Legal

Privacy Policy.

What data exists, where it lives, and what Whispyr can and cannot access.

Effective date: 3 October 2026

On this page

Summary

This policy covers the Whispyr app for iPhone, iPad and Mac and the getwhispyr.app website. Your direct chats are end-to-end encrypted with ChaCha20-Poly1305, use per-session X25519 keys for forward secrecy on current app versions, are bound to your long-term Ed25519 identity, and travel directly between devices over Bluetooth, local Wi-Fi or Apple Multipeer Connectivity. They never pass through a Whispyr-operated message relay, so no Whispyr server ever sees your conversations, and your encryption keys stay on your device. Analytics are off unless you opt in. The only other personal data we receive is support correspondence and in-app feedback you choose to send.

1. Our core principle

Whispyr operates no servers that process, store, or relay your messages. All conversation traffic happens directly between devices using Bluetooth Low Energy, Apple’s Multipeer Connectivity framework, and an optional local-network transport that uses your Wi-Fi network when both devices are on it. We cannot read your messages, see who you talk to, or access your conversations. That data never reaches us.

Whispyr does operate a website and a small opt-in analytics endpoint described in sections 4 and 9. Neither receives any message content, attachment content, profile data, contact data, or location data.

Android (not yet publicly available). This policy describes Whispyr for iPhone, iPad and Mac. If and when an Android version becomes available, Android devices will connect to each other using Google’s Nearby Connections framework (Bluetooth and peer-to-peer Wi-Fi) and to iPhones over Bluetooth Low Energy or the local-network transport, and the Android app will store its encryption keys and analytics install ID in EncryptedSharedPreferences, encrypted with a master key held in the Android Keystore. We will update this policy to describe any other Android-specific processing before the Android version is publicly released.

2. Data that stays on your device

The following data is created and stored on your device, not on any Whispyr server. Whispyr Limited has no access to it. Some of it is shared with other devices by design: your profile with nearby users (section 6) and your messages with their recipients.

  • Profile information: your display name, handle, profile photo and any bio you add. Nearby Whispyr users can see this information according to your Visibility setting
  • Messages and media: all text, photos, voice messages, videos, files, location shares, and contact-card attachments
  • Encryption keys: your long-term Ed25519 signing key and X25519 identity key, stored in the Keychain on your iPhone, iPad or Mac as device-only items that are never synced to iCloud Keychain. Per-session ephemeral keys are held only in memory and are never written to disk
  • Contacts and chat history: the list of people you’ve connected with inside Whispyr (independent of your phone’s address book) and your conversation history
  • Spaces data: any Spaces you create or join, including group chat messages, event records, and poll responses
  • Stories: stories you create or receive from nearby users
  • App settings: your preferences, wallpaper choices, notification settings, and blocked users

This data is not synced to any cloud service operated by Whispyr. Photos, voice messages and files you send or receive are stored in the app’s documents folder and can be included in your own iCloud or computer backup of the device. Uninstalling the app removes your message database, chat history, and app settings stored in the app sandbox. Identity keys held in the Keychain can persist after uninstall; you can clear them explicitly from inside the app before uninstalling via Settings → Clear All Data.

3. Data you choose to provide

We only receive personal information when you actively send it to us:

  • Support requests: if you email support@getwhispyr.app, we receive your email address and message content
  • Feedback: if you use the in-app feedback feature, we receive the text you submit

We use this information solely to respond to your request. We do not add it to marketing lists or share it with third parties.

4. Opt-in analytics

If you opt in, Whispyr sends small analytics events, to monitor stability and feature usage, to a database we operate on Cloudflare D1. This data is pseudonymous: it is keyed to a random install ID that we cannot link to you. Each event contains that install ID, a random per-record ID, an event name from a fixed list defined in the app source code (such as app_open, message_sent, space_joined), a timestamp, and the app version and build number. It never contains message content, attachment content, contact handles, chat or space identifiers, or location. The install ID is generated on your device, stored in the Keychain, not derived from any device hardware or account identifier, and reset if you reinstall the app.

Analytics are off by default and only start if you opt in. You can turn them on or off at any time in Profile → Advanced options → Diagnostics → Anonymous Analytics. Turning them off immediately stops the network path, clears any queued events, and survives app restart. If you have opted in, crash reports additionally carry a sanitised stack trace together with your iOS version, device model and region setting. Legal basis: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time with the same switch. The data we receive is engineered so it cannot identify you on its own.

5. Encryption and security

Direct chats in Whispyr are end-to-end encrypted. Emergency broadcasts are deliberately unencrypted, and Spaces between iPhones rely on Apple’s Multipeer Connectivity encryption (see Security and cryptography). The protocol stack for direct chats is:

  • Forward-secret session keys: a fresh X25519 key pair is generated for every session when both devices run a current version of Whispyr. Compromise of a long-term identity key cannot retroactively decrypt those sessions.
  • X25519: ECDH key agreement between per-session ephemeral keys
  • Ed25519: digital signatures bind each session’s ephemeral key to the contact’s identity key, which is pinned the first time you talk (trust on first use); comparing safety numbers in person confirms that no one is in the middle
  • HKDF-SHA256: derives the AEAD key from the ECDH output, with a fixed salt and both handles as context, so both peers compute byte-identical keys
  • ChaCha20-Poly1305: authenticated encryption with associated data (AAD). The AAD binds the sender handle and frame type, defeating cross-channel replay and ciphertext-swap attacks
  • BLE transport layer: additionally wraps every frame with its own per-link AES-256-GCM envelope using deterministic counter nonces, providing an independent second layer of confidentiality for Bluetooth traffic
  • Replay protection: replayed frames are rejected by per-direction counters on Bluetooth and local-network links and de-duplicated by message ID on all transports; handshakes carry a timestamp checked against a ±10-minute window

Encryption keys are generated on your device and never leave it. There is no key escrow, no recovery mechanism controlled by Whispyr, and no way for us to decrypt your messages, even under court order. For full technical details, see our Security and cryptography page.

6. Bluetooth, local networking, and sensors

Whispyr uses three local-network mechanisms to discover and communicate with nearby devices:

  • Apple Multipeer Connectivity: Bluetooth + peer-to-peer Wi-Fi
  • Bluetooth Low Energy: a GATT service published by every Whispyr device, identified by a fixed service UUID
  • Local-network mDNS (optional): devices on the same Wi-Fi network can also discover each other directly, skipping Bluetooth

These mechanisms require Bluetooth and local-network permissions. When Radar is active, your device makes itself discoverable to nearby Whispyr devices and shares your display name, handle and profile photo with them, according to your Visibility setting. Discovery is local-only: it does not travel over the internet, does not reach Whispyr Limited, and does not reach any third party.

Bump to Connect uses your device’s motion sensor solely to detect the physical bump gesture. Motion readings are processed in memory on your device, are never stored, and are never transmitted. When a bump is detected, the app broadcasts a short bump announcement (a timestamp and your handle) over the local transports above so the two bumped devices can find each other. The sensor is only active while the Bump screen is open.

The Visibility setting (Public / Private / Hidden) controls how your handle appears to peers, for example whether you surface in their Radar list and how prominently you are presented. It is a peer-cooperative, in-app setting; it does not guarantee that no signal at all is observable at the radio layer. If you want full radio silence, quit the app and disable Bluetooth and Wi-Fi at the operating-system level.

Map and link previews. When you view a shared location while online, your device requests a map image for those coordinates from Apple Maps. If you turn on link previews, your device fetches the linked page. These requests go directly from your device to Apple or to the linked website; Whispyr Limited does not receive them.

7. Photo metadata

When you send a photo through Whispyr, the image is re-encoded as JPEG on your device before it leaves. On iPhone, iPad and Mac, the EXIF, GPS, TIFF, and IPTC metadata blocks are explicitly written as empty during this re-encode, so embedded data such as GPS coordinates, camera model, and original timestamps is removed before the bytes are transmitted. The recipient receives the pixel content without the original metadata block.

8. Backups

Whispyr offers an optional local backup feature that exports your profile and chat history to an encrypted file. Backups do not contain your encryption keys; a restored device generates new keys. Backups are initiated by you, encrypted with a passphrase you choose, and saved to a location you select (for example Files or iCloud Drive, or any other destination your device offers).

Backup files do not pass through any Whispyr server. Whispyr Limited does not have access to your backups or your passphrase. If you lose your passphrase, we cannot recover your backup. You are responsible for storing backup files and passphrases securely.

Separately from Whispyr backups, your device’s own iCloud or computer backup can include photos, voice messages and files stored by Whispyr (see section 2).

9. Website data

getwhispyr.app is a static website hosted on Cloudflare Pages. It sets no cookies, loads no third-party resources, and uses no analytics, advertising or tracking.

When you visit the site, Cloudflare processes standard technical information such as your IP address, browser user agent and the time of the request, in order to deliver the site and protect it from abuse. Whispyr Limited does not store this information. Cloudflare’s documented default retention for HTTP access logs is approximately 72 hours (see section 13).

10. What we do not do

  • We do not store, process, or relay your messages on any server
  • We do not collect your phone number, email address, or real name through the app
  • We never read, import or upload your phone’s address book. If you save a contact card someone shared with you, iOS asks for permission to add it
  • We do not build profiles of your contacts or social graph
  • We do not serve advertisements or sell data to third parties
  • We do not use tracking pixels, fingerprinting, or cross-app tracking
  • We do not have a “backdoor” or law-enforcement access mechanism for message content
  • We do not share data with data brokers, advertisers, or analytics companies
  • We do not include message content, contact handles, chat or space identifiers, or precise location in our analytics

11. Children’s privacy

You must be at least 13, or the age of digital consent in your country if higher. Whispyr is not directed at children below that age. We do not knowingly collect personal information from such children. If you believe a child has provided us with personal information through a support request, please contact us and we will delete it promptly.

12. Your rights

Depending on your location, you may have the following rights under the GDPR, the UK GDPR, or analogous legislation:

  • Access: request a copy of any personal data we hold (limited to support correspondence, in-app feedback and analytics rows associated with your install ID)
  • Correction: request correction of inaccurate data
  • Deletion: request deletion of your support correspondence, in-app feedback or analytics rows
  • Data portability: receive your data in a structured format
  • Objection / withdrawal of consent: object to processing; for analytics, this is a single toggle inside Profile → Advanced options → Diagnostics → Anonymous Analytics
  • Complaint: lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office)

For on-device data, you have full control at all times. You can delete all app data instantly through Settings → Clear All Data. Deleting the app removes most data but can leave your identity keys in the iOS Keychain (see section 2). We cannot fulfil access or deletion requests for on-device data because we do not hold it.

To exercise any rights related to support correspondence, in-app feedback or analytics, contact support@getwhispyr.app.

13. Data retention

  • On-device data: retained until you delete it; identity keys can persist after uninstall until you use Clear All Data
  • Support correspondence and in-app feedback: retained for up to 12 months after resolution, then deleted
  • Analytics (if you opted in): we minimise retention. We do not retain raw analytics events indefinitely, and we may shorten retention windows as we refine our analytics pipeline. Material changes to retention are reflected in this policy
  • Website / CDN logs: set by Cloudflare; their documented default HTTP-access-log retention is approximately 72 hours

14. International transfers

Whispyr Limited is incorporated in England. If you contact us for support from outside the UK, your correspondence may be processed in the UK.

If you opt in to analytics, the events are processed by Cloudflare, Inc. on infrastructure that may be located in the United States or the European Union depending on the routing decision Cloudflare’s edge network makes at request time. The legal basis for this processing is your consent (Article 6(1)(a) GDPR), given when you opt in. Where required for transfers outside the UK or EEA, transfers rely on the Standard Contractual Clauses and, where applicable, on Cloudflare’s published participation in successor frameworks such as the EU-US Data Privacy Framework and the UK Extension; see cloudflare.com/trust-hub/gdpr for Cloudflare’s current status. Application-layer chat traffic is peer-to-peer and does not cross our infrastructure.

15. Changes to this policy

We may update this policy to reflect changes in the app or in applicable law. Material changes will be communicated through the app or our website. The effective date at the top reflects the most recent revision.

16. Contact

For privacy questions, data requests, or concerns, contact us at: