1. Information We Collect
Account and authentication information
- Email address, display name, avatar URL, login method, email verification status, session tokens, and account security status.
- If you sign in with Google, we receive basic account information returned by Google, such as your email address, name, and profile image.
- Registration, login, password reset, verification code, and email verification actions may generate security logs and verification records.
Audio, transcription, subtitle, and translation information
- Audio data that you actively provide or authorize us to capture for real-time transcription, floating subtitles, media subtitles, live interpretation, or audio file transcription.
- Generated transcripts, translations, interpreted speech audio, summaries, export files, session status, processing duration, and model usage information.
- History record metadata, including session title, source type, language, model, timestamps, billing usage, and audio file access URLs.
Device and runtime information
- Device operating system version, app platform, app version, distribution channel, network request information, error logs, API status, WebSocket connection status, and performance metrics.
- Local model download status, model file size, download progress, and on-device offline capability status.
- Firebase app instance identifiers, a random app-installation identifier, crash and ANR diagnostics, non-content product events, notification delivery metadata, and an FCM registration token used to route push notifications to this app installation. The random installation identifier is not a hardware identifier.
Payment and subscription information
- Order IDs, purchase tokens, product IDs, subscription status, renewal status, and transaction verification results returned by Google Play.
- Whisp-generated point balances, bills, usage records, top-up records, membership cycles, and quota reset times.
2. App Permissions
- Microphone: Used for speech transcription, floating subtitles, and live interpretation.
- Screen recording / media projection: Used to capture system playback audio for floating subtitle or live interpretation floating-window modes. This permission is granted through the Android system prompt.
- Display over other apps: Used to show real-time subtitles or live interpretation subtitles above other apps.
- Media access: Used when you choose local audio or video files for media subtitles or audio file transcription.
- Notifications: Used for model downloads, background transcription status, floating subtitle service status, and necessary service reminders.
- Vibration: Used for lightweight haptic feedback during button actions or state changes.
- Network: Used to connect to Whisp servers, model providers, object storage, and Google Play billing verification services.
Whisp does not collect microphone audio, screen audio, or local media files unless you actively start the relevant feature and grant the required system permission.
3. How We Use Information
- To create and maintain your account, complete login, verify email, reset passwords, and manage sessions.
- To provide real-time transcription, subtitle display, translation, interpreted speech, summaries, exports, and history records.
- To calculate model usage, Credit consumption, subscription quota, top-up balance, and bill status.
- To diagnose crashes, API errors, WebSocket disconnections, model timeouts, upload failures, and other service issues.
- To detect abnormal requests, abuse, payment fraud, API attacks, and account security risks.
- To improve product experience, model selection, performance, reliability, and service quality.
- To deliver push notifications you permit. An installation can be registered without an account for offline use and is linked to your account only while you are signed in. Signing out removes that account link.
- To measure non-content feature funnels such as session starts, mode changes, model actions, exports, and purchase flow status.
4. Audio and Content Processing
- Real-time audio may be transmitted to Whisp servers over encrypted network connections and processed by the model selected for your session.
- Audio file transcription may upload the source file or processed audio before it is submitted for transcription.
- Session history may store audio archives, transcripts, translations, interpreted speech audio, summaries, and export results so that you can review them later.
- If you delete a history record or request account data deletion, we will delete or anonymize related data within a reasonable period, subject to backup, security, billing, dispute resolution, and legal requirements.
5. Third-Party Services
To provide the service, we may use the following third-party services or infrastructure providers when necessary:
- OpenAI: Text translation, summaries, and speech generation when the selected online feature uses an OpenAI model.
- OpenRouter: Routes selected online transcription and language-model requests to the model provider chosen by Whisp.
- Microsoft MAI: Processes online speech transcription through the MAI-Transcribe model.
- Google AI / Gemini: May process translation or summary requests when a Gemini model is selected or used as a configured fallback.
- Qualcomm AI Hub and Whisp model distribution hosts: Provide optional on-device model packages. Download requests include ordinary network metadata, but offline inference content remains on your device.
- Cloudflare R2: Object storage for encrypted audio files, generated exports, and related service assets; only public avatars are stored without private-object encryption.
- Google Sign-In: Google account authentication.
- Google Play Billing: Subscriptions, top-ups, order verification, and payment status synchronization.
- Google Firebase: Analytics for non-content product events, Crashlytics for crash, ANR, and non-fatal diagnostics, and Cloud Messaging for app-instance push notification delivery. Whisp does not intentionally include transcripts, translations, email addresses, filenames, or FCM tokens in Analytics event parameters.
- Email service providers: Registration verification, verification codes, and password reset emails.
We only provide third parties with the information necessary to perform the requested function and expect them to protect such information according to applicable requirements.
6. Data Storage and Security
- Server-side data may be stored in PostgreSQL, Redis, and Cloudflare R2 for account, session, history, billing, and task processing.
- Private audio and generated service objects are encrypted in Cloudflare R2 with a server-held AES-256 customer-provided key and are only streamed through authenticated service endpoints.
- Data transmission uses encrypted HTTPS/WSS connections where applicable. Sensitive tokens are not displayed to ordinary users in plain text.
- We use access control, logging, least-privilege permissions, monitoring, and operational safeguards to reduce the risk of unauthorized access, alteration, loss, or disclosure.
- No internet service can guarantee absolute security. If you believe there is a security issue, please contact us promptly.
7. Data Retention
- Account data is retained while your account remains active.
- Basic-plan history records, audio archives, subtitles, translations, and summaries are retained for up to 15 days. A paid plan may provide longer or unlimited retention while active. You may delete individual records earlier.
- Bills, orders, usage records, and security logs may be retained for payment verification, dispute handling, compliance, audit, and anti-abuse purposes.
- Temporary tasks, queue messages, caches, and short-term logs are automatically expired or cleaned up according to system policies.
8. Your Choices and Rights
- You can view history records, billing records, account status, model settings, and subscription status in the App.
- You can delete history records that you no longer need. You can permanently delete your account from Account details in the App, or use our account deletion page.
- You can disable microphone, notification, overlay, or media permissions in Android system settings. Some features may stop working after permissions are disabled.
- You can disable notification permission in Android settings. Uninstalling the App removes the local FCM registration and Firebase app instance data from the device; Firebase may retain previously collected diagnostics or aggregate analytics according to its policies and applicable law.
- You can manage subscriptions, cancel renewals, and view payment records through Google Play.
9. Children
Whisp is intended for users who have the legal capacity to use the service. Minors should use Whisp only with the consent and guidance of a parent or guardian. If a guardian believes that a minor has provided personal information to us, please contact us.
10. Changes to This Policy
We may update this Privacy Policy due to product changes, service migration, third-party service changes, or legal requirements. For material changes, we will provide notice through the App, website, or other reasonable means. The updated policy becomes effective on the date stated on this page.
11. Contact Us
If you have questions about this Privacy Policy, account data, history records, audio data, or billing, contact us:
- Service website: https://whispserver.transfers.club
- Email: zs19971226@gmail.com