Skip to main content
Back to Legal

Privacy Policy

Effective April 28, 2026

Version 2026-04-28

Privacy Policy

Last Updated: 2026-04-08

1. Introduction and Controller Identity

This Privacy Policy explains how TriDev Tech EOOD, a company registered under the laws of Bulgaria, with its registered office at Bulgaria, Sofia, “Nikolay Liliev” 12, fl. 1, office 2 (“we,” “us,” or “our”), collects, uses, shares, and protects personal data when you use Whisper (the “App”).

We act as the data controller for the personal data processed through the App, within the meaning of Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”).

Data Protection Contact: office@whisper-app.net

2. Categories of Personal Data Collected

We collect the following categories of personal data:

2.1 Data You Provide Directly

Category

Examples

Purpose

Account Information

Name, email address, username, password, profile picture, date of birth

Account creation and management

Profile Data

Biography, interests, location (if provided), profile preferences

Personalizing your experience and enabling social features

User Content

Posts, answers, photos, and other content you share

Providing the App’s core social functionality

Communications

Communications with our support team

Providing user support

Age Confirmation

Your date of birth (stored securely; never displayed publicly or to the user) and the timestamp when you confirmed your age (computed from date of birth at registration)

Age verification and legal compliance (18+ requirement)

Third-Party Authentication Providers

When you sign up or log in using a third-party provider (Google or Apple), we receive the following information from that provider:

  • Your name
  • Your email address

We do not receive or store your password from these providers. Your authentication is handled securely by the provider’s own systems. Date of birth is collected immediately after account creation for age verification. If you are under 18, all personal data is permanently and immediately deleted.

2.2 Data Collected Automatically

Category

Examples

Purpose

Device Information

Device type, operating system, unique device identifiers, mobile network information

App functionality, security, and analytics

Usage Data

Features used, interactions, time spent, click patterns

Improving the App and user experience

Log Data

IP address, access times, pages viewed, app crashes

Security, debugging, and service improvement

Location Data

Approximate location inferred from IP address; precise GPS not collected

Fraud prevention and regional compliance

Embeddings

Vector representations of your text content, generated for search and content recommendation

Enabling search functionality and content recommendations

Push Notification Tokens

Device push notification tokens (FCM/APNs)

Delivering push notifications

Photos (write only)

Share card images saved to your device’s photo library at your request

Not transmitted to our servers; stored locally on your device only

2.3 Sharing to Third-Party Platforms

Whisper allows you to generate share cards — branded images containing your public profile information, public book details, or individual answers to a book — and share them to third-party platforms such as Instagram, WhatsApp, X (Twitter), or other applications via your device’s native sharing functionality. Share cards are generated entirely on your device and are not transmitted to our servers.

Answer share cards display the question and the answer text (or a visual summary for structured answer types such as polls, ratings, or rankings). When the answer was submitted anonymously, the share card attributes it to “Anonymous” and does not include any information that could identify the answerer.

When you use a sharing option, we record which sharing method you selected (e.g., Instagram Stories, WhatsApp, Copy Link), which content you shared (e.g., book, profile, or answer identifier), and whether the shared content was anonymous. This helps us understand which sharing features are most useful and improve the sharing experience. We do not record the content of your share card images or any data you transmit to the third-party platform.

When you share content to a third-party platform, that content is transmitted directly from your device to the selected platform. Once shared, the content is governed by that platform’s own terms of service and privacy policy. We have no ability to moderate or remove content once it has been shared to a third-party platform. We encourage you to review the privacy policies of any platform you share content to.

If you choose to save a share card to your device’s photo library, the App will request your permission to access your photo library for this purpose only.

2.4 Data from Third-Party Sources

Source

Data

Purpose

Advertising Partners

Google AdMob

Delivering relevant advertisements and measuring advertising effectiveness

| Google Identity Services | Authentication (Sign in with Google) | Email, name (received during sign-in) | | Apple Sign-In | Authentication (Sign in with Apple) | Email, name (received during sign-in; email may be private relay) |

Other Users

Tags, mentions, shared content

Enabling social features

3. Legal Bases for Processing

We process your personal data on the following legal bases under Article 6(1) GDPR:

• Contract Performance (Art. 6(1)(b)): Processing necessary to provide you with the App’s services, including account management, core social features, content hosting, and user communications.

• Legitimate Interests (Art. 6(1)(f)): Processing for our legitimate interests, including fraud prevention, network and information security, service improvement, and analytics, provided these interests are not overridden by your fundamental rights and freedoms.

• Legal Obligation (Art. 6(1)©): Processing required to comply with applicable laws, such as responding to legal requests, tax obligations, and regulatory requirements.

• Consent (Art. 6(1)(a)): Where required, we obtain your consent for specific processing activities, including marketing communications, personalized advertising, and certain tracking technologies. You may withdraw consent at any time as described in Section 8.

4. Special Categories of Data and Minors

We do not intentionally collect special categories of personal data (Article 9 GDPR), such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or sexual orientation, unless you voluntarily include such information in your user content.

Whisper is exclusively for users aged 18 and older. We do not knowingly collect personal data from individuals under 18. If we become aware that a user is under 18, we will promptly delete their account and associated data. Please see our Age Restriction and Child Safety Policy for further details.

5. Data Sharing and Recipients

We may share your personal data with the following categories of recipients:

• Service Providers: Third parties that provide services on our behalf, including:

• Google Cloud Platform (GKE europe-west1) — application hosting and infrastructure

• Supabase (eu-central-1) — database and authentication services

• Google AdMob — advertising services; processes advertising identifiers and usage signals

• Sentry — crash reporting and error monitoring

• OpenAI (Ireland Ltd.) — automated content moderation; processes text and image content submitted to the App; data processed under standard contractual clauses

• Google Analytics (GA4) — Web analytics and traffic measurement on our website (whisper-app.net). Collects anonymised usage data including page views, session duration, and traffic source. Data is processed in the EU/US under Google’s Data Processing Terms.

• Google Tag Manager — Tag management system that controls the loading of analytics and marketing scripts on our website. GTM itself does not collect personal data; it manages which tags fire based on your consent preferences.

• Meta Platforms (Meta Pixel) — Conversion measurement and audience building for advertising campaigns on Meta platforms (Facebook, Instagram). Collects page view data and conversion events on our website when marketing consent is given. Data is processed under Meta’s Data Processing Terms with Standard Contractual Clauses.

• Google Ads — Conversion tracking for Google advertising campaigns. Measures when website visitors take actions after interacting with our ads. Processed under Google’s Data Processing Terms.

• AppsFlyer Ltd. — Mobile attribution and analytics platform. Measures which advertising campaigns drive app installs and in-app actions. Collects device identifiers, install attribution data, and in-app events. Data is processed under AppsFlyer’s Data Processing Agreement with Standard Contractual Clauses for international transfers (Israel/US).

• Firebase Analytics (Google) — In-app analytics for measuring user engagement, feature adoption, and conversion funnels within the mobile application. Collects anonymised event data. Processed under Google’s Data Processing Terms.

• Resend Inc. (United States) — Transactional email delivery service for authentication emails (account confirmation, password reset, email change). Processes email addresses, preferred language setting, and email delivery metadata (delivery status, timestamps). Data is processed under Resend’s Data Processing Agreement with Standard Contractual Clauses for international transfers (US).

All service providers are bound by data processing agreements in accordance with Article 28 GDPR.

• Other Users: Depending on your privacy settings, certain information (such as your profile, posts, and comments) may be visible to other users.

• Legal and Regulatory Authorities: Where required by law, court order, or to protect our legal rights.

• Business Transfers: In connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality obligations.

• Advertising Partners: We work with Google AdMob to serve advertisements. AdMob may collect and process advertising identifiers and usage data as described in Google’s Privacy Policy. We do not sell personal data to advertising partners.

6. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (for OpenAI content moderation services and Google AdMob).

For such transfers, we rely on the following safeguards:

• European Commission adequacy decisions (Article 45 GDPR)

• Standard Contractual Clauses approved by the European Commission (Article 46(2)© GDPR)

• Israel — AppsFlyer Ltd. is headquartered in Israel, which benefits from an EU adequacy decision. Additional safeguards are in place under AppsFlyer’s Data Processing Agreement.

You may obtain a copy of the relevant transfer mechanisms by contacting us at office@whisper-app.net.

7. Data Retention

We retain your personal data for the following periods:

Data Category

Retention Period

Account Information

Until account deletion request, then personal data anonymized immediately; residual account record permanently deleted after 90 days

User Content

Until deleted by you or account termination; answers retained for 90 days after deletion then permanently purged

Transaction Records

N/A — Whisper does not process payments directly

Usage and Analytics Data

Up to 90 days in identifiable form (Sentry); aggregated analytics retained indefinitely

Support Communications

3 years from resolution

Legal Compliance Data

As required by applicable law

Push Tokens

Deleted immediately upon account deletion or notification opt-out

Web analytics (GA4)

14 months from collection (Google default)

Meta Pixel data

Per Meta’s data policy; typically 180 days for optimisation

AppsFlyer attribution data

Up to 24 months from install date

Firebase Analytics

14 months from collection (configurable)

8. Your Rights

Under the GDPR, you have the following rights:

• Right of Access (Art. 15): Obtain confirmation of whether we process your data and receive a copy.

• Right to Rectification (Art. 16): Correct inaccurate or incomplete personal data.

• Right to Erasure (Art. 17): Request deletion of your personal data in certain circumstances.

• Right to Restriction (Art. 18): Restrict processing in certain circumstances.

• Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.

• Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling, and to direct marketing.

• Right to Withdraw Consent: Where processing is based on consent, withdraw at any time without affecting the lawfulness of prior processing.

• Right to Lodge a Complaint: File a complaint with your local data protection authority OR contact Commission for Personal Data Protection Republic of Bulgaria (CPDP) at Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Еmail: kzld@cpdp.bg

Web-site: www.cpdp.bg

To exercise these rights, contact us at office@whisper-app.net or use the in-app settings at your account Settings > Privacy.

We will respond to requests within one month, extendable by two additional months for complex requests.

9. Automated Decision-Making

We use automated decision-making for content moderation purposes. By creating an account and submitting content to Whisper, you expressly consent to the automated screening of your content (text and images) by OpenAI’s content moderation system (omni-moderation-latest) for the purpose of enforcing our Community Guidelines and applicable law. This system processes your content in real-time upon submission to detect policy violations including sexual content, violence, harassment, self-harm, and illegal activity.

Where automated moderation results in content removal or account restriction, you have the right to obtain human review of the decision, express your point of view, and contest the outcome by contacting office@whisper-app.net.

We do not use automated decision-making for profiling that produces legal or similarly significant effects unrelated to content moderation.

10. Security Measures

We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS) and at rest, row-level security policies, access controls, and regular security reviews. For recommender systems and content moderation tools, we apply human-in-the-loop oversight for decisions that may significantly affect users.

11. Updates to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated through the App or by email 30 days before taking effect. Continued use of the App after changes constitutes acceptance of the updated policy.

12. Contact Information

For privacy-related inquiries: TriDev Tech Bulgaria, Sofia, “Nikolay Liliev” 12, fl.1, office 2 Email: office@whisper-app.net

User Support: support@whisper-app.net

Automated Emails (no-reply): noreply@whisper-app.net — used for authentication and notification emails; this address does not accept incoming mail

Privacy Policy | Whisper