5 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.
Erase one person permanently
data_subject.erase_personwriteconfirmadmin only
PERMANENTLY DESTROYS everything this account holds about one contact and CANNOT BE UNDONE. Deletes their profile, messages, conversations, calls, session recordings, page views, IP addresses, form submissions, support tickets and community activity outright. Their stored files are deleted from storage first — call recording audio, email attachments, contact files, form uploads, session recordings — and any files held in the account's own connected Twilio, Gmail or Meta are listed in `storedFiles`, with the provider's ids, for deletion there; if any file cannot be deleted the erasure stops before touching a record and reports itself incomplete. Orders, bookings, reservations and referrals are kept for the account's accounting but stop naming them (name, email, phone, addresses, notes, IP and browser removed). Issued invoices keep the buyer's name and billing details because tax law requires invoices to be retained; signed contracts and accepted proposals keep the signer's name as evidence of the agreement. Their unsubscribe and do-not-contact entries are KEPT, and their email and phone go on a do-not-re-add list so no import or Stripe/Shopify sync recreates them. Copies of the account's own Stripe and Shopify customers are unlinked, not edited — the result lists those customer ids so they can be erased in Stripe or Shopify. Pending booking reminders are cancelled. This is how you answer a GDPR Article 17 erasure request. Writes an audit record proving it was done, and returns a plain-language receipt. If any table fails the result says the erasure is incomplete — re-running it is safe.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Also answers to right to be forgotten, erase this person, GDPR delete request, forget this contact, article 17 request.
Parameters
Field
Type
Required
Description
contact_id
string (uuid)
required
The contact to erase. VERIFY THIS IS THE RIGHT PERSON FIRST — the operation cannot be undone and there is no recovery short of a database restore. Use contacts.get to confirm the name and email before calling.
note
string
optional
How the request arrived, recorded in the audit log — for example 'emailed privacy@ on 2026-09-04'. The question after 'did you erase them' is always 'on what basis', so this is worth filling in.
Over MCP the same operation is the tool data_subject_erase_person at https://app.chirply.io/api/mcp, same bearer token, same input.
What an erasure does to each table
data_subject.erasure_policyread
Explains, table by table, what erasing a person destroys, what it keeps without their name, what it keeps WITH their name (issued invoices, signed agreements) and what it deliberately retains — with the reason for each. Read this before running data_subject.erase_person if you need to tell someone exactly what will happen to their data, or to answer an auditor asking how erasure is implemented. Read-only and takes no arguments.
Also answers to what does erasing someone delete, erasure policy, how does the right to be forgotten work here.
Over MCP the same operation is the tool data_subject_erasure_policy at https://app.chirply.io/api/mcp, same bearer token, same input.
Everything held about one person
data_subject.export_personreadconfirmadmin only
Collects everything this account holds about one contact, across every table that can reference them — their profile, every message and conversation, calls and recordings metadata, page views and session recordings, form submissions, orders and invoices, bookings, course and community activity, and their suppression status — plus reseller-store sign-ups, store leads and carts held under their email address. This is what you send someone who makes a GDPR Article 15 access request or an Article 20 portability request. Returns the rows themselves as JSON, capped per table. Nothing is changed or deleted.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Also answers to subject access request, what do we hold on this person, GDPR data request, export everything about this contact, DSAR.
Parameters
Field
Type
Required
Description
contact_id
string (uuid)
required
The contact to assemble the record for. Use contacts.find_by_phone, contacts.find_by_facebook_id or contacts.list to identify the right person first — exporting the wrong person's data is itself a disclosure.
limit
integer
optional
Maximum rows returned per table, default 1000. Tables that hit the cap are named in `truncated` so you know the answer is partial.
Over MCP the same operation is the tool data_subject_export_person at https://app.chirply.io/api/mcp, same bearer token, same input.
How long this account keeps data
data_subject.get_retentionread
Reports the account's own automatic-deletion windows: how many days website visitor data, session recordings, call recordings and transcripts, message content and form submissions are kept before being deleted. A value of 0 means that kind is kept forever, which is the default for all of them. Read-only.
Also answers to retention policy, how long do we keep data, auto delete settings, storage limitation.
Over MCP the same operation is the tool data_subject_get_retention at https://app.chirply.io/api/mcp, same bearer token, same input.
Change how long this account keeps data
data_subject.set_retentionwriteconfirmadmin only
Sets the account's automatic-deletion windows. SWITCHING A WINDOW ON PERMANENTLY DESTROYS DATA ON A TIMER and cannot be undone: anything already older than the window you set is deleted on the next nightly run. Pass a number of days per kind, or 0 to keep that kind forever. Contacts, deals, invoices and orders are never affected. Call retention removes the audio and transcript but keeps the call record itself. A value below a kind's documented minimum or above its maximum is stored as 0 (keep forever) rather than being clamped, so a mistyped number never becomes a deletion schedule nobody chose.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Also answers to set retention policy, auto delete old data, delete recordings after, storage limitation policy.
Parameters
Field
Type
Required
Description
tracking
integer
optional
Days to keep website visitor data — page views, visit history, IP addresses, device fingerprints. 0 keeps it forever. Otherwise between 30 and 3650.
replays
integer
optional
Days to keep session recordings of people using the workspace's pages. 0 keeps them forever. Otherwise between 7 and 730.
callRecordings
integer
optional
Days to keep call audio and transcripts. The call record itself — who called, when, how long, the outcome — is always kept. 0 keeps recordings forever. Otherwise between 30 and 3650.
messages
integer
optional
Days to keep the bodies of SMS, email and social messages. This removes conversation history the workspace's own team reads, so choose a window they can work with. 0 keeps them forever. Otherwise between 90 and 3650.
formResponses
integer
optional
Days to keep form and survey submissions. Contacts created from a submission are not affected. 0 keeps them forever. Otherwise between 30 and 3650.