Privacy Policy
What we hold about you, why, and what you can do about it.
The operator has not yet published: legal entity name, registered address, governing law / jurisdiction, legal contact address, privacy contact address. Each missing item is marked in the text below. Until they are published this service should not be taking money from the public.
Controller. [not yet published: legal entity name], [not yet published: registered address] ([not yet published: country of establishment]) decides why and how your personal data is processed. Privacy contact: [not yet published: privacy contact address].
EU representative (GDPR Art. 27). [not yet published: EU representative (GDPR Art. 27)]
UK representative. [not yet published: UK representative]
What we hold, and why
| Data | Why | Lawful basis |
|---|---|---|
| Username, email, password hash | To have an account at all | Performance of a contract |
| Date of birth | To apply a minimum age | Legal obligation |
| Country you declare | Sanctions screening, age rules, tax | Legal obligation |
| Messages and files you send | To deliver them | Performance of a contract |
| Contacts you connect with | To route messages and calls | Performance of a contract |
| Call signalling records (who rang whom, when) | Diagnosing failed calls | Legitimate interest in a working service |
| Device-reported media failures | Fixing calls that fail on some phones | Legitimate interest |
| Seller identity, address, tax id (last 4) | Marketplace law (INFORM Act) | Legal obligation |
| Payment records | Taking and settling money | Contract and legal obligation |
| Reports you make about content | Safety, and mandatory reporting | Legal obligation and legitimate interest |
| Updates you post, their hashtags, and who viewed or reacted | To show them to the audience you chose, for 24 hours | Performance of a contract |
| Songs you add to the music library, with the licence you agreed to | To offer them to everyone on Whinchat, credited to the name you gave | Performance of a contract — the Artist Licence |
| Lives you host or watch: the title, the comments, the hearts, and who watched | To run the live, and to act on a report about it | Performance of a contract, and legitimate interest in keeping lives safe |
| Shops and categories you follow | To send you one message a day when something new is listed | Performance of a contract — you asked to be told |
| How the app performed for you, and which screens and buttons were used | To find what is slow or broken, and to see which parts of the app people actually reach | Legitimate interest in a service that works. You can switch it off — see below |
Updates and hashtags
An update is deleted 24 hours after you post it, with its file, its views and its reactions — unless it has been reported, in which case it is kept, hidden from everyone, until a moderator has dealt with the report.
Who sees it is chosen for each update. By default only your contacts do, within the limits you set under Who can see this. If you choose Everyone for an update, anyone signed in to the app can see that update and find it through its hashtags, and you will see them in its list of viewers. Choosing Everyone for one update changes nothing about your others. People who are not your contacts can view and react to a public update but cannot reply, because a reply is a direct message. Blocking works as it always does, in both directions, public or not.
Hashtags. We read the hashtags out of what you write so the update can be found by them. A hashtag page, a suggestion while typing, a trending list or a count only ever includes updates the person looking at it is allowed to see — so a hashtag on an update for your contacts is invisible to everyone else, including in counts.
Suggestions while you type. When you type a hashtag, the app suggests matching ones and shows how many public updates have used each. That count is kept per hashtag, with no names attached, and only public updates add to it. To suggest familiar names (people, places, teams), the letters you have typed after # are sent from our server to Wikipedia — not from your phone, and without your name or account.
Feelings and music. A feeling you add ("feeling blessed") is one of a fixed list and is shown to whoever can see the update. Music is free music from independent artists, licensed so that anyone may use it, and each track is credited on the update. Some tracks are licensed "share-alike" (CC BY-SA): the artist asks that what is made with the track is shared under the same licence. When you search for music, the search words go from our server to Openverse — not from your phone, and without your name or account. Tracks play from Whinchat's own storage: the first time a track is chosen, our server fetches a copy from the site that published it (usually Jamendo), so your phone does not contact that site when you preview or play music.
Shops you follow
If you follow a shop or a category, we keep that choice so we can tell you when something new is listed. It is one message a day at most, never one per item, and it arrives in your chat with the app — with a notification only if you have them switched on and have not silenced that chat.
What you follow is private. A seller is never told who follows them and is never given a follower count, and no one else can see your list. Unfollow from the shop's page, or under Market, and the messages stop.
Large meetings and recordings
Calls and ordinary meetings go directly between the people on them; we do not see or keep them. A large meeting — one a Business host chose to make large, for more people than a direct call can carry — goes through LiveKit's servers instead: they receive everyone's audio and video, encrypted, and forward it to the others. That makes a large meeting not end-to-end encrypted: LiveKit could technically access it. LiveKit does not record it and neither do we. LiveKit also learns each person's username, display name and network address, as any server a call goes through must.
The one thing we do keep is a cloud recording, which the host of a meeting on the Business plan can choose to make. Everyone in the meeting is told while it runs. The host's device records everyone's video and voice and uploads it to us, and we keep it in private, encrypted storage for two days, then delete it. Only the host and the people who were in the meeting can download it. Details are in Recording & Consent.
Going live
Who can watch. When you go live, your contacts and the people who follow your shop can watch, and they are sent a notification (at most once every 10 minutes, however many times you go live). So can anyone you send your live's link to — and anyone they pass it on to, so share it with care. To watch from a link you must be 18 or over: we use the date of birth you gave when you signed up, and only ask an account that has none, once. No one else can find your live, and anyone you have blocked, or who has blocked you, cannot see it at all, even with the link.
How it travels. A live goes through LiveKit's servers, which receive your audio and video, encrypted, and forward them to the people watching. That makes a live not end-to-end encrypted: LiveKit could technically access it. Nothing is recorded, by us or by LiveKit. LiveKit also learns each person's username, display name and network address, as any server a live goes through must.
What we keep. The title, the comments, the number of hearts and who watched, for 30 days after the live ends, then we delete them. We keep them that long so that a report about a live can still be looked into. Comments are shown to everyone watching.
Who you are seen by. Everyone watching a live can see the names of the others watching, and is told when someone joins. If you ask to join the host on stage and the host lets you, your camera and microphone are seen and heard by everyone watching, until you leave the stage or the host takes you off. Guests must be 18 or over. Guests are not in the host's recording.
Comments are checked. Before a comment is shown, it is checked automatically for slurs, threats, sexual harassment and rude emoji, which are refused, and for everyday swearing, which is masked (f•••). A refused comment is not kept — we log only that one was refused, not what it said. Three refusals in one live pause commenting for 10 minutes.
Recording. The host can record their own live, to download and share it. Everyone watching is told while it is being recorded. Only the host is in the recording — their picture and voice, the title and the Whinchat name — never a viewer's name, face or words. It is kept for 2 days for the host to download, then deleted. If our staff stop a live, or it is stopped by a report, its recording is not given to the host: it is held for as long as the law requires such material to be preserved (90 days), then deleted.
Moderation. Our staff can see which lives are running and may watch any of them to check a report, without being shown to the host or the audience. They can stop a live at once. A live reported as child sexual abuse is stopped automatically.
Measuring how the app performs
The app reports how long it took to load, which screens you opened, which named buttons you pressed, and when something took too long or failed. It is counted so we can see what is slow, what is broken, and which parts of the app people never reach.
What it never contains. Nothing you typed or wrote. A button reports the internal name it was given by us, never its contents, never the text of a message, search, listing or profile. No advertising identifier is created and nothing is shared with anyone else — there is no third-party analytics service in this app.
Before you sign in, these reports carry a random identifier that is created for that browser tab and destroyed when you close it. It is not a cookie, it is not kept between visits, and it cannot be used to recognise you on a later visit or anywhere else. Once you are signed in, they are recorded against your account, so that support can see what your app actually did when you ask for help.
How to switch it off. Settings → Privacy → Help improve the app. We also honour Global Privacy Control and Do Not Track automatically: if your browser sends either, nothing is measured and you do not need to change anything here.
How long it is kept. Reports that name you are deleted on the same schedule as the technical log — see Retention. What survives longer is a daily count with no account, identifier or device in it: how many people opened a screen, not which people.
What happens when you sign up
Two things are set up for you the moment your account is created, and you can undo both:
- The app's own account sends you a welcome message, and becomes one of your contacts. That thread is our support channel: what you write in it is read and answered by staff, so please do not put anything in it you would not want a member of staff to read. The operator's account is added as a contact too, without a message, so that support can reach you. Remove either like any other contact if you would rather not have it; nothing else about your account changes.
- If you arrived on somebody's personal invite link, the two of you are connected immediately, they are told that you joined, and we record who invited you. That record is yours to see — it is in your data export — and it is deleted with your account.
Feedback
What you send from Settings → Rate & review Whinchat is kept with your username, the rating you gave (0 to 5 stars), if you gave one, the kind you picked (a review, an idea, a problem, praise or something else) and the name of the browser you sent it from, so we can tell which device a problem happened on. Only our staff can read it. If we reply, the reply arrives in your chat with the app. It is in your data export, and it is deleted with your account.
Now and then the app asks whether you would like to rate it: at most once a month and four times in all, never in your first few days, and not for six months after you have given a rating. To keep to that, we record when we last asked you and how many times. Answering is optional — "Not now" is always there.
What we do not hold
We do not sell personal data, and we do not use it for advertising profiles. We do not use advertising or tracking cookies. Promoted listings inside the marketplace are sold by placement, not by targeting you.
Phone-number contact matching is opt-in and one-shot: the numbers you choose are hashed for the lookup and are not stored, and someone only appears if they separately chose to be findable by phone.
How well it is protected
Ordinary chats are not end-to-end encrypted, and we can read them. A private chat is, and we cannot. Which one you are in is shown in the conversation itself, and either person can switch a direct chat to private at any time.
A private chat
Open any direct conversation, tap the menu and choose Make this chat private. From that moment the two devices encrypt to each other and we hold only ciphertext: we cannot read it, cannot produce it for anyone who asks, and cannot recover it for you. Our server refuses to accept readable text in a private chat, so it cannot be quietly turned off by a modified app — and if anyone does turn it off, a line saying so appears in the conversation for both of you.
What a private chat does not cover, stated plainly because a padlock invites people to assume more than it means:
- Who you talked to, and when. We route the messages, so we see that.
- Photos, voice notes and files. These are not encrypted yet, so a private chat refuses them rather than sending them in the clear under a padlock.
- Reactions and read receipts. Small, but we can see them.
- Messages already sent before you turned it on. They stay as they were.
- Direct chats only. Group chats cannot be made private yet.
- The app itself. This is a web app: your browser runs code it downloads from us each time. End-to-end encryption protects your messages from us on our servers; it cannot, in any web app, protect you from us if we served you dishonest code. If that is part of your threat model, you need an app you can verify independently.
An ordinary chat
Your messages are not end-to-end encrypted, and we can read them. Message text is stored on our servers in a form we can open. It is protected by HTTPS in transit and by encrypted storage at rest, and access to production data is limited and logged — but the protection is our word and our controls, not mathematics. Please read that sentence as the plain warning it is: do not put anything in a message here that would harm you if the operator, a member of staff, or anyone who compelled or breached us could read it.
Earlier versions of this policy said the opposite. Until 26 July 2026 direct messages really were end-to-end encrypted, and the messages sent before that date are still stored as ciphertext we cannot read. Encryption was then switched off, because a key that lives on one device silently orphans your own history when that device changes, and people were losing their conversations. This document was not updated at the time. That was our mistake, and this is the correction.
What is encrypted, and what that is worth:
- Calls — audio and video — are encrypted between the participants by WebRTC (DTLS-SRTP), and we cannot listen to them. The exception is a large meeting: a large meeting's audio and video are encrypted to LiveKit's servers, which forward them to everyone in it, so it is not end-to-end encrypted.
- Messages sent before 26 July 2026 remain ciphertext. We hold your wrapped private key but it is sealed with your password, which we do not have.
- Passwords are stored hashed, in a form nobody here can reverse.
Everything else, you should assume we can see:
- Message text you send from now on, as described above.
- Photos, videos and voice notes are stored on our servers as files. They are protected in transit and at rest, but staff with server access could open them.
- Metadata — who you talk to, when, and how often — is visible to us because routing a message requires it.
- That a call happened, and between whom. When your network forces the media through our relay, the relay forwards encrypted packets it cannot read — but it still sees the call took place.
- Marketplace listings and shop pages are public by design.
Who else processes it
See Subprocessors for the current list, what each one receives, and where it is. In summary: our hosting provider, the payment processor, the push-notification services your own operating system uses, an optional translation service, and an optional AI provider for the listing assistant.
Where it goes
The Service is hosted in the United States. If you are in the European Economic Area or the United Kingdom, using it means your data is transferred there. Transfers rely on the Standard Contractual Clauses where an adequacy decision does not apply; the transfer machinery is described, honestly including what is not yet in place, in Subprocessors.
How long we keep it
See Data Retention. System logs are kept 14 days.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to processing, and withdraw consent where consent is the basis. Export and deletion are both self-service, in Settings → Your data & privacy — you do not have to ask us and wait. Everything else: [not yet published: privacy contact address].
If you are in the EEA or UK you may complain to your national supervisory authority. If you are in California, see US State Privacy Rights.
Children
The Service is not for children below the ages in Child Safety. We do not knowingly collect their data, and we delete an account when we learn it belongs to someone under the age limit.
Changes
Material changes are signalled in the app and the date at the top of this page changes.
What has changed
24 September 2026 · version 23
- §3 Going live — to watch from a shared link you must be 18 or over; we use the date of birth you gave when you signed up and ask only accounts that have none. A reply to a comment shows a short quote of it; the host can pin a comment for everyone.
24 September 2026 · version 22
- §3 Going live — everyone watching a live can see who else is watching. A viewer the host lets on stage is seen and heard by everyone watching (and is not in the host's recording). Comments are checked automatically before they are shown; one that is refused is not kept, and only the fact that it was refused is logged.
24 September 2026 · version 21
- §3 Going live — the host can record their own live. Only the host is in the recording, never a viewer's name, face or words. Everyone watching is told. It is kept 2 days for the host to download. A live stopped by our staff or by a report is not handed to the host: its recording is held for as long as the law requires, then deleted.
24 September 2026 · version 20
- §3 Feedback — a review can carry a rating of 0 to 5 stars, kept with the rest of what you sent. Now and then the app asks whether you would like to rate it: at most once a month and four times in all, and not for six months after you rate. We keep when we last asked.
24 September 2026 · version 19
- §3 Whinchat Artists — if you add a song to the music library, the title, the artist name, the genre and language you give, and the recording are shown to everyone who uses the music sheet, and the artist name is credited on every update that uses it.
24 September 2026 · version 18
- §3 Going live — anyone you send your live's link to can also watch it, and the people told you are live are told at most once every 10 minutes (it was once an hour).
24 September 2026 · version 17
- §3 Going live — who can watch (your contacts and the people who follow your shop), who is notified, that a live goes through LiveKit and is not end-to-end encrypted, that nothing is recorded, that staff may watch any live to moderate it, and that comments and who watched are kept 30 days after it ends.
24 September 2026 · version 16
- §3 Feedback — what you send from Settings → Send feedback is kept with your username, the kind you picked and your browser's name, read only by staff, included in your data export and deleted with your account.
24 September 2026 · version 15
- §3 Large meetings and recordings — a Business host can make a meeting large (up to 50 people). Its audio and video then go through LiveKit's servers instead of directly between phones, so a large meeting is not end-to-end encrypted: LiveKit forwards it and could technically access it. Neither LiveKit nor we record it unless the host starts a cloud recording.
- §4 How well it is protected — calls stay encrypted between the people on them, except large meetings, which are encrypted to LiveKit's servers.
24 September 2026 · version 14
- §3 Meeting recordings — the host of a meeting on the Business plan can record it to the cloud. Everyone in the meeting is told, including anyone who joins later. The recording is stored privately, encrypted, can be downloaded only by the host and the people who were in the meeting, and is deleted after 2 days. See Recording & Consent.
24 September 2026 · version 13
- §3 Updates and hashtags — music now plays from Whinchat's own storage. Previewing or playing a track no longer makes your phone contact the site that published it; our server fetches one copy of each track instead.
24 September 2026 · version 12
- §3 Updates and hashtags — music may now also be licensed share-alike (CC BY-SA), where the artist asks that what is made with the track is shared under the same licence.
24 September 2026 · version 11
- §3 Updates and hashtags — while you type a hashtag, the app suggests matching ones with how many public updates have used each. To suggest familiar names, the letters you have typed after # are sent from our server to Wikipedia — never from your phone, and never with your name. The count for each hashtag covers public updates only.
24 September 2026 · version 10
- §3 Updates and hashtags — an update can now carry a feeling from a fixed list and a piece of free music. Music searches are sent from our server to Openverse, never from your phone and never with your name. Playing a track streams it from the site that hosts it (usually Jamendo), which sees your device's address the way any website you visit does.
23 September 2026 · version 9
- §3 Updates and hashtags — updates you post last 24 hours and go to your contacts unless, for that one update, you choose Everyone. A public update can be seen by anyone signed in and found through its hashtags. Hashtag pages, suggestions and counts only ever include updates the person looking is allowed to see.
20 September 2026 · version 8
- §3 Shops you follow — following a shop or a category is recorded so that you can be told when something new is listed. At most one message a day, never one per item. What you follow is private: a seller is never told who follows them and never given a follower count.
20 September 2026 · version 7
- §3 Measuring how the app performs — the app now reports load times, which screens were opened and which named buttons were pressed, so that what is slow or unreachable can be found. It never carries anything you typed. Before sign-in it uses an identifier that lasts one browser tab. It can be switched off in Settings, and Global Privacy Control and Do Not Track are honoured automatically.
20 September 2026 · version 6
- §3 Private chats: either person can make a direct chat end-to-end encrypted. What it covers, and the five things it does not, are listed.
20 September 2026 · version 5
- CORRECTION. This document said direct messages were end-to-end encrypted. They have not been since 26 July 2026: we can read message text sent on or after that date. Messages sent before it remain ciphertext we cannot open, and calls are still encrypted between the people on them.
- §3 How well it is protected — rewritten to say what is really encrypted (calls, old messages, passwords) and what we can read (everything else).
20 September 2026 · version 4
- §3 What happens when you sign up — the app's own account sends you a welcome message and becomes a contact; that thread is read and answered by staff. The operator's account is added as a contact as well. Both can be removed.
- §3 If you signed up on somebody's personal invite link, we record who invited you, tell them you joined, and connect the two of you.
29 August 2026 · version 3
- §3 What we collect — the app now reports JavaScript errors from your browser so faults can be found without waiting to be told. The report carries the error, the page and the build, never message content.
- §6 Where it is held — photos and voice notes now live in private object storage rather than on the application server's own disk.
7 August 2026 · version 2
- §11 added: US state privacy rights, split into its own notice.
12 July 2026 · version 1
- First published.