It is Chirp’s policy to respect your privacy. This Privacy Policy explains what information Rocket Source Ltd. (“Chirp”, “us” or “we”) collects when you use the Chirp shared inbox at https://app.teamchirp.io, the Chirp API and the website at https://teamchirp.io (together, the “Service”), how we use it, and when we share it. It applies only to information collected through the Service.
This Privacy Policy and our Terms of Service set out the rules for your use of the Service.
Who is responsible for your data
For the email, contacts and other content that a customer connects to Chirp, the customer’s organisation decides what is processed and why, and we process it on their behalf. For account details and information about how people use the Service, Rocket Source Ltd. is the controller. [DATA PROCESSING TERMS: the owner decides whether customers get a separate data processing agreement.]
Contact: Rocket Source Ltd., a company registered in England and Wales (company number 16517484), 38b Arbery Road, London, E3 5DD, [email protected].
The website
teamchirp.io is a static website. It sets no cookies, runs no analytics or advertising scripts, and serves its own fonts. Our hosting provider, Cloudflare, receives the technical data that every web request carries, such as your IP address and browser type.
Information in the app
Your account. Your name, email address, a hash of your password (scrypt; we never store the password itself), your time zone, your role (Admin, Agent or Viewer), your team, and your preferences for replies, triage and notifications. If you sign in with Google, we receive your name, email address and profile picture from Google, and store the sign-in tokens that Google returns. For each sign-in, we store a session record with its expiry, your IP address and your browser’s user agent. Accounts are created only from an invitation; an invitation stores the invited email address, role and team, and expires after 14 days.
Connected mailboxes. An admin connects a mailbox with Google (Gmail) or with IMAP and SMTP.
- For Gmail, we store an OAuth refresh token and the mailbox address. Chirp copies every message in the mailbox, including spam and trash, so your team can work on it, and sends the replies your team writes.
- For IMAP, we store the username and password for the mailbox, and copy the inbox and the sent folder.
Refresh tokens and passwords are encrypted (AES-256-GCM) before we store them.
Messages and attachments. For each message, we store the sender, recipients, subject, body, dates and message identifiers, the list of attachments, and the original message file with its attachments. Messages are stored in our database and file storage, which our hosting and storage providers run for us.
Customer contact data. The people who write to your inboxes are identified by the name and email address in their messages. Chirp shows your team each sender’s past conversations. Admins can link an email address to a Stripe customer; we store that link.
Your team’s work. Assignments, statuses, snoozes, tags, internal notes, mentions, facts, saved views, automation rules and their run history, notifications, and a log of changes to each conversation.
Stripe. If an admin connects Stripe, we store a restricted API key for the customer’s own Stripe account, encrypted. When an agent opens the customer panel, Chirp reads that customer’s details, subscriptions and payments from Stripe and keeps them in memory for up to one minute. We do not store Stripe customer or payment data in our database, apart from the email-to-customer links above. Disconnecting Stripe deletes the key.
Linear. If an admin connects Linear, we store an OAuth token, encrypted, and the workspace name. When your team links a conversation to a Linear issue, we store the issue’s identifier, URL, title and state, and keep the state up to date. When an agent links an issue, they can choose to post the customer’s latest message (up to 5,000 characters) as a comment on the Linear issue, with a link back to the conversation. Each inbox sets whether that choice starts on or off. Disconnecting Linear deletes the token and asks Linear to revoke it.
API keys. When you create an API key, we store its name, first characters, scopes, expiry, and a SHA-256 hash of the secret. We show the full key once and cannot show it again. We log each API request: the key, the method, the route, the conversation and the result.
Translation. [CONFIRM: translation is off unless the deployment sets an OpenRouter key.] When translation is on, Chirp sends the text of recent incoming messages that do not look English, and any message an agent asks to translate, to OpenRouter, which passes it to a language model (by default DeepSeek). Each request tells OpenRouter to use only model providers that do not store or train on the data. We store the translation with the message.
Telemetry and logs. When telemetry is configured, we record traces and logs of requests, database queries and background jobs to find errors and slow pages, and send them to Axiom. Before anything leaves our servers, we keep only a fixed list of technical fields, remove message identifiers and email addresses from URLs, remove secrets from query text, and drop all error messages, because an error message can quote email content. Telemetry does not include the subject, body or attachments of any email.
Cookies. The app sets one session cookie when you sign in, to keep you signed in. It sets no analytics or advertising cookies. Your browser keeps your unsent reply and note drafts and your view preferences in its local storage, on your own device. The app loads its fonts from Google Fonts, so your browser sends your IP address to Google when it loads a page.
How we use information
We use the information above only to provide the Service to you and your team: to sync, show, search, organise and send email; to run the automations and integrations that your team sets up; to keep the Service secure; to find and fix errors; and to contact you about your account. We do not sell personal information, we do not use your email content for advertising, and we do not use it to train AI models.
Under UK data protection law, we rely on these legal bases: performing our contract with you or your organisation; our legitimate interests in running, securing and improving the Service; and meeting our legal obligations.
Google API Services: Limited Use
Chirp’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Chirp requests these Google scopes when an admin connects a Gmail mailbox:
| Scope | Why Chirp needs it |
|---|---|
https://www.googleapis.com/auth/gmail.readonly |
Read the mailbox’s messages and labels, so your team can see and answer them in Chirp. |
https://www.googleapis.com/auth/gmail.send |
Send the replies and new messages that your team writes in Chirp, from that mailbox. |
Google sign-in, when it is on, asks only for your basic profile and email address.
In particular, for data from Gmail:
- We use it only to provide and improve the user-facing features of Chirp that your team uses: the shared inbox, search, automations, the customer panel and translation.
- We transfer it to others only to provide those features, with your consent (for example, a customer message that an agent chooses to post to a Linear issue, or a message sent for translation when your workspace uses translation); for security purposes; to comply with applicable law; or as part of a merger, acquisition or sale of assets, after obtaining your explicit prior consent.
- We do not use it, or let others use it, to serve advertisements, to build user profiles for advertising, or to develop, improve or train generalised AI or machine-learning models.
- Our staff do not read it unless you give us permission for specific messages, it is needed for security purposes such as investigating abuse, it is needed to comply with law, or the data is aggregated and anonymised for internal operations.
Who processes your data
We share personal information only with the service providers below, and only as needed to run the Service. They process it on our behalf or, for services that you connect, on yours.
| Provider | What it does for Chirp | Data |
|---|---|---|
| Our hosting and storage providers | Hosting, database and file storage | Everything described above |
| Cloudflare | Hosting for the teamchirp.io website | The technical data of each web request |
| Gmail sync and sending; Google sign-in; fonts in the app | Mailbox content; your Google profile; your IP address | |
| Stripe | Your own Stripe account, read with your key | Customer email addresses sent in lookups |
| Linear | Your own Linear workspace | Issue searches; customer messages that agents choose to post as comments |
| Your email provider | The IMAP and SMTP server of a mailbox connected with a password | Mailbox content, and the replies your team sends |
| Axiom | Traces and logs, when telemetry is configured | Technical data, without email content |
| OpenRouter and its model providers | Translation, when on | The text of messages to translate |
Several of these providers are in the United States. [INTERNATIONAL TRANSFERS: the safeguards that apply, such as the UK International Data Transfer Addendum.]
We also disclose information in response to a subpoena, court order or other governmental request, or when we believe in good faith that disclosure is reasonably necessary to protect the property or rights of Chirp, third parties or the public at large. We will not rent or sell personal information to anyone.
Security
We take measures reasonably necessary to protect personal information against unauthorised access, use, alteration or destruction. For example: mailbox tokens and passwords, the Linear token and Stripe keys are encrypted; passwords and API keys are stored only as hashes; each person sees only the inboxes that their workspace gives them access to; and telemetry leaves out email content.
How long we keep data
We keep your workspace’s data while your organisation uses Chirp. Chirp has no automatic deletion schedule, and deleting a message in your mailbox does not delete Chirp’s copy. To delete a workspace, an account or specific data, email us. [DELETION: the owner sets the process and the time frame. The app has no self-serve deletion or export today.]
Your rights
Depending on where you live, you can ask us for a copy of your personal information, and ask us to correct it, delete it, restrict or object to its use, or move it to another service. Email [email protected]. If an organisation’s workspace holds your data (for example, you emailed a company that uses Chirp), we will pass your request to that organisation. You can also complain to the UK Information Commissioner’s Office (ico.org.uk) or your local data protection authority.
You can revoke Chirp’s access to a Gmail mailbox at any time from your Google Account’s security settings.
Children
Chirp is a service for businesses and is not directed at children under 16.
Business transfers
If Rocket Source Ltd., or substantially all of its assets, were acquired, or in the unlikely event that it goes out of business or enters bankruptcy, user information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer may continue to use your personal information as set forth in this policy.
Changes to this policy
We may change this Privacy Policy from time to time. When we make a material change, we will post it here and update the date above. [NOTICE OF CHANGES: the owner decides whether to email workspace admins about material changes.]
Contact
You can contact us about any privacy question at [email protected], or write to Rocket Source Ltd., a company registered in England and Wales (company number 16517484), 38b Arbery Road, London, E3 5DD.