Privacy Policy
Last updated: 27 July 2026
Wisp is a peer-to-peer messenger built so that no one — including the people who make it — can read your messages or see who you talk to. This policy explains, plainly, what that means for your data.
The short version: Wisp has no accounts and no server that we control which holds your messages, your contacts, or your identity. We do not collect, store, sell, or share your personal data. There are no ads, no analytics, and no third-party trackers.
Who we are
Section titled “Who we are”Wisp (“the app”) is an independent, open-source project. For any question about this policy or your privacy, contact mahdi.business7@gmail.com.
What Wisp does not collect
Section titled “What Wisp does not collect”We, the developers, do not receive or store any of the following:
- Your name, email address, or phone number — Wisp never asks for them.
- Your messages or their contents.
- Your contacts or your list of conversations.
- Your identity keys or seed phrase.
- Usage analytics, device advertising identifiers, crash telemetry, or location.
There is no sign-up and no account. Your identity is a cryptographic key generated on your device.
What stays on your device
Section titled “What stays on your device”Wisp stores the following locally on your device only. It is never uploaded to a server we control:
- Your identity keys, derived from a 12-word recovery phrase, held in your device’s secure storage.
- Your contacts and their verification status.
- Your message history, in a local database on the device.
If you uninstall the app, this local data is removed by the operating system. You can also “log out,” which erases your keys from the device.
What the network can and cannot see
Section titled “What the network can and cannot see”To deliver messages when a direct connection isn’t possible, Wisp uses two kinds of public infrastructure — a distributed hash table (DHT) for discovery and relays for forwarding. These are deliberately designed to learn as little as possible:
- Messages are end-to-end encrypted using the Noise protocol and a Double Ratchet. A relay only ever sees padded ciphertext, never readable content.
- Relays cannot see who is talking to whom. Offline messages are left at rotating, unguessable addresses derived from a shared secret, so a relay cannot link a sender to a recipient or link two messages as belonging to the same conversation.
- Relays hold no accounts and no history. Undelivered encrypted blobs are stored only briefly (a default of 7 days) and then deleted.
- Relays are interchangeable and can be self-hosted. You can point Wisp at a relay you run yourself, or a relay a third party runs. A relay operator you don’t control still only sees opaque, unlinkable, encrypted blobs.
Your IP address is necessarily visible to peers you connect to and to any relay you route through, as it is for any internet application. Wisp does not log or retain it on our side, because there is no “our side” that receives it.
Permissions the app requests
Section titled “Permissions the app requests”- Internet / network access — to send and receive messages.
- Run a foreground service (Android) — to keep the connection open so messages can arrive while the app is in the background. Android requires an ongoing notification for this; you can hide that notification in the app’s system notification settings without stopping message delivery.
- Post notifications — to alert you to new messages.
Wisp does not request access to your contacts list, camera, microphone, location, or files beyond what you explicitly pick (for example, choosing a file when you export or restore a chat backup).
No third-party sharing
Section titled “No third-party sharing”We do not share data with third parties, because we do not collect data to share. Wisp contains no advertising SDKs, no analytics SDKs, and no social-network trackers.
Data retention and deletion
Section titled “Data retention and deletion”- On your device: your data persists until you delete it. Uninstalling the app or logging out removes your keys; uninstalling removes the local message database.
- On relays: undelivered encrypted blobs expire automatically (default 7 days). Once a message is delivered and acknowledged, it is removed from the relay.
Because we hold no personal data about you, there is nothing for us to delete on request — but you are always in full control of the data on your own device.
Children’s privacy
Section titled “Children’s privacy”Wisp is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children.
Security
Section titled “Security”Wisp uses well-established cryptography — Ed25519, X25519, the Noise XX handshake, ChaCha20-Poly1305, and the Signal Double Ratchet with header encryption — to provide end-to-end encryption with forward secrecy. No system is perfectly secure, and a compromised device can expose data on that device. The full design and threat model are described in the protocol specification.
Changes to this policy
Section titled “Changes to this policy”If this policy changes, the “Last updated” date above will change with it. Material changes will be reflected here on this page.
Contact
Section titled “Contact”Questions about privacy or this policy: mahdi.business7@gmail.com.
