Privacy Policy

What we hold about you, why, and what you can do about it.

Version 23 · in force since 24 September 2026 · what changed. Drafted in good faith; not legal advice.

This document is incomplete.
The operator has not yet published: legal entity name, registered address, governing law / jurisdiction, legal contact address, privacy contact address. Each missing item is marked in the text below. Until they are published this service should not be taking money from the public.

Controller. [not yet published: legal entity name], [not yet published: registered address] ([not yet published: country of establishment]) decides why and how your personal data is processed. Privacy contact: [not yet published: privacy contact address].

EU representative (GDPR Art. 27). [not yet published: EU representative (GDPR Art. 27)]
UK representative. [not yet published: UK representative]

What we hold, and why

DataWhyLawful basis
Username, email, password hashTo have an account at all Performance of a contract
Date of birthTo apply a minimum age Legal obligation
Country you declareSanctions screening, age rules, tax Legal obligation
Messages and files you sendTo deliver them Performance of a contract
Contacts you connect withTo route messages and calls Performance of a contract
Call signalling records (who rang whom, when)Diagnosing failed calls Legitimate interest in a working service
Device-reported media failuresFixing calls that fail on some phones Legitimate interest
Seller identity, address, tax id (last 4)Marketplace law (INFORM Act) Legal obligation
Payment recordsTaking and settling money Contract and legal obligation
Reports you make about contentSafety, and mandatory reporting Legal obligation and legitimate interest
Updates you post, their hashtags, and who viewed or reacted To show them to the audience you chose, for 24 hours Performance of a contract
Songs you add to the music library, with the licence you agreed to To offer them to everyone on Whinchat, credited to the name you gave Performance of a contract — the Artist Licence
Lives you host or watch: the title, the comments, the hearts, and who watched To run the live, and to act on a report about it Performance of a contract, and legitimate interest in keeping lives safe
Shops and categories you follow To send you one message a day when something new is listed Performance of a contract — you asked to be told
How the app performed for you, and which screens and buttons were used To find what is slow or broken, and to see which parts of the app people actually reach Legitimate interest in a service that works. You can switch it off — see below

Updates and hashtags

An update is deleted 24 hours after you post it, with its file, its views and its reactions — unless it has been reported, in which case it is kept, hidden from everyone, until a moderator has dealt with the report.

Who sees it is chosen for each update. By default only your contacts do, within the limits you set under Who can see this. If you choose Everyone for an update, anyone signed in to the app can see that update and find it through its hashtags, and you will see them in its list of viewers. Choosing Everyone for one update changes nothing about your others. People who are not your contacts can view and react to a public update but cannot reply, because a reply is a direct message. Blocking works as it always does, in both directions, public or not.

Hashtags. We read the hashtags out of what you write so the update can be found by them. A hashtag page, a suggestion while typing, a trending list or a count only ever includes updates the person looking at it is allowed to see — so a hashtag on an update for your contacts is invisible to everyone else, including in counts.

Suggestions while you type. When you type a hashtag, the app suggests matching ones and shows how many public updates have used each. That count is kept per hashtag, with no names attached, and only public updates add to it. To suggest familiar names (people, places, teams), the letters you have typed after # are sent from our server to Wikipedia — not from your phone, and without your name or account.

Feelings and music. A feeling you add ("feeling blessed") is one of a fixed list and is shown to whoever can see the update. Music is free music from independent artists, licensed so that anyone may use it, and each track is credited on the update. Some tracks are licensed "share-alike" (CC BY-SA): the artist asks that what is made with the track is shared under the same licence. When you search for music, the search words go from our server to Openverse — not from your phone, and without your name or account. Tracks play from Whinchat's own storage: the first time a track is chosen, our server fetches a copy from the site that published it (usually Jamendo), so your phone does not contact that site when you preview or play music.

Shops you follow

If you follow a shop or a category, we keep that choice so we can tell you when something new is listed. It is one message a day at most, never one per item, and it arrives in your chat with the app — with a notification only if you have them switched on and have not silenced that chat.

What you follow is private. A seller is never told who follows them and is never given a follower count, and no one else can see your list. Unfollow from the shop's page, or under Market, and the messages stop.

Large meetings and recordings

Calls and ordinary meetings go directly between the people on them; we do not see or keep them. A large meeting — one a Business host chose to make large, for more people than a direct call can carry — goes through LiveKit's servers instead: they receive everyone's audio and video, encrypted, and forward it to the others. That makes a large meeting not end-to-end encrypted: LiveKit could technically access it. LiveKit does not record it and neither do we. LiveKit also learns each person's username, display name and network address, as any server a call goes through must.

The one thing we do keep is a cloud recording, which the host of a meeting on the Business plan can choose to make. Everyone in the meeting is told while it runs. The host's device records everyone's video and voice and uploads it to us, and we keep it in private, encrypted storage for two days, then delete it. Only the host and the people who were in the meeting can download it. Details are in Recording & Consent.

Going live

Who can watch. When you go live, your contacts and the people who follow your shop can watch, and they are sent a notification (at most once every 10 minutes, however many times you go live). So can anyone you send your live's link to — and anyone they pass it on to, so share it with care. To watch from a link you must be 18 or over: we use the date of birth you gave when you signed up, and only ask an account that has none, once. No one else can find your live, and anyone you have blocked, or who has blocked you, cannot see it at all, even with the link.

How it travels. A live goes through LiveKit's servers, which receive your audio and video, encrypted, and forward them to the people watching. That makes a live not end-to-end encrypted: LiveKit could technically access it. Nothing is recorded, by us or by LiveKit. LiveKit also learns each person's username, display name and network address, as any server a live goes through must.

What we keep. The title, the comments, the number of hearts and who watched, for 30 days after the live ends, then we delete them. We keep them that long so that a report about a live can still be looked into. Comments are shown to everyone watching.

Who you are seen by. Everyone watching a live can see the names of the others watching, and is told when someone joins. If you ask to join the host on stage and the host lets you, your camera and microphone are seen and heard by everyone watching, until you leave the stage or the host takes you off. Guests must be 18 or over. Guests are not in the host's recording.

Comments are checked. Before a comment is shown, it is checked automatically for slurs, threats, sexual harassment and rude emoji, which are refused, and for everyday swearing, which is masked (f•••). A refused comment is not kept — we log only that one was refused, not what it said. Three refusals in one live pause commenting for 10 minutes.

Recording. The host can record their own live, to download and share it. Everyone watching is told while it is being recorded. Only the host is in the recording — their picture and voice, the title and the Whinchat name — never a viewer's name, face or words. It is kept for 2 days for the host to download, then deleted. If our staff stop a live, or it is stopped by a report, its recording is not given to the host: it is held for as long as the law requires such material to be preserved (90 days), then deleted.

Moderation. Our staff can see which lives are running and may watch any of them to check a report, without being shown to the host or the audience. They can stop a live at once. A live reported as child sexual abuse is stopped automatically.

Measuring how the app performs

The app reports how long it took to load, which screens you opened, which named buttons you pressed, and when something took too long or failed. It is counted so we can see what is slow, what is broken, and which parts of the app people never reach.

What it never contains. Nothing you typed or wrote. A button reports the internal name it was given by us, never its contents, never the text of a message, search, listing or profile. No advertising identifier is created and nothing is shared with anyone else — there is no third-party analytics service in this app.

Before you sign in, these reports carry a random identifier that is created for that browser tab and destroyed when you close it. It is not a cookie, it is not kept between visits, and it cannot be used to recognise you on a later visit or anywhere else. Once you are signed in, they are recorded against your account, so that support can see what your app actually did when you ask for help.

How to switch it off. Settings → Privacy → Help improve the app. We also honour Global Privacy Control and Do Not Track automatically: if your browser sends either, nothing is measured and you do not need to change anything here.

How long it is kept. Reports that name you are deleted on the same schedule as the technical log — see Retention. What survives longer is a daily count with no account, identifier or device in it: how many people opened a screen, not which people.

What happens when you sign up

Two things are set up for you the moment your account is created, and you can undo both:

Feedback

What you send from Settings → Rate & review Whinchat is kept with your username, the rating you gave (0 to 5 stars), if you gave one, the kind you picked (a review, an idea, a problem, praise or something else) and the name of the browser you sent it from, so we can tell which device a problem happened on. Only our staff can read it. If we reply, the reply arrives in your chat with the app. It is in your data export, and it is deleted with your account.

Now and then the app asks whether you would like to rate it: at most once a month and four times in all, never in your first few days, and not for six months after you have given a rating. To keep to that, we record when we last asked you and how many times. Answering is optional — "Not now" is always there.

What we do not hold

We do not sell personal data, and we do not use it for advertising profiles. We do not use advertising or tracking cookies. Promoted listings inside the marketplace are sold by placement, not by targeting you.

Phone-number contact matching is opt-in and one-shot: the numbers you choose are hashed for the lookup and are not stored, and someone only appears if they separately chose to be findable by phone.

How well it is protected

Ordinary chats are not end-to-end encrypted, and we can read them. A private chat is, and we cannot. Which one you are in is shown in the conversation itself, and either person can switch a direct chat to private at any time.

A private chat

Open any direct conversation, tap the menu and choose Make this chat private. From that moment the two devices encrypt to each other and we hold only ciphertext: we cannot read it, cannot produce it for anyone who asks, and cannot recover it for you. Our server refuses to accept readable text in a private chat, so it cannot be quietly turned off by a modified app — and if anyone does turn it off, a line saying so appears in the conversation for both of you.

What a private chat does not cover, stated plainly because a padlock invites people to assume more than it means:

An ordinary chat

Your messages are not end-to-end encrypted, and we can read them. Message text is stored on our servers in a form we can open. It is protected by HTTPS in transit and by encrypted storage at rest, and access to production data is limited and logged — but the protection is our word and our controls, not mathematics. Please read that sentence as the plain warning it is: do not put anything in a message here that would harm you if the operator, a member of staff, or anyone who compelled or breached us could read it.

Earlier versions of this policy said the opposite. Until 26 July 2026 direct messages really were end-to-end encrypted, and the messages sent before that date are still stored as ciphertext we cannot read. Encryption was then switched off, because a key that lives on one device silently orphans your own history when that device changes, and people were losing their conversations. This document was not updated at the time. That was our mistake, and this is the correction.

What is encrypted, and what that is worth:

Everything else, you should assume we can see:

Who else processes it

See Subprocessors for the current list, what each one receives, and where it is. In summary: our hosting provider, the payment processor, the push-notification services your own operating system uses, an optional translation service, and an optional AI provider for the listing assistant.

Where it goes

The Service is hosted in the United States. If you are in the European Economic Area or the United Kingdom, using it means your data is transferred there. Transfers rely on the Standard Contractual Clauses where an adequacy decision does not apply; the transfer machinery is described, honestly including what is not yet in place, in Subprocessors.

How long we keep it

See Data Retention. System logs are kept 14 days.

Your rights

You can ask for a copy of your data, correct it, delete it, restrict or object to processing, and withdraw consent where consent is the basis. Export and deletion are both self-service, in Settings → Your data & privacy — you do not have to ask us and wait. Everything else: [not yet published: privacy contact address].

If you are in the EEA or UK you may complain to your national supervisory authority. If you are in California, see US State Privacy Rights.

Children

The Service is not for children below the ages in Child Safety. We do not knowingly collect their data, and we delete an account when we learn it belongs to someone under the age limit.

Changes

Material changes are signalled in the app and the date at the top of this page changes.

What has changed

24 September 2026 · version 23

24 September 2026 · version 22

24 September 2026 · version 21

24 September 2026 · version 20

24 September 2026 · version 19

24 September 2026 · version 18

24 September 2026 · version 17

24 September 2026 · version 16

24 September 2026 · version 15

24 September 2026 · version 14

24 September 2026 · version 13

24 September 2026 · version 12

24 September 2026 · version 11

24 September 2026 · version 10

23 September 2026 · version 9

20 September 2026 · version 8

20 September 2026 · version 7

20 September 2026 · version 6

20 September 2026 · version 5

20 September 2026 · version 4

29 August 2026 · version 3

7 August 2026 · version 2

12 July 2026 · version 1

Whinchat · All documents · Open the app