Privacy Policy
Last updated: 15 August 2026
Whisprompt is built privacy-first. This policy explains what we do and, just as importantly, what we do not collect. It covers every Whisprompt app — on phone, tablet, watch, television and Mac — and this website. Where something applies to only one of them, it says so.
The short version: Your scripts stay on your devices and never reach us; nothing sends one anywhere else unless you connect a service yourself (section 3). Speech recognition is done by your phone’s own engine, which may send audio to Apple or Google to do it — install an offline language pack and it never leaves the device. Either way it never reaches us. No account is required, and we do not sell your data. The app can measure how well it performs — counts and timings, never a word of what you write or say — but only if you say yes: nothing is measured until you do, the question comes only after you have used the app, and your answer covers the devices you link as your own (section 6).
1. Who is responsible (Data Controller)
Leonid Kabanov (autónomo), Spain. Contact: support@whisprompt.app. Full identification details are in the Imprint. We are established in Spain, and therefore inside the European Union, so Article 27 GDPR — which requires a representative in the Union — does not apply to us. We have appointed no Data Protection Officer and are not obliged to: Whisprompt is not a public body, it does not monitor people regularly and systematically on a large scale, and no special category of data reaches us at all. The supervisory authority for our establishment is the Agencia Española de Protección de Datos (AEPD), aepd.es.
2. Data processed on your device
- Microphone audio. Captured live for voice tracking and (when you record) for video. It is handed to the speech-recognition engine built into your phone — Apple’s on iOS, Google’s on Android — which, depending on the device, the language and your settings, may process it on that platform’s servers under that platform’s own privacy terms. Install an offline language pack and recognition happens entirely on the device, with no network involved. In both cases the audio never reaches us: we operate no speech servers and store no recordings, apart from video files you choose to save, which remain on your device or in your own cloud storage.
- Your scripts and settings. Stored locally on your device (and, if you enable it, in your personal cloud storage, governed by that provider’s privacy terms). If you cast the prompter to your other devices, the text travels between them encrypted — see section 5.
- Downloaded language models. Stored on your device. Downloading a model is a direct request to the model host; we do not attach an identity to it.
3. Data processed by services you connect
Some optional features connect to services you authorise. We act only as your client; each provider is an independent controller under its own policy:
- Notion and documents you open. If you connect Notion, Whisprompt reads the pages you select as a read-only mirror, using the access you grant. If you open a file from your device or a cloud service, it is read to display the script. Copies of these credentials do not reach any server of ours.
- The AI assistant in the Mac operator station. The assistant does nothing until you give it a key of your own for an AI provider. Once you have, each request carries the whole of the open script, the fragment you have selected, your instruction and the conversation so far — straight from your Mac to that provider, Anthropic or OpenAI depending on the key, under your key and your own account with them, on their terms and their retention. It passes through no server of ours: we see neither the key nor the text. The key is kept in the macOS Keychain, is not synced, and is not carried to your other devices. The phone and tablet apps have no assistant.
- Apple & Google (app stores & subscriptions). Purchases, any free trial and subscription billing are handled by Apple or Google. We never see your payment details; all we receive is subscription status — section 4 explains exactly how.
4. Subscription and Pro
Whisprompt has no accounts. There is nothing to sign in to and nothing to create, no provider is ever asked for your email address, and we hold neither a name nor an address for you. The prompter, recording and casting work as they are, and a subscription is bought and restored without an account. The app does still contain the code for an optional account — Sign in with Apple, with Supabase as the processor — and it is inert: it is switched on by keys the app is not built with, so there is no sign-in screen, nothing reaches Supabase, and no email address is collected. Should an account be introduced, this page will describe what it processes before the release that brings it, not after.
- RevenueCat (subscription management). Our processor for determining whether a subscription is active, whether you bought it in the App Store or on Google Play. It receives your purchase history in this app, an identifier for the customer, and the device or installation identifier the operating system issues to the app (on Apple devices, the IDFV), along with technical details about the device and OS version. The customer identifier is not derived from anything about you: before your first purchase it is one RevenueCat generates for itself, and from that purchase onwards it is a random one your device generates and keeps — the same one your other devices carry, which is how a single subscription covers them all (section 5). This is what unlocks Pro and restores your purchase across your devices. We collect no advertising identifiers and enable no advertising or attribution integrations in RevenueCat; this data is not used for tracking and is not combined with data from other companies.
- Deleting what we hold. There is no account to delete, and the app has no button for one. What we hold on a server of ours is the list of devices your subscription covers, and you can delete it in the app at any time, under Settings → Data on our servers (section 11). Deleting it does not cancel your subscription: that belongs to your App Store or Google Play account and is cancelled where you bought it. Scripts and recordings stay on your device either way; to clear a device itself, see section 7.
5. Casting to your other devices
Whisprompt can run the prompter across several of your own devices at once. On the same local network they connect directly. With no shared network, the connection goes through our relay on Cloudflare Workers:
- Sharing a library between your own devices. Devices you link as your own mirror each other's libraries: a script written on one appears on the others, and an edit made on one reaches them. The copies live on your devices and travel between them the same encrypted way as everything else here — no server of ours holds a copy, and nobody outside your own devices receives one unless you share a script deliberately.
- Every session frame is encrypted on the sending device (AES-GCM), and the key travels only inside the invitation — a QR code or join code. The relay sees encrypted frames only: it cannot read your text, audio or video.
- The relay stores no session content. A room lives at most four hours and is then deleted. The mailbox your devices use to find each other holds only a service key and a last-seen timestamp — for no longer than 30 days, and with no content whatsoever.
- If you use Pro on more than one device, the relay also keeps the list of those devices, so that one subscription can cover up to six of them. It holds an identifier the app generates per device, the name that device reports for itself, and the dates it was added and last seen — no scripts, audio or video. The whole record is deleted after a year in which none of your devices has used it, and you can delete it yourself at any time from the app.
- Like any web service, the relay sees an IP address on connection. It is used in passing, to rate-limit requests and prevent abuse, and is not linked to your subscription or to the list of devices it covers.
6. Usage data
Whisprompt can measure how well it performs and send us those measurements — counts, durations and codes, never a word of what you write or say. None of it happens unless you say yes. Until you do there is no measuring, no identifier, and nothing stored on your device for it. The app asks once, and never at the moment you first open it, because a question put before the app has done anything is a question you have no way to answer. It comes after your first read has got somewhere — or, if you link a second device before that happens, at the end of the linking, on one card alongside the question below about counting your devices. That card has two answers and no third way out: it does not close if you tap beside it or press back, because a card closed by a stray tap would have recorded a refusal you never gave. Nothing is written unless you answer it, so if something else takes it off the screen first — the app closes, another screen replaces it — the question is simply still open, and comes back after your next read. Once you have answered, either way, it does not come back at all. Your answer covers the devices you link as your own, and the card says so where you give it: a device you link later takes that answer the next time it connects and tells you plainly that it has, rather than putting the same question a second time. It works in both directions — turn the measuring off on one of your devices and the others stop too. An answer given on a device is never overwritten by one arriving from another, so switching it off here cannot be undone by a device that has not heard yet. Say no and nothing else about the app changes, and that device does not ask again. Say yes and the switch is in the app’s settings, under “Usage data”, so you can turn it back off at any moment without giving a reason. What this rests on legally is in section 9; the ways to withdraw are at the end of this section. Turning it off stops the measuring itself, not just the reporting, and deletes from the device the identifier below, anything that was still waiting to be sent, and the note about a read in progress described under “What is measured”.
- What is measured. Counts, durations and codes — and what follows is all of them, not a selection. For a read: whether it ran on voice tracking or auto-scroll, how long it lasted, how many words the script had, how far through it you got as a percentage, how many times you had to take the text over by hand, the language code, which speech engine was running, whether the device was offline, whether the read was being shown on a second screen at the same time, how much audible input the check for a broken recogniser below managed to take in — one of four brackets (none at all, under ten seconds, under a minute, a minute or more), never a number of seconds, and only when speech recognition was running at all: it is that check’s own running total and not a measurement of how long you spoke, because sound quieter than the level it listens for adds nothing to it, each loudness reading the engine sends adds at most half a second, and the first reading after every start adds nothing at all — so on an engine that reports its level once a second it comes to a fraction of the time you were actually talking; what it tells us is whether that check could have worked on your device, and it says nothing about what was said, and how it ended: that nothing went wrong, that the read never got anywhere at all, or that the speech recognition broke — and if it broke, in which of the four ways below. If a read never gets an ending — the system closes the app while it is in the background, the battery runs out, the app fails, or you swipe it away mid-read — none of that can be measured, because the part of the app that would have measured it is gone with the rest. So while a read is running, a short note is kept on your device saying what was known when it began, and nothing more: voice tracking or auto-scroll, the language code, how many words the script had, and which speech engine was running. The note is removed the moment the read ends normally. If the app finds one still there the next time it starts, it sends those four facts, deletes the note, and never sends them again — one interrupted read is reported once. Nothing else about such a read is reported: not how long it lasted, not how far through it you got, not how it ended, because nothing was left to measure any of it. The note is written only while the measuring is switched on, holds nothing beyond those four facts, and is deleted with everything else when you switch it off. When the voice tracking loses you: the language code, the engine, whether it caught up again at all, and how long that took when it did. When the speech recognition itself breaks: the language code, the engine, how many seconds that engine had been running, whether it had been started by the script changing language part-way through rather than by you pressing play, and which of four things happened — it went on hearing sound and stopped returning any words, it stopped saying anything at all so that even the microphone reading went away, it failed and another engine took over, or it failed with nothing left to take over. Once per installation: whether your first read got past the halfway mark within an hour of installing, within a day, a week, a month, or later than that — a bracket, not a time. For a language-model download: the language code, the size in bytes, and whether it started, finished or failed. For a connection to another device: how it ended and how the two devices found each other. For a cast: what kind of screen it went to (phone, tablet, desktop, TV, watch, or a kind the app did not recognise), how long it lasted, and whether it ended because the connection dropped. For the subscription screen: which of the locked features you were standing at when it appeared, or that you opened it from Settings yourself rather than being stopped by anything. For an attempt to buy: which of four kinds of plan it was — monthly, yearly, lifetime, or one whose period the app did not recognise — and whether it completed, was cancelled by you, was left pending by the store, was unavailable, or failed. For a restore: whether something was restored, whether there was nothing to restore, or whether it was cancelled or failed. Two facts about the subscription are also kept beside the identifier below and updated when they change: whether Whisprompt Pro is currently active on this device, and whether it was bought here rather than on another of your devices. Alongside all of them: the moment it happened, the app version, the platform, and how long this installation has been measuring — a bracket, never a date and never a number of days: the first day, the first week, the first month, one to three months, three to six, six to twelve, one to two years, or longer. That bracket is counted from the day you allowed the measuring, because nothing is stored for this before then, and unlike the first-read bracket above it travels with every measurement rather than once. And, about the device the measurement was taken on: what kind of device it is — phone, tablet, computer, TV or watch, and nothing more specific than that — which operating system it runs, that system’s major version number and only that (“18”, never “18.3.1”), the language the app’s own interface is in, and the country your device is set to. Two of those are worth being precise about. The country is read from your device’s own region setting: it is the country you chose in your settings, not one worked out from the network address you happen to be connected through — see “Who processes it” below. And the version is the major number alone, because that is what tells us whether an old system can be dropped; the rest of it would say more about your particular device than about the system.
- What is never measured. Your scripts, their titles, the names of files you open, audio, recordings, transcripts, the names of your devices, your contacts. A language code travels; a script title does not. Of the subscription measurements above: no price, no currency, no receipt, no order or transaction number, no store product identifier, no payment detail of any kind, and no error text from the store — what travels is which of eight named features opened the screen, which of four kinds of plan, and which of a fixed set of outcomes. Not how many devices you use your subscription on, either. Every measurement is a fixed set of numbers, timings and codes, so there is nowhere for anything you wrote, named or paid for to appear.
- It is not anonymous, and we would rather say so. The measurements from this device carry one lasting random identifier. It belongs to this installation of the app and to nothing else: it is created by the measuring component itself, on the day you allow the measuring and not a moment before, it is used for nothing but these measurements, and it is not the identifier your subscription uses — that one is never sent with a measurement, so the two records are kept apart and neither carries the other’s identifier. Nothing in a measurement says which of your devices belongs with which: unless you grant the separate permission below, your phone and your tablet arrive as two unconnected installations and are counted as two. The identifier is replaced at most thirteen months after it was created, whether or not you have been using the app in the meantime, and the replacement does not join up with the one before it — so the record of an installation cannot grow longer than that. Turning measurement off deletes the identifier from the device. Random as it is, it is still an identifier, which is why this paragraph exists rather than a claim that the measurements are anonymous.
- Counting your devices as one person — a separate permission, off unless you grant it. If you use Whisprompt on more than one device, the app can ask you once whether the measurements from all of them should carry one shared identifier, so that a phone and a tablet count as one person rather than two. That question changes only the identifier, and nothing about what is measured: the same list above, the same properties, no extra event and no new recipient. It is off unless you say yes, saying no changes nothing else about the app, and you can turn it on or off later in the same settings section. Like the measuring above, this is asked once rather than on every device: say yes and the other devices on your subscription take that answer the next time they are connected — the shared identifier reaches them over the same encrypted channel your devices already use with each other, and nothing else about measurement travels with it. It reaches only a device where you have allowed the measuring, since on any other there is nothing for it to count. A no is not carried anywhere, so a device you link later may put the counting question itself; refusing again costs one tap and is remembered. That card, too, has two answers and no third way out, and nothing is recorded unless you give one. When you turn it on it applies from that moment forward — measurements already collected are not re-labelled, and the identifier this installation used before is not sent or linked to the shared one. One case is worth naming apart from that. If this installation is already carrying a shared identifier and then takes on a different one — which is what happens when you link it to devices that already share an identifier of their own — the next measurement carries the previous shared identifier once, so that the records of one person are not read as two: one who stops existing and one who appears from nowhere. Only a shared identifier ever travels that way; the per-installation identifier above is never sent in that field, at any transition. When you turn it off, this installation goes back to an identifier of its own, and it is a new one rather than the one it had before. It cannot be on while the measuring is off, because there would be nothing to count: if you switch the measuring off, the shared identifier is deleted from the device along with the other one. And if you link a second device before the measuring question has been put to you at all, the app may put the two together — once in the life of the app, on one card that says what both of them are. That card is the one asking about measuring, not an extra one: on that device, neither question is put again. A yes there is a yes to both, because both were named on it; a no refuses both. Your devices link either way, and neither answer is ever taken as the other.
- Who processes it. Amplitude, our processor, on its European endpoint. Each request asks Amplitude to derive nothing from the address it arrives from, so no city, region or location of any kind is worked out from where you connected. The country in the list above is not an exception to that: it is the one set on your device, sent because we put it there, and it would be the same country whichever network you were on.
- How to withdraw, and what happens then. Two ways, and either is enough. In the app: Settings → Usage data → turn the switch off. Or write to support@whisprompt.app and say so, and we will stop. Withdrawing takes no more taps than agreeing did, you do not have to give a reason, and we do not ask for one. Switching it off is treated as your objection and not as one handset’s setting: your other linked devices are told, over the encrypted channel they already share with this one, and stop measuring as well the next time they are connected — one that is asleep is told when it comes back, because the notice is repeated until it lands. Switching it back on does not travel as far: it reaches a device you have linked but have never been asked on, which takes the answer and tells you it has, and it never displaces an answer a device has given for itself — so a device you switched off here stays off until you switch it on there. The asymmetry is deliberate. An objection to being measured is made by a person and we would rather it reached too far than not far enough; a permission should not be able to overrule an answer somebody already gave on the device in their hands. Your answer is remembered on the device across restarts and app updates, and it survives the thirteen-month replacement of the identifier — a new identifier does not restart the measuring for somebody who has switched it off. If you want the measurements already sent deleted as well, ask us: section 11.
6a. Crash reports — a separate permission, off unless you grant it
If the app stops working, it can send us a report about the failure. This is not part of the measurement in section 6: it is a different purpose, with a different recipient, and it has its own switch. It is put on a card of its own, just before the measuring question, and answered separately — a yes to one is not a yes to the other, in either direction. That card works the way the measuring one does: two answers, no third way out, and nothing recorded unless you give one.
It is off unless you turn it on. Until you do, nothing is installed for it and nothing is sent — that rule has no exceptions at all. What does have exceptions is storage, and there are two of them below. Both exist to put you the question rather than to collect anything, both are about a crash that has already happened to you, and neither sends a thing until you answer.
The first is a failure to start. If Whisprompt cannot start at all, there is no later moment at which to put the question, so the error screen puts it there. If you have already turned crash reports on, one report about that failure is sent and the screen tells you it was. If you have already turned them off, nothing is offered and nothing is sent. If you have never been asked, the screen asks — send this one report, don’t send it, or send them from now on — and nothing leaves the device until you choose. A report sent this way is smaller than the one described below: it carries no identifier of any kind, and it says where the app stopped, the app version, and which operating system this is — nothing further about the device, no interface language, and none of the steps that came before. It goes to Sentry, the same processor and the same European servers, and what is said below about the internet address a report arrives from applies to it as well. Choosing to send them from now on is the same answer as the switch in Settings, and it is turned off in the same place. The same screen, with the same three answers, also appears when a single part of the app fails while it is running rather than at startup. This is the phone and tablet app only: the Mac and television apps have no such screen.
The second is a crash we could not ask you about at the time — because the app was gone before you could answer, or because you closed it instead of answering. If you have never been asked, one report about it is kept on your device, and the next time the app starts properly it says so at the bottom of the screen and offers you the question. It is a single report and not a queue; a second crash does not replace it. Nothing about it is sent unless you say yes there. It is deleted when you answer either way, when you tell that notice to delete it, when crash reports are switched off, and in any case seven days after it was kept. That file is the only thing stored on your device for crash reporting before you have agreed to anything, and we would rather name it than let the paragraph above imply there is nothing there: it exists so the question can be put at all. The crashes it recovers are the ones we would otherwise never see — the first launches of a brand new installation, which are the worst crashes there are and belonged to exactly the people the question had never reached. What it does not recover is a crash the operating system handles itself, below the app: those still need the reporting to have been switched on beforehand.
- What a report contains. Where the app stopped — the technical trace of the failure — the kind of device, the operating system and its version, the app version, the interface language, and a short list of what the app was doing beforehand: screens opened, low-memory warnings, the app going to the background.
- And, when the failure was in the prompter, what the prompter was doing. A recogniser that stops working does so at the end of a chain of events, and one line saying it stopped is not enough to fix it — so a report about a reading session carries a short timeline of that session: the speech engine starting and stopping and why, the language of the paragraph you had reached, crossings from one language to another and whether they succeeded, whether the recognition was running on the device or through the platform’s servers, how long it took to return its first words, when the voice tracking lost your place and when it found it again, the screen moving between waiting, listening, paused and stopped, how far a language model had downloaded if one was downloading, and the moment the failure was declared. It also carries the SHAPE of what you were reading and where in it you were — how many words and paragraphs the script had, how many languages it mixed, which word number you had reached, and the moments you took the text over by hand with a rewind or a drag. Those are what make the rest of the timeline mean anything: a position with no length to measure it against says nothing, and a jump the recogniser did not cause reads as a fault unless the page says a hand made it. Each line is a count, a code, a language code or a duration. One further number rides beside them: how much memory the app itself was using at that moment, in whole megabytes — it is a plausible cause of the failure and there is no other way to see it, and it says nothing about you or about what else is on your device. Not a word of the script, ever — not its title, not a line of it, not what the recogniser thought it heard, and no name of yours or of your devices. The times in it are stated as gaps — “four seconds before the failure” — rather than as clock times, because a clock time carries a time zone and a time zone is a coarse location.
- What is removed before it is sent. A crash report is assembled by the reporting component and not written by us, so we take it apart and strip it: file names and paths, web addresses beyond the name of the service, email addresses, network addresses, the name of your device and your time zone. No screenshot and no copy of the screen is ever attached — your script is what is on that screen — and no report carries any identifier of yours that we hold. What is left is a stack trace, the kind of failure, and the kind of device.
- The one thing our app cannot strip. Sentry works out an approximate location — country and city — from the internet address a report arrives from. It happens on their side, after everything our app can edit, so unlike the measurement above there is no per-report way for us to switch it off. Two settings on the project answer for it: one stops the address itself being stored, and one removes the location worked out from it. The first is set. Where the second is not, the country and the city stay with the report for as long as the report is kept, which is at most 90 days. We are naming it here rather than letting the sentence above imply we had removed something we had not.
- The identifier. Reports from one installation carry a random identifier the reporting component makes for itself, so that ten crashes from one device can be recognised as one device rather than ten. It is not the identifier the measurements use, and not the one your subscription uses.
- Who processes it. Sentry, our processor, on its European servers.
- How to withdraw, and what happens then. Settings → Crash reports → turn the switch off. Reporting stops, and what is still waiting to be sent is deleted from the device. Your answer to this question travels the way your answer about measuring does: a device you link that has never been asked takes the answer you already gave and tells you it has, a device that has answered for itself keeps its own answer, and switching reporting off reaches your linked devices even where they have already answered. What this rests on legally, and what withdrawing does and does not undo, is in section 9.
We do not put a processor’s key into a release before that processor’s data processing agreement is in force. What Sentry holds besides the reports people send us are the test reports we sent ourselves from a developer machine, to check that names, paths and addresses really are stripped out. Those are ours, not yours, and we delete them.
6b. What you send us yourself
The app has a “Send feedback” screen. Nothing on it reaches us until you tap send, and what reaches us then is what you wrote plus whichever of the optional things you chose to add. It is not a measurement and it is not a crash report: you write it, you decide what goes with it, and it is used for answering you and for fixing what you told us about.
What always goes with a message, because a report we cannot place is a report we cannot act on: the app’s version and build number, the operating system and its version, the model of the device, and the language it is set to. The screen lists exactly these before you send, in the same words as here, so you know what you are sending as you write it.
What goes only if you add it. Files — up to three, screenshots or a short screen recording, picked by you from your own library; we receive what you attach and nothing you did not. An address to reply to, if you want an answer; without one we still read every word, and we then have no way of knowing who wrote it. And the measurement identifier from section 6, behind a switch that appears only when there is one to attach: it is what lets us look at how the app was behaving before you wrote.
The one thing we work out ourselves is whether the message came from a subscriber, so that it can be answered first. Your device sends the random subscription identifier of section 4, our server asks RevenueCat whether it is entitled, and writes down that answer — yes or no — and never the identifier itself. So nothing joins what you said to what you bought.
Messages are held for us by Cloudflare on servers in Western Europe: the text in a database, the files in object storage, both under the reference code the app shows you once it has sent. They are kept for two years and deleted automatically then, and sooner if you ask — quote that code, or tell us anything else that lets us find the message. No one but us reads them, and they are used for nothing else: not for measuring, not for profiling, not for deciding anything about you.
One thing to know before you attach a picture: a screenshot holds whatever was on the screen when you took it, which may include a script you were reading. Attach only what you would want us to hold, and we will delete what we do not need.
7. Erasing a device before it leaves your hands
The app’s settings hold an “Erase this device” button, under “Usage data”. It is the right thing to press before you sell, return, trade in or hand on a device, and the Terms ask you to.
It removes from that device: your scripts, your recordings, the voice models you downloaded, the connections you granted to services such as Notion, the measurement identifier, and every privacy answer you gave on it. It also takes the device out of your linked devices, so it stops mirroring your library and stops sharing your subscription. Your other devices keep everything.
Your subscription is not affected. It belongs to your App Store or Google Play account and restores on your next device.
Two limits, stated plainly. If the device is offline when you erase it, the local wipe still completes but your other devices are not told; the app says so, and you can remove it from the device list on any of them. And measurements already sent before the erase are not recalled by it — for those, use the deletion request in section 11.
8. What we do NOT collect
- No advertising identifiers and no third-party ad SDKs.
- No analytics or tracking on this website. In the app, nothing at all unless you have agreed to it, and then the measurement described in section 6 and nothing besides it: no advertising, no profiling, and no tracking of you across other companies’ apps or sites.
- No crash reporting unless you switch it on yourself, and nothing in a report that identifies you — see section 6a.
- No selling or sharing of personal data within the meaning of the GDPR.
This website sets no cookies. It keeps two preferences in your browser: the theme, which you set with the sun-and-moon button in the header, and the language, so that whisprompt.app opens next time in the language you were last reading. Both are readable only by this site, neither identifies you, neither is sent to us or to anyone else, and clearing this site’s data in your browser removes them. The site is served by Cloudflare, which sees the address you connect from, as any web server does, and derives from it only the country used to show the price for your store.
9. Legal bases (GDPR Art. 6)
Processing your audio and scripts to run the prompter is performed to provide the functionality you request (Art. 6(1)(b), performance of a contract / your request). Optional connected sources, subscription entitlements and purchase restoration rest on the same basis. Protecting the relay from abuse rests on our legitimate interest (Art. 6(1)(f)).
Everything in section 6 rests on your consent (Art. 6(1)(a)): the measuring itself, and counting your devices as one person under a shared identifier. The crash reports in section 6a rest on your consent too — a third permission, part of neither of the others: a crash reporter stores things on your device and is not needed to run a teleprompter, so there is nothing to rest it on but your yes. All three are asked separately and withdrawn separately, at any time; withdrawing is as easy as agreeing was, and costs no more taps. Withdrawing takes effect from that moment: it does not make what we did while your consent stood unlawful, and it does not on its own delete what was already sent — for that, ask us, and section 11 says how. The measuring and the crash reports are answered for a person rather than for a handset: the answer you give fills in on a device you link that has not been asked yet — which tells you it has taken it — and it never displaces an answer already given on a device. The counting is asked once for a related reason, because it is a fact about a set of devices rather than about any one of them, and a yes to it is carried to the others on the same subscription. A withdrawal travels further than any of them: it reaches your devices even where they have already answered, because an objection is made by a person, and between reaching one device too many and leaving one measuring against their wishes, we take the first. We ask rather than assume, and the reason is worth stating plainly: measuring an app by storing an identifier on your device could only be done without asking if our measurement provider agreed in writing never to reuse the data for its own ends, and made it impossible to look at a single person inside its own tool. We have not asked it for either, so we ask you instead.
What we do with the measurements is worth naming rather than describing in the abstract: Whisprompt follows your voice through a script in ten languages, the quality of that following differs from language to language, and the only way we learn that a language is being tracked badly is to count how often people had to take the text over by hand — per language, across enough installations for the number to mean anything. The measurements about the subscription screen answer a smaller question: which locked feature people are actually stopped by. Either way the measurements carry nothing you wrote or said, the address they arrive from is not turned into a location, the identifier is replaced after thirteen months, and nothing is combined with data from anywhere else or used to make decisions about you.
Nothing here is required of you. No law obliges you to give us any of it, and nothing we sell is conditional on it: the app installs, the prompter runs, and a subscription is bought and restored without an account. One feature depends on one permission — following your voice cannot work without the microphone — and refusing it leaves the prompter scrolling on its own, which is a mode in its own right rather than a fallback. The measurements in section 6 and the crash reports in section 6a are needed by nothing at all: refuse either or both and the app behaves exactly as it otherwise would. The consequence of refusing falls on us rather than on you — we simply do not have the measurement.
We take no decisions about you by automated means, and we build no profiles. Nothing described here evaluates you, predicts anything about you or sorts you into a group, and nothing here produces a legal effect on you or anything comparable to one. Two things are decided by a machine, and both are about equipment rather than about you: the relay turns away requests that arrive too fast, and it will not add a seventh device to a subscription that already covers six. Neither weighs anything about you — one counts requests, the other counts devices.
What you send us yourself — a message from the feedback screen (section 6b), or anything you choose to send us by email — rests on your consent (Art. 6(1)(a)). Nothing is collected until you send it, and what goes with it is your choice as you write. Answering you, and fixing what you reported, is that same act being honoured.
10. Processors, and transfers outside the EEA
Every processor named here is bound to us by a written data processing agreement that requires it to protect your data to the standard this policy sets, to process it only on our instructions and only for the purpose named here, and never for its own. Our processors — RevenueCat (subscriptions), Cloudflare (the relay, and the messages you send from the feedback screen), Amplitude (usage data) and Sentry (crash reports) — may process data outside the European Economic Area, including in the United States. Amplitude receives the measurements on its European endpoint and Sentry holds crash reports in its European region, but both companies are American, so those transfers rest on the clauses below all the same. Every such transfer is made under the EU Standard Contractual Clauses, incorporated into the data processing agreement we hold with each of these processors: Amplitude’s addendum forms part of its terms of service and carries the 2021 Clauses, and Sentry’s data processing addendum carries the same Clauses together with the UK addendum. To obtain a copy of the Clauses relied on for any of these transfers, write to support@whisprompt.app and name the processor you are asking about; we will send you the clauses that apply to it. (What Amplitude holds beyond your measurements are the test events we sent ourselves from our own devices, to check that the address a measurement arrives from is not turned into a location. They are ours, not yours, and we delete them.) None of these services holds a name for you, and only one of them can hold an email address: if you give one on the feedback screen so that we can reply, it sits inside your message on Cloudflare until that message is deleted, and nowhere else. Beyond that, what they hold is a random subscription identifier, per-device identifiers, the identifier the measurements carry, the name each device reports for itself, and technical connection details.
11. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to processing. We hold no name and no email address for you: Whisprompt has no accounts. We do hold one record on our own server: if you use Whisprompt Pro across several of your devices, we keep a list of those devices — an identifier the app generates for each one, the name each device reports for itself, and when it was added and last seen — under a random subscription identifier. You can delete that record from the app at any time (Settings → Data on our servers), and everything else stays on your device: you can delete scripts, models and the app whenever you like. To withdraw your consent to the usage measurements, turn them off (Settings → Usage data) or write to us — section 6 sets out both, and either stops the collection and deletes the identifier from the device. To have the measurements already sent deleted as well, ask us and we will delete them: they are held under that one random identifier and under no name of yours. Deleting your subscription record does not reach them and turning measurement off does not reach it, because the two are kept under different identifiers on purpose: ask us for whichever you want gone, or both. If you have written to us from the feedback screen and want that message and its attachments gone, quote the reference code the app showed you — that code is how we find it, and there is no name of yours filed with it to find it by. For any request, email support@whisprompt.app. You also have the right to lodge a complaint with a supervisory authority — the one where you live, the one where you work, or the one where you think something went wrong. Ours is the Agencia Española de Protección de Datos in Spain (aepd.es).
12. Data retention
Local data persists until you delete it or remove the app. Subscription data is removed with your RevenueCat customer profile, though anonymised transaction records may be retained by RevenueCat and the app store for accounting purposes. Relay rooms live at most four hours, the connection mailbox up to 30 days, and the list of devices on your subscription until a year has passed with none of them using it — or until you delete it from the app. Usage measurements carry no expiry date; what decides how long they are kept is what they are for. They stay while they can still answer the question they were collected to answer — whether the version of the app people are running now behaves the way we think it does — and they are deleted once they cannot, or sooner if you ask us to delete yours. Nothing is kept on the chance that it proves useful later. The identifier those measurements are held under runs on a clock of its own, and a short one: it is replaced at most thirteen months after it is created, counted from the day it is created and not extended by use, so no record kept under one identifier can span more than that. Crash reports are kept at Sentry for no longer than 90 days. A message sent from the feedback screen, with anything attached to it, is kept for two years from the day it arrives and is then deleted automatically — that deletion is done by the system that holds it, nightly, and not by anybody remembering; ask us and yours goes sooner. Support emails are kept only as long as needed to handle your request.
13. Children
Whisprompt is not directed at children under 16 and does not knowingly process their data.
14. Changes
We will update this page when our practices change and revise the date above. Where the change is ours to time, the page is updated before the release that makes it, not after.