Last updated: 7 August 2026
Welcome to Whispr ("we", "us", "our"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use the Whispr mobile application (the "App").
Whispr is operated by Greenvision Labs, a partnership firm registered in India ("Company"). By using Whispr, you agree to the collection and use of information in accordance with this policy.
Information you provide directly:
Information collected automatically:
We collect and process only the data reasonably necessary for these stated purposes, and we do not use your data for purposes beyond what is described in this Policy.
Text messages sent between matched users are end-to-end encrypted. This means the content of your messages cannot be read by Whispr, our staff, or any third party in transit. Messages sent in random "ephemeral" chats are permanently deleted from our servers when either user ends the chat. Messages in ongoing conversations with mutually connected users ("Whispr'd" contacts) are retained until either user deletes the conversation.
Photos and voice messages shared in chat are stored on our servers (Firebase Storage) but are not end-to-end encrypted, and access is restricted to the two participants in that conversation only. Photos and voice messages sent as "view once" media are permanently deleted after being viewed, or after their set timer expires, whichever comes first.
Optional encrypted key backup. Whispr allows you to optionally back up your encryption key by setting a passphrase known only to you. If you choose to enable this feature, an encrypted copy of your key — protected by your passphrase — is stored in our systems so you can recover access to your message history after reinstalling the app or switching devices. We never see, store, or have any way to recover your passphrase; if you forget it, the backup cannot be decrypted or recovered by us or anyone else. This feature is off by default and entirely optional.
Whispr allows you to upload up to 6 gallery photos. These photos are only visible to another user once you have both mutually chosen to "Whispr" each other. We do not disclose to a user whether someone has Whispr'd them until the connection becomes mutual.
We do not sell your personal information. We may share information with:
Depending on your location, you may have the right to:
You can delete your account at any time from within the App via Profile → Settings → Delete Account, or via our web-based account deletion page. You can export a copy of your profile data at any time from within the App via Profile → Settings → Export My Data. You can also exercise these rights by contacting us at the email below.
If you are located in India, your personal data is processed in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"). Under the DPDP Act you are a "Data Principal" and have the right to access, correct, and erase your personal data, to withdraw consent at any time, and to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
We have appointed a Grievance Officer to address complaints relating to the processing of your personal data. You may contact our Grievance Officer at privacy@getwhisprd.com. We will acknowledge and address grievances within the timelines prescribed under applicable law.
If you are a California resident, you have certain rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), including the right to:
To exercise any of these rights, contact us at privacy@getwhisprd.com. We may need to verify your identity before fulfilling certain requests.
Whispr is intended for users aged 18 and over. We do not knowingly collect data from anyone under 18. If we become aware that a user is under 18, we will suspend and delete the account. See also the Child Safety section of our Terms of Service.
We use industry-standard security measures including encryption of messages, secure authentication, and Firebase App Check to prevent unauthorized access to our systems. However, no method of electronic transmission or storage is 100% secure.
Your data may be processed on servers located outside your country of residence, including in the United States (via Google Firebase infrastructure). We take steps to ensure appropriate safeguards are in place for such transfers, consistent with applicable data protection law in your region.
We may update this Privacy Policy from time to time. We will notify you of material changes via the App or by email. Continued use of the App after changes constitutes acceptance of the updated policy.
General privacy queries: privacy@getwhisprd.com
Grievance Officer (India / DPDP Act): privacy@getwhisprd.com
Child Safety Point of Contact: privacy@getwhisprd.com