LEGAL
Privacy Policy
Effective and last updated: August 19, 2026
This Privacy Policy explains how Whispaw (“Whispaw,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use the Whispaw desktop application, iPhone companion, relay services, Music Discovery features, and this website (collectively, the “Services”). Features vary by installation and configuration.
1. Information we collect
Account and identity information
If you sign in to an account-backed feature, we receive a provider-specific account identifier and, when permitted, an email address. We may store cryptographic hashes of those values, an internal Whispaw account identifier, session records, preferences, and security events.
Device, pairing, and diagnostics
We process pairing identifiers, public encryption material, encrypted relay envelopes, device push tokens, connection state, app version, operating-system information, timestamps, error reports, and audit events needed to connect, secure, troubleshoot, and improve the Services.
Voice, text, and assistant activity
We process the commands you type or speak, transcriptions, responses, and related context needed to complete a request. Depending on your settings, audio or text may be processed on your device, on your paired desktop, through Whispaw relay infrastructure, or by a model or transcription provider you configure. Background microphone access is used only when you enable the applicable listening feature.
Location and navigation
When you request nearby places, location descriptions, or directions—or enable a related background feature—we process precise or approximate location, route progress, destination, travel mode, and map or street imagery needed to provide that feature. Whispaw does not use location for advertising.
Connected financial and trading services
If you connect a broker or market-data provider, the desktop app may process credentials or OAuth tokens, account identifiers, balances, positions, orders, quotes, and transaction activity. Secrets are intended to remain in operating-system protected storage on the desktop. Encrypted companion commands and approvals may pass through the relay, but the relay is not intended to hold broker passwords.
Music Discovery, wallet, and artist information
Music features may process wallet balances and ledger entries, playback progress, skips, purchases, library records, fraud-prevention signals, explicit-content preferences, artist submissions, audio fingerprints, moderation results, rights attestations, payout onboarding status, and artist earnings. Payment and payout providers receive the information they require to process their services.
Files, code, websites, communications, and purchases
When you direct Whispaw to work with selected files or folders, websites, calls, messages, food delivery, retail purchases, or other third-party services, it processes the content and instructions needed to perform that request. Website cookies and login sessions generally remain in the local app browser profile. A connected model provider receives prompts and context only when selected or required for the requested feature.
2. Google user data
Whispaw’s Music Discovery sign-in requests the openid and email scopes. We use the Google-provided stable account identifier and email address only to create, secure, recover, and protect the user’s Whispaw Music Discovery account and to prevent duplicate or abusive account activity.
- Whispaw does not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or advertising data through this sign-in.
- The Google access token is used transiently to retrieve the authorized identity and is not retained as a continuing Google API credential.
- We do not sell Google user data, use it for targeted advertising, or permit humans to read it except when necessary for security, support, legal compliance, or with the user’s affirmative permission.
- We disclose it only to service providers acting for Whispaw, when legally required, or as part of a user-directed action.
Whispaw’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3. How we use information
- Provide, personalize, synchronize, and secure requested features.
- Authenticate accounts and paired devices.
- Execute user-directed actions and maintain idempotent transaction records.
- Detect fraud, abuse, entitlement failures, stale data, and technical problems.
- Maintain required financial, rights, safety, and audit records.
- Comply with law and enforce our Terms of Service.
4. When information is shared
We share information only as needed with infrastructure and service providers, connected providers selected by the user, payment and payout processors, model or transcription providers selected for a request, professional advisers, and authorities when legally required. Examples may include Cloudflare for relay infrastructure, Google and Apple for sign-in or location services, Stripe for payments and payouts, telecom providers for calls or messages, connected brokers, and websites or merchants the user directs Whispaw to use. Each third party handles information under its own terms and privacy policy.
We do not sell personal information and do not share personal information for cross-context behavioral advertising.
5. Storage, security, and retention
Whispaw uses measures designed to protect information, including encrypted pairing, scoped capabilities, redacted logs, short-lived authorization state, operating-system protected secret storage, and restricted service interfaces. No system is completely secure.
Local workspace information remains until the user removes it or the app’s data. Account sessions expire or are revoked. We retain wallet, transaction, artist, payout, fraud, and audit records as needed to provide the service, prevent duplicate charges, resolve disputes, and satisfy legal, tax, accounting, and rights obligations. Other records are deleted or de-identified when no longer reasonably needed.
6. Your choices and rights
You can decline optional permissions, disconnect providers, sign out, disable background features, clear local data, and request access to or deletion of account information. Some ledger, fraud, payment, tax, or legal records may need to be retained. You can also revoke Google access from your Google Account security settings.
7. Children
The Services are not directed to children under 18. Features involving trading, payments, purchases, artist payouts, or contractual commitments are available only to users legally able to use them.
8. International use
Information may be processed in countries other than the one where you live. Availability is limited to jurisdictions where Whispaw and its providers can support the relevant legal, payment, sanctions, tax, and rights requirements.
9. Changes and contact
We may update this policy as the Services change. Material changes will be identified by a new effective date and, when appropriate, an in-app notice.
For privacy questions or requests, use the support contact shown in the Whispaw application and on its Google OAuth consent screen. Please include “Whispaw privacy request” and do not send passwords, API keys, or broker credentials.
