Legal

Privacy Policy

Effective: [DATE — after legal review]

The short version

Whist has no ads, no trackers, and no analytics — not in the app, not on this site. Your messages live on your device in an encrypted database. Your profile stays on your device. Our servers carry messages between devices as encrypted data and delete them once delivered.

Most privacy policies are long because the product collects a lot. This one is short because we collect as little as the product can run on — and where something isn’t finished yet, we say so instead of claiming it.

Who we are

Whist is made by Buildable Labs Studio. The data controller responsible for Whist under the GDPR is [DATA CONTROLLER — FULL LEGAL NAME], [CITY], Romania.

For anything in this policy: [email protected].

What this covers

This policy covers the Whist iOS app and the whistapp.com website. If the app’s practices ever diverge from what’s written here, the policy gets updated first — the App Store listing links to this page.

The website

The site has no accounts, no forms, no cookies, and no analytics. It is served by Cloudflare Pages, which processes standard technical logs (IP address, user agent, pages requested) to deliver and protect the site — we don’t use those logs to identify anyone. Cloudflare’s practices are described in their privacy policy.

What stays on your device

Your profile — display name, phone number, email, photo, bio, occupation — is stored on your device with iOS file protection and is excluded from device backups. We do not upload it. Your contacts’ details likewise stay local.

Your messages and media are stored on your device in a database encrypted with SQLCipher (AES-256), with the key held in your device’s Keychain. Your cryptographic identity keys are generated on the device and never leave it.

What our servers handle

To move a message from your device to someone else’s, our servers (hosted on Cloudflare, with data processed in the EU where the platform allows) temporarily hold:

Messages in transit — as encrypted data, deleted on delivery. Undelivered messages are deleted after 30 days, no exceptions. Verification codes — stored hashed, used once, rate-limited. Invite codes — the code, its expiry, and which circle it belongs to. Public key material — the public keys other members need to start an encrypted conversation with you. Routing metadata — the minimum needed to deliver a message to the right device. We do not build social graphs from it, sell it, or share it.

Encryption, honestly

What is true today, and verified: everything stored on your device is encrypted at rest, your identity keys are generated and kept on-device, and deleted messages are actually deleted — not hidden.

End-to-end encryption of messages between devices is in active development on the MLS protocol (RFC 9420). We will not describe Whist as end-to-end encrypted until it ships, and when it first ships it will be labeled as beta and unaudited until an independent review says otherwise. If a claim isn’t on this page, don’t assume it.

Payments

Subscriptions are handled entirely by Apple through the App Store. We never see your payment details. Apple tells us only which subscription tier is active so the app can unlock it. Apple’s handling of your data is covered by Apple’s privacy policy.

Retention and deletion

Disappearing messages are deleted from your device — the data, not just the row — on a sweep that runs at least every minute, and the matching encrypted media is deleted from our servers. Deleting your account from Settings destroys your keys, your messages, your circles, and your profile on that device, and asks our servers to delete what they hold for you.

One honest limit: a message that has already been delivered to someone else’s device is on their device. No messenger can reach into another person’s phone, and we won’t pretend otherwise.

Your rights

Under the GDPR you can ask for access to, correction of, or deletion of the data we hold about you, ask for it in a portable format, object to processing, and withdraw consent. Because almost everything lives on your device, most of these you can do yourself in the app — but email us and we’ll handle the rest: [email protected].

You can also lodge a complaint with the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or your local data protection authority.

Legal bases

We process the data above to provide the service you signed up for (contract — Art. 6(1)(b)), to keep the service secure and abuse-free (legitimate interest — Art. 6(1)(f)), and where the law requires it (legal obligation — Art. 6(1)(c)). We don’t process anything for advertising, because there isn’t any.

Age

Whist requires you to be at least 16 — the age of digital consent in Romania. We don’t knowingly hold data on anyone younger; if you believe we do, email us and it will be deleted.

Changes

If this policy changes, the update gets posted here with a new effective date. If a change actually matters, we’ll call it out plainly rather than bury it.