TrademarkTrademarkTrademarkTrademark

Privacy Policy

Last updated 2026-07-24

Chirio ("we", "us") is a social publishing service that lets you connect social media accounts and publish content to them through a dashboard and an API. This policy explains what data we handle and why. Questions: lorant.toth.94@gmail.com.

What we collect

  • Account data. Your email address, used to sign you in and communicate about the service.
  • Connected social accounts. When you connect a social account (Instagram, Threads, X), the platform gives us your platform user ID, username, and access tokens scoped to publishing. Tokens are stored encrypted at rest. We never receive or store your social media passwords.
  • Content you publish. The text and media URLs of posts you create through Chirio, plus the per-platform publishing result (post ID, URL, or error).
  • API usage. API keys you create (stored as hashes), request timestamps, and technical logs needed to operate the service.

How we use it

We use this data solely to provide the service: authenticating you, publishing the content you ask us to publish to the platforms you choose, showing you your publishing history, and keeping the service secure. We do not sell your data, use it for advertising, or read your social accounts beyond what publishing requires.

Platform data

Data received from Meta (Instagram, Threads) and X is used only to publish content on your behalf and display the results to you, in accordance with each platform's terms. Access tokens are refreshed automatically only to keep your connection working.

Third parties

We run on Supabase (database, authentication) and Vercel (hosting). Content is transmitted to the social platforms you explicitly connect. No other third parties receive your data.

Data retention and deletion

  • Disconnect an account in the dashboard at any time — this permanently deletes its access tokens immediately.
  • Delete your data: email lorant.toth.94@gmail.com from your account email and we will delete your account, connected-account tokens, and publishing history within 30 days. This is also the process to request deletion of any data obtained from Meta or X platforms.

Security

Platform tokens are encrypted at rest with keys held outside the database. API keys are stored only as salted hashes. Transport is HTTPS everywhere.

Changes

We may update this policy as the service evolves; the date above reflects the latest revision. Material changes will be announced on this page.

TrademarkTrademarkChirio — one API for social publishing