Skip to main content

Privacy Policy

Last updated: August 26, 2026

This policy explains how A2 Foundry, Inc. collects, uses, and protects information in Chrona Actions, available at app.chronaactions.com.

1. How Chrona Actions handles your content

Chrona Actions reconciles what a team discusses against what its systems of record say, and it has to do that continuously, over months. That requires us to store content: the evidence that justifies each finding, as short excerpts from the artifacts you provide, and the record of how work evolved. That content is stored on systems we operate.

The meeting artifacts themselves are not retained. A transcript, recap, or note is read in transit during a reconciliation run; Chrona Actions keeps the evidence excerpts its findings cite and does not keep the rest.

We store what the service requires and no more, we tell you how long we keep it, and we delete it when you leave. The rest of this policy is the detail.

2. Our role

Your organisation decides what artifacts to provide, which systems to connect, and what to do with the findings. Your organisation is the controller of that information. A2 Foundry is a processor acting on its instructions, under the data processing agreement between us.

We are the controller only of account and usage information: the data in Section 3 under "Your account" and "How you use the product."

3. What we collect

Your account

Email address, display name, and organisation name.

Access is by invitation. An account can only be created for an address an authorised administrator of your organisation has already added to a workstream. You sign in either through Microsoft Entra single sign-on or with a single-use numeric code sent to your email address, depending on your organisation's configuration.

If you sign in with Microsoft: we receive the identity claims your organisation releases through Microsoft Entra (your name and email address). This sign-in is for authentication only. It does not give Chrona Actions access to your files, mail, calendar, or any other Microsoft 365 content. Chrona Actions requests only the openid, profile and email scopes. Access to a system of record is a separate, explicit authorisation you grant in that system.

Content your organisation provides or connects

Meeting transcripts, recaps, notes, status documents, decks, and similar recurring artifacts, which are processed in transit and not retained (Section 1). Records read from the systems of record you connect: item titles, owners, statuses, dates, and change history.

What we derive and keep

To reconcile work across time, Chrona Actions creates and stores:

Information about people who are not our users

Meeting artifacts and connected records name people who may never use Chrona Actions: participants in a meeting, people holding an action, people mentioned in a discussion. We store their names, organisational identity, work assignments, statements attributed to them in the artifacts provided to us, and the status they report. Section 7 explains what that means for them.

Where identity is unclear, we do not guess. If we cannot confidently match a name in an artifact to a person, the item stays unresolved for a human to decide. We do not assign work to someone by inference.

How you use the product

Pages visited and features used, together with browser and device information, collected through PostHog. This is product analytics. It does not include your meeting content, your evidence, or your findings.

4. How we use it

To operate your account, run reconciliation and generate findings, deliver requests to the people your organisation designates, maintain and secure the service, support you, and comply with law.

5. What we don't do

6. AI processing

Chrona Actions uses Anthropic as its large language model provider to generate findings from the artifacts you provide, under an agreement that prohibits the provider from retaining your content or using it to train its models.

7. Service providers

We share information only with the providers that operate the service:

Provider Purpose
SupabaseDatabase, authentication and file storage
VercelApplication and website hosting
RailwayHosting the reconciliation engine
ResendDelivering sign-in codes and service email
Microsoft (Entra ID)Single sign-on, where your organisation uses it
PostHogProduct analytics
AnthropicGenerating findings from your artifacts
The systems of record you connectReading and writing coordination fields, under your own authorisation

These providers access your information only to perform services on our behalf and are not permitted to use it for any other purpose. We give at least 30 days' notice before adding or replacing a subprocessor that handles Chrona Actions content.

We may also disclose information if required by law or legal process, or to protect the rights or safety of A2 Foundry, our customers, or others.

8. If you appear in a workstream but aren't a Chrona Actions user

Your information is in Chrona Actions because the organisation running that workstream provided it. Requests to access, correct, or delete it should go to that organisation, which decides how to respond.

If you contact us at contact@chronaactions.com, we will identify the relevant customer and pass your request to them.

9. Separation between customers

Each customer's data is isolated at the database level through row-level security, and access is scoped by workstream and role. Within a customer, a person invited only to respond to a request sees only what is directed to them. They do not see the workstream, other people's work, or findings under review.

Credentials for a connected system of record are held in an encrypted secret store, keyed to the individual person who authorised the connection, and are never readable by the browser or by any signed-in user. Disconnecting a system deletes the stored credential.

10. How long we keep it

Evidence excerpts are kept for the duration of your subscription, unless your agreement specifies a shorter period. The artifacts they were taken from are not retained at all: they are processed in transit, as described in Section 1.

Workstream, lane, topic, action and timeline records are kept for the duration of your subscription and for 90 days afterward, to support export.

Account information is deleted within 30 days of account closure.

After the export window, we delete or de-identify your content within 60 days, unless law or your enterprise agreement requires otherwise. Changes already applied to your connected systems of record remain in those systems, because they are records in your systems rather than ours.

11. Security

We use encrypted connections, encryption at rest, role-based access controls, tenant isolation enforced at the database layer, and audit logging of changes and access. Access by A2 Foundry personnel is limited to what is required to operate and support the service.

12. Cookies

We use cookies for session management and for product analytics. We do not use advertising or cross-site tracking cookies, and we do not track you across other websites.

13. Your rights

You may request a copy of your information, ask us to correct or delete it, and opt out of product communications, by emailing contact@chronaactions.com.

We honour rights under the EU and UK GDPR and the California Consumer Privacy Act for all users regardless of location. Where we act as a processor, we assist our customers in responding to individuals' requests and act on their instructions. See Section 8.

14. Age

Chrona Actions is not intended for anyone under 18.

15. Changes to this policy

Material changes take effect on an updated "Last updated" date, with notice by email or in the product.

16. Contact

contact@chronaactions.com
A2 Foundry, Inc.

See also our Terms of Service.