What we collect
- — An anonymous session token, and a one-way hash of your IP (not the IP itself) used for abuse prevention
- — An emotional fingerprint derived from what you type when you arrive: an inferred mood, topic, and a few behavioral signals, used to find your match
- — Conversation outcome signals (whether it went well, aggregate only — no message content)
- — If a conversation ever shows signs of real distress, a content-free safety-event record (a score and a timestamp, never the words that triggered it)
- — If you choose to save a moment as a shareable card, or send a “last message” into the world, that specific text you chose to share — nothing else from the conversation
- — If you and the person you talked to both choose to save the connection, a token linking your two anonymous sessions so you can find each other again — see “Reconnecting” below
- — If you submit feedback, the message you wrote and which category you picked — kept indefinitely, since it's something you chose to tell us
What we don't collect
- — Your name, email, phone number
- — Your raw IP address (only a one-way hash, which can't be reversed to your IP)
- — Your location
- — The content of your conversations, unless you deliberately choose to share a piece of one (see above)
Advertising
We use the Meta (Facebook) Pixel to measure how people find WHISPAR and whether our ads are working. This means Meta receives standard browsing signals from your device — which pages you visit and when — the same way it would on most websites. It never receives anything about your conversations, your emotional fingerprint, or anything you type. If you arrived here from a Facebook or Instagram ad, Meta already has some of this information regardless of this site.
How conversations work
Your messages live in Redis with a 25-minute TTL. When the timer expires, they are gone from storage. Nothing is written to our database. If a conversation trips our safety monitor, an AI model reads the recent messages in that moment to check for signs of crisis — but only a numeric score is ever kept afterward, never the messages themselves.
Reconnecting
After a conversation ends, you can choose to save it. If the person you talked to makes the same choice, we create a token pairing your two anonymous sessions so you can talk again later. This token doesn't expire on its own — it lasts until you use it or it's removed. It never reveals who either of you is; it only lets the app recognize “these two specific anonymous sessions agreed to reconnect.”
Data retention
- Conversations: 25 minutes maximum, never written to our database at all
- Emotional fingerprints: deleted within about 30 minutes of expiring (a 35-minute window)
- Outcome signals: deleted within about 30 minutes of expiring (a 30-day window), aggregate and anonymous
- Saved cards / last messages you choose to share: kept for the period we tell you at the time (currently up to 30 days for cards, 7 days for a shared last message)
- Reconnect tokens: kept until used or removed, since removing them would break reconnecting for both people
- Safety-event records and basic usage analytics: kept longer, to keep the ban system and matching working correctly — never conversation content
- Feedback you submit: kept indefinitely, so it can actually inform what we build
Contact
privacy@xeres.tech