Privacy Policy
Effective September 10, 2026
This policy describes how Chirp handles personal information, including data from your Google account. It applies to the website, the app, and the community. Capitalised terms not defined here are defined in the Terms of Service.
1. Overview
Chirp (“Chirp”, “we”, “us”) is operated by contact@chirpmail.io. Chirp helps students and early-career job seekers find people to contact, write outreach emails, send them from their own Gmail account, follow up, and track replies. This policy explains what we collect, why, who we share it with, and the choices you have.
The short version: we only touch the parts of your Google account you explicitly authorise, we never sell personal information, we do not run advertising or analytics trackers, our AI provider does not train on your data, and you can delete your account and everything in it yourself from Settings at any time.
2. Information we collect
Account information
You sign in with Google. We receive your name, email address, profile photo, and Google account identifier. We never see or store your Google password.
Profile information you add
School, graduation year, target role, headline, a short bio, an email signature, timezone and sending preferences, and, if you upload one, your resume as a PDF. Your resume is stored in our database and used only to personalise your emails and, when you tick “Attach my resume”, to attach it to the first email in a campaign.
Google account data (Gmail)
When you connect Google you grant two Gmail permissions. Here is exactly what each is used for:
- Send email on your behalf (
gmail.send): to send the outreach emails and follow-ups you queue, from your own address, inside your sending window and daily limit. - Read email (
gmail.readonly): to check only the threads Chirp started for replies, bounces, and opt-outs, so follow-ups stop the moment someone answers. For those threads we store the Gmail thread and message IDs, who replied and when, a short snippet of the reply, and a sentiment label (positive, neutral, negative). We do not read, index, store, or analyse any other mail in your inbox.
OAuth tokens are stored server-side, encrypted at rest, and used for nothing else. You can revoke access at any time at myaccount.google.com/permissions, and deleting your Chirp account revokes it automatically.
Information about the people you contact (“prospects”)
When you search, Chirp queries Google’s public search index (through Serper) for LinkedIn profile pages matching the terms you choose, and stores the results you keep: name, headline, title, company, location, and the public profile URL. If you ask Chirp to find an email address, we send the person’s name and their company’s domain to Hunter.io, or generate a pattern-based guess, and store the result with a confidence label. You may add notes and tags. If you log a meeting with someone, we also store when and how you met, the rating you give it, the notes you write, a next step and the day it is due, and any PDF of notes you upload (up to 4 MB each). This is your own record of your own conversations; it is never shared with other users or sent to a third party. You decide whom to search for and store, and you are responsible for using that information lawfully (see the Terms of Service). Chirp does not log in to, scrape, or otherwise access LinkedIn.
Outreach data
Campaign templates and settings, the emails Chirp writes or you write, send status and timestamps, follow-up schedules, and reply information as described above. Emails Chirp sends include a one-pixel image that records when, and how many times, the message was opened. This tells you whether a message was read; recipients are not otherwise tracked.
Community content
Posts, replies, reactions, bookmarks, your handle, and your community profile (name, photo, school, graduation year, target role, headline, and the intro you write) are visible to other signed-in Chirp users. Other members can mention your handle. Do not post other people’s private correspondence or personal details.
Payment information
Paid plans are billed by Stripe. Card details go directly to Stripe and never reach our servers. We store your Stripe customer, subscription, and price identifiers, your plan, and its renewal date.
Technical information and cookies
Our hosting provider records standard request logs (IP address, browser, pages requested, timestamps) for security and debugging. Chirp uses only strictly necessary cookies: a session cookie that keeps you signed in and the short-lived cookies the sign-in flow needs. We do not use advertising cookies, third-party analytics, or cross-site tracking, so there is no cookie banner to click.
3. How we use information
- To provide the service: find people, find emails, write and send outreach, schedule follow-ups, detect replies, and show you results.
- To personalise: your profile, resume, and campaign settings are used to draft emails that sound like you, and the assistant uses them to answer your questions.
- To run the community: display your posts and profile to other members and notify you about replies and mentions.
- To bill you and manage your plan.
- To keep the service safe: enforce sending limits, honour opt-outs and bounces through a suppression list, and prevent abuse.
- To communicate with you about your account, the service, and changes to these terms. We do not send marketing email without consent.
Where the GDPR or UK GDPR applies, we rely on performance of our contract with you (running the service), your consent (connecting Google, which you can withdraw at any time), and our legitimate interests in securing and improving Chirp.
4. AI processing
Chirp uses Anthropic’s Claude models to draft personalised emails, classify the sentiment of replies, read your resume to fill in your profile, and power the assistant. To do that we send the relevant text to Anthropic’s API: your profile and resume text, details of the prospect being emailed, your campaign content, the text of a reply being classified, and your assistant conversation. Anthropic processes this as our service provider under commercial terms that prohibit it from using your data to train its models. AI output can be wrong; you review every email before a campaign goes live and are responsible for what you send.
5. Google API Services User Data Policy
Chirp’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Gmail data is used only to provide the user-facing features described above: sending the emails you queue and detecting replies on those threads.
- We do not use Gmail data for advertising, and we do not sell it.
- We do not transfer Gmail data to anyone else except our service providers as needed to provide those features (Anthropic, for classifying a reply’s sentiment; our hosting providers), as required by law, or with your explicit consent.
- No human at Chirp reads your Gmail data unless you ask us to for support, it is necessary for security or to comply with the law, or it has been aggregated and anonymised.
7. If you received an email sent through Chirp
Chirp is a tool; the person who emailed you chose to contact you and is responsible for that message. It was sent from their own Gmail account. Reply to them, or ask them to stop, and Chirp automatically stops all further follow-ups from that sender to you and adds your address to their suppression list. If you want to know what a Chirp user stored about you, or want us to help, contact us at contact@chirpmail.io and include the sender’s address.
8. Retention and deletion
We keep your data for as long as your account exists so the service keeps working.
- Delete your account from Settings. This immediately and permanently deletes your profile, resume, prospects, meeting notes and uploaded files, campaigns, sent-message records, reply data, suppression list, community posts and replies, notifications, and sessions, cancels any subscription, and revokes Chirp’s access to your Google account.
- Backups and server logs that may contain your data are overwritten within 30 days.
- Stripe retains invoices and transaction records for as long as tax and accounting law requires.
- Emails already delivered to recipients stay in their inboxes, as with any email.
9. Security
All traffic is encrypted in transit with TLS and our database is encrypted at rest. Google access tokens are stored only on the server and are never sent to your browser. We request the narrowest Google permissions the product needs, store no passwords, and enforce a strict Content-Security-Policy, cross-site request protection, and per-plan sending limits. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.
10. Your rights and choices
Depending on where you live (including the EU, UK, and California) you may have the right to:
- access the personal information we hold about you and receive a copy in a portable format;
- correct inaccurate information (most of it is editable in Settings);
- delete your information (use the delete button in Settings, or ask us);
- object to or restrict certain processing, and withdraw consent for Google access at any time;
- not be discriminated against for exercising these rights.
We do not sell or “share” personal information as those terms are defined under California law. To exercise any right, email contact@chirpmail.io. We will verify the request through your signed-in account and respond within the time the law requires. If you are in the EU or UK you may also complain to your local data protection authority.
11. International transfers
Chirp is hosted in the United States and our providers may process data there and elsewhere. If you use Chirp from outside the US, your information is transferred to the US. Where required we rely on standard contractual clauses or equivalent safeguards offered by our providers.
12. Children
Chirp is for people who are at least 18 years old. We do not knowingly collect information from anyone younger. If you believe a minor has created an account, contact us and we will delete it.
13. Changes to this policy
We may update this policy as Chirp changes. We will post the new version here with a new effective date and, for material changes, tell you by email or in the app before they take effect. Continued use after that date means you accept the updated policy.
14. Contact
Questions, requests, or complaints: contact@chirpmail.io. contact@chirpmail.io is the controller of the personal information described in this policy.