Privacy Policy
How Chronico handles your personal and health information — including everything read from a smartwatch or fitness tracker.
Version 1.0 · Last updated 23 September 2026
The short version
Chronico is an app for people managing a long-term condition. It keeps your medication reminders, your readings, and — if you choose to connect one — data from your smartwatch, so that you and the clinicians you choose can see how you are doing.
Our core commitments
- •We do not sell your data. Not to anyone, ever, in any form.
- •We do not use your health data for advertising or marketing, and we do not share it with advertising networks or data brokers.
- •Your health data is shared only with people you choose — the doctors and caretakers you are linked to in the app.
- •You can disconnect your watch or delete your account at any time, from inside the app.
This summary is for orientation only. The sections below are the policy.
Who we are and who this covers
Chronico is operated by Bulletpoint SHPK (company number [NIPT]), registered at Rr. Ishull Shëngjin, Nr. Ap. 7, Shëngjin, Lezhë, Albania. For the purposes of data protection law we are the controller of the personal data described here.
This policy covers everyone who uses Chronico:
- •Patients — people using the app to manage their own condition.
- •Doctors— clinicians linked to a patient's account who can see that patient's data and leave notes.
- •Caretakers — family members or carers a patient has linked to their account.
- •Administrators — staff at the organisation operating this deployment.
We are based in Albania and process personal data under Albanian data protection law. Where you are in the European Economic Area or the United Kingdom, the GDPR applies to you as well, and we honour the rights it gives you regardless of where you live.
Health information is special category data under both. We process it on the basis of your explicit consent, which you give when you create an account and again, separately, when you connect a health device. You can withdraw either at any time — see Your rights.
Information you give us
Account and profile
- •Your email address and password (stored only as a cryptographic hash — we cannot read it).
- •Your name, and optionally a phone number, profile photo, address, city and country.
- •Your role: patient, doctor or caretaker.
- •The conditions you tell us you are managing.
- •Your language preference.
- •Which doctors and caretakers you are linked to.
Health information you enter yourself
- •Medication reminders: the medicine, dose amount and unit, number of pills, schedule, and any notes you add.
- •Readings you record by hand — blood pressure (systolic, diastolic and pulse), blood glucose, weight, temperature and others.
- •Whether you marked a reminder as done, and when — your adherence record.
- •Activities and treatment-tracking entries.
- •Notes your doctor leaves on your record.
- •Messages you send to the in-app AI assistant.
Health data from wearables and phone health apps
This section describes exactly what happens when you connect a smartwatch or fitness tracker. It is the most sensitive data the app handles and we have tried to describe it precisely rather than generally.
How the connection actually works
Chronico never connects to your watch directly. It has no Bluetooth pairing with your device and cannot control it. Instead it reads from the health store already on your phone, which your watch writes into:
Android: Galaxy Watch (or other) → Samsung Health / the watch's own app → Health Connect → Chronico
iOS: Apple Watch → Apple Health (HealthKit) → Chronico
This means two things. First, we only ever see data that is already on your phone. Second, the accuracy, completeness and timeliness of that data are determined by your watch and by Samsung Health, Health Connect or Apple Health — not by us. Data can arrive hours late, or not at all, if those apps are not syncing.
What we read
We ask for permission to read the following measurements. You choose which of them to allow, and you can allow some and refuse others. We only ever read the ones you have granted.
| Measurement | Internal name | Unit |
|---|---|---|
| Steps | steps | count |
| Heart rate | heart_rate | bpm |
| Resting heart rate | resting_heart_rate | bpm |
| Heart rate variability | heart_rate_variability | ms |
| Blood pressure (systolic) | blood_pressure_systolic | mmHg |
| Blood pressure (diastolic) | blood_pressure_diastolic | mmHg |
| Blood glucose | blood_glucose | mg/dL |
| Oxygen saturation | oxygen_saturation | percent |
| Body temperature | body_temperature | celsius |
| Respiratory rate | respiratory_rate | breaths per minute |
| Weight | weight | kg |
| Active energy burned | active_energy_burned | kcal |
| Total energy burned | total_energy_burned | kcal |
| Distance | distance | meters |
| Exercise time | exercise_time | minutes |
| Sleep (asleep) | sleep_asleep | minutes |
| Sleep (deep) | sleep_deep | minutes |
| Sleep (light) | sleep_light | minutes |
| Sleep (REM) | sleep_rem | minutes |
| Sleep (awake) | sleep_awake | minutes |
| Sleep (whole session) | sleep_session | minutes |
For each reading we store the value, the time it was recorded, the unit, the name of the app that wrote it (for example “Samsung Health”), and — on iOS only — the hardware model that recorded it. On Android, Health Connect does not tell us which device recorded a reading, only which app wrote it, so that field is always empty.
We also store a de-duplication identifier for each reading so that re-reading the same period does not create duplicates. The app deliberately re-reads an overlapping window on every sync, because Samsung Health can write to Health Connect hours after the fact.
Permissions, and historical access
- •Health permissions are granted by you in Health Connect or Apple Health, per measurement. Refusing one only affects that measurement.
- •Historical access is a separate permission on Android. If you do not grant it, we can only ever read data recorded after the moment you connected. Your older data is not hidden from you — it is unreachable to us, and cannot be reached retroactively.
- •Physical Activity is a separate Android system permission needed for step counts. Refusing it affects steps only; everything else still works.
Diagnostic sync logs
Connecting a watch can fail silently in several places, and when it does, the only symptom you see is an empty dashboard. So each sync attempt writes a diagnostic log we can use to tell you what went wrong. A log entry records:
- •The stage reached (availability, permissions, historical access, reading, upload, finish) and a machine-readable outcome code.
- •A human-readable message, such as “Permissions are granted but Health Connect returned no samples for the last 30 days.”
- •Which measurement was being read, how many readings were returned, and how many were new.
- •How long the step took, and when it happened according to your phone's clock.
- •Your device model, OS version, app version, and the name of the health app that supplied the data.
- •A diagnostic detail object containing counts, source app names, permission lists and error strings.
What diagnostic logs never contain
Sync logs never contain your actual health values — no heart rates, no glucose readings, no weights — and no identifying details beyond the account the sync belongs to. They record that 412 readings moved, never what those readings said. This is a deliberate design constraint of the system, not a matter of policy alone.
Connection records
We keep a record of the current state of each connection: which health platform, which measurements you granted and refused, whether historical access was given, when it last synced successfully, the last error if there was one, your device and app version, and a running total of readings received. If you use more than one device, there is one such record per device platform.
Apple Health (HealthKit) — specific commitments
- •We do not use HealthKit data for advertising, marketing, or any use-based data mining.
- •We do not sell HealthKit data, or disclose it to data brokers or advertising platforms.
- •We use HealthKit data only to provide health and care features to you and the clinicians you have linked to your account.
- •We do not share HealthKit data with third parties without your consent, beyond the processors named in this policy who act on our instructions.
- •We do not write data back to Apple Health.
Health Connect (Android) — specific commitments
- •We use Health Connect data only for the purposes described in this policy and shown to you at the point of permission.
- •We do not sell Health Connect data or share it for advertising.
- •We do not transfer Health Connect data to any party for a purpose you have not been told about.
- •Disconnecting in the app, or revoking permission in Health Connect, stops all further reading immediately.
- •We do not write data back to Health Connect.
Turning it off
You can disconnect at any time from the app's settings, and you can revoke any or all permissions directly in Health Connect or Apple Health. Doing so stops all future reading immediately. Readings already synced remain in your Chronico record so your history stays intact — to remove those as well, delete your account or ask us to erase them (see Deleting your account and data).
Information collected automatically
- •Device and app information: device model, operating system version, and app version.
- •Authentication events: when you sign in, and whether your email is verified.
- •Technical logs generated by our servers, including IP address and request times, kept for security and debugging.
- •Push notification tokens, so reminders can reach your device.
- •Error and crash diagnostics.
We do not use third-party advertising identifiers, and we do not track you across other apps or websites.
The AI health assistant
Chronico includes an AI assistant you can ask questions about your condition and about using the app. You should understand how it works before using it.
Your health data is sent to an AI provider
To answer usefully, each message you send is accompanied by a summary of your record — your medications, recent readings, data from your connected device, and your adherence — and sent to [AI PROVIDER NAME, e.g. OpenAI, Anthropic], which processes it in [WHERE THAT PROVIDER PROCESSES THE DATA]. They act as our processor under contract and are not permitted to use your data to train their models or for any purpose of their own.
If you would rather your health data were not processed this way, do not use the assistant. Every other part of the app works without it.
We store your conversations with the assistant so you can return to them, along with a count of the tokens used. You can delete a conversation at any time. Administrators at the operating organisation can see conversation records for support and safety review.
The assistant is not a clinician and does not diagnose. See our Terms & Conditions for what it will and will not do.
How we use your information
| What we do | Why | Lawful basis |
|---|---|---|
| Run your account and show you your data | To provide the service you signed up for | Contract; explicit consent for health data |
| Send medication and appointment reminders | The core purpose of the app | Contract; explicit consent |
| Read and display data from your connected device | So your readings and activity appear without manual entry | Explicit consent, given separately at connection |
| Show your data to doctors and caretakers you are linked to | So the people caring for you can see how you are doing | Explicit consent |
| Answer your questions through the AI assistant | Only when you choose to use it | Explicit consent |
| Diagnose failed device syncs | So support can tell you why your watch isn't working | Legitimate interests — providing a working service |
| Keep the service secure and prevent abuse | Protecting accounts and health data | Legitimate interests; legal obligation |
| Produce aggregate, de-identified statistics | Understanding how the product is used overall | Legitimate interests |
Who can see your health data
- •You. Always.
- •Doctors linked to your account. A doctor can see the record of a patient they are linked to, including readings, adherence and device data, and can leave notes. The link must exist before any access is possible — every request is checked against it.
- •Caretakers linked to your account. The same, subject to the same check.
- •Administrators at the organisation operating this deployment, for support, safety and to keep the service running. Administrator access to sync diagnostics is designed around counts and error codes rather than your readings.
You control who is linked to you, and can remove a link at any time from the app, which ends that person's access.
What we never do
- •We never sell your personal or health data.
- •We never use health data — from any source, including your watch — for advertising or marketing.
- •We never share health data with advertising networks, data brokers, or analytics companies.
- •We never use your health data to train AI models, and our AI provider is contractually barred from doing so.
- •We never share your data with your employer or your insurer.
- •We never write data back to your watch or your phone's health store.
International transfers
Your data is stored in [HOSTING REGION, e.g. EU (Frankfurt)]. Where a provider listed above processes data outside your country, we rely on appropriate safeguards — Standard Contractual Clauses, or an adequacy decision covering the destination. You can ask us for a copy of the safeguards that apply to you.
How long we keep things
| Data | Kept for |
|---|---|
| Your account and health record | As long as your account is open |
| An inactive account | 24 months, after which we contact you and then delete it |
| Readings synced from a device | As long as your account is open, or until you ask us to erase them |
| Diagnostic sync logs | 12 months — long enough to diagnose a recurring fault |
| AI assistant conversations | Until you delete them, or your account closes |
| Security and access logs | 12 months |
| Backups | 35 days on a rolling cycle |
Security
- •All traffic between the app and our servers is encrypted in transit (TLS).
- •Data is encrypted at rest.
- •Passwords are stored only as salted cryptographic hashes and are never recoverable.
- •Access to production systems is restricted to named staff and logged.
- •Access to a patient's record is checked against an explicit link on every request, not assumed from a role.
- •Diagnostic logging is designed so that health values never enter it.
No system is perfectly secure. If a breach affects your data and is likely to put your rights at risk, we will tell you and the relevant regulator without undue delay, and in any case within the statutory deadline.
Your rights
Under Albanian data protection law, and under the GDPR where it applies to you, you have the right to:
- •Access the personal data we hold about you, and get a copy.
- •Correct anything inaccurate.
- •Delete your data — see the next section.
- •Port your data to another service in a machine-readable format.
- •Object to or restrict certain processing.
- •Withdraw consent at any time — for health data generally, for the device connection specifically, or for the AI assistant. Withdrawing does not affect processing that already happened.
- •Complain to a data protection regulator — in Albania, the Information and Data Protection Commissioner (Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale); in the EEA or UK, your national supervisory authority.
To exercise any of these, email privacy@chronico.app. We respond within one month. We will not charge you or make the service worse for asking.
Data Protection Officer: [DPO NAME AND EMAIL, or remove this line]
Deleting your account and data
How to delete your account
- •In the app: Settings → Account → Delete account. This is available to every user without contacting us.
- •By email: write to privacy@chronico.app from the address on your account.
When you delete your account we erase:
- •Your profile, contact details and login credentials.
- •Your reminders, readings, adherence history and notes.
- •Every reading synced from your watch or phone health app.
- •Your device connection records and sync diagnostics.
- •Your AI assistant conversations.
- •Your links to doctors and caretakers.
Deletion is completed within 30 days. Backups are purged on a 35-day rolling cycle, after which no copy remains. We may retain a minimal record of the deletion itself, and anything we are legally required to keep, in which case we will tell you what and why.
You can also delete individual items — a reading, a reminder, a conversation — without deleting your whole account, and you can disconnect your device while keeping the rest of your record.
Children
Chronico is not intended for children under 16. We do not knowingly collect data from them. If a child under that age has created an account, contact privacy@chronico.app and we will delete it. Where a child is managed by a parent or guardian through the caretaker role, the adult account holder is responsible for that relationship and for the consent it relies on.
Changes to this policy
We will post any change here and update the date at the top. If a change materially affects how we use your health data, we will tell you in the app and, where the law requires it, ask for your consent again before the change applies to you.
Contact us
Privacy questions and rights requests: privacy@chronico.app
Everything else: support@chronico.app
Bulletpoint SHPK
Rr. Ishull Shëngjin, Nr. Ap. 7, Shëngjin, Lezhë, Albania