← Chronox

Privacy Policy

Version 1.5.1 · Effective August 1, 2026 · v1.5.1: Sentry and Check Technologies clarified as integrated but not currently enabled (no data is sent to them), matching the sub-processors page. · Supersedes v1.5 (July 30, 2026) and v1.4 (July 26, 2026). v1.5: the anti-spoofing (liveness) description was updated for the provider now in force - the standard liveness check runs on our servers through Luxand, Inc. (Alexandria, Virginia, USA) on the punch-moment image, which is sent with no name or identifier attached, is used only to confirm a live person is present (never to train Luxand's software), and is deleted by Luxand within 90 days under its published policy; Luxand was added to the vendor list in §4, and the optional AWS cloud liveness tier is described as the certified per-company alternative. The matching worker consent, notice at collection, and retention policy were republished the same day (consent v3.4, notice v1.6, retention v1.5). v1.4 (July 26, 2026): workers-under-18 section added; text made the single canonical Privacy Policy - the same words are served on chronoxapp.net, at app.chronoxapp.net/privacy.html, and inside the Chronox app (including the link on the sign-in screen). · Chronox is operated by Foundation Digital LLC, an Illinois limited liability company ("Chronox", "we").

1. Who we are

Chronox, a product of Foundation Digital LLC, provides workforce timekeeping software to construction companies. For employee data processed in the app, your employer is the controller/business and Chronox is the processor/service provider acting on its instructions. Employee privacy requests are routed through the employer, which verifies identity; we support every request with export and deletion tooling (§7).

2. What we collect

3. Purposes

Timekeeping and payroll preparation; identity verification at punch; wage-hour record-keeping for your employer; security and anti-spoofing; support; legal compliance. No advertising. No sale or sharing of personal information. No profiting from biometric data - ever (our binding commitments are public in the No-Sale / No-Harvest Pledge).

4. Service providers (sub-processors)

All face matching runs in the cloud. On every Chronox company today, face-geometry templates are created and matched by Amazon Web Services (Amazon Rekognition, in an isolated per-company collection, Oregon, USA) - cloud matching is the configuration in force everywhere and is the only matching path in use. Chronox also ships an optional on-device (offline) matching path built on the Neurotechnology VeriLook SDK: it is not enabled for any company, no offline face templates exist, and no matching runs on it today. If it is ever enabled, matching would run entirely on your own device and no data would reach that vendor. The anti-spoofing (liveness) check on every scan is performed on our servers by Luxand, Inc. (Alexandria, Virginia, USA): the same single camera image used to verify your identity is sent to Luxand with no name or identifier attached, is used only to confirm a real person is in front of the camera (never to train Luxand's software), and is deleted by Luxand within 90 days under its published policy. An optional certified cloud liveness tier using AWS (Rekognition Face Liveness) is available per company but is not currently enabled for any company. The other vendors we use to run the service are: Supabase (database and authentication, USA), Cloudflare (hosting/CDN), Google (Firebase push notifications; Google Sign-In where chosen), Amazon Web Services – Amazon Location Service (reverse geocoding of punch coordinates; Oregon, USA), Stripe (billing - no biometric or punch data), Anthropic and OpenAI (AI features - user-submitted text and attached document images, never face templates or any biometric identifier), Resend (email), Twilio (SMS), Check Technologies (embedded payroll — integrated but not enabled by any company, so no data has been sent), and Sentry (crash reporting — integrated but switched off in production, so no data is sent). Each is bound to use data only to provide its service and never to train its own models on it. The complete, current list - including exactly which data each vendor touches and where - is public at chronoxapp.net/subprocessors, and biometric-path changes carry 30 days' advance customer notice. Employer-directed payroll/accounting exports (e.g., Gusto, QuickBooks, Square, BambooHR, OnPay) go to the provider your employer connects, at its direction.

5. Retention

Biometric identifiers are destroyed at employment end, on a processed revocation, or at the statutory deadline - whichever comes first (automated, with logged destruction receipts; full schedule in the retention policy). Time and payroll records are kept per employment-law schedules (default 7 years). Punch GPS coordinates are retained for up to 6 years (for payroll verification, wage-hour record-keeping, and dispute/audit defense) and then anonymized; the punch record itself is kept per the 7-year record schedule, and a legal hold preserves location for the duration of the hold. Timekeeping photos in Photo mode are permanently deleted within 90 days - sooner once the pay period and any dispute window close. Consent and audit logs are append-only legal proof.

6. Security

TLS in transit; encryption at rest; keystore-backed AES-256-GCM encryption of on-device face templates where offline mode is enabled (not currently enabled for any company); per-company tenant isolation and role-scoped access enforced in the database; consent-before-enrollment enforced by database trigger; append-only consent, event, and audit logs; a written incident-response plan. Suspected incidents involving biometric data trigger notification of affected individuals, customers, and regulators as required by law.

7. The data rights we honor

Regardless of which state or province you work in, Chronox supports these rights for every worker in the system, exercised through your employer (which must verify your identity), within the deadline the law sets - 45 days in California (one 45-day extension where permitted); 30 days in Canada - tracked request-by-request in our DSAR tooling:

  • Know / access - receive a copy of the personal information held about you (machine-readable export).
  • Correction - have inaccurate records fixed; time-record corrections generate a notice you acknowledge in-app.
  • Deletion - have personal information deleted where the law allows (wage-hour records must legally be kept for their statutory period; biometric data is deleted on request via consent revocation, always).
  • Revoke biometric consent - in writing, at any time, from the Privacy & Face ID card in the app. Your request is recorded the moment you make it and your consent is withdrawn at that point. Management then completes the destruction of your face data, and every destruction is logged with an auditable receipt you can ask for. Revoking has no effect on your employment and no effect on your time records.
  • Portability - exports are provided in common formats (CSV/JSON/PDF).
  • Limit sensitive-PI use - biometric data and precise geolocation are used only for the purposes in §3; there is no secondary use to limit.
  • No discrimination or retaliation - declining biometric enrollment or exercising any right cannot cost you pay, hours, or your job; alternative timekeeping is always available (§9).
  • Appeal - if a request is denied, you may appeal via your employer or directly to privacy@chronoxapp.net; appeals are reviewed within the same statutory timelines.

Quebec: Face ID (biometric timekeeping) is not offered in Quebec, so Chronox's biometric program - including biometric enrollment and biometric consent revocation - is out of scope there (see §10). Photo mode is non-biometric and is a separate question, addressed in §10.

8. California employees

Biometric information and precise geolocation are sensitive personal information under the CCPA/CPRA. Where your employer is a covered business, you receive a Notice at Collection and may exercise the rights in §7 - including the right to limit use of sensitive PI - through your employer; Chronox acts under service-provider terms (no sale, no sharing, no targeted advertising, purpose limitation, no retention beyond instructions). We have never sold or shared personal information as those terms are defined by the CCPA.

9. State biometric laws (Illinois, Texas, Washington, Colorado)

Chronox is built to the strictest reading of Illinois BIPA (740 ILCS 14), Texas CUBI (§503.001), Washington RCW 19.375, and Colorado C.R.S. §6-1-1314 everywhere, by default: informed written consent before any collection (release signed in-app; enrollment is blocked without it), a public written retention-and-destruction schedule, destruction deadlines with receipts, a strict no-sale/no-profit rule, and disclosure only with consent or as required by law. Your employer also maintains its own written policy - we provide a publishable template.

10. Canada

Biometric data is treated as sensitive and collected only with express consent supported by a documented necessity assessment. A genuine alternative to face-scan (manager-recorded time) is always available, so consent remains voluntary. Data is processed and stored in the United States and may be accessible to U.S. authorities under U.S. law. Face ID (biometric timekeeping) is not currently offered in Quebec. If it is ever offered there, the biometric database would first be declared to the Commission d'accès à l'information (CAI) at least 60 days before service and French-language documentation would apply (Law 25). Photo mode (non-biometric selfie timekeeping) involves no facial recognition and requires no CAI biometric declaration.

11. Your choices

You may decline biometric enrollment - for religious or medical reasons or otherwise where the law requires an alternative - and your employer maintains an accommodation procedure: management records your time without penalty (the system supports a per-employee Face ID exemption that blocks any biometric collection). You may revoke biometric consent in writing at any time; your face data is then permanently destroyed and a receipt is logged. Access, correction, and deletion requests go through your employer (§7).

12. Automated processing & AI

Chronox uses artificial intelligence in two distinct ways, both with human oversight and neither used to profile workers or make significant decisions about them automatically:

Accuracy and demographic-bias testing. Before deployment and on an ongoing basis, Chronox evaluates the accuracy of the facial-recognition matching, reviews the available demographic-performance evidence for the engine actually in use, and tunes match thresholds accordingly, so that the technology performs reliably across users. Our testing methodology, the vendor evidence we rely on, and our operational monitoring are documented in our internal Bias & Accuracy Testing Evidence file. Repeated non-matches trigger a worker-protective fallback - a non-biometric identity check and manual time entry by management - rather than any automatic adverse action. A match, a match score, or a missing scan is an input to a human decision, never the decision itself: no significant employment decision - pay, discipline, correction, or any similar outcome - is made solely by the technology, and a supervisor with authority to change the result reviews the record before it affects a worker.

What we never do with AI. Biometric identifiers - face images or templates - are never sent to our generative-AI providers and are never used to train, fine-tune, improve, or evaluate any AI model, ours or a vendor's (a binding commitment in our No-Sale / No-Harvest Pledge). Our AI providers are contractually barred from training their models on data we send them. Chronox does not use AI for advertising, does not sell personal information, and does not track workers across other apps or companies. No solely-automated decision produces legal or similarly significant effects about a worker; meaningful information about this logic is summarized above and requests may be directed to your employer or to privacy@chronoxapp.net.

13. Workers under 18

Chronox is not offered to anyone under 16. Workers aged 16 and 17 may use Face ID or Photo timekeeping only where a parent or guardian has signed a consent form covering that use and it is on file with the employer. Our database enforces this: a face template cannot be stored for a worker under 16 at all, and enrollment is blocked for a worker under 18 unless a signed guardian consent is recorded. Where no date of birth and no adult attestation is on record, biometric enrollment is refused rather than allowed by default. A guardian may withdraw that consent at any time through the employer, and the worker's biometric data is then destroyed on the same automated schedule as any other revocation.

14. Workers under 18

Chronox is not offered to anyone under 16. Workers aged 16 and 17 may use Face ID or Photo timekeeping only where a parent or guardian has signed a consent form covering that use and it is on file with the employer. Our database enforces this: a face template cannot be stored for a worker under 16 at all, and enrollment is blocked for a worker under 18 unless a signed guardian consent is recorded. Where no date of birth and no adult attestation is on record, biometric enrollment is refused rather than allowed by default. A guardian may withdraw that consent at any time through the employer, and the worker's biometric data is then destroyed on the same automated schedule as any other revocation.

14. Changes & contact

Material changes are versioned, and re-consent is captured in-app where required - the exact policy text and version you agreed to is stamped on your consent record. Contact: privacy@chronoxapp.net, or Foundation Digital LLC, Attn: Privacy.