Chronicle

The data covenant

Privacy at Chronicle

Personal stories ask for particular care. This page explains what Chronicle keeps, what it does with story material, who can see each kind of information, and the choices that remain yours.

Effective

The commitment in plain language

Drafts stay private until you choose to publish. Published stories stand on their own: public reading surfaces do not show an author name, profile, email address, or links between stories by the same person. Stories are found by what they are about, not who wrote them.

Chronicle has no public profiles, follower system, public comments, counts, rankings, popularity ordering, or activity feed. Quiet signals exist to help a writer know that their story reached someone; they are not a public score.

What Chronicle keeps

  • Account and access information: your email address, a protected password record, email-confirmation and reset records, invitation or request-to-join information, and the life threshold you may choose during arrival.
  • Your writing: drafts, published stories, interview questions and reflections, story dates and settings, and the consent and sensitivity choices attached to a story.
  • Discovery information: themes, milestones, keywords, places, time periods, embeddings, and related-story connections used to organize and search the archive.
  • Reading signals: marks, echo notes, story-view history and the route by which a story was found. When you are signed in, an account identifier may be used internally to avoid counting your own story views and to prevent duplicate signals.
  • Safety and stewardship records: reports, moderation decisions, approval requests, story designations, job and delivery status, and the limited operator records needed to run and protect Chronicle.

How story material is used

Chronicle uses your writing to save and display the story you asked it to keep. When you request them, story text is also used to ask reflection questions and point out details you may want to soften before publishing. Answering or accepting those suggestions is always your choice; Chronicle does not write or rewrite your story.

Published story material is processed to create discovery metadata and embeddings, support meaning-based search, open milestone and theme doorways, and find related or kindred stories. Operators and stewards may also review story material when curating the archive, handling a report, resolving an approval request, or protecting the service.

Who can see what

  • Public readers can read stories deliberately made available on public reading surfaces. They see the story and its reader-facing context, never the member's account identity.
  • You can see and manage your own drafts, stories, reflections, settings, and author-only signals. You can see the words of a delivered echo note, but not the reader's identity.
  • Stewards see the story material and operational context needed for curation, reports, moderation, and approvals. Steward views do not reveal who wrote a story or who sent a reader signal or report.
  • The operator may access account, story, and operational data when needed to provide support, secure the service, fulfill a deletion request, or recover Chronicle.
  • Service providers receive only what is needed for their part of the service: hosting and database operation, email delivery, backups, and the OpenAI API functions described below.

Quiet signals stay quiet

Marks, echo notes, and reading activity are for the story's author, not the public. Reader and viewer identity is not shown to authors, public readers, or stewards. Chronicle may show an author a private total or a general route by which readers found a story, but never a list of the people behind it.

A report travels in the other direction: from a reader to a steward. Its words do not appear to the author, and the steward is not shown who sent it. An author may be told what action was taken and why, without being told which steward acted.

Do you train AI on my stories?

No. Chronicle does not train its own model on your stories, and it does not opt in to sharing OpenAI API inputs or outputs for model training. Chronicle sends story material to the OpenAI API only to provide reflection questions, privacy review, discovery metadata, embeddings, search, and related-story features.

OpenAI currently states that API inputs and outputs are not used to train or improve its models by default unless an organization explicitly opts in. Chronicle will revise this section before making any different use of story material or if that provider posture changes.

Your choices and deletion requests

You can edit, unpublish, or delete one of your stories from My Stories. Where Chronicle offers a choice about featuring, public reading, or sensitive framing, you can change that choice later.

Chronicle does not yet have a self-serve account deletion button. To request deletion of your account and account-linked data, reply from your registered address to an email Chronicle sent you, or contact the operator who invited you. The operator will verify the request, review its scope, remove the account and linked data from the live service, and confirm when the work is complete.

This process is manual and is not instant. Removing an echo note from Chronicle cannot undo what its recipient already read or copied. Recovery backups retain historical database snapshots; they are not used as a second live source, and a deletion is re-applied before an older snapshot is returned to service. Chronicle does not promise that any story or the archive itself will remain available forever.

Care, retention, and change

Chronicle limits access according to the roles above and keeps operational records only for providing, securing, moderating, and recovering the service. No internet service can promise perfect security. If Chronicle's data practices materially change, this page will be updated with a new effective date.

Privacy explains custody. Read the Terms for the promises and responsibilities that apply when writing, publishing, and reading in Chronicle.