Legal
Last updated: August 2026
Quirre ("we", "our", "us") is an AI agent that writes social media posts about your product and publishes them to social media accounts you connect. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website at quirre.com and the Quirre application.
By creating an account or using Quirre, you agree to the practices described in this policy.
We collect the following categories of information:
Account information: Your email address and hashed password when you sign up.
Product information: Details about your product, target audience, competitors, niche, website URL, budget, and weekly hours — which you provide during onboarding and in settings.
Social account credentials: When you connect a social media account, we receive and store an access token (and, where the platform provides one, a refresh token) that lets us publish on your behalf. We also store your public account name and account ID so we can show you which account is connected. We never receive or store your social media password.
Brand voice data: Writing samples you paste in, or a description you write of how you want to sound. These are used to generate posts that read like you.
Generated and published content: The posts Quirre writes for you, their scheduled times, whether they were approved or auto-published, whether publishing succeeded, and the resulting post URL.
Usage data: Chat messages you send to the AI, plans generated, tasks you complete, and analytics metrics you log.
Technical data: IP address, browser type, device type, and pages visited, collected automatically for security and performance purposes.
Payment information: We do not store your payment card details. Payments are handled by Stripe, which processes and stores card information securely under their own privacy policy.
We use your information to:
— Provide, personalise, and improve the Quirre service — Generate social posts about your product, in your voice, on your schedule — Publish those posts to the accounts you have connected — Notify you when posts are waiting for your approval, and when publishing fails — Process payments and manage your subscription via Stripe — Send transactional and notification emails via Resend — Monitor for abuse, fraud, and security threats — Analyse aggregate usage patterns to improve the product
We do not use your data to train third-party AI models. Your product details, brand voice, and conversations are used only to generate content for you within the Quirre service.
We share data with the following third parties only to the extent necessary to operate Quirre:
Supabase — database and authentication. Your data is stored on Supabase-managed infrastructure in the EU.
OpenAI — powers the AI features. Your product context, brand voice, and prompts are sent to OpenAI's API to generate posts. OpenAI does not use API data to train their models by default.
X (Twitter) and LinkedIn — where you have connected an account, we send the generated post content to that platform's API in order to publish it. Once published, that content is governed by the platform's own privacy policy and terms.
Stripe — payment processing. Stripe receives your email and payment details to process subscriptions.
Resend — email delivery (confirmations, password resets, approval notifications, digests).
Vercel — hosting and analytics. Vercel Analytics and Speed Insights collect aggregate, cookieless performance and pageview data with no personal identifiers.
PostHog — product analytics, used to understand how Quirre is used so we can improve it. Where you have accepted analytics cookies, PostHog receives your account id, email address, the pages you visit, and errors your browser encounters. It runs on PostHog's EU infrastructure and is loaded through our own domain. If you decline, PostHog is never loaded and receives nothing from your browser. See section 7.
X Ads — advertising measurement. Where you have accepted cookies and you create an account, we tell X's conversion pixel that a signup happened, so we can see which ads led to accounts. X receives the fact of the conversion and whatever its own cookies already identify about your browser; we do not send it your email address or your account id. If you decline, the pixel is never loaded. This is separate from the X account connection above, which is about publishing your posts.
Google — where you connect Google Search Console, we exchange tokens with Google and read your search performance data for the site you selected. We also send page URLs to Google's PageSpeed Insights API when you run an SEO audit.
Serper — search-results data used by the SEO features. Keywords and domains you enter are sent to this API; your account details are not.
We do not sell or rent your personal information. Apart from the X Ads conversion pixel described above, which reports that a signup occurred so we can measure our own advertising, we do not share your personal information with third parties for marketing purposes. We do not use your data to train third-party AI models.
If you are in the EU or UK, we must tell you the legal basis we rely on for each purpose. They are:
Performance of a contract — creating and running your account, generating posts, publishing them to accounts you connect, taking payment, and sending the transactional emails the service depends on. Without this processing there is no service to provide.
Consent — product analytics cookies (section 7), and connecting any social or Google account. You can withdraw either at any time, by declining analytics in the cookie banner or by disconnecting the account. Withdrawing does not affect processing already carried out.
Legitimate interests — keeping the service secure, preventing abuse and fraud, and understanding aggregate usage patterns to improve the product. We balance these against your rights, and use the least identifying data that answers the question.
Legal obligation — retaining invoices and transaction records for the period Danish tax and accounting law requires.
Your database is hosted by Supabase in the European Union, and PostHog runs on EU infrastructure.
Some of our providers are based in the United States, and our application servers currently run in a United States region on Vercel. This means your personal data is transferred to and processed in the US by Vercel, OpenAI, Stripe and Resend, and by X or LinkedIn where you have connected an account.
These transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the providers' certification under the EU–US Data Privacy Framework. You can ask us for details of the safeguards in place for any specific provider by emailing officialdolostudio@gmail.com.
We retain your account and product data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or tax purposes.
To close your account, email officialdolostudio@gmail.com and we will action it. Social access tokens are deleted immediately when you disconnect an account or delete your account — we do not keep them for the 30-day window.
Generated posts, their publishing history, and your brand voice data are retained for as long as you have an account, so you can see what went out and so future posts stay consistent with past ones. Posts already published to a social platform are not ours to delete; you remove those on the platform itself.
Depending on your location, you may have the following rights regarding your personal data:
— Access: request a copy of the data we hold about you — Correction: request we correct inaccurate data — Deletion: request we delete your data ("right to be forgotten") — Portability: request your data in a machine-readable format — Objection: object to certain types of processing — Restriction: ask us to limit how we use your data while a question is resolved — Withdraw consent: where we rely on your consent, withdraw it at any time, without affecting processing already carried out
To exercise any of these rights, email officialdolostudio@gmail.com. We will respond within 30 days, and we will not charge you for it.
If you are unhappy with how we have handled your personal data, you have the right to complain to a data protection supervisory authority. In Denmark that is Datatilsynet (datatilsynet.dk, Carl Jacobsens Vej 35, 2500 Valby). If you live elsewhere in the EU, you may complain to the authority in your own country.
We take reasonable measures to protect your data, including encrypted connections (HTTPS), hashed passwords, database row-level security, and access controls. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to Datatilsynet within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will also tell you directly, without undue delay.
Quirre is not directed at children under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page. For significant changes, we will notify you by email. Continued use of Quirre after changes constitutes acceptance of the updated policy.
For any privacy-related questions or requests, contact us at officialdolostudio@gmail.com.
3. Social account access
Connecting a social media account is the most sensitive permission you grant us, so here is exactly what it means.
What we request: permission to publish posts as you, to read your basic profile (so we can display which account is connected), and — on X — offline access, which is what allows us to keep publishing on a schedule without you re-authorising every couple of hours.
What we do with it: we use the token solely to publish posts you have scheduled through Quirre, and to refresh the token when it expires. We do not read your direct messages, we do not read your timeline or followers, we do not post anything you have not scheduled through Quirre, and we do not use your account for any purpose of our own.
How it is stored: access and refresh tokens are stored in our database on Supabase infrastructure in the EU, protected by row-level security so they are only reachable by your own account and our server processes.
Revoking access: you can disconnect any account at any time from your settings page, which deletes the stored tokens. You can also revoke Quirre's access from within the platform's own app settings, which we recommend as a belt-and-braces step. Revoking stops future publishing; it does not delete posts already published.
Google Search Console: if you connect Search Console, we store a Google OAuth token the same way and with the same protections. We use it only to read search performance data for the site you select — the queries you rank for, impressions, clicks and positions — so Quirre can decide what to write about. We request read-only access. We do not modify anything in your Search Console or Google account, and we cannot access Gmail, Drive, or any other Google service. Disconnecting deletes the token.