problem through the contact page.

Changes and children

We will change the “last updated” date when this policy changes, and email account holders about material changes in advance. Chronika is not meant for children under 16, and we do not knowingly collect their data. If you think a child has an account, tell us and we will delete it.

Questions about this page? Use the contact page.