Chirio ("we", "us") is a social publishing service that lets you connect social media accounts and publish content to them through a dashboard and an API. This policy explains what data we handle and why. Questions or requests: support@dopler.app.
Chirio is operated by Tóth Lóránt e.v., 1134 Budapest, Kassák Lajos utca 67/B, Hungary, who is the data controller for the personal data described in this policy. Contact: support@dopler.app.
We do not collect special-category data, and we do not read your inbox, direct messages, or followers.
We use this data solely to provide the service: authenticating you, publishing the content you ask us to publish to the platforms you choose, showing you your publishing history, and keeping the service secure. We do not sell your data, use it for advertising, or read your social accounts beyond what publishing requires.
Where the GDPR applies, we process this data to perform our contract with you (providing the service you signed up for) and, for security logging, on our legitimate interest in keeping the service safe and available.
Data received from Meta (Instagram, Threads), X, and LinkedIn is used only to publish content on your behalf and display the results to you, in accordance with each platform's terms. Access tokens are refreshed automatically only to keep your connection working.
If you remove Chirio from a platform's own app settings, that platform notifies us and we delete the affected connected account and its tokens automatically.
We use the following processors, and no others:
Content is transmitted to the social platforms you explicitly connect. For usage statistics we rely solely on the cookieless Vercel Web Analytics described above; we do not use advertising trackers or any analytics that profile individual users.
Card details are entered on Stripe's own checkout and never reach our servers; we store only Stripe's customer and subscription identifiers alongside your project. If you never subscribe to a paid plan, no data is sent to Stripe at all.
Usage totals — how many posts you published in a billing period — are sent to Stripe to produce your invoice. The content of your posts is not.
These processors may process data outside your country, including in the United States, under the transfer safeguards in their own data processing terms.
We set only the cookies needed to keep you signed in. There are no advertising or analytics cookies — Vercel Web Analytics operates without cookies.
Publishing history is kept for as long as your account exists, so you can see what was posted; deleting your account deletes it. Tokens for a disconnected account are deleted immediately, not retained.
Step-by-step instructions for each of these are on the data deletion page.
Where the GDPR or similar laws apply, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. Email the address above and we will respond within 30 days. You also have the right to complain to your local data protection authority.
Platform tokens are encrypted at rest with AES-256-GCM using keys held outside the database. API keys are stored only as salted hashes. Transport is HTTPS everywhere.
We may update this policy as the service evolves; the date above reflects the latest revision. Material changes will be announced on this page.