Skip to content
kronikl
  • What it records
  • Security
  • Pricing
  • FAQ
Connect your tenant

Privacy

Kronikl is a product of Asumafy. It reads your Azure environment so it can tell you what changed in it. This page says what we collect, what we do with it, and what we will never do with it.

Last updated 18 August 2026.

What Kronikl reads

With your administrator's approval, Kronikl reads the record of changes in your Azure environment: resource configuration, role assignments, policy assignments, and the directory information needed to show a change as a person's name rather than an identifier.

Access is read-only. Kronikl cannot create, modify or delete anything in your environment, and no code path in the product is capable of doing so.

Who can see your data

People you invite to your organization, and nobody else. Your data is separated from every other customer's at the database level, so an account belonging to one customer cannot read another's.

We do not sell your data. We do not share it with third parties. We do not use it to train models, and we do not use it for advertising.

Our own staff have limited access, covering your account rather than your environment: your plan, who is on your team, and whether your tenant connection is healthy. Data collected from your Azure environment is not part of that, except where it is necessary to resolve a support issue you have raised with us. Every look is recorded against the name of the person who made it, and there is no way for us to sign in as you.

Where it is stored

In Microsoft Azure, in the United States, encrypted in transit and at rest. Microsoft is our only infrastructure provider.

We collect anonymised operational telemetry — timings, error rates, and similar — so we can keep the service healthy. Identifiers and configuration values are stripped from it before it leaves the application.

How long it is kept

Your plan sets how far back your history goes: 14 days on Free, 90 days on Pro. Older history is not part of what your plan provides. Close your account and we remove your data.

Your account

You sign in with your existing Microsoft work account. We store your name, work email address and the organization you belong to. There is no Kronikl password, so there is none for us to lose.

This website

Separately from the product, this marketing site records which pages are visited and which link brought you here, so we know what people find useful. We also use a Microsoft analytics service to understand how these pages are used, which sets cookies in your browser. Both are limited to this marketing site: neither runs in the product, and neither sees anything from your Azure environment.

The product itself is treated differently. The pages you use once signed in show your own cloud configuration, so nothing on them is built to hand that to anyone else.

Deleting your data

An owner can close the account from inside Kronikl. We delete the organization and everything in it — change history, configuration snapshots, diffs, alerts, users and tenant connections — within seven days, and email you when it is done. You can also email us and we will do the same.

Two records survive, and both are about us rather than about your Azure environment: which of our staff looked at your account, and what plan you were on. Neither holds anything collected from your tenant, and keeping them is the point of having them. Copies in routine encrypted backups age out on their own and are never restored to serve anyone.

Your access to your Azure environment is yours to end: remove Kronikl's role assignment, or withdraw its consent in your directory, and Kronikl loses access. There is no stored credential — nothing to expire and nothing for us to forget to delete.

To be precise about the timing, because it is the kind of claim worth being precise about: Microsoft issues us short-lived access tokens, and withdrawing consent stops new ones being issued rather than cancelling one already in hand. The next time Kronikl looks at your tenant it finds the access gone, discards the token it was holding, and marks the connection revoked. In practice that is minutes; the outside edge is the lifetime of a single Entra token, which Microsoft sets and which is typically an hour.

Contact

Kronikl is operated by Asumafy LLC. Questions about this page, or anything else: hello@kronikl.io. Security issues go to security@kronikl.dev or through security.txt, so they are not queued behind general enquiries.

If this page changes, the date at the top changes with it, and a change affecting what we collect will be told to customers directly.

kronikl

Azure change history for the people who own the tenant.

Product

  • What it records
  • How it works
  • Pricing
  • FAQ

Trust

  • Security and access
  • Privacy
  • Terms of service
  • Reporting a vulnerability
  • security@kronikl.dev

Contact

  • hello@kronikl.io
  • Sign in
  • Connect a tenant

© 2026 Kronikl — a product of Asumafy Read-only · Entra ID · No stored credentials