Legal
Privacy Policy
Last updated 17 August 2026.
Chirpy is a private organiser for your household — and almost everything you put in it is personal by nature. This explains exactly what we collect, why, who ever sees it, and the controls you have. We've written it to be read, not skimmed. Chirpy is operated by Chirpy, reachable at the contact address we publish here before Chirpy opens to the public.
Three things worth knowing before you read on: everything you put in a shared area is visible to everyone in your household; using an AI feature sends the relevant part of your data to Anthropic to answer you (details on the AI page); and your data is stored in the United States. We make no money from your data — there are no adverts and no trackers in Chirpy, and there is nothing here we would have to hide behind a cookie banner.
1. What we collect
Things you give us
- Account basics — your name, email and avatar from sign-in; your display name, theme and accent colour; and your household's name, country, region, town, postcode, timezone and currency. The location fields set your tax defaults, your currency formatting and the weather panel — they are not a verified address and we never ask for a street.
- Signup extras — if you arrived through a referral or a promotional code, we record the code, who referred you, and the email address the invitation was sent to, so the referrer can be credited. Your plan tier is stored against your household.
- Vault documents — titles, issuers, reference numbers (such as a passport or licence number), dates and notes for documents you catalogue. If you attach a file, it stays in your own Google Drive; we store only a link to it, never the file.
- Money — transactions, budgets, recurring bills, and account nicknames with only the last four digits (never full account numbers). If you import a bank or card statement, the rows you import and the file's name. If you use the tax tools: your filing country, status and the income figures you enter.
- What you own and owe — if you use Invest or net worth: the accounts and assets you add, the institution behind them, balances, liabilities, holdings and quantities, what you paid, your contributions, precious metals, and a history of these totals over time. Taken together this is a detailed picture of your finances, and we treat it that way.
- Family details — the people you add to Family: their name, your relationship to them, their town and timezone, and if you add them, their phone number, email address and notes, plus birthdays, anniversaries and other dates. Most of these people are not Chirpy users and have not agreed to anything — see section 3.
- Kitchen and health details — recipes, meal plans and grocery lists, and if you add them, each member's allergies, dietary needs and food goals. See section 4.
- Lists, notes and records — to-dos, shopping links, sticky notes, and records for your car, home, health, travel and investments.
Collected automatically
- Cookies and device storage — see section 8. No advertising trackers, and no third-party analytics of any kind.
- Push subscription details, if you turn notifications on.
- Basic server logs kept briefly by our host for security.
- An email check at signup. When you create a household we send the email address you gave to a verification service to confirm it is a real, deliverable address and not a throwaway one. This is how we keep spam signups out now that anyone can join. The address is all that is sent, we do not store what comes back beyond allowing or refusing the signup, and obvious cases are caught by a local list without contacting anyone.
- Your approximate location, only if you turn the weather panel on. If you allow it, your device's coordinates are sent from your browser to the weather providers in section 6 — which means they also see your IP address. This is the one place Chirpy talks to an outside company directly from your device rather than through our servers. Your coordinates stay on your device; we do not store them.
- Product analytics, built by us and stored only on our own servers. We record which features get used so we know what to fix and what to build next. Concretely, one row per action containing: a random-looking code that stands in for your account, your plan tier, the name of the action taken from a fixed list of around three dozen (“opened the app”, “added a transaction”, “scanned a receipt”), the shape of the screen you were on (
/money/[id], never the actual record), and how many seconds the screen was in front of you.
What is never in it: your name, email, user id, household, IP address, device, location, or anything you typed or saved. There is no free-text field and no catch-all bag of properties — the database physically cannot store them.
The stand-in code is a one-way hash made with a secret key that is kept outside the database, so the analytics cannot be joined back to your account. Anything to do with health features is recorded with no code at all (see section 4). Individual rows are deleted after 30 days; only totals remain. And any figure covering fewer than five people is withheld even from us. - Crash reports. When something breaks we keep the error type, a shortened message and one line of code — with URLs, email addresses, ID numbers and any quoted values stripped out first. No record of what you were doing beforehand is kept.
From services you connect
- Gmail (optional, read-only) — we read messages that look like receipts and keep only the merchant, amount, date, a short subject line and the message ID (so the same receipt is never imported twice). We never store the body of your emails. See section 5.
2. Why we use it, and our legal grounds
| Purpose | Data | Legal basis (UK/EU GDPR) |
|---|---|---|
| Running Chirpy for your household | Everything you add | Contract |
| AI features you invoke | Only the content that feature needs | Consent; explicit consent for health data |
| Health features — allergies, diets, food goals, medical documents | What you choose to add | Explicit consent (Art. 9(2)(a)) |
| Gmail receipt import | Messages matching receipt patterns | Consent, withdrawable any time |
| Push notifications | Subscription details | Consent |
| Checking an email address is real at signup | The address you typed | Legitimate interests — keeping fake and abusive signups out |
| Weather panel | Your coordinates, sent from your browser | Consent — it does nothing until you allow location or save a town |
| Referrals and promotional codes | The code, the referrer, the invited email address | Legitimate interests — running the referral scheme you or your referrer chose to use |
| Contacts and dates you add to Family | Names, and any phone, email, dates and notes you enter | Legitimate interests — you are keeping a household address book; see section 3 |
| Improving Chirpy | Pseudonymous feature-usage counts and crash reports — never content | Legitimate interests |
| Security and abuse prevention | Logs, account data | Legitimate interests |
We do not use your data for advertising, do not sell or share it, and our agreement with our AI provider prohibits training on your content.
3. Who sees what, and other people's data
Chirpy is built for sharing within one household, so most content — documents, money, meals, lists, allergies — is visible to the members of your household. A few things stay private to you alone: your tax profile, your Gmail connection, your notification preferences and your sign-in credentials. When you add information about another member, make sure they're comfortable with it.
For that data you are the one deciding what to keep, and we hold it for you. Purely household and personal record-keeping is not something data protection law tries to police — but if one of those people asks us to remove their details, we will contact your household and act on it. They can reach us at the contact address we publish here before Chirpy opens to the public.
4. Health-related information
If you use them, Chirpy stores per-member allergies, dietary needs and food notes; medical and health-insurance documents in the Vault; and health records such as appointments and policies. We treat all of it as sensitive:
- We ask for your explicit consent before health information about you is stored, and you can withdraw it at any time — withdrawing deletes the data.
- It is used only to provide the feature you asked for — never for marketing and never for training. It is never used to build a profile of you, and health content never reaches our analytics at all (see the next point for the one narrow exception, which counts nobody).
- It is sent to our AI provider only if you have individually turned AI features on, and only the minimum needed (for example, your allergy list so a suggested recipe avoids it). Another member enabling AI does not send your health data.
- It is never sold, and never shared outside the providers in section 6.
- It is excluded from our analytics as an individual. Using a health feature — opening Health, editing allergies or diets — is recorded with no code standing in for you, so no trail exists of which person used a health feature, only that a health feature was used at all. Even those totals stay hidden until enough of them accumulate that no individual could be picked out.
To access, delete or withdraw consent for health data, contact us at the contact address we publish here before Chirpy opens to the public. If you are in Washington State and we deny a request, you may appeal by replying to our decision, and may then contact the Washington Attorney General.
5. AI features, and what leaves our servers
Chirpy has built-in AI provided by Anthropic (United States). It runs only when you use an AI feature, and receives only what that feature needs:
- Ask Chirpy — your question plus relevant household context, such as recent transactions and document titles and dates.
- Scanning — the photo or text of the receipt or document you are scanning.
- Statement import — the text of the bank or card statement you upload, to turn its rows into transactions.
- Gmail import — the sender, subject and body of receipt-like messages, to extract merchant, amount and date. The content is processed and discarded; only the extracted fields are kept.
- Kitchen — recipe context including the allergies of members who have consented.
- Money, tax and Invest helpers — the figures on the screen you are using, such as your income and filing status, or the holdings and balances of the account you are viewing.
- Wishlist — the product URL and title. Anthropic then fetches that shop page from their own systems to read the price.
We log that a call happened — feature, model, tokens, cost — so credits and spend caps work, but we do not keep your prompts or the AI's replies. You can turn AI features off at any time, per person; nothing is sent when they are off, and nothing runs in the background.
No automated decisions. Nothing in Chirpy makes a solely-automated decision that has a legal or similarly significant effect on you. The AI suggests and extracts; a person always decides.
6. Service providers
| Provider | What they do | Where |
|---|---|---|
| Vercel | Hosts the app and serves every page | United States |
| Supabase (on AWS) | Database, authentication and file storage | United States (us-west-1) |
| Anthropic | Powers every AI feature — receives only what the feature you used needs, and is contractually barred from training on it | United States |
| Googleoptional | Sign-in; plus Gmail receipt reading and Google Drive file storage if you connect them | United States |
| apilayer (mailboxlayer) | Checks at signup that the email address you gave is real and not a disposable one — receives the address itself | European Union / United States |
| apilayer (marketstack)optional | Daily closing share prices. Receives ticker symbols only, batched across all of Chirpy, so they can't be traced to a household | European Union / United States |
| Open-Meteooptionalsees your IP | The forecast in the weather panel, and turning a town name into map coordinates | Germany |
| BigDataCloudoptionalsees your IP | Turns coordinates into a town name to label the weather panel | Australia / United States |
| Aviation Weather Center (NOAA)optional | A real thermometer reading from the nearest airport. We round your location into a wide box before asking | United States |
| Frankfurter (European Central Bank rates) | Converts between currencies so a multi-currency household gets one total. Receives currency codes only — never an amount, never anything about you | European Union |
| Apple, Google and Mozilla push servicesoptional | Deliver push notifications to your device | Varies by device |
Almost every one of these is contacted by our servers, so they see our address and not yours. The two marked sees your IP are contacted by your browser directly — both are the weather panel, and neither is given your name, your email or anything you have saved in Chirpy.
The current list always lives at /legal/subprocessors.
7. Where your data lives
Your data is stored in the United States. If you are in the UK, EU, India or anywhere else, using Chirpy means your data is transferred there. A few of the providers in section 6 are in the EU or elsewhere, but the database that holds your household is in the US.
We rely on the Standard Contractual Clauses in our agreements with those providers, and, where a provider is certified under it, the EU–US Data Privacy Framework. We apply the protections in this policy wherever you live rather than only where the law compels them. You can ask us at the contact address we publish here before Chirpy opens to the public which safeguard covers a particular provider.
8. Cookies and device storage
| What | Why | Type |
|---|---|---|
| Sign-in cookies | Keep you signed in | Strictly necessary |
| Preferences cookie | Remembers your theme and timezone | Functional, set by your choice |
| Gmail connect cookie | Protects the connect flow from forgery | Strictly necessary, short-lived |
| Local storage | What's-new you've seen; your chosen weather location (stays on your device) | Functional |
There is no cookie banner because there is nothing to consent to: everything above is either required to run the app or set because you chose it. Chirpy loads no third-party scripts, contacts no advertising or analytics network, and sets no cookie for measurement — our own product analytics (section 1) use no cookie, no local storage and no device identifier of any kind. No third party sets a cookie through Chirpy. If that ever changes, this policy changes first.
The one thing your browser does reach out to on its own is the weather panel, and that is why it asks before it does anything: allowing location, or saving a town, is the consent. Turn the panel off in Settings and your browser stops contacting anyone but us.
9. Your rights
Wherever you live you can access and export your data, correct it, delete your account and data, and withdraw any consent as easily as you gave it. We respond within 30 days. You do not have to ask us for a copy: Settings → Your data downloads your money as a spreadsheet and your whole household as a machine-readable file, and Settings → Security deletes your account outright.
- UK/EU — you also have rights to restriction, objection and portability, and the right not to be subject to a solely-automated decision with legal or similarly significant effects (we do not make any — see section 5). You may complain to your data protection authority; in the UK that is the Information Commissioner's Office.
- Canada — you may complain to the Office of the Privacy Commissioner.
- India — you may nominate someone to exercise your rights if you die or become incapacitated, contact us as your grievance contact, and escalate to the Data Protection Board if we do not resolve it.
- United States — you can know, delete, correct and obtain a copy of your personal information, limit how sensitive information is used, and not be discriminated against for asking. We do not sell or share personal information as California and other states define those words, and we have never done so — there is no opt-out link because there is nothing to opt out of. We use sensitive information only to provide the service you asked for.
We do not ask for identification to answer a request beyond being satisfied you are who you say you are, we do not charge for it, and you can have someone act for you.
10. Keeping and deleting data
- Your household's content is kept while your household uses Chirpy.
- If you leave a household — your private data (tax profile, Gmail connection, push subscriptions, allergies) is deleted. Things you contributed to shared areas, such as a transaction you logged, remain with the household.
- If you delete your account — all of the above, plus your profile, is permanently deleted.
- If an owner deletes the household — every document, transaction, recipe, list and record in it is permanently deleted for everyone.
- Deleted data leaves our backups within 30 days. Gmail and Google Drive tokens are deleted the moment you disconnect, and we tell Google to revoke them too.
- Referral records — the code, who referred whom and the invited address — are kept while the scheme runs, because they are the proof a credit was earned. If either account is deleted the link to it is removed.
- Contacts and dates you added to Family stay with the household until someone deletes them or the household is deleted. They do not leave with you if you leave.
- The signup email check keeps nothing. The address is sent, an answer comes back, the signup is allowed or refused, and that is the end of it.
- Analytics rows are deleted after 30 days, whether or not you are still using Chirpy. What is kept past that point is counted totals — how many people opened Kitchen in a given week — with nothing in them that stands in for a person. One pseudonymous row per account is kept longer, holding only the week you joined and the dates you first added something and last used Chirpy, so we can tell whether people keep coming back. Ask us and we erase it.
- Crash reports are kept until the bug is fixed, then cleared. They are grouped by fault, not by person, and contain no code standing in for you.
- Problem reports you send us are kept until they are dealt with. They contain exactly what you wrote plus the screen you were on — you can see your household's reports, and they go with your household if it is deleted.
11. Security
Encryption in transit everywhere and at rest in the database. Gmail tokens are additionally encrypted by the application with a key held outside the database. Every table is protected by row-level security, so only your household's members can read your household's rows. Sign-in is handled by your provider — we never see a password — with optional passkeys and a Face ID app-lock.
12. Children
Nobody under 16 can sign themselves up for Chirpy (18 where local law requires it, which includes India). If we learn that a child has created their own account we delete it.
There is one deliberate exception, and it is worth understanding properly. An adult who owns a household can invite a child into it as a child member. That gives the child a real sign-in, but a restricted one: the AI assistant is off by default and only an adult can switch it on, the child cannot be made an owner, and the adults control what the account can reach.
- The adult who sends that invitation is confirming they are the child's parent or guardian and is consenting on the child's behalf. Please do not invite someone else's child.
- Details a parent keeps about a child — allergies, birthdays, school documents — sit in the household like any other content, under the adults' control.
- We do not profile children, do not track them across other services, and show nobody advertising. Our own usage counting never identifies a person at all, and health-related activity is recorded with nothing standing in for who did it (section 4).
- A parent or guardian can see, export or delete everything about their child by removing the member or deleting the household, or by contacting us at the contact address we publish here before Chirpy opens to the public.
13. If something goes wrong
If a breach ever puts your data at risk we will tell you what happened, what was involved and what we are doing — within the timelines the law requires.
14. Google API disclosure
Chirpy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: the optional read-only Gmail connection is used solely to find purchase receipts and turn them into transactions in your Money tool. We store only the extracted receipt fields, never email bodies. Receipt-like messages are processed by our AI provider only to extract those fields, under an agreement forbidding any other use including model training. We do not use Gmail data for advertising, do not sell it, and do not let humans read it except with your explicit permission, for security, or where the law requires. Disconnect any time in Settings → Connectors, or via your Google Account permissions.
15. Changes
We post changes here with a date and version, and tell you in the app before anything material takes effect.