Legal

Privacy Policy

Last updated July 30, 2026. Chirply is operated by Vaughn Labs. This policy explains what we collect, why, who we share it with, and how to get it deleted.

Who we are

Chirply is a customer-relationship, telephony, email, and advertising platform sold to businesses (“customers”). Those customers use Chirply to communicate with their own contacts (“end users”). For data our customers upload or generate, we act as a processor — we handle it on their instructions. For our own account and billing records we act as a controller.

What we collect

Account data. Name, email address, organization details, and authentication records for the people who log in.

Billing data. Subscription status and payment metadata. Card numbers are handled by Stripe and never reach our servers.

Customer content. Contacts, conversations, call recordings and transcripts, email campaigns, invoices, notes, and anything else our customers create or import.

Connected-platform data. When a customer connects a third-party account, we access only what that integration needs. See the Meta section below for the specifics there.

Technical data. IP address, browser and device information, and request logs used for security, abuse prevention, and debugging.

Data we access from Meta

If a customer connects a Facebook or Instagram account, they authorize Chirply to access specific assets through Meta’s APIs. We request only what the features they enable require:

  • Profile basics — the name and email of the person authorizing, so we can show who connected the account.
  • Pages— the list of Pages they manage, plus each Page’s name, category, and access token.
  • Messages — Messenger and Instagram conversations sent to their Page, so those conversations appear in their Chirply inbox and can be replied to.
  • Posts and comments — Page content and the comments on it, so they can respond from Chirply.
  • Lead Ads — form submissions from their own lead ads, imported as contacts.
  • Ad accounts — campaign structure and performance, and the ability to create ads when they use the ad builder.

This data is used onlyto provide these features to the customer who authorized it. We do not sell it, use it to build advertising profiles, use it to train machine-learning models for other customers, or share it with any other customer. Access tokens are encrypted at rest with AES-256-GCM. A customer can disconnect at any time from Settings → Integrations, or from Facebook → Settings → Business Integrations; doing so revokes our access and deletes the stored tokens and derived Page records.

How we use data

  • To provide, maintain, and secure the service.
  • To authenticate users and enforce permissions.
  • To carry out actions a customer asks for — sending a message, placing a call, publishing an ad.
  • To bill for the service and prevent fraud.
  • To respond to support requests.
  • To comply with legal obligations.

We do not sell personal information, and we do not use customer content for advertising.

Sub-processors

We use a small set of vendors to run the service. Each is bound by contract to protect the data they handle:

  • Supabase — database, authentication, file storage
  • Cloudflare — hosting, DNS, object storage (R2)
  • Stripe — payment processing
  • Twilio — telephony and SMS
  • Mailgun — email delivery
  • Meta — Facebook and Instagram messaging, leads, and ads
  • OpenRouter — AI model routing for assistive features

Where a customer supplies their own credentials for one of these providers, their usage is governed by their own agreement with that provider in addition to this policy.

Retention

We keep customer content for as long as the account is active. After an account is closed we delete or anonymize it within 90 days, except where we must retain records longer to meet a legal, tax, or accounting obligation. Backups are purged on a rolling schedule.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. If you are an end user of one of our customers, contact that business first — we will refer your request to them and support them in answering it.

To exercise a right directly, email privacy@chirply.io. See Data Deletion for how to remove your data, including data obtained from Meta.

Security

Data is encrypted in transit with TLS and at rest. Provider credentials and access tokens receive an additional layer of application-level AES-256-GCM encryption. Access between customer workspaces is isolated at the database level with row-level security.

International transfers

We operate from the United States and our infrastructure providers may process data in other countries. Where required, transfers rely on Standard Contractual Clauses or another approved mechanism.

Children

Chirply is a business tool and is not directed to anyone under 16. We do not knowingly collect information from children.

Changes

We will update this page when our practices change and revise the date above. Material changes will be announced in-app or by email before they take effect.

Contact

Vaughn Labs — privacy@chirply.io