Privacy

Privacy Policy

Last Updated: June 17, 2026

Summary of Key Points

What data do we collect? We collect only the minimum account metadata needed to operate: your email, subscription status, and a hardware fingerprint for license enforcement. Your audio, screen captures, and chat content are processed locally or stored on our servers only for chat persistence — we do not sell, rent, or share this content.

Do we use your data for AI training? No. We do not use your data to train or improve any AI models.

Where is data processed? Audio transcription and screen analysis happen locally on your machine. AI assistance requests are sent directly from your device to your chosen third-party AI provider (OpenAI, Google, etc.) — they never pass through WhisprBar servers.

Do we use cookies? No tracking cookies. We use only essential browser storage for authentication session management.

What are your rights? You can access, correct, delete, or export your data at any time. You may also withdraw consent and lodge a complaint with your local data protection authority. See the Your Rights section for details.

Architectural Principle: Local-First Processing

The core software architecture of WhisprBar is engineered to be local-first. This means that by default, all primary technical operations — including audio capture, real-time microphone monitoring, system sound extraction, desktop screen content parsing, overlay rendering, and localized transcription compilation — occur entirely within the volatile memory (RAM) and local storage environment of your physical machine.

The Company does not maintain, control, operate, or lease backend application databases designed to ingest, monitor, copy, or retain your raw audio feeds, transcript files, or screenshot captures on remote cloud servers. Your content stays on your device.

Data Categories & Handling

Audio Streams (Microphone & System Audio)

When you activate the communication assistance features, the Platform accesses your local machine's microphone input hardware and system audio routing layers. These continuous audio streams are converted into transient digital data segments solely for the purpose of local speech-to-text conversion. These streams are held transiently in local cache or temporary volatile memory. They are never transmitted to WhisprBar servers.

Screen Capture & Visual Content

To enable contextual overlay support, the Platform may take rapid, local, high-frequency screenshots or scan designated display coordinates. This visual information is read locally to perform analysis and provide contextual assistance. This data remains completely confined to your local workstation environment and is overwritten continuously during the application session.

Local Cache & Data Deletion

Any local log files, historical prompt-response pairs, or application configuration metrics generated during a session are stored exclusively within the local application directory on your machine. You can clear, delete, or wipe these local historical caches at any time through the purging mechanism inside the software settings or by manually deleting the application data subfolder.

AI Processing

WhisprBar uses a Bring Your Own Key (BYOK) model. When you use the AI assistance features, your text inputs and transcribed content are sent directly from your machine to the third-party AI provider whose API key you have configured (e.g., OpenAI, Google Gemini). These requests do not route through or stop at any intermediary servers controlled by WhisprBar.

WhisprBar does not store the content transmitted to or from the AI provider during active processing sessions. The privacy and data retention policies of your chosen AI provider govern how they handle data transmitted through their services. It is your responsibility to review and accept those terms.

Cookies & Local Storage

WhisprBar does not use tracking cookies, analytics cookies, or third-party advertising cookies.

We use only essential browser local storage to maintain your authenticated session and application preferences. This data is stored locally in your browser, is not accessible to third parties, and is cleared when you log out. No cookie consent banner is required because we do not deploy any non-essential tracking mechanisms.

Account Metrics Collected

To maintain platform security, subscription enforcement, and license authentication, the Company collects only the absolute minimum amount of metadata necessary to operate the Platform. This is limited to:

  • Your registered account email address and account credential hashes.
  • Subscription billing status indicators received from our third-party payment processors (Razorpay).
  • Hardware fingerprint identifiers: desaturated cryptographic hashes of specific local hardware component IDs (e.g., CPU, motherboard, or MAC address combinations) used exclusively to enforce the single-machine license binding rule and detect multi-device piracy, account sharing, or emulator usage.
  • Usage metrics: speech-to-text processing duration (minutes) and token usage counts, used exclusively for plan limit enforcement.

We do not sell your personal information. We do not use your data for training AI models. We do not engage in targeted advertising.

Chat Storage

Your conversation history — including messages, AI responses, timestamps, and any attached files — is stored on our servers to provide persistent chat history across sessions, enable the dashboard and portal, and allow you to review past transcripts.

You can delete individual conversations or clear your entire chat history at any time through the application settings. Deletion is permanent and removes all associated message data from our servers.

Data Retention

We retain your data only as long as necessary to provide the Platform services:

  • Account information (email, subscription status, hardware fingerprint): Retained until you delete your account or deactivate your license.
  • Chat history: Retained until you delete individual conversations or clear your entire history. You control the deletion timeline.
  • Backups: Encrypted backups containing account data are retained for a maximum of 90 days after deletion, after which they are permanently purged.
  • Payment records: Retained as required by applicable tax and accounting laws (typically 5-7 years).
  • Local cache: Resides on your device and is cleared at your discretion via the application settings.

Third-Party Processors

We engage the following third-party service providers to operate the Platform. Each provider processes data only on our instructions and is contractually bound by data processing agreements consistent with this Privacy Policy:

When you use the BYOK AI feature, your data is transmitted directly to the third-party AI provider you have configured. WhisprBar is not a data processor for those transmissions.

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right to Access — Request a copy of the personal data we hold about you.
  • Right to Rectification — Request correction of inaccurate or incomplete data.
  • Right to Erasure (Right to be Forgotten) — Request deletion of your personal data.
  • Right to Data Portability — Request a machine-readable export of your data.
  • Right to Restrict Processing — Request limitation of how we use your data.
  • Right to Object — Object to our processing of your data.
  • Right to Withdraw Consent — Withdraw consent at any time where processing is based on consent.
  • Right to Lodge a Complaint — File a complaint with your local data protection authority.

To exercise any of these rights, contact us at support@whisprbar.com. We will respond within 30 calendar days. We may need to verify your identity before processing your request.

International Compliance

Legal Bases for Processing (GDPR — European Economic Area)

If you are located in the European Economic Area (EEA), we process your personal data under the following lawful bases:

  • Contract performance — To provide the Platform services under our Terms of Service (account creation, license management, subscription billing).
  • Legitimate interest — For security, fraud prevention, and license enforcement (hardware fingerprinting, usage monitoring).
  • Legal obligation — To comply with applicable tax, accounting, and regulatory requirements (payment record retention).
  • Consent — Where you have explicitly consented (e.g., optional features you enable).

International Data Transfers

Your account data is stored on servers located in the United States (via Supabase). When we transfer data from the EEA, UK, or other jurisdictions with transfer restrictions, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, or equivalent adequacy mechanisms, to ensure an equivalent level of protection.

California Consumer Privacy Act (CCPA)

If you are a California resident, we disclose the following:

  • We do not sell your personal information as defined by the CCPA.
  • We do not share your personal information for cross-context behavioral advertising.
  • You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you.
  • You have the right to request deletion of your personal information, subject to certain exceptions.
  • You have the right to non-discrimination for exercising your CCPA rights.

India — Digital Personal Data Protection Act (DPDP Act)

As an Indian entity, we comply with the DPDP Act, 2023. Your data is processed lawfully and for specified purposes only. You have the right to access, correct, and erase your personal data as described in the Your Rights section.

Security

We implement appropriate technical and organizational measures to protect your data:

  • All data transmitted between your device and our servers is encrypted using TLS 1.3.
  • Data at rest is encrypted using industry-standard encryption (AES-256).
  • Access to production systems is restricted to authorized personnel only, with multi-factor authentication required.
  • We conduct periodic security reviews and penetration testing.

In the event of a data breach that affects your personal data, we will notify you without undue delay (within 72 hours where required by applicable law) and take appropriate remedial steps.

Minor Protection

The Platform is strictly prohibited to individuals under eighteen (18) years of age. We do not knowingly or intentionally collect, track, aggregate, or request data from anyone under the age of 18. If we discover that an individual under 18 has managed to bypass account creation limits, we will immediately delete all corresponding account metrics and revoke subscription access permanently.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of the Platform after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at support@whisprbar.com.