TrademarkTrademarkTrademarkTrademark

Privacy Policy

Last updated 2026-08-20

Chirio ("we", "us") is a social publishing service that lets you connect social media accounts and publish content to them through a dashboard and an API. This policy explains what data we handle and why. Questions or requests: support@dopler.app.

Who we are

Chirio is operated by Tóth Lóránt e.v., 1134 Budapest, Kassák Lajos utca 67/B, Hungary, who is the data controller for the personal data described in this policy. Contact: support@dopler.app.

What we collect

  • Account data. Your email address, used to sign you in and communicate about the service.
  • Connected social accounts. When you connect a social account (Instagram, Threads, X, or LinkedIn), the platform gives us your platform user ID, username, and access tokens scoped to publishing. Tokens are stored encrypted at rest. We never receive or store your social media passwords.
  • LinkedIn company pages. If you enable company-page publishing, LinkedIn also tells us which pages you administer, so you can choose one as a publishing target. We store each page's ID and name.
  • Content you publish. The text and media URLs of posts you create through Chirio, including any first comment posted alongside a post, plus the per-platform result (post ID, URL, comment ID, or error).
  • API usage. API keys you create (stored as hashes), request timestamps, and technical logs needed to operate the service.

We do not collect special-category data, and we do not read your inbox, direct messages, or followers.

How we use it, and on what basis

We use this data solely to provide the service: authenticating you, publishing the content you ask us to publish to the platforms you choose, showing you your publishing history, and keeping the service secure. We do not sell your data, use it for advertising, or read your social accounts beyond what publishing requires.

Where the GDPR applies, we process this data to perform our contract with you (providing the service you signed up for) and, for security logging, on our legitimate interest in keeping the service safe and available.

Platform data

Data received from Meta (Instagram, Threads), X, and LinkedIn is used only to publish content on your behalf and display the results to you, in accordance with each platform's terms. Access tokens are refreshed automatically only to keep your connection working.

If you remove Chirio from a platform's own app settings, that platform notifies us and we delete the affected connected account and its tokens automatically.

Third parties

We use the following processors, and no others:

  • Supabase — database and authentication. Holds your account, project, connected-account and post records.
  • Vercel — hosting and web analytics. Holds request logs and, through Vercel Web Analytics, aggregated page-view statistics. The analytics are cookieless and do not identify individual visitors or track you across sites.
  • Stripe — payments and invoicing, on paid plans only. Receives your name, email, billing address, tax status, payment method, and invoice and usage totals.

Content is transmitted to the social platforms you explicitly connect. For usage statistics we rely solely on the cookieless Vercel Web Analytics described above; we do not use advertising trackers or any analytics that profile individual users.

Card details are entered on Stripe's own checkout and never reach our servers; we store only Stripe's customer and subscription identifiers alongside your project. If you never subscribe to a paid plan, no data is sent to Stripe at all.

Usage totals — how many posts you published in a billing period — are sent to Stripe to produce your invoice. The content of your posts is not.

These processors may process data outside your country, including in the United States, under the transfer safeguards in their own data processing terms.

Cookies

We set only the cookies needed to keep you signed in. There are no advertising or analytics cookies — Vercel Web Analytics operates without cookies.

Data retention and deletion

  • Disconnect an account in the dashboard at any time — this permanently deletes its access tokens immediately.
  • Remove Chirio from the platform (for example in your Instagram or Threads app settings) and we delete that connected account and its tokens automatically when the platform tells us, without you having to contact us.
  • Delete your data: email support@dopler.app from your account email and we will delete your account, connected-account tokens, and publishing history within 30 days. This is also the process to request deletion of any data obtained from Meta, X, or LinkedIn.

Publishing history is kept for as long as your account exists, so you can see what was posted; deleting your account deletes it. Tokens for a disconnected account are deleted immediately, not retained.

Step-by-step instructions for each of these are on the data deletion page.

Your rights

Where the GDPR or similar laws apply, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. Email the address above and we will respond within 30 days. You also have the right to complain to your local data protection authority.

Security

Platform tokens are encrypted at rest with AES-256-GCM using keys held outside the database. API keys are stored only as salted hashes. Transport is HTTPS everywhere.

Changes

We may update this policy as the service evolves; the date above reflects the latest revision. Material changes will be announced on this page.

TrademarkTrademark// One API for social publishing