Privacy Policy
Last updated: 26 July 2026
Please read this Privacy Policy carefully. It explains who we are, what personal data we collect when you use the CHIRP website and service, why we collect it, who we share it with, and the rights you have over it.
Who we are
This Privacy Policy is issued on behalf of Chirp USA, LLC, 336 E. College Ave, Suite 301, Tallahassee, FL 32301, USA ("CHIRP", "we", "us", "our"). For the processing described here, we are the controller. We are a US company, so your data is processed in the United States. We process personal data in accordance with applicable law, including Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") where it applies to you.
If you have a question about privacy, or want to exercise any of the rights described below, contact us at [email protected].
1. What this policy covers
This policy covers the CHIRP website at chirpwireless.io, the CHIRP web and mobile applications, and the CHIRP service — including the sensors and gateways you connect to it, the automations you build, the alerts we send you, and the AI Helper.
Third-party links: our website may link to other websites and services we do not control. Following those links may allow the operators of those sites to collect data about you. We are not responsible for their privacy practices, and we encourage you to read the privacy policy of any site you visit.
2. Data we collect when you visit our website
Connection data
When you visit chirpwireless.io, our infrastructure automatically receives technical data that your browser sends: your IP address, the date and time of the request, the page requested, the referring page, and information about your browser and operating system. This data is needed to deliver the site securely and to detect and defend against abuse. The legal basis is our legitimate interest in operating a secure website, Art. 6(1)(f) GDPR.
Content delivery and security (Cloudflare)
Our website is served through Cloudflare, which acts as a content delivery network and protects the site against attacks. Cloudflare processes connection data, including your IP address, on our behalf under a data processing agreement.
Analytics (Google Analytics)
Our website uses Google Analytics, a service provided by Google. It sets cookies and collects information about how visitors use the site — pages viewed, approximate location derived from IP address, device and browser type — so that we can understand which parts of the site are useful and improve them. This data is transmitted to and stored by Google.
You can prevent analytics cookies by adjusting your browser settings, by using the browser add-on Google provides to opt out of Google Analytics, or by using a tracking-blocking extension. Declining analytics does not affect your ability to use the site or the service.
Cookies
Cookies are small text files stored on your device. We use two kinds:
Strictly necessary cookies: required for the site and the application to work — for example to keep you signed in and to protect against cross-site request forgery. These cannot be switched off in our systems.
Analytics cookies: set by Google Analytics as described above, to measure how the website is used. These are not required for the site to function.
3. Data we collect when you use the CHIRP service
Account data
To create an account we process your email address and the password you set, which is stored only as a cryptographic hash and is never visible to us. If you add them, we also process your name and profile details, the homes or organisations you belong to, and the role you hold in each. The legal basis is performance of our contract with you, Art. 6(1)(b) GDPR.
Contact details for alerts
If you set up alerts, we process the contact details you provide for the channels you choose — email address, mobile number for SMS, and device tokens for push notifications — so that we can deliver those alerts. Sending SMS and push messages involves telecommunications and messaging providers acting on our behalf.
Billing data
If you take a paid plan, payment is handled by our payment provider. We receive the information needed to manage your subscription and issue invoices — such as your billing details, the plan you hold, and the transaction record. We do not receive or store your full card number.
4. Data from the sensors in your home
This is the part of the service that deserves the clearest explanation, because it concerns your home.
When you connect a device to CHIRP, we receive and store the readings it sends: measurements such as temperature, humidity, water detection, door or window state, motion, air quality, soil moisture, battery level and signal strength, together with the time of each reading, the identifier of the device, and any name, room or location you have given it. Where you use a tracker, that includes the location it reports. We keep this history so that you can look back at it, so that dashboards and charts work, and so that automations and alerts can evaluate it.
We recognise what this data can reveal. Readings from a home can indicate when a property is occupied or empty and what its routines are. We treat it accordingly: it is processed to provide the service you asked for, it is not sold, it is not used for advertising, and it is not shared with third parties for their own purposes. The legal basis is performance of our contract with you, Art. 6(1)(b) GDPR.
Data belonging to a home is isolated from every other home on the platform, and is visible only to the members of that home, according to the permissions its owner grants. If you invite someone into your home, they can see the data your permissions allow them to see.
5. The AI Helper and connected AI applications
CHIRP includes an AI Helper, and you can also connect an external AI application to your account using our MCP server. In both cases the assistant acts within your own permissions: it can reach only what your account can reach, and important or irreversible changes are shown to you for confirmation before they happen.
Your conversations with the AI Helper are stored so that you can scroll back through them. Chat history is private to your individual account and is not visible to other members of your home. Raw sensor readings are not duplicated into the conversation log, and passwords, payment details and API keys are never captured in it.
To generate answers, the content of a conversation and the relevant data it refers to are processed by an AI model provider acting on our behalf under a data processing agreement. If you connect your own external AI application, that application is operated by you or by a third party of your choosing, and what it does with the data it receives is governed by that provider — not by us.
6. Support and correspondence
If you contact us for support, we process what you send us — your message, your contact details, and any details about your setup you choose to share — in order to answer you and to keep a record of the request.
7. Marketing
If you subscribe to updates from us, we process your email address to send them. Where consent is required we ask for it first, and you can withdraw it at any time with effect for the future — every message includes an unsubscribe link, and you can also write to us. You may object to the use of your personal data for direct marketing at any time, without giving a reason.
8. Who we share data with
We use service providers who process personal data on our instructions under data processing agreements: hosting and infrastructure providers, our content delivery and security provider, our payment provider, messaging and telecommunications providers used to deliver alerts, our analytics provider, and the AI model provider behind the AI Helper. We disclose data to anyone else only where the law requires it or where there is another valid legal basis. We do not sell personal data.
9. International transfers
We are based in the United States, and personal data may be processed there and in other countries where our service providers operate. Where data is transferred out of the European Economic Area to a country without an adequacy decision under Art. 45 GDPR, we put appropriate safeguards in place under Art. 46 GDPR, such as the European Commission’s standard contractual clauses together with any additional measures needed to protect the data.
10. Data security
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. Traffic between your devices, your browser and our services is encrypted in transit. Access to personal data is limited to those who need it to do their work, and they are bound by confidentiality. We have procedures for handling suspected data breaches and will notify you and the relevant regulator where the law requires.
11. How long we keep data
We keep personal data only for as long as we need it for the purposes described here, and for as long as required to meet legal, tax, accounting or reporting obligations.
- Account data is kept while your account exists.
- Sensor history is kept according to the retention included in your plan, and is available to you in the application for that period.
- AI Helper conversations are kept until you delete them or your account is closed.
- Billing and transaction records are kept for as long as tax and accounting law requires.
When you close your account we delete or anonymise the personal data associated with it, except where we are required to retain something. Data that has been anonymised, so that it can no longer be linked to you, may be kept and used for statistical purposes.
12. Your rights
Subject to the conditions of applicable law, you have the right to:
- confirmation of whether we process personal data about you, and access to a copy of it (Art. 15 GDPR);
- correction of inaccurate personal data (Art. 16 GDPR);
- erasure of your personal data (Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- portability of the data you provided to us, in a machine-readable format (Art. 20 GDPR);
- object to processing carried out on the basis of legitimate interests (Art. 21(1) GDPR);
- object to direct marketing at any time, without giving a reason (Art. 21(2) GDPR);
- withdraw consent at any time, with effect for the future, where processing is based on consent (Art. 7(3) GDPR);
- lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
To exercise any of these rights, write to [email protected]. Much of it you can also do yourself in the application: you can view and edit your profile, delete devices and their data, delete conversations, and close your account.
13. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, including profiling. Automations you build yourself — a rule that sends you an alert or operates a device — run on your instructions and under your control.
14. Children
CHIRP is not directed at children, and accounts are intended for adults. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this policy
Changes in the law, in our services, or in the technology we use may require changes to this policy. The current version is always published on this page, with the date it was last updated shown at the top.