Last updated September 13, 2026. Chirply is operated by Vaughn Labs. This policy explains what we collect, why, who we share it with, and how to get it deleted.
Chirply is a customer-relationship, telephony, email, and advertising platform sold to businesses (“customers”). Those customers use Chirply to communicate with their own contacts (“end users”). For data our customers upload or generate, we act as a processor — we handle it on their instructions. For our own account and billing records we act as a controller.
Account data. Name, email address, organization details, and authentication records for the people who log in.
Billing data. Subscription status and payment metadata. Card numbers are handled by Stripe and never reach our servers.
Customer content. Contacts, conversations, call recordings and transcripts, email campaigns, invoices, notes, and anything else our customers create or import.
Connected-platform data. When a customer connects a third-party account, we access only what that integration needs. See the Meta section below for the specifics there.
Technical data. IP address, browser and device information, and request logs used for security, abuse prevention, and debugging.
If a customer connects a Facebook or Instagram account, they authorize Chirply to access specific assets through Meta’s APIs. We request only what the features they enable require:
This data is used only to provide these features to the customer who authorized it. We do not sell it, use it to build advertising profiles, use it to train machine-learning models for other customers, or share it with any other customer. Access tokens are encrypted at rest with AES-256-GCM. A customer can disconnect at any time from Settings → Integrations, or from Facebook → Settings → Business Integrations; doing so revokes our access and deletes the stored tokens and derived Page records.
Customers authorize each optional Google integration through Google’s OAuth consent screen. Each connection requests the permissions for that integration. Google Calendar supports scheduling:
Gmail: when an account owner or administrator connects a Gmail mailbox, Chirply can search and read messages, sender and recipient details, thread history, labels and attachments. Incoming messages and explicitly imported history are stored in the account’s Conversations inbox. New incoming messages can trigger workflows the customer has enabled. Chirply sends messages and replies through the selected Gmail mailbox when a user sends them or an enabled workflow performs a configured send. Those messages appear in Gmail Sent. Reads preserve Gmail’s read/unread state; this integration does not modify labels or delete mail in Gmail.
Google Sheets and Drive metadata: Chirply lists the names, identifiers and links of accessible spreadsheets so users can choose a file. It reads worksheet names, headers and cell values for selected spreadsheet actions, including finding rows, appending rows and updating matched cells. Row watches store snapshots and detect subsequent new or changed rows for enabled workflows. Workflow runs can retain selected inputs and outputs for inspection. Drive metadata access is used for spreadsheet discovery; other Drive file contents are not downloaded through this integration.
Sharing within an account: Gmail and Sheets connections are shared with authorized members of the Chirply account where they are connected, including its authorized API, MCP and assistant access. Customer-configured workflows can pass selected data to other connected services to perform the actions the customer enables. Mailbox content, spreadsheet data and workflow history are processed on Chirply’s servers to provide these features. Connection identifiers and the Google email address identify which connected account an action uses.
Google Ads: when a customer connects campaign management, Chirply reads accessible advertiser accounts and campaign results, and saves the campaign settings, creative and operation results needed to validate, create and manage the campaigns the customer chooses. Campaign activation can incur advertising charges. The separate server conversion connection sends consented lead and confirmed purchase events to the Google Ads conversion destinations the customer configures. These advertising features use their own Google permissions; Gmail, Calendar and Sheets data is not used for advertising.
Chirply’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google Calendar, Gmail and Google Sheets is used to provide the integrations and workflows the customer enables. We do not sell it, use it for advertising, use it to train generalized machine-learning models, or share it with any other customer, and we do not allow human access to it except with the customer’s consent for support, for security and abuse investigations, or where required by law. OAuth tokens are encrypted at rest with AES-256-GCM. Disconnect Calendar in Scheduling → Connections, Gmail in Conversations → Email setup, and Sheets in Settings → Integrations → Google Sheets. Disconnecting removes the stored credentials for that integration; other Google integrations remain separately connected. Imported messages, saved snapshots and workflow or delivery history remain subject to our retention policy. To request deletion, use our Data Deletion process or email privacy@chirply.io. You can also revoke Google authorization from your Google account permissions. Revoking the Google application there can affect every integration authorized through that application.
Browser Agent is a free Chrome Web Store extension that operates only after you pair it with an active, paid Chirply Marketplace installation. It holds Chrome permission for HTTPS sites so you can point it at any page you choose, including a tab you are not currently viewing. It reads a page only when you select that tab and ask it to preview a task, or when your own scheduled Chirply queue has work for a website you explicitly saved as a standing approval, in which case it opens that one page in a background tab. When you explicitly start a Capture walkthrough, it also collects steps from the selected tab until you stop recording. It does not otherwise watch or log your browsing. Each task inspection creates a bounded snapshot containing the page URL and title, visible text, and safe metadata about visible links, fields, menus, and buttons. Password, hidden, and file inputs are excluded. The extension does not request access to authentication cookies or your general browsing history.
To pair a Chirply workspace, the extension sends a single-use pairing code, the browser name you choose, its release channel, and extension version to Chirply. Chirply returns a device credential that Chrome stores locally; our servers retain only a one-way hash and a short identifying prefix. Workspace owners and admins can revoke each browser separately, and uninstalling the Marketplace app ends all paired-browser access for that workspace. Standing approvals — the grants that let a browser act on one website on a schedule without anyone watching — are recorded by scope and name only, never by their steps or values, so that a workspace owner can see and revoke one. The browser re-checks that list before every unattended run.
On supported Chrome devices, the task instruction and bounded page snapshot are processed by Chrome’s built-in on-device language model to propose a plan made only from actions packaged with the extension. When that model is unavailable, a deterministic packaged planner handles supported commands instead. The task, snapshot, form values, and extracted results remain in the extension and are not sent to Chirply. Local task and result data can be cleared by removing the extension or clearing its site data.
Before a plan changes a page, Browser Agent shows the exact page title and URL, every proposed action, complete planned values, and existing non-secret form values. Every click receives the strongest outward-action warning and runs only after you approve that displayed plan. A SHA-256 page-state token binds approval to the inspected URL, title, visible state, controls, and non-secret form values; a mismatch halts the run and requires a new inspection rather than allowing the extension to guess through an unexpected screen. Browser Agent does not bypass passwords, CAPTCHAs, paywalls, access controls, or a website’s rules.
Chirply receives a redacted audit record so workspace administrators can review and revoke Browser Agent use. That record contains the paired install and device, page origin, packaged action types and risk levels, approval and completion status, a result count, and a generic error code when applicable. It does not contain the task instruction, page snapshot, extracted content, form values, passwords, cookies, or full results. Workspace social handoffs still retrieve only the content and destination assigned to that workspace.
Browser Agent data is used only to provide and secure the extension. It is not sold, used for advertising, or used to train a generalized AI model. We do not allow human access except when you request support, when needed to investigate abuse or a security incident, or when required by law. You can clear local data by removing the extension and can delete paired access from Browser Agent settings.
When you start Capture, your browser asks you to choose a screen, window, or tab and grant any camera or microphone access. The video can include everything visible on that selected surface, including personal information. Walkthrough mode additionally captures selected page actions, safe control labels, page addresses, timestamps, and screenshots to help create a guide. Input values are excluded from step metadata, but information visible in the video or screenshots is still part of your recording.
Capture saves recording segments locally for recovery. When you upload a recording, Chirply stores the video and associated guide content for your workspace. Local recordings remain on the device until uploaded and cleared or deleted; clearing browser storage or uninstalling the extension can remove local recovery data. Deleting a cloud recording and deleting a local copy are separate actions.
Recordings start private to your workspace. Enabling link sharing lets anyone with that link access the formats you select: video, guide, or both. You can revoke the link. Revocation cannot erase copies someone already downloaded. Shared playback records view, play, and completion events for the recording owner. If you request AI processing, the necessary recording content is sent to the processing provider to generate the requested result.
We do not sell personal information, and we do not use customer content for advertising.
We use a small set of vendors to run the service. Each is bound by contract to protect the data they handle:
Where a customer supplies their own credentials for one of these providers, their usage is governed by their own agreement with that provider in addition to this policy.
The full list — including what data each vendor can see and where it processes — is on the sub-processors page, where you can also subscribe to be notified before it changes.
We keep customer content for as long as the account is active. After an account is closed we delete or anonymize it within 90 days, except where we must retain records longer to meet a legal, tax, or accounting obligation. Backups are purged on a rolling schedule.
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. If you are an end user of one of our customers, contact that business first — we will refer your request to them and support them in answering it.
To exercise a right directly, email privacy@chirply.io. See Data Deletion for how to remove your data, including data obtained from Meta.
Data is encrypted in transit with TLS and at rest. Provider credentials and access tokens receive an additional layer of application-level AES-256-GCM encryption. Access between customer workspaces is isolated at the database level with row-level security.
The full set of technical and organisational measures — and what we deliberately do not claim — is on our security page.
We operate from the United States and our infrastructure providers may process data in other countries. Where required, transfers rely on Standard Contractual Clauses or another approved mechanism.
Business customers processing personal data of people in the EEA, the UK, or Switzerland should accept our Data Processing Agreement, which incorporates those Clauses. You can put it in force yourself from Settings → Your data.
Chirply is a business tool and is not directed to anyone under 16. We do not knowingly collect information from children.
We will update this page when our practices change and revise the date above. Material changes will be announced in-app or by email before they take effect.
Vaughn Labs — privacy@chirply.io