Privacy Policy
Effective April 28, 2026
Version 2026-04-28Privacy Policy
Last Updated: 2026-04-08
1. Introduction and Controller Identity
This Privacy Policy explains how TriDev Tech EOOD, a company registered under the laws of Bulgaria, with its registered office at Bulgaria, Sofia, “Nikolay Liliev” 12, fl. 1, office 2 (“we,” “us,” or “our”), collects, uses, shares, and protects personal data when you use Whisper (the “App”).
We act as the data controller for the personal data processed through the App, within the meaning of Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”).
Data Protection Contact: office@whisper-app.net
2. Categories of Personal Data Collected
We collect the following categories of personal data:
2.1 Data You Provide Directly
Category
Examples
Purpose
Account Information
Name, email address, username, password, profile picture, date of birth
Account creation and management
Profile Data
Biography, interests, location (if provided), profile preferences
Personalizing your experience and enabling social features
User Content
Posts, answers, photos, and other content you share
Providing the App’s core social functionality
Communications
Communications with our support team
Providing user support
Age Confirmation
Your date of birth (stored securely; never displayed publicly or to the user) and the timestamp when you confirmed your age (computed from date of birth at registration)
Age verification and legal compliance (18+ requirement)
Third-Party Authentication Providers
When you sign up or log in using a third-party provider (Google or Apple), we receive the following information from that provider:
- Your name
- Your email address
We do not receive or store your password from these providers. Your authentication is handled securely by the provider’s own systems. Date of birth is collected immediately after account creation for age verification. If you are under 18, all personal data is permanently and immediately deleted.
2.2 Data Collected Automatically
Category
Examples
Purpose
Device Information
Device type, operating system, unique device identifiers, mobile network information
App functionality, security, and analytics
Usage Data
Features used, interactions, time spent, click patterns
Improving the App and user experience
Log Data
IP address, access times, pages viewed, app crashes
Security, debugging, and service improvement
Location Data
Approximate location inferred from IP address; precise GPS not collected
Fraud prevention and regional compliance
Embeddings
Vector representations of your text content, generated for search and content recommendation
Enabling search functionality and content recommendations
Push Notification Tokens
Device push notification tokens (FCM/APNs)
Delivering push notifications
Photos (write only)
Share card images saved to your device’s photo library at your request
Not transmitted to our servers; stored locally on your device only
2.3 Sharing to Third-Party Platforms
Whisper allows you to generate share cards — branded images containing your public profile information, public book details, or individual answers to a book — and share them to third-party platforms such as Instagram, WhatsApp, X (Twitter), or other applications via your device’s native sharing functionality. Share cards are generated entirely on your device and are not transmitted to our servers.
Answer share cards display the question and the answer text (or a visual summary for structured answer types such as polls, ratings, or rankings). When the answer was submitted anonymously, the share card attributes it to “Anonymous” and does not include any information that could identify the answerer.
When you use a sharing option, we record which sharing method you selected (e.g., Instagram Stories, WhatsApp, Copy Link), which content you shared (e.g., book, profile, or answer identifier), and whether the shared content was anonymous. This helps us understand which sharing features are most useful and improve the sharing experience. We do not record the content of your share card images or any data you transmit to the third-party platform.
When you share content to a third-party platform, that content is transmitted directly from your device to the selected platform. Once shared, the content is governed by that platform’s own terms of service and privacy policy. We have no ability to moderate or remove content once it has been shared to a third-party platform. We encourage you to review the privacy policies of any platform you share content to.
If you choose to save a share card to your device’s photo library, the App will request your permission to access your photo library for this purpose only.
2.4 Data from Third-Party Sources
Source
Data
Purpose
Advertising Partners
Google AdMob
Delivering relevant advertisements and measuring advertising effectiveness
| Google Identity Services | Authentication (Sign in with Google) | Email, name (received during sign-in) | | Apple Sign-In | Authentication (Sign in with Apple) | Email, name (received during sign-in; email may be private relay) |
Other Users
Tags, mentions, shared content
Enabling social features
3. Legal Bases for Processing
We process your personal data on the following legal bases under Article 6(1) GDPR:
• Contract Performance (Art. 6(1)(b)): Processing necessary to provide you with the App’s services, including account management, core social features, content hosting, and user communications.
• Legitimate Interests (Art. 6(1)(f)): Processing for our legitimate interests, including fraud prevention, network and information security, service improvement, and analytics, provided these interests are not overridden by your fundamental rights and freedoms.
• Legal Obligation (Art. 6(1)©): Processing required to comply with applicable laws, such as responding to legal requests, tax obligations, and regulatory requirements.
• Consent (Art. 6(1)(a)): Where required, we obtain your consent for specific processing activities, including marketing communications, personalized advertising, and certain tracking technologies. You may withdraw consent at any time as described in Section 8.
4. Special Categories of Data and Minors
We do not intentionally collect special categories of personal data (Article 9 GDPR), such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or sexual orientation, unless you voluntarily include such information in your user content.
Whisper is exclusively for users aged 18 and older. We do not knowingly collect personal data from individuals under 18. If we become aware that a user is under 18, we will promptly delete their account and associated data. Please see our Age Restriction and Child Safety Policy for further details.
5. Data Sharing and Recipients
We may share your personal data with the following categories of recipients:
• Service Providers: Third parties that provide services on our behalf, including:
• Google Cloud Platform (GKE europe-west1) — application hosting and infrastructure
• Supabase (eu-central-1) — database and authentication services
• Google AdMob — advertising services; processes advertising identifiers and usage signals
• Sentry — crash reporting and error monitoring
• OpenAI (Ireland Ltd.) — automated content moderation; processes text and image content submitted to the App; data processed under standard contractual clauses
• Google Analytics (GA4) — Web analytics and traffic measurement on our website (whisper-app.net). Collects anonymised usage data including page views, session duration, and traffic source. Data is processed in the EU/US under Google’s Data Processing Terms.
• Google Tag Manager — Tag management system that controls the loading of analytics and marketing scripts on our website. GTM itself does not collect personal data; it manages which tags fire based on your consent preferences.
• Meta Platforms (Meta Pixel) — Conversion measurement and audience building for advertising campaigns on Meta platforms (Facebook, Instagram). Collects page view data and conversion events on our website when marketing consent is given. Data is processed under Meta’s Data Processing Terms with Standard Contractual Clauses.
• Google Ads — Conversion tracking for Google advertising campaigns. Measures when website visitors take actions after interacting with our ads. Processed under Google’s Data Processing Terms.
• AppsFlyer Ltd. — Mobile attribution and analytics platform. Measures which advertising campaigns drive app installs and in-app actions. Collects device identifiers, install attribution data, and in-app events. Data is processed under AppsFlyer’s Data Processing Agreement with Standard Contractual Clauses for international transfers (Israel/US).
• Firebase Analytics (Google) — In-app analytics for measuring user engagement, feature adoption, and conversion funnels within the mobile application. Collects anonymised event data. Processed under Google’s Data Processing Terms.
• Resend Inc. (United States) — Transactional email delivery service for authentication emails (account confirmation, password reset, email change). Processes email addresses, preferred language setting, and email delivery metadata (delivery status, timestamps). Data is processed under Resend’s Data Processing Agreement with Standard Contractual Clauses for international transfers (US).
All service providers are bound by data processing agreements in accordance with Article 28 GDPR.
• Other Users: Depending on your privacy settings, certain information (such as your profile, posts, and comments) may be visible to other users.
• Legal and Regulatory Authorities: Where required by law, court order, or to protect our legal rights.
• Business Transfers: In connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality obligations.
• Advertising Partners: We work with Google AdMob to serve advertisements. AdMob may collect and process advertising identifiers and usage data as described in Google’s Privacy Policy. We do not sell personal data to advertising partners.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (for OpenAI content moderation services and Google AdMob).
For such transfers, we rely on the following safeguards:
• European Commission adequacy decisions (Article 45 GDPR)
• Standard Contractual Clauses approved by the European Commission (Article 46(2)© GDPR)
• Israel — AppsFlyer Ltd. is headquartered in Israel, which benefits from an EU adequacy decision. Additional safeguards are in place under AppsFlyer’s Data Processing Agreement.
You may obtain a copy of the relevant transfer mechanisms by contacting us at office@whisper-app.net.
7. Data Retention
We retain your personal data for the following periods:
Data Category
Retention Period
Account Information
Until account deletion request, then personal data anonymized immediately; residual account record permanently deleted after 90 days
User Content
Until deleted by you or account termination; answers retained for 90 days after deletion then permanently purged
Transaction Records
N/A — Whisper does not process payments directly
Usage and Analytics Data
Up to 90 days in identifiable form (Sentry); aggregated analytics retained indefinitely
Support Communications
3 years from resolution
Legal Compliance Data
As required by applicable law
Push Tokens
Deleted immediately upon account deletion or notification opt-out
Web analytics (GA4)
14 months from collection (Google default)
Meta Pixel data
Per Meta’s data policy; typically 180 days for optimisation
AppsFlyer attribution data
Up to 24 months from install date
Firebase Analytics
14 months from collection (configurable)
8. Your Rights
Under the GDPR, you have the following rights:
• Right of Access (Art. 15): Obtain confirmation of whether we process your data and receive a copy.
• Right to Rectification (Art. 16): Correct inaccurate or incomplete personal data.
• Right to Erasure (Art. 17): Request deletion of your personal data in certain circumstances.
• Right to Restriction (Art. 18): Restrict processing in certain circumstances.
• Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
• Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling, and to direct marketing.
• Right to Withdraw Consent: Where processing is based on consent, withdraw at any time without affecting the lawfulness of prior processing.
• Right to Lodge a Complaint: File a complaint with your local data protection authority OR contact Commission for Personal Data Protection Republic of Bulgaria (CPDP) at Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Еmail: kzld@cpdp.bg
Web-site:Â www.cpdp.bg
To exercise these rights, contact us at office@whisper-app.net or use the in-app settings at your account Settings > Privacy.
We will respond to requests within one month, extendable by two additional months for complex requests.
9. Automated Decision-Making
We use automated decision-making for content moderation purposes. By creating an account and submitting content to Whisper, you expressly consent to the automated screening of your content (text and images) by OpenAI’s content moderation system (omni-moderation-latest) for the purpose of enforcing our Community Guidelines and applicable law. This system processes your content in real-time upon submission to detect policy violations including sexual content, violence, harassment, self-harm, and illegal activity.
Where automated moderation results in content removal or account restriction, you have the right to obtain human review of the decision, express your point of view, and contest the outcome by contacting office@whisper-app.net.
We do not use automated decision-making for profiling that produces legal or similarly significant effects unrelated to content moderation.
10. Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS) and at rest, row-level security policies, access controls, and regular security reviews. For recommender systems and content moderation tools, we apply human-in-the-loop oversight for decisions that may significantly affect users.
11. Updates to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated through the App or by email 30 days before taking effect. Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact Information
For privacy-related inquiries: TriDev Tech Bulgaria, Sofia, “Nikolay Liliev” 12, fl.1, office 2 Email: office@whisper-app.net
User Support: support@whisper-app.net
Automated Emails (no-reply): noreply@whisper-app.net — used for authentication and notification emails; this address does not accept incoming mail