LEGAL

Privacy Policy

Effective and last updated: August 19, 2026

This Privacy Policy explains how Whispaw (“Whispaw,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use the Whispaw desktop application, iPhone companion, relay services, Music Discovery features, and this website (collectively, the “Services”). Features vary by installation and configuration.

1. Information we collect

Account and identity information

If you sign in to an account-backed feature, we receive a provider-specific account identifier and, when permitted, an email address. We may store cryptographic hashes of those values, an internal Whispaw account identifier, session records, preferences, and security events.

Device, pairing, and diagnostics

We process pairing identifiers, public encryption material, encrypted relay envelopes, device push tokens, connection state, app version, operating-system information, timestamps, error reports, and audit events needed to connect, secure, troubleshoot, and improve the Services.

Voice, text, and assistant activity

We process the commands you type or speak, transcriptions, responses, and related context needed to complete a request. Depending on your settings, audio or text may be processed on your device, on your paired desktop, through Whispaw relay infrastructure, or by a model or transcription provider you configure. Background microphone access is used only when you enable the applicable listening feature.

Location and navigation

When you request nearby places, location descriptions, or directions—or enable a related background feature—we process precise or approximate location, route progress, destination, travel mode, and map or street imagery needed to provide that feature. Whispaw does not use location for advertising.

Connected financial and trading services

If you connect a broker or market-data provider, the desktop app may process credentials or OAuth tokens, account identifiers, balances, positions, orders, quotes, and transaction activity. Secrets are intended to remain in operating-system protected storage on the desktop. Encrypted companion commands and approvals may pass through the relay, but the relay is not intended to hold broker passwords.

Music Discovery, wallet, and artist information

Music features may process wallet balances and ledger entries, playback progress, skips, purchases, library records, fraud-prevention signals, explicit-content preferences, artist submissions, audio fingerprints, moderation results, rights attestations, payout onboarding status, and artist earnings. Payment and payout providers receive the information they require to process their services.

Files, code, websites, communications, and purchases

When you direct Whispaw to work with selected files or folders, websites, calls, messages, food delivery, retail purchases, or other third-party services, it processes the content and instructions needed to perform that request. Website cookies and login sessions generally remain in the local app browser profile. A connected model provider receives prompts and context only when selected or required for the requested feature.

2. Google user data

Whispaw’s Music Discovery sign-in requests the openid and email scopes. We use the Google-provided stable account identifier and email address only to create, secure, recover, and protect the user’s Whispaw Music Discovery account and to prevent duplicate or abusive account activity.

Whispaw’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

3. How we use information

4. When information is shared

We share information only as needed with infrastructure and service providers, connected providers selected by the user, payment and payout processors, model or transcription providers selected for a request, professional advisers, and authorities when legally required. Examples may include Cloudflare for relay infrastructure, Google and Apple for sign-in or location services, Stripe for payments and payouts, telecom providers for calls or messages, connected brokers, and websites or merchants the user directs Whispaw to use. Each third party handles information under its own terms and privacy policy.

We do not sell personal information and do not share personal information for cross-context behavioral advertising.

5. Storage, security, and retention

Whispaw uses measures designed to protect information, including encrypted pairing, scoped capabilities, redacted logs, short-lived authorization state, operating-system protected secret storage, and restricted service interfaces. No system is completely secure.

Local workspace information remains until the user removes it or the app’s data. Account sessions expire or are revoked. We retain wallet, transaction, artist, payout, fraud, and audit records as needed to provide the service, prevent duplicate charges, resolve disputes, and satisfy legal, tax, accounting, and rights obligations. Other records are deleted or de-identified when no longer reasonably needed.

6. Your choices and rights

You can decline optional permissions, disconnect providers, sign out, disable background features, clear local data, and request access to or deletion of account information. Some ledger, fraud, payment, tax, or legal records may need to be retained. You can also revoke Google access from your Google Account security settings.

7. Children

The Services are not directed to children under 18. Features involving trading, payments, purchases, artist payouts, or contractual commitments are available only to users legally able to use them.

8. International use

Information may be processed in countries other than the one where you live. Availability is limited to jurisdictions where Whispaw and its providers can support the relevant legal, payment, sanctions, tax, and rights requirements.

9. Changes and contact

We may update this policy as the Services change. Material changes will be identified by a new effective date and, when appropriate, an in-app notice.

For privacy questions or requests, use the support contact shown in the Whispaw application and on its Google OAuth consent screen. Please include “Whispaw privacy request” and do not send passwords, API keys, or broker credentials.