Back to Whisprompt

Privacy Policy

Last updated: 15 August 2026

Whisprompt is built privacy-first. This policy explains what we do and, just as importantly, what we do not collect. It covers every Whisprompt app — on phone, tablet, watch, television and Mac — and this website. Where something applies to only one of them, it says so.

The short version: Your scripts stay on your devices and never reach us; nothing sends one anywhere else unless you connect a service yourself (section 3). Speech recognition is done by your phone’s own engine, which may send audio to Apple or Google to do it — install an offline language pack and it never leaves the device. Either way it never reaches us. No account is required, and we do not sell your data. The app can measure how well it performs — counts and timings, never a word of what you write or say — but only if you say yes: nothing is measured until you do, the question comes only after you have used the app, and your answer covers the devices you link as your own (section 6).

1. Who is responsible (Data Controller)

Leonid Kabanov (autónomo), Spain. Contact: support@whisprompt.app. Full identification details are in the Imprint. We are established in Spain, and therefore inside the European Union, so Article 27 GDPR — which requires a representative in the Union — does not apply to us. We have appointed no Data Protection Officer and are not obliged to: Whisprompt is not a public body, it does not monitor people regularly and systematically on a large scale, and no special category of data reaches us at all. The supervisory authority for our establishment is the Agencia Española de Protección de Datos (AEPD), aepd.es.

2. Data processed on your device

3. Data processed by services you connect

Some optional features connect to services you authorise. We act only as your client; each provider is an independent controller under its own policy:

4. Subscription and Pro

Whisprompt has no accounts. There is nothing to sign in to and nothing to create, no provider is ever asked for your email address, and we hold neither a name nor an address for you. The prompter, recording and casting work as they are, and a subscription is bought and restored without an account. The app does still contain the code for an optional account — Sign in with Apple, with Supabase as the processor — and it is inert: it is switched on by keys the app is not built with, so there is no sign-in screen, nothing reaches Supabase, and no email address is collected. Should an account be introduced, this page will describe what it processes before the release that brings it, not after.

5. Casting to your other devices

Whisprompt can run the prompter across several of your own devices at once. On the same local network they connect directly. With no shared network, the connection goes through our relay on Cloudflare Workers:

6. Usage data

Whisprompt can measure how well it performs and send us those measurements — counts, durations and codes, never a word of what you write or say. None of it happens unless you say yes. Until you do there is no measuring, no identifier, and nothing stored on your device for it. The app asks once, and never at the moment you first open it, because a question put before the app has done anything is a question you have no way to answer. It comes after your first read has got somewhere — or, if you link a second device before that happens, at the end of the linking, on one card alongside the question below about counting your devices. That card has two answers and no third way out: it does not close if you tap beside it or press back, because a card closed by a stray tap would have recorded a refusal you never gave. Nothing is written unless you answer it, so if something else takes it off the screen first — the app closes, another screen replaces it — the question is simply still open, and comes back after your next read. Once you have answered, either way, it does not come back at all. Your answer covers the devices you link as your own, and the card says so where you give it: a device you link later takes that answer the next time it connects and tells you plainly that it has, rather than putting the same question a second time. It works in both directions — turn the measuring off on one of your devices and the others stop too. An answer given on a device is never overwritten by one arriving from another, so switching it off here cannot be undone by a device that has not heard yet. Say no and nothing else about the app changes, and that device does not ask again. Say yes and the switch is in the app’s settings, under “Usage data”, so you can turn it back off at any moment without giving a reason. What this rests on legally is in section 9; the ways to withdraw are at the end of this section. Turning it off stops the measuring itself, not just the reporting, and deletes from the device the identifier below, anything that was still waiting to be sent, and the note about a read in progress described under “What is measured”.

6a. Crash reports — a separate permission, off unless you grant it

If the app stops working, it can send us a report about the failure. This is not part of the measurement in section 6: it is a different purpose, with a different recipient, and it has its own switch. It is put on a card of its own, just before the measuring question, and answered separately — a yes to one is not a yes to the other, in either direction. That card works the way the measuring one does: two answers, no third way out, and nothing recorded unless you give one.

It is off unless you turn it on. Until you do, nothing is installed for it and nothing is sent — that rule has no exceptions at all. What does have exceptions is storage, and there are two of them below. Both exist to put you the question rather than to collect anything, both are about a crash that has already happened to you, and neither sends a thing until you answer.

The first is a failure to start. If Whisprompt cannot start at all, there is no later moment at which to put the question, so the error screen puts it there. If you have already turned crash reports on, one report about that failure is sent and the screen tells you it was. If you have already turned them off, nothing is offered and nothing is sent. If you have never been asked, the screen asks — send this one report, don’t send it, or send them from now on — and nothing leaves the device until you choose. A report sent this way is smaller than the one described below: it carries no identifier of any kind, and it says where the app stopped, the app version, and which operating system this is — nothing further about the device, no interface language, and none of the steps that came before. It goes to Sentry, the same processor and the same European servers, and what is said below about the internet address a report arrives from applies to it as well. Choosing to send them from now on is the same answer as the switch in Settings, and it is turned off in the same place. The same screen, with the same three answers, also appears when a single part of the app fails while it is running rather than at startup. This is the phone and tablet app only: the Mac and television apps have no such screen.

The second is a crash we could not ask you about at the time — because the app was gone before you could answer, or because you closed it instead of answering. If you have never been asked, one report about it is kept on your device, and the next time the app starts properly it says so at the bottom of the screen and offers you the question. It is a single report and not a queue; a second crash does not replace it. Nothing about it is sent unless you say yes there. It is deleted when you answer either way, when you tell that notice to delete it, when crash reports are switched off, and in any case seven days after it was kept. That file is the only thing stored on your device for crash reporting before you have agreed to anything, and we would rather name it than let the paragraph above imply there is nothing there: it exists so the question can be put at all. The crashes it recovers are the ones we would otherwise never see — the first launches of a brand new installation, which are the worst crashes there are and belonged to exactly the people the question had never reached. What it does not recover is a crash the operating system handles itself, below the app: those still need the reporting to have been switched on beforehand.

We do not put a processor’s key into a release before that processor’s data processing agreement is in force. What Sentry holds besides the reports people send us are the test reports we sent ourselves from a developer machine, to check that names, paths and addresses really are stripped out. Those are ours, not yours, and we delete them.

6b. What you send us yourself

The app has a “Send feedback” screen. Nothing on it reaches us until you tap send, and what reaches us then is what you wrote plus whichever of the optional things you chose to add. It is not a measurement and it is not a crash report: you write it, you decide what goes with it, and it is used for answering you and for fixing what you told us about.

What always goes with a message, because a report we cannot place is a report we cannot act on: the app’s version and build number, the operating system and its version, the model of the device, and the language it is set to. The screen lists exactly these before you send, in the same words as here, so you know what you are sending as you write it.

What goes only if you add it. Files — up to three, screenshots or a short screen recording, picked by you from your own library; we receive what you attach and nothing you did not. An address to reply to, if you want an answer; without one we still read every word, and we then have no way of knowing who wrote it. And the measurement identifier from section 6, behind a switch that appears only when there is one to attach: it is what lets us look at how the app was behaving before you wrote.

The one thing we work out ourselves is whether the message came from a subscriber, so that it can be answered first. Your device sends the random subscription identifier of section 4, our server asks RevenueCat whether it is entitled, and writes down that answer — yes or no — and never the identifier itself. So nothing joins what you said to what you bought.

Messages are held for us by Cloudflare on servers in Western Europe: the text in a database, the files in object storage, both under the reference code the app shows you once it has sent. They are kept for two years and deleted automatically then, and sooner if you ask — quote that code, or tell us anything else that lets us find the message. No one but us reads them, and they are used for nothing else: not for measuring, not for profiling, not for deciding anything about you.

One thing to know before you attach a picture: a screenshot holds whatever was on the screen when you took it, which may include a script you were reading. Attach only what you would want us to hold, and we will delete what we do not need.

7. Erasing a device before it leaves your hands

The app’s settings hold an “Erase this device” button, under “Usage data”. It is the right thing to press before you sell, return, trade in or hand on a device, and the Terms ask you to.

It removes from that device: your scripts, your recordings, the voice models you downloaded, the connections you granted to services such as Notion, the measurement identifier, and every privacy answer you gave on it. It also takes the device out of your linked devices, so it stops mirroring your library and stops sharing your subscription. Your other devices keep everything.

Your subscription is not affected. It belongs to your App Store or Google Play account and restores on your next device.

Two limits, stated plainly. If the device is offline when you erase it, the local wipe still completes but your other devices are not told; the app says so, and you can remove it from the device list on any of them. And measurements already sent before the erase are not recalled by it — for those, use the deletion request in section 11.

8. What we do NOT collect

This website sets no cookies. It keeps two preferences in your browser: the theme, which you set with the sun-and-moon button in the header, and the language, so that whisprompt.app opens next time in the language you were last reading. Both are readable only by this site, neither identifies you, neither is sent to us or to anyone else, and clearing this site’s data in your browser removes them. The site is served by Cloudflare, which sees the address you connect from, as any web server does, and derives from it only the country used to show the price for your store.

Processing your audio and scripts to run the prompter is performed to provide the functionality you request (Art. 6(1)(b), performance of a contract / your request). Optional connected sources, subscription entitlements and purchase restoration rest on the same basis. Protecting the relay from abuse rests on our legitimate interest (Art. 6(1)(f)).

Everything in section 6 rests on your consent (Art. 6(1)(a)): the measuring itself, and counting your devices as one person under a shared identifier. The crash reports in section 6a rest on your consent too — a third permission, part of neither of the others: a crash reporter stores things on your device and is not needed to run a teleprompter, so there is nothing to rest it on but your yes. All three are asked separately and withdrawn separately, at any time; withdrawing is as easy as agreeing was, and costs no more taps. Withdrawing takes effect from that moment: it does not make what we did while your consent stood unlawful, and it does not on its own delete what was already sent — for that, ask us, and section 11 says how. The measuring and the crash reports are answered for a person rather than for a handset: the answer you give fills in on a device you link that has not been asked yet — which tells you it has taken it — and it never displaces an answer already given on a device. The counting is asked once for a related reason, because it is a fact about a set of devices rather than about any one of them, and a yes to it is carried to the others on the same subscription. A withdrawal travels further than any of them: it reaches your devices even where they have already answered, because an objection is made by a person, and between reaching one device too many and leaving one measuring against their wishes, we take the first. We ask rather than assume, and the reason is worth stating plainly: measuring an app by storing an identifier on your device could only be done without asking if our measurement provider agreed in writing never to reuse the data for its own ends, and made it impossible to look at a single person inside its own tool. We have not asked it for either, so we ask you instead.

What we do with the measurements is worth naming rather than describing in the abstract: Whisprompt follows your voice through a script in ten languages, the quality of that following differs from language to language, and the only way we learn that a language is being tracked badly is to count how often people had to take the text over by hand — per language, across enough installations for the number to mean anything. The measurements about the subscription screen answer a smaller question: which locked feature people are actually stopped by. Either way the measurements carry nothing you wrote or said, the address they arrive from is not turned into a location, the identifier is replaced after thirteen months, and nothing is combined with data from anywhere else or used to make decisions about you.

Nothing here is required of you. No law obliges you to give us any of it, and nothing we sell is conditional on it: the app installs, the prompter runs, and a subscription is bought and restored without an account. One feature depends on one permission — following your voice cannot work without the microphone — and refusing it leaves the prompter scrolling on its own, which is a mode in its own right rather than a fallback. The measurements in section 6 and the crash reports in section 6a are needed by nothing at all: refuse either or both and the app behaves exactly as it otherwise would. The consequence of refusing falls on us rather than on you — we simply do not have the measurement.

We take no decisions about you by automated means, and we build no profiles. Nothing described here evaluates you, predicts anything about you or sorts you into a group, and nothing here produces a legal effect on you or anything comparable to one. Two things are decided by a machine, and both are about equipment rather than about you: the relay turns away requests that arrive too fast, and it will not add a seventh device to a subscription that already covers six. Neither weighs anything about you — one counts requests, the other counts devices.

What you send us yourself — a message from the feedback screen (section 6b), or anything you choose to send us by email — rests on your consent (Art. 6(1)(a)). Nothing is collected until you send it, and what goes with it is your choice as you write. Answering you, and fixing what you reported, is that same act being honoured.

10. Processors, and transfers outside the EEA

Every processor named here is bound to us by a written data processing agreement that requires it to protect your data to the standard this policy sets, to process it only on our instructions and only for the purpose named here, and never for its own. Our processors — RevenueCat (subscriptions), Cloudflare (the relay, and the messages you send from the feedback screen), Amplitude (usage data) and Sentry (crash reports) — may process data outside the European Economic Area, including in the United States. Amplitude receives the measurements on its European endpoint and Sentry holds crash reports in its European region, but both companies are American, so those transfers rest on the clauses below all the same. Every such transfer is made under the EU Standard Contractual Clauses, incorporated into the data processing agreement we hold with each of these processors: Amplitude’s addendum forms part of its terms of service and carries the 2021 Clauses, and Sentry’s data processing addendum carries the same Clauses together with the UK addendum. To obtain a copy of the Clauses relied on for any of these transfers, write to support@whisprompt.app and name the processor you are asking about; we will send you the clauses that apply to it. (What Amplitude holds beyond your measurements are the test events we sent ourselves from our own devices, to check that the address a measurement arrives from is not turned into a location. They are ours, not yours, and we delete them.) None of these services holds a name for you, and only one of them can hold an email address: if you give one on the feedback screen so that we can reply, it sits inside your message on Cloudflare until that message is deleted, and nowhere else. Beyond that, what they hold is a random subscription identifier, per-device identifiers, the identifier the measurements carry, the name each device reports for itself, and technical connection details.

11. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to processing. We hold no name and no email address for you: Whisprompt has no accounts. We do hold one record on our own server: if you use Whisprompt Pro across several of your devices, we keep a list of those devices — an identifier the app generates for each one, the name each device reports for itself, and when it was added and last seen — under a random subscription identifier. You can delete that record from the app at any time (Settings → Data on our servers), and everything else stays on your device: you can delete scripts, models and the app whenever you like. To withdraw your consent to the usage measurements, turn them off (Settings → Usage data) or write to us — section 6 sets out both, and either stops the collection and deletes the identifier from the device. To have the measurements already sent deleted as well, ask us and we will delete them: they are held under that one random identifier and under no name of yours. Deleting your subscription record does not reach them and turning measurement off does not reach it, because the two are kept under different identifiers on purpose: ask us for whichever you want gone, or both. If you have written to us from the feedback screen and want that message and its attachments gone, quote the reference code the app showed you — that code is how we find it, and there is no name of yours filed with it to find it by. For any request, email support@whisprompt.app. You also have the right to lodge a complaint with a supervisory authority — the one where you live, the one where you work, or the one where you think something went wrong. Ours is the Agencia Española de Protección de Datos in Spain (aepd.es).

12. Data retention

Local data persists until you delete it or remove the app. Subscription data is removed with your RevenueCat customer profile, though anonymised transaction records may be retained by RevenueCat and the app store for accounting purposes. Relay rooms live at most four hours, the connection mailbox up to 30 days, and the list of devices on your subscription until a year has passed with none of them using it — or until you delete it from the app. Usage measurements carry no expiry date; what decides how long they are kept is what they are for. They stay while they can still answer the question they were collected to answer — whether the version of the app people are running now behaves the way we think it does — and they are deleted once they cannot, or sooner if you ask us to delete yours. Nothing is kept on the chance that it proves useful later. The identifier those measurements are held under runs on a clock of its own, and a short one: it is replaced at most thirteen months after it is created, counted from the day it is created and not extended by use, so no record kept under one identifier can span more than that. Crash reports are kept at Sentry for no longer than 90 days. A message sent from the feedback screen, with anything attached to it, is kept for two years from the day it arrives and is then deleted automatically — that deletion is done by the system that holds it, nightly, and not by anybody remembering; ask us and yours goes sooner. Support emails are kept only as long as needed to handle your request.

13. Children

Whisprompt is not directed at children under 16 and does not knowingly process their data.

14. Changes

We will update this page when our practices change and revise the date above. Where the change is ours to time, the page is updated before the release that makes it, not after.