← Back to Home

Wisp Privacy Policy

Last updated: August 29, 2026

Introduction

Wisp is a private messenger published by Codelio ("we", "us"). Wisp was designed so that we know as little about you as possible: your messages and calls are end-to-end encrypted, and your conversation history lives only on your device. This policy explains what little data we do handle, why we need it, and what your rights are.

End-to-End Encryption

Messages, voice calls, and video calls in Wisp are end-to-end encrypted using the Signal protocol. The encryption keys exist only on your device and the devices of the people you talk to. We cannot read your messages or listen to your calls, and neither can anyone who gains access to our servers. Message history is stored only on your device — we keep no copy.

Information We Collect

To operate the service we need a small amount of account and technical data:

  • Account Data: your phone number, used to create and verify your account. Verification is performed via SMS.
  • Profile Data: the name and profile photo you optionally set, stored on our servers so your contacts can see them.
  • Contacts: if you grant the contacts permission, phone numbers from your address book are used to discover which of your contacts use Wisp. Granting this permission is optional; the app works without it.
  • Technical Data: a push notification token (so we can notify you of new messages and calls) and the transient connection data — such as IP addresses — that any internet service processes to deliver traffic and prevent abuse.
  • Delivery Data: the routing information needed to deliver an encrypted message or connect a call (essentially, which account a message is addressed to). This is processed to deliver the message, not to build a record of your relationships.

What We Do Not Collect

  • We cannot access the content of your messages or calls.
  • We do not show ads and we do not use advertising or tracking SDKs.
  • We do not sell, rent, or monetize your personal data. Ever.

How We Use Your Information

  • To create your account and let other Wisp users reach you by your phone number
  • To deliver encrypted messages and connect encrypted calls
  • To send you push notifications for new messages and incoming calls
  • To keep the service secure and prevent spam and abuse

Service Providers

Wisp runs on infrastructure operated by third parties acting as processors on our behalf: Google Firebase (phone number verification and push notification delivery) and Cloudflare (server hosting and storage). These providers process the technical data described above solely to provide their services to us. They cannot read your end-to-end encrypted content.

App Permissions

Wisp asks for permissions only when a feature needs them, and every permission is optional:

  • Notifications — to announce new messages and incoming calls
  • Contacts — to find which of your contacts use Wisp
  • Microphone — for voice and video calls and voice messages
  • Camera — for video calls, photos, and stories

Data Retention

Account data (your phone number and profile) is kept for as long as your account exists. Encrypted messages awaiting delivery are stored temporarily and removed once delivered. Because your message history exists only on your device, deleting the app deletes your conversations; deleting your account removes your account data from our servers.

Children

Wisp is not directed at children under 13 (or the minimum age required in your country), and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.

Your Rights

Codelio is based in France, and we honour the rights granted by the GDPR to all our users: access, rectification, erasure, restriction, portability, and objection. Most of these you can exercise directly in the app — your profile is editable, and deleting your account removes your data from our servers. For anything else, contact us and we will respond within the legal deadlines. You also have the right to lodge a complaint with your data protection authority (in France, the CNIL).

Interoperability with Third-Party Services (WhatsApp)

We intend for Wisp to interoperate with WhatsApp in the European Union under the Digital Markets Act, so that you can exchange messages with WhatsApp users without leaving Wisp. This feature is not yet available. If and when it launches:

  • It will be strictly opt-in — nothing changes for you unless you enable it.
  • Messages exchanged with WhatsApp users will remain end-to-end encrypted, using the same class of encryption as Wisp-to-Wisp messages.
  • To deliver those messages, WhatsApp (operated by Meta Platforms Ireland Limited) will process the data needed to route them — such as an identifier for your account and the encrypted messages themselves — as described in its own privacy policy for third-party chats.
  • Before you can enable the feature, this policy will be updated with the exact categories of data shared with WhatsApp and the legal basis for sharing them.

Changes to This Policy

If we change this policy, we will update this page and the date at the top. Material changes will be announced in the app before they take effect.

Contact

For any question about this policy or your data, write to [email protected]. Also see the Wisp Terms of Service.