Privacy Policy
Stand / Last updated: 2026-08-22
This is a courtesy translation. Only the German Datenschutzerklärung is legally binding.
1. Controller
Thomas Kraaibeek
Wilhelmstr. 20, 48149 Münster, Germany
Email: kontakt@cronloom.io
Phone: +49 1590 6269275
Further details in the Impressum.
We are not legally required to appoint a data protection officer and have not done so. Please direct all privacy questions to the address above.
2. Processing activities
2.1 Visiting the website
Our server processes technically necessary connection data (IP address, date and time, resource requested, volume transferred, status code, referrer, browser and operating system). Purpose: delivering the page, stability and security. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in secure, trouble-free operation. Retention: server logs are deleted after 14 days.
2.2 Account and use of the Service
For an account we process your name and email address and, depending on how you sign in, a password (stored only as a hash) or the identifier of your Google or GitHub account. In use, we process the content you enter: time entries, clients, projects, rates, budgets and settings. Purpose: performing the contract. Legal basis: Art. 6(1)(b) GDPR. Retention: until you delete your account, then erased within 30 days unless a statutory retention duty applies. Providing this data is necessary to conclude the contract; without an email address we cannot create an account.
2.3 Sign-in with Google or GitHub
If you sign in via Google or GitHub we receive your email address, name and a user identifier. Google and GitHub are independent controllers for the processing on their side. Legal basis: Art. 6(1)(b) GDPR.
2.4 Google Calendar connection (optional)
You can voluntarily connect your Google Calendar to turn appointments into time entries. We request read-only access to your calendars and store the access and refresh tokens issued by Google in order to maintain the connection. Legal basis: Art. 6(1)(a) GDPR (consent, given by granting access). Retention: until you disconnect it in the settings or delete your account. You may withdraw consent at any time with effect for the future; this does not affect the lawfulness of processing carried out beforehand.
Limited Use of Google user data: CronLoom’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use your calendar data solely to provide the features you asked for in CronLoom. We do not transfer it to third parties except as necessary to provide the service, for security purposes, or to comply with applicable law. We do not use it for advertising, and we do not allow humans to read it unless you have given explicit consent, it is necessary for security or to resolve a technical problem, or the law requires it. Calendar data is not used to train generalised AI models.
2.5 Email
We send contract-related email (password resets, running-timer reminders, weekly summaries, budget alerts) via the provider Scaleway (Transactional Email, Paris). Legal basis: Art. 6(1)(b) GDPR and, for summaries and alerts, Art. 6(1)(f) GDPR — our legitimate interest in keeping you informed about your tracking. Every such email contains an unsubscribe link and the preferences can be changed in your account at any time.
2.6 Reach measurement with Plausible
On our website we measure reach using Plausible Analytics, which we run on
our own server in Germany (analytics.kraaibeek.tech); no data is
transmitted to the vendor or any third party. We record the page requested,
the referrer, an approximate country-level location, and coarse device and
browser information. No cookies are set and no cross-device identifiers are
created. To recognise repeat visits within a single day, a hash of IP
address and browser signature is generated server-side; it rotates daily and
cannot be reversed, and the IP address itself is not stored.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in
privacy-preserving reach measurement without profiling.
Retention: aggregated statistics only, no individual
profiles.
2.7 In-app product analytics
Inside the signed-in application we measure product use with PostHog (EU cloud, Frankfurt). This runs on two paths with two different legal bases: the analytics SDK in your browser, and a short list of events our server records when you perform them.
In your browser: the PostHog SDK only runs after you have consented in the application. A notice asks separately; you can allow or decline with equal weight and change your decision any time under Settings → Product analytics. Without consent the SDK is not even loaded, so nothing is measured or sent. It is cookieless (memory-only persistence), does not record sessions, and does not autocapture clicks. Legal basis: Art. 6(1)(a) GDPR — your consent, which you can withdraw at any time with effect for the future.
On our server: when you create an account, a time entry, a client or a project, set a floor rate, run an export, share a report, or change your plan, we record that it happened. These events carry your user id and the event name. Account creation may also carry the landing CTA that sent you here: a short placement label such as "hero", never a URL or page content. They never carry work content, and they neither read nor write anything on your device, so § 25 TDDDG does not apply to them. They are therefore not covered by the in-app consent decision. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in understanding which parts of the product are used, without profiling for advertising. You can object as described in section 6.
Events on both paths are linked to your user id, which makes them pseudonymous rather than anonymous. Page paths that contain access tokens — such as shared client reports — are stripped before anything is sent. We do not send email addresses or other account content with these events. Landing-page reach measurement stays with self-hosted Plausible (section 2.6) and is separate.
2.8 Error reports
Crashes and server errors in the application and API are sent to Sentry (EU cloud, Frankfurt) so we can fix faults. Request bodies and user profiles are not sent. Tokens in URLs are stripped as in section 2.7. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping the service reliable.
2.9 Operational logs
The API writes operational logs (severity, message, NestJS context) to Better Stack in the EU so we can diagnose outages. We also run an uptime check against the public health endpoint. These logs are not used for product analytics or advertising. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating and restoring the service.
2.10 AI quick add (optional)
The quick add turns a sentence like “yesterday 2.5h Acme website” into a proposed time entry. To do that we send the text you typed or dictated, together with the names of your projects, clients and tags, to Anthropic, PBC (USA). No other account content, email addresses or rates are transmitted. Under our contract Anthropic does not use this data to train its models and retains it only briefly for abuse prevention. A proposal is only booked once you confirm it. Legal basis: Art. 6(1)(a) GDPR — your consent, which we ask for separately before first use. You can withdraw it at any time under Settings → AI quick add with effect for the future; the feature switches off immediately.
Dictation: In the iOS app, speech is converted to text entirely on your device; audio never leaves it. In the browser, dictation uses your browser’s speech recognition. Where your browser supports local recognition (current Chrome versions), the audio stays in the browser; otherwise your browser’s vendor (Google or Apple) processes the audio under its own privacy terms — that happens through your browser, not on our behalf. The app tells you which case applies while you dictate.
3. Recipients and processors
- Hetzner Online GmbH, Germany — hosting of the application and database. Data processing agreement in place.
- Scaleway SAS, France (Paris data centre) — sending contract-related email. Data processing agreement in place.
- PostHog, EU cloud, Frankfurt — in-app product analytics. Data processing agreement being put in place.
- Functional Software, Inc. (Sentry), EU cloud, Frankfurt — crash and error reports from the app and API. Data processing agreement being put in place.
- Better Stack, EU cloud (Nuremberg) — API operational logs and uptime monitoring. Data processing agreement being put in place.
- Anthropic, PBC, USA — AI parsing of the quick-add input (only after consent: typed or dictated text plus project, client and tag names). Data processing agreement in place.
Beyond this we disclose personal data only with your consent or where legally required. We do not sell data and use no advertising networks.
4. Transfers to third countries
Personal data leaves the European Union in one case only: if you use the AI quick add (section 2.10), Anthropic, PBC (USA) processes the text you entered for it together with your project, client and tag names. This transfer rests on the EU Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR); you can obtain a copy via the contact details in the imprint. Without your consent this transfer does not happen. All other processing stays in the EU: hosting (Hetzner, Germany), email delivery (Scaleway, France), in-app product analytics (PostHog, Frankfurt), error reports (Sentry, Frankfurt) and API logs (Better Stack, EU).
5. Retention
We keep personal data only as long as necessary for the purposes described. Account and content data are deleted within 30 days of the contract ending. Once we issue invoices, the relevant records become subject to statutory retention periods — accounting records are kept for eight years under German tax law, running from the end of the calendar year in which the record arose. During that period processing is restricted to storage.
6. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to withdraw consent with effect for the future (Art. 7(3)).
Right to object under Art. 21 GDPR: You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Art. 6(1)(f) GDPR. This applies in particular to reach measurement and product analytics. We will then stop processing unless we can demonstrate compelling legitimate grounds that override your interests. An informal message, for example by email to kontakt@cronloom.io, is sufficient.
You can also export and delete your data yourself under Settings → Privacy & data.
You further have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2–4, 40213 Düsseldorf, Germany.
7. Processing on behalf of our users
When you record data about your own clients in CronLoom, you are the controller and we act as processor under Art. 28 GDPR. We provide a data processing agreement free of charge on request at kontakt@cronloom.io.
8. Cookies and local storage
Signing in sets strictly necessary cookies: your session, and short-lived values that carry a Google or GitHub sign-in through to the end. They are essential for the service you requested and therefore require no consent. We set no advertising or tracking cookies. Beyond that, the application keeps a few entries in your browser's local storage so it works the way you left it: your product analytics decision (section 2.7), your theme and language, the project and description your last timer used, and, if you arrived from one of our calculators, the rate you entered there. These entries stay in your browser and are not read on our servers.
9. Changes to this policy
We update this policy when our processing or the legal situation changes. The version published on this page applies.