krono

Privacy

LAST UPDATED 2026-05-26

What this policy covers. This policy applies to the Krono desktop application (Krono.app), our landing page at krono.simkinselgazar.com, and our account dashboard at app.krono.simkinselgazar.com when it ships. It is published by Simkins & Elgazar LLC, a Virginia limited liability company (“S&E,” “we,” “us”).

The desktop app

Krono is a desktop application for macOS and Windows. It records audio, transcribes it, and writes notes, all entirely on your machine. Nothing about your meetings, calls, recordings, transcripts, or notes is sent to us or to any third party at any point.

System audio on macOS.To capture the other side of a video call, Krono records your computer’s audio output. macOS only permits this alongside a screen stream, so Krono requests the “Screen & System Audio Recording” permission. It then opens the smallest screen stream macOS allows, a 2 by 2 pixel area, and never reads a single frame of it. Krono records audio only. It never views, captures, or stores an image of your screen. On Windows, system audio is captured through the standard audio loopback and no screen permission is involved.

The app makes a single first-launch network call to download the AI models required to transcribe and write notes. After that, the app does not open any network connection during normal use. You can verify this by inspecting network activity on your device.

Updates check.The app contacts our update server when you open Settings → About → “Check for updates,” and when it verifies your license at install. These calls send your license JWT, this device’s hardware identifier, the app version, and the operating system platform. They do not send any audio, transcript, or note content.

The landing page (krono.simkinselgazar.com)

When you visit krono.simkinselgazar.com, our server logs your request as part of normal web hosting (IP, timestamp, requested URL, user agent). These logs are kept for operational debugging only and are not joined to any identifier you provide later. Server logs are retained for 90 days and then deleted.

If you arrive via a referral link, we store an opaque referral code in a first-party cookie for 30 days so we can credit the referrer if you purchase a license. The cookie holds no other information.

The landing page does not use any third-party analytics, advertising, or tracking cookies.

EU and UK visitors. Our launch period restricts access from the EU and the UK at the edge. If you reach us from those regions, you should see a brief notice page from our hosting provider rather than the full landing page, and no referral cookie is set on your visit. We will add EU/UK cookie consent and full regional support before opening sales in those jurisdictions.

If you buy a license

We collect the email address you enter at checkout and use it to deliver your license file. We also store the Stripe customer ID, the launch tier you bought at, the issued license JWT, your license’s active device fingerprints (the hardware IDs of the Macs you activated Krono on), and any review URL or referral records you later submit.

What’s in your license file. The license JWT itself contains: an opaque license identifier (a random UUID), your Stripe customer identifier (the cus_string Stripe issues, which is meaningful only to us and to Stripe), the launch tier you bought at (a number from 1 to 5), the minimum app version this license unlocks (a semver string), and standard JWT metadata (issue time, expiration time, issuer, audience). The JWT does not contain your name or your email address; those live only in our database, keyed by the Stripe customer ID.

Retention. We retain your account record (email, Stripe customer ID, launch tier, license JWT, device fingerprints, review URL, referral records) for as long as your license is active, and for 7 years after expiration for tax and audit purposes. After that period we delete or anonymize the record.

Payments are processed by Stripe, acting as an independent data controller for payment information. We do not see or store payment card numbers; Stripe holds the card data under PCI scope. Stripe’s privacy practices are at stripe.com/privacy.

Email delivery uses Resend, acting as our data processor. We have disabled open- and click-tracking in our Resend project so the license-delivery email contains no tracking pixel and no rewritten links. The license-delivery message is the only email we send automatically, plus periodic renewal-reminder emails as your license approaches its update anniversary. We do not run marketing campaigns, drip sequences, or product analytics on your email. Resend’s privacy practices are at resend.com/privacy.

Sub-processors. A current list of sub-processors (Stripe for payments; Resend for transactional email; AWS Amplify and Neon for hosting and database; AWS Route 53 for DNS) is available on request at privacy@simkinselgazar.com.

International transfers.Our sub-processors may process your data in the United States and in other countries where they operate. If you are in the EU, UK, or another jurisdiction with restrictions on international data transfers, we rely on each sub-processor’s standard contractual clauses or equivalent transfer mechanism.

What we do not do

We do not sell, rent, or share your information with third parties. We do not embed analytics, ad pixels, or trackers on this landing page. We do not run any usage telemetry from the desktop app, because the desktop app does not make network calls during use.

Your rights

You can email privacy@simkinselgazar.com to exercise any of the following rights regarding the personal data we hold about you. We will respond within 30 days.

  • Access. Request a copy of the data we hold about you.
  • Correction.Ask us to fix data that’s wrong or out of date.
  • Deletion. Ask us to delete your data, subject to legal retention obligations (e.g., tax records).
  • Portability. Receive your data in a structured, machine-readable format.
  • Objection / restriction. Object to our processing of your data, or ask us to restrict it, where permitted by law.
  • Withdraw consent. Where our processing is based on your consent, withdraw it at any time.

If you are a Virginia resident, the Virginia Consumer Data Protection Act gives you these rights and a right to appeal if we decline a request. To appeal, reply to our decision email and we will respond within 60 days.

If you are an EU or UK resident, the GDPR / UK GDPR gives you these rights and the right to lodge a complaint with your local data protection authority.

If you are a California resident,the California Consumer Privacy Act / California Privacy Rights Act gives you these rights and the right to non-discrimination for exercising them. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not process sensitive personal information beyond what’s needed to deliver your license.

Changes to this policy

We may update this policy from time to time. If we make a material change, we will post the updated policy with a new “Last updated” date and, where we have your email address, send a notification to that email at least 30 days before the change takes effect. Continued use of Krono after a change indicates acceptance of the updated policy.

Children's data

Krono is sold to professionals and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us at privacy@simkinselgazar.com.

Simkins & Elgazar LLC operates this site. Reach us at hello@simkinselgazar.com. For privacy-specific questions, use privacy@simkinselgazar.com. Our registered address is Simkins & Elgazar LLC, Virginia, USA.

← BACK TO KRONO.SIMKINSELGAZAR.COM