Cirrden Privacy Policy
Effective date: 15 June 2026 | Last updated: 30 August 2026
Cirrden is a platform where African creators earn from their content and fans support the creators they love. To run it, we collect and use some of your data. This policy explains exactly what we collect, why we collect it, what we do with it, what we never do with it, and the rights you have over it.
We wrote this to be read. Where the law requires technical language, we include it, but we lead with plain English.
Who we are
Cirrden is operated by Cirrden Innovation Services, a business registered in Nigeria under the Companies and Allied Matters Act 2020 (Business Name Registration No. 7975540). Under data protection law, we are the controller of your personal data. You can reach us about anything in this policy at privacy@cirrden.com.
Who Cirrden is for
Cirrden is for users aged 18 and older. We do not knowingly collect data from anyone under 18. If we learn an account belongs to someone under 18, we close the account and delete its data.
Cirrden has zero tolerance for child sexual abuse and exploitation. Our Child Safety Standards explain what is prohibited, how we act on it, and how to report a concern.
What we collect
Account information. Your name, username, email address, phone number, country, and password (stored hashed, we cannot read it).
Profile information. Photo, bio, and any links you add.
Your content and activity. Videos, clips, posts, comments, likes, saves, reshares, the Circles you create or join, and what you watch.
Chats, stories, and attachments. The messages you send and receive, replies, reactions, photos, files, voice notes, stories, story views, and story reactions. We also process the people in a conversation, the time a message was sent or read, message expiry, and online or last-active status so chats can be delivered, displayed, and kept safe.
Topics and preferences. The topics you pick and the creators you follow. This is what powers your home feed.
Wallet and payment data. Your wallet balance, transaction history, billing country, and currency. For creators, payout details such as your bank account. Card payments are processed by our payment partners. We never see or store your full card number.
Identity verification. Where required for creator payouts or by law, we collect verification information.
Usage and device data. IP address, browser type, device information, and how you move through the platform.
Communications. Emails you send us, replies to our emails, and support conversations.
How we use your data
- To run the platform: your account, your feed (built from your topics and activity), Circles, and everything you signed up for.
- To deliver chats, attachments, stories, read status, and real-time features such as typing, recording, and presence. We use your message content only to provide those features, protect the service, and meet legal obligations, never to target advertising.
- To process payments to and from your wallet, and payouts to creators.
- To keep Cirrden safe: responding to reports and investigating suspected fraud, abuse, spam, impersonation, violent extremism, and credible threats of serious harm to people or public safety.
- To comply with valid legal process and legal obligations, and in a genuine emergency involving an imminent risk of death or serious physical harm.
- To communicate with you: transaction confirmations, product updates, and, only if you consent, marketing. You can unsubscribe from marketing at any time.
- To improve the product, using aggregated or anonymized data wherever possible.
- To meet our legal obligations.
What we never do
- We do not sell your personal data. To anyone. Ever.
- We do not alter or manipulate your data. What you put in is what is there.
- We do not read your private Circles or private content for advertising.
- We do not use the contents of private chats or chat attachments for advertising.
- We do not use your content to train general-purpose AI models. Features that use AI to help you, like analytics or pricing suggestions, work on your own data, for your benefit.
Who we share data with
- Payment processors (currently Paystack, Stripe, and Transfaar) to process transactions and payouts.
- Infrastructure providers that host the platform and deliver content.
- Notification, email, and analytics providers that help us deliver product communications and understand product usage. If you enable device notifications, the notification provider may receive the sender's identity and a short message preview so it can deliver the notification to your device.
- Competent authorities, when legally required. We may disclose information in response to valid legal process, or where disclosure is necessary to respond to an imminent risk of death or serious physical harm. We review every request, push back on requests that are overbroad, and disclose only what is legally required or necessary in the circumstances. Where the law permits, we will notify you before disclosure.
- A buyer or successor, if Cirrden is ever acquired or merged. You would be notified before your data changes hands.
We never share your data with data brokers or sell audience lists to advertisers.
Where your data goes
Cirrden operates from Nigeria and serves users in multiple countries. Your data may be processed outside your home country. When it is, we use recognized safeguards such as standard contractual clauses or transfers to jurisdictions with adequate protection.
How long we keep your data, and account deletion
Chats and stories are temporary.Direct messages, including their attachments and the encryption keys that protect message content, are hard-deleted 24 hours after they are created. Stories are also hard-deleted 24 hours after publication. Deleting a message earlier permanently removes it from Cirrden. Deleting a conversation removes it from your Inbox only. It does not remove the conversation or messages from the other participant's Inbox, and a new message can make it visible to you again.
These deletion controls cannot remove a copy another participant has already made, including a screenshot, download, or copied text.
When you delete your account, it enters a 30-day deletion window. During those 30 days your account is deactivated and invisible to other users. If you change your mind, contact our support team within the window and we will restore your account. After 30 days, your account and personal data are permanently deleted.
One exception, because the law requires it: records of financial transactions (payments, payouts, and wallet activity) are retained for as long as financial regulations require, even after account deletion. These records are kept for legal compliance only and are never used for anything else.
Your rights
Wherever you are, you can:
- Access the personal data we hold about you.
- Correct data that is wrong.
- Delete your account and data (see the 30-day window above).
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent for anything that runs on consent, like marketing.
- Complain to your data protection regulator.
To exercise any of these, email privacy@cirrden.com. We respond within one calendar month.
Regional terms
Nigeria. We comply with the Nigeria Data Protection Act 2023 (NDPA). Our regulator is the Nigeria Data Protection Commission (NDPC).
European Economic Area and the United Kingdom. We process personal data under the GDPR and UK GDPR on these legal bases: performance of our contract with you (running your account), your consent (marketing), our legitimate interests (product improvement and safety), and legal obligation. You may lodge a complaint with your local supervisory authority.
United States. Residents of states with privacy laws (including California) have rights to know, delete, and correct their data, and to opt out of the sale of personal data. We do not sell personal data.
Kenya. We comply with the Data Protection Act 2019, regulated by the Office of the Data Protection Commissioner.
Ghana. We comply with the Data Protection Act 2012, regulated by the Data Protection Commission.
South Africa. We comply with the Protection of Personal Information Act (POPIA), regulated by the Information Regulator.
Security
Data is encrypted in transit. Passwords are hashed. Access to personal data inside Cirrden is restricted to people who need it to do their jobs. We vet the providers we share data with. No system is perfectly secure, and if a breach affects your data we will notify you and the relevant regulator within the timelines the law requires.
Chat message bodies, attachment file names, and conversation previews are encrypted at rest at the application layer. Chat attachments are stored privately and delivered with time-limited signed links. Cirrden's systems only return chat content to authenticated participants in that conversation. Chats are not end-to-end encrypted, so do not use them to send passwords, payment-card details, government identification numbers, or other highly sensitive information.
Changes to this policy
If we make material changes, we will email you before they take effect. The latest version always lives at cirrden.com/privacy-policy.
Contact
Cirrden Innovation Services (Business Name Registration No. 7975540)
43 Emmaco House, Back of Happiness Eatery, Zarmaganda - Rayfield Road, Jos, Plateau State, Nigeria
privacy@cirrden.com