WhishperLock WhishperLock
  • Home
  • User Guide
  • Support
  • Privacy
  • Terms

Privacy Policy

Last updated: May 30, 2026

WhishperLock (“we,” “our,” or “the App”) is a secure messaging application developed by Aaron Yang. This Privacy Policy explains how we collect, use, store, and protect information when you use the iOS app and related services.

1. Summary

WhishperLock is designed for end-to-end encrypted private messaging, encrypted voice calls, and encrypted attachments. Message content, file payloads, and location shares are encrypted on your device before transmission. Our servers store and relay ciphertext without the ability to decrypt your conversations.

2. Information We Collect

2.1 Account information

  • Registration: Username, email address, and password (passwords are hashed on the server; we do not store plaintext passwords).
  • Sign in with Apple: If you use Apple Sign-In, we receive the identifiers and account information Apple provides according to your Apple ID settings.
  • Profile: Display name and profile details you choose to provide.

2.2 Messages and chat data

  • Chat messages are encrypted on your device using AES-256-GCM with room-specific keys derived on-device.
  • Our backend stores encrypted message payloads (ciphertext) to enable delivery and history sync. We cannot read decrypted message content.
  • Self-destruct message metadata (timers, read state) may be stored to support disappearing messages.

2.3 Encrypted attachments and location

  • Files and images you send are encrypted on-device before upload. Encrypted blobs may be stored in cloud object storage; decryption keys are not sent to the server.
  • Location shares are encrypted inside the message payload. We do not use your location for advertising or unrelated analytics.

2.4 Voice calls

  • Voice call audio is encrypted on-device and transmitted in real time over WebSocket signaling.
  • Call audio is not recorded or stored on our servers. Packets are forwarded and discarded.
  • VoIP push tokens are used only to wake the app for incoming calls via Apple PushKit and CallKit.

2.5 Device and technical data

  • APNs device token — for message and friend-request notifications.
  • VoIP push token — for incoming call notifications when the app is not active.
  • Connection metadata — such as online presence, room membership, and timestamps needed to operate chat and calls.
  • Authentication tokens — session tokens stored securely in the iOS Keychain on your device.

2.6 Data stored only on your device

  • Encryption keys derived for chat rooms (iOS Keychain).
  • Biometric authentication (Face ID / Touch ID / Optic ID) is processed by iOS; we do not receive your biometric data.
  • Local app preferences (e.g., notification toggles).

2.7 Subscriptions

Purchases are processed by Apple through the App Store. We receive subscription status from StoreKit to enable app features. We do not receive or store your full payment card details.

3. How We Use Information

  • Provide account registration, login, and session management.
  • Deliver, sync, and display encrypted messages between you and your friends.
  • Operate friend requests, chat rooms, and real-time presence.
  • Establish encrypted voice calls and deliver VoIP push notifications.
  • Send push notifications you have authorized (messages, friend requests, calls).
  • Manage subscriptions and free trial eligibility.
  • Maintain security, prevent abuse, and improve reliability of the service.
  • Respond to support requests you send to us.

4. Legal Bases (where applicable)

Depending on your region, we process data based on: performance of our contract with you (providing the service), your consent (notifications, microphone, location when you use those features), and legitimate interests (security and fraud prevention).

5. Sharing with Third Parties

  • Apple — Sign in with Apple, App Store purchases, Push Notifications, PushKit (VoIP), and CallKit.
  • Cloudflare — Application backend (Workers, D1 database, WebSocket, and related infrastructure).
  • Cloud storage — Encrypted attachment blobs (e.g., Cloudflare R2) without decryption keys.

We do not sell your personal information. We do not use your message content for advertising.

6. Data Retention

  • Account and profile data are retained while your account is active.
  • Encrypted messages are retained until deleted by users or account deletion.
  • Self-destruct messages are designed to expire after the timer you set once read.
  • Voice call streams are not retained after the call ends.
  • When you delete your account, we delete associated profile, messages, friendships, and notification records as described in the app.

7. Security

We use TLS for network transport, server-side password hashing, JWT session tokens, and client-side AES-256-GCM encryption. Keys are stored in the iOS Keychain with device-only accessibility where supported. No security method is perfect; you are responsible for keeping your device and credentials secure.

8. Your Rights and Choices

  • Access and update: Edit your profile in the Profile tab.
  • Delete account: Profile → Delete Account (permanent; removes messages and friends).
  • Notifications: Toggle in-app under Notification Settings or revoke in iOS Settings → WhishperLock → Notifications.
  • Microphone / Location / Face ID: Manage in iOS Settings → WhishperLock.
  • Subscriptions: Manage or cancel in iOS Settings → Apple ID → Subscriptions.

Depending on your jurisdiction, you may have additional rights (access, portability, erasure, objection). Contact us at aaronyang470128@hotmail.com.

9. Children’s Privacy

WhishperLock is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.

10. International Transfers

Data may be processed in countries where our infrastructure providers operate. We rely on appropriate safeguards required by applicable law.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change. Continued use of the App after changes constitutes acceptance of the updated policy.

12. Contact Us

Aaron Yang — WhishperLock
Email: aaronyang470128@hotmail.com
Support: Support page

Home Privacy Policy Terms of Service Support Contact GitHub

© 2026 WhishperLock. All rights reserved.