Skip to content
WhispRai
Home About Communities Safety Support
Join Beta
Home About Communities Safety Support Join Beta

WHISPR

Privacy Policy

WPP-001 • Version 1.0

Voice-first. Private by default. Built for meaningful connection.

Version

v1.0

Effective date

29 July 2026

Last updated

29 July 2026

Operator. WhispR is operated by D. K. Pahwa, trading under the WhispRai™ brand.

Table of contents

  1. 1. Introduction
  2. 2. Definitions
  3. 3. Scope
  4. 4. Eligibility
  5. 5. Information We Collect
  6. 6. Legal Bases for Processing
  7. 7. How We Use Information
  8. 8. Voice Recordings and AI Processing
  9. 9. Community Participation and User Content
  10. 10. Notifications and Communications
  11. 11. Analytics and Diagnostics
  12. 12. Sharing and Third-Party Services
  13. 13. Data Retention
  14. 14. Your Privacy Rights
  15. 15. Account Deletion
  16. 16. Security
  17. 17. International Data Transfers
  18. 18. Children’s Privacy
  19. 19. Changes, Contact, and Final Provisions

1. Introduction

Welcome to WhispR. WhispR is a voice-first mobile service offered under the WhispRai™ brand and operated by D. K. Pahwa (“WhispRai”, “we”, “our”, or “us”). It enables adults to privately record personal thoughts, intentionally publish selected recordings to communities, and connect through meaningful voice conversations.

Your trust is fundamental to our mission. This Privacy Policy explains what information we collect, how we use and share it, how we protect it, how long we retain it, and the rights and choices available to you.

By creating an account or using the WhispR mobile application, website, or related services, you acknowledge that you have read and understood this Privacy Policy.

WhispR may make some Services or features available as beta, preview, experimental, early-access, pilot, or pre-release offerings (“Beta Features”). Beta Features may be invitation-based or limited by geography, Account, device, or availability. This Privacy Policy applies to them unless a different privacy notice is presented.

2. Definitions

Account means your registered WhispR user account.

AI Features means optional artificial-intelligence services, such as transcription, summaries, emotion or sentiment analysis, and similar features made available by WhispR.

Beta Feature means a Service or feature identified as beta, preview, experimental, early access, pilot, or pre-release.

Data Principal means the individual to whom Personal Information relates, including a WhispR user.

Data Processor means a service provider that processes Personal Information on our behalf.

Processing means an operation performed on Personal Information, including collection, storage, use, disclosure, transmission, analysis, deletion, or anonymisation.

Personal Information means information that identifies you or can reasonably be linked to you.

Private Recording means a voice recording visible only to you unless you intentionally publish it.

Public Recording means a recording that you intentionally publish to one or more WhispR communities.

Services means the WhispR mobile application, website, backend services, customer support, AI Features, and related functionality operated by WhispR.

Subscription means a paid plan that may provide access to premium functionality, including eligible AI Features when introduced.

Voice Reply means a voice response submitted by another user to a Public Recording.

3. Scope

This Privacy Policy applies whenever WhispR processes Personal Information in connection with the Services, including:

  • the WhispR mobile application and hellowhispr.com website;
  • account registration, authentication, profile, onboarding, and legal acceptance;
  • voice recordings, playback, publishing, unpublishing, and Voice Replies;
  • community feeds, follows, likes, bookmarks, categories, reporting, blocking, and moderation;
  • current and future Subscription and AI Features;
  • push notifications, email, security, and service communications;
  • customer support and Beta Feature feedback; and
  • other WhispR services that refer to this Privacy Policy.

This Privacy Policy does not apply to third-party products, websites, or services that are not owned or controlled by WhispR, even if they are linked from our Services.

4. Eligibility

WhispR is intended only for individuals who are 18 years of age or older. Some Beta Features may be invitation-based or limited to users in India. By using the Services, you confirm that you are at least 18, have the legal capacity to enter into binding agreements, are permitted to use the Services under applicable law, and provide accurate and current information.

We record your age confirmation and the applicable legal-document version, but we do not currently require collection of your full date of birth.

If we determine that an Account belongs to an individual under 18, we may suspend or permanently remove the Account and take reasonable steps to delete associated Personal Information, subject to applicable legal obligations.

5. Information We Collect

5.1 Account Information

When you register or maintain an Account, we may collect:

  • display name, username, and profile details;
  • email address;
  • profile photograph, if provided;
  • authentication provider and account-security information;
  • age-confirmation, Terms, and Privacy Policy acceptance dates and versions;
  • account status and account-deletion choices; and
  • preferences, categories, and followed communities.

5.2 Voice Content and Community Activity

Depending on how you use WhispR, we may process:

  • Private Recordings, Public Recordings, and associated audio files;
  • Voice Replies and associated audio files;
  • recording titles, duration, visibility, categories, moods, timestamps, and community selections;
  • likes, bookmarks, followed communities, and interaction counts;
  • reports, blocks, hidden posts, moderation interactions, and notification history;
  • support requests and Beta Feature feedback; and
  • other content and interactions you choose to provide.

5.3 AI Processing Information

AI Features are planned for a later phase and are intended to be available only through eligible paid Subscriptions. They are not currently available as part of the general free Services. Before activation, we will provide an appropriate feature disclosure and request any consent required by law.

If you later choose to use an AI Feature, eligible recording audio or transcripts may be transmitted to an AI service provider to generate a transcript, summary, emotion label, or related result. Generated outputs and processing status may be stored with the recording. We do not use Private Recordings to train public AI models without permission.

5.4 Device, Technical, and Usage Information

We may automatically collect limited technical and usage information, including:

  • device model, platform, operating system, language, and app version;
  • IP address, network information, and timestamps;
  • push-notification token, platform, and notification interactions;
  • login, password-recovery, security, and authentication events;
  • crash reports, diagnostic logs, performance information, and error categories;
  • features used and general interaction patterns; and
  • information you intentionally include in support requests, feedback, screenshots, or diagnostic submissions.

We seek to collect only information reasonably necessary to provide, improve, maintain, secure, and support the Services.

6. Legal Bases for Processing

For users in India, we process Personal Information for lawful purposes based on consent or other uses permitted under the Digital Personal Data Protection Act, 2023 and applicable rules. Where another jurisdiction applies, we rely on the legal basis recognised there.

  • your freely given, specific, informed, and unambiguous consent where required;
  • processing necessary to provide a feature or service you request;
  • specified legitimate uses permitted by applicable Indian law;
  • compliance with legal obligations and lawful requests; and
  • other lawful grounds recognised in an applicable jurisdiction.

Where processing is based on consent, you may withdraw that consent where permitted by law. Withdrawal does not affect processing already carried out lawfully before withdrawal.

7. How We Use Information

We use Personal Information to:

  • create, authenticate, secure, and manage Accounts;
  • record legal-document acceptance and age confirmation;
  • operate voice recording, storage, playback, publishing, reply, bookmarking, following, community, and notification features;
  • provide paid AI Features if introduced and specifically requested;
  • personalise relevant parts of the experience, including community and content discovery;
  • send account verification, password recovery, account-deletion, security, transactional, and service communications;
  • register devices for push notifications and maintain unread-notification state;
  • respond to support requests, privacy requests, grievances, and Beta Feature feedback;
  • detect, investigate, and prevent fraud, abuse, spam, unlawful activity, and security threats;
  • moderate reported content and enforce our Terms of Service and Community Guidelines;
  • produce aggregated or de-identified statistics and improve quality, reliability, accessibility, and performance; and
  • comply with legal obligations and protect users, WhispR, and the public.

WhispR does not sell your Personal Information.

8. Voice Recordings and AI Processing

8.1 Private Recordings

Recordings are Private by default. Private Recordings are visible only to you, are not searchable by other users, and are not shared with a community unless you explicitly choose to publish them.

8.2 Public Recordings

If you intentionally publish a recording, it becomes visible within the selected community or communities. Other users may listen, respond where permitted, and encounter the recording through feeds, recommendations, search, or other discovery features within WhispR.

You may unpublish or remove content where supported. However, we cannot guarantee removal of copies, quotations, references, caches, or records already created or retained by others where permitted by law.

8.3 AI Features

AI Features are planned premium features and will be optional. If introduced, eligible recording audio or transcripts may be securely transmitted to a disclosed AI provider solely to deliver the requested functionality and for other uses disclosed to you or permitted by law. Transcripts, summaries, emotion labels, emotion scores, and processing status may be stored with the recording.

AI-generated outputs may be inaccurate, incomplete, or inappropriate. They are not medical, mental-health, legal, financial, emergency, or other professional advice. You should exercise your own judgement and seek qualified professional help where appropriate.

9. Community Participation and User Content

WhispR enables users to connect through shared experiences. When you publish content, it becomes visible within the selected community and may appear in Explore, Following, category, recommendation, or similar discovery surfaces. Other users may listen, like, save, report, or submit Voice Replies where permitted.

Moderators may review reported Public Recordings, Voice Replies, profile information, and relevant interaction records to investigate suspected violations. We may restrict visibility, remove content, preserve evidence, warn users, or suspend or terminate Accounts in accordance with our policies and applicable law.

Public voice content may reveal personal characteristics or identify a speaker even when the profile name is removed. Consider this before publishing.

You remain responsible for content you publish. Do not share passwords, authentication credentials, financial-account details, government identifiers, medical records, highly confidential information, or information that could place you or another person at risk.

10. Notifications and Communications

WhispR may send push notifications, emails, or in-app communications relating to:

  • Voice Replies and other relevant community activity;
  • account verification, authentication, password recovery, and security alerts;
  • account-deletion confirmation and grace-period communications;
  • important operational, legal, safety, or policy announcements; and
  • Beta Feature or product updates where permitted by law.

You can manage many notification preferences in WhispR or through your device settings. Essential account, security, and legal communications may still be sent where necessary.

11. Analytics and Diagnostics

Where enabled in the relevant build, we use Firebase Analytics and Firebase Crashlytics to identify and fix defects, monitor stability and security, understand general feature usage, and improve the Services. This may include app performance metrics, crash reports, error logs, device information, identifiers supplied by those services, and usage events.

Where reasonably possible, we use aggregated, pseudonymised, or de-identified information. Diagnostic logs are not intended to contain passwords, authentication tokens, or the content of Private Recordings.

12. Sharing and Third-Party Services

We do not sell Personal Information. We may disclose information in the limited circumstances described below.

12.1 Service Providers

We use carefully selected providers for functions such as authentication, databases, storage, hosting, push notifications, analytics, crash reporting, email delivery, customer support, and future AI processing. These providers may process information on our behalf only as needed to provide their services and subject to appropriate contractual, privacy, and security obligations.

Current core providers include Supabase for authentication, databases, storage, and backend functions; Firebase for analytics, crash reporting, and push-notification infrastructure where enabled; platform authentication providers when selected by the user; and email-delivery infrastructure for account and deletion communications. If paid AI Features are activated, an AI provider such as OpenAI may process eligible audio or transcripts after appropriate disclosure.

12.2 Legal, Safety, and Security Disclosures

We may disclose information when we reasonably believe it is necessary to comply with applicable law, regulation, court order, or lawful government request; protect the rights, property, or safety of WhispR, users, or the public; investigate fraud, abuse, or security incidents; or enforce our agreements.

12.3 Business Transfers

If WhispR is involved in a merger, acquisition, investment, financing, restructuring, sale of assets, insolvency, or similar transaction, information may be transferred as part of that transaction, subject to applicable law and appropriate notice where required.

13. Data Retention

We retain Personal Information only for as long as reasonably necessary to provide the Services, maintain Account functionality, comply with legal and regulatory obligations, resolve disputes, enforce agreements, and protect platform security.

Retention periods vary by information type and context. In general:

  • Account, profile, legal-acceptance, preference, and content information is retained while your Account is active and while needed to provide the Services;
  • individual recordings, Voice Replies, bookmarks, likes, follows, notifications, and similar user-scoped information remain until deleted, removed, anonymised, or affected by Account deletion, subject to lawful exceptions;
  • when you request Account deletion, the Account enters a 30-day grace period during which you may cancel the request;
  • at the end of the grace period, Private Recordings and profile data are deleted; Public Recordings and public Voice Replies are either deleted or preserved as “Deleted User” according to the choice presented when deletion is requested;
  • device tokens, user-scoped notifications, bookmarks, likes, follows, blocks, hidden posts, and eligible reports or support records are deleted or detached during permanent deletion;
  • non-identifying account-deletion audit results, aggregated analytics, and records required for security, fraud prevention, disputes, or legal compliance may be retained for an appropriate period; and
  • backup copies may persist for a limited operational cycle before deletion or overwriting under the applicable provider’s backup process.

When information is no longer required, we delete, anonymise, or securely dispose of it in accordance with applicable law and our retention practices.

14. Your Privacy Rights

Depending on your location and applicable law, you may have rights to:

  • obtain information about Personal Information being processed and the identities or categories of Data Processors or recipients, as applicable;
  • access Personal Information we hold about you;
  • correct, complete, or update inaccurate or incomplete information;
  • request erasure of eligible information;
  • withdraw consent where processing is based on consent, with comparable ease;
  • object to or restrict certain processing where applicable law provides that right;
  • request a portable copy of eligible information where applicable;
  • nominate another individual to exercise applicable rights in the event of death or incapacity, as provided by Indian law;
  • use our grievance-redressal mechanism; and
  • lodge a complaint with the Data Protection Board of India or another competent authority after exhausting applicable internal remedies.

You may exercise some rights through Account settings where available. For other requests, contact us using Section 19.2. We may request reasonable information to verify your identity and protect your Account before fulfilling a request.

15. Account Deletion

You may request deletion of your WhispR Account through the Services where available or by contacting support.

Deletion is not immediate. After confirmation, your Account enters a 30-day grace period. During that period, access is restricted and you may cancel deletion through the available process. After the scheduled date, permanent deletion cannot be reversed.

When permanent deletion is completed:

  • access to the Account and active sessions is revoked;
  • profile information, email association, avatar, and other user-scoped Account data are deleted or anonymised where reasonably practicable;
  • Private Recordings and associated storage objects are deleted;
  • by default, Public Recordings and public Voice Replies are also deleted; however, if you expressly choose preservation during deletion, eligible public content remains attributed to “Deleted User” with Account identity removed;
  • bookmarks, notifications, device tokens, likes, follows, blocks, hidden posts, and eligible user-scoped safety or support records are deleted or detached; and
  • limited non-identifying audit results and records required for legal compliance, dispute resolution, fraud prevention, security, or enforcement may be retained.

Preserved public voice content may still identify you by your voice even after profile information is removed. Copies or references may also remain where content has already been lawfully quoted, cached, archived, retained in backups, or preserved for legitimate moderation, security, or legal purposes. A new Account created with the same email does not regain ownership of preserved content.

16. Security

We implement reasonable administrative, technical, and organisational safeguards designed to protect Personal Information from unauthorised access, alteration, disclosure, misuse, loss, or destruction. Measures include or may include secure authentication, encrypted transmission, database and storage access policies, role-based access, restricted service credentials, monitoring, software updates, and backup and disaster-recovery practices.

No internet-connected system is completely secure, and we cannot guarantee absolute security. You should use a strong, unique password, protect your credentials and devices, and promptly notify us of suspected unauthorised access.

If we become aware of a security incident affecting Personal Information, we will investigate, contain, and respond as appropriate, including notifying affected individuals and authorities where required by law.

17. International Data Transfers

WhispR and its service providers may process or store information in countries other than your country of residence. Those countries may have different data-protection laws.

Where required, we take reasonable steps to use appropriate safeguards, such as contractual protections or other legally recognised transfer mechanisms, so Personal Information continues to receive protection consistent with applicable law. We will also comply with any transfer restriction notified by the Government of India.

18. Children’s Privacy

WhispR is intended exclusively for individuals aged 18 or older. We do not knowingly permit or collect Personal Information from anyone under 18. Users must affirm the minimum-age requirement during onboarding; we currently do not collect full dates of birth.

If we learn that an individual under 18 has created an Account or provided Personal Information, we may suspend or terminate the Account and take reasonable steps to remove associated information, subject to applicable legal obligations. If you believe a minor is using WhispR, contact childsafety@hellowhispr.com (or support@hellowhispr.com).

19. Changes, Contact, and Final Provisions

19.1 Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the Services, providers, technology, security practices, business operations, or applicable law. We will assign a new policy version, update the “Last updated” date and, where required or appropriate, provide notice through the app, email, or website. Material changes may require renewed acceptance before continued use.

19.2 Contact Us

For privacy questions, requests, concerns, or complaints, contact:

Operator and Grievance Officer: D. K. Pahwa
Product: WhispR
Brand: WhispRai™
Email: support@hellowhispr.com
Website: https://hellowhispr.com

Privacy enquiries and grievances may be submitted by email. We aim to acknowledge intermediary-related grievances within 24 hours and resolve them within the period required by applicable law. Certain urgent complaints, including qualifying intimate-content or impersonation matters, may be handled on an accelerated timeline. Privacy grievances will be handled through our internal mechanism before escalation to a competent authority where applicable.

19.3 Final Provisions

Nothing in this Privacy Policy limits rights that cannot lawfully be limited. If any provision is held invalid or unenforceable, the remaining provisions will continue in effect.

This Privacy Policy should be read with WhispR’s Terms of Service, Community Guidelines, Child Safety Standards, and other policies published from time to time. If this Privacy Policy conflicts with mandatory applicable law, that law prevails to the extent of the conflict.

WhispRai™

Voice. Share. Connect. A safe place where real people share real experiences.

Product

  • How It Works
  • Communities
  • Download App
  • Join Beta

Company

  • About Us
  • Our Mission
  • Our Story
  • Careers
  • Blog

Support

  • Support
  • Contact Us
  • Report a Bug
  • Help Center
  • Trust & Safety

Legal

  • Privacy Policy
  • Terms of Service
  • Community Guidelines
  • Account Deletion
  • Copyright
  • AI Disclosure

© 2026 WhispRai™. All rights reserved.

English

WhispRai™ is a trademark. WhispR is the product and visual brand.