Wispic LogoWispic
How it worksFAQ
ES/EN

Privacy Policy

Last updated: 2026-08-15

⚠️ About this policy and our service
This policy describes how we handle your data when you use Wispic. We are committed to complying with the GDPR and best practices for data protection while providing our service.

1. Data Controller

Controller: Wispic UG (haftungsbeschränkt)
Represented by: Álvaro Rodríguez (Managing Director / Geschäftsführer)
Address: Salvador-Allende-Straße 20, 28203 Bremen, Germany
Commercial register: Amtsgericht Bremen, HRB 42924
VAT ID (USt-IdNr): DE463876042
Content responsible party (§18 (2) MStV): Álvaro Rodríguez
Residence: European Union (Germany)
Contact email: support@wispic.app

Applicable law: The EU General Data Protection Regulation (GDPR) and German data protection law.

Supervisory authority: You have the right to lodge a complaint with a data protection authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.

2. Data We Collect

2.1 Account and Profile Data

  • Email: For authentication and service communications (required)
  • Display name or profile alias: Text other users will see on your profile (required)
  • Date of birth: To verify the 18+ minimum age and show your age on your profile (required)
  • Gender and sexual orientation: To personalize matching (optional)
  • Photos: Up to 6 profile photos (at least 1 required)
  • Bio: Free text, max. 160 characters (optional)
  • Interests and prompts: Answers to predefined questions (optional)

2.2 Location Data

  • Approximate location (city): To show nearby events and groups
  • GPS coordinates: Only when you use the "Nearby events" feature (with your explicit permission)

Note: We never share your exact location with other users. We only show city or approximate distance (e.g. "5 km" without exact coordinates).

2.3 Usage Data

  • Messages sent in 1-on-1 chats and groups
  • Likes, superlikes, matches
  • Groups you create or join
  • Events you join or mark as interested/attending
  • Reports of inappropriate content
  • Logs of critical actions (login, email change, account deletion) for security auditing

2.4 Technical Data

  • IP address (for fraud prevention and security analysis)
  • User agent (browser/device)
  • Push notification token (if you enable notifications)
  • Error and crash logs (via Sentry on Android and Firebase Crashlytics on iOS, see section 4)

3. Legal Basis and Purpose of Processing

Data Purpose Legal Basis (GDPR)
Email, name, age Contract performance (dating/groups service) Art. 6(1)(b) - Contract
Photos, bio, interests Contract performance (showing your profile to other users) Art. 6(1)(b) - Contract
Location (city) Core functionality (showing nearby events/groups) Art. 6(1)(b) - Contract
Location (precise GPS) Improving the experience (nearby events) Art. 6(1)(a) - Consent
Messages, matches Contract performance (matching/chat functionality) Art. 6(1)(b) - Contract
IP, security logs Fraud prevention, security Art. 6(1)(f) - Legitimate interest
Analytics (PostHog) Product improvement Art. 6(1)(f) - Legitimate interest

4. Sharing Data with Third Parties

4.1 Infrastructure Providers

  • Supabase (AWS EU-Central-1): Database hosting, authentication, photo storage. Servers in Frankfurt, Germany. Privacy policy
  • PostHog (EU Cloud): Usage analytics (anonymized events). Servers in the EU. Privacy policy
  • Sentry (Android): Error and crash monitoring on Android. Privacy policy
  • Firebase Crashlytics (iOS): Crash monitoring on iOS. Privacy policy
  • Hive AI: Automated content moderation (detection of inappropriate photos). Temporary analysis with no permanent storage. Privacy policy

4.2 Content Moderation

We use automated moderation services (Hive AI) to detect inappropriate content in photos. This service:

  • Automatically scans photos to detect nudity, violence, illegal content
  • Does not permanently store your photos (only temporary analysis during validation)
  • Complies with the GDPR and has servers in the EU with appropriate transfer safeguards
  • Automatically rejects photos with detected inappropriate content
  • Our moderation team may review content reported by users or flagged by the automated system

4.3 Payment Processors (Future Implementation)

When we implement paid premium features, we will use secure, PCI-DSS-compliant processors (e.g. Stripe, RevenueCat). We do not store credit card data.

4.4 Data We NEVER Share

  • ❌ We do not sell your data to third parties for marketing
  • ❌ We do not share your exact location with other users (only city or approximate distance)
  • ❌ We do not share private messages with third parties (except where legally required)

5. Data Retention

Data Type Retention Period
Profile photos and media messages 90 days after account closure
Text messages Until you delete your account or the chat
Audit logs (login, critical changes) 90 days (security and compliance)
Banned user data Between 7 and 90 days depending on the severity of the violation; indefinitely in serious safety cases (sexual content involving minors, serious threats) so we can cooperate with authorities and prevent repeat offenses. After the applicable period, the data is automatically deleted.
Analytics (PostHog) 12 months (anonymized data)

6. Your Rights (GDPR)

As an EU user, you have the following rights:

  • Access (Art. 15): You can request a copy of all your data. Available in Profile Settings → Help & Legal → "Export my data" (JSON format)
  • Rectification (Art. 16): You can correct inaccurate data from Profile Settings → edit profile
  • Erasure (Art. 17): You can delete your account from Profile Settings. See detailed instructions
  • Portability (Art. 20): Data export in JSON format ("Export my data" feature)
  • Objection (Art. 21): You can object to certain processing (e.g. analytics). Contact support@wispic.app
  • Restriction (Art. 18): You can request that processing be temporarily restricted

Exercising your rights: Send your request to support@wispic.app. We will respond in accordance with the GDPR (within 30 days maximum, extendable to 90 days for complex requests; we will inform you of any extension).

Right to complain: If you believe we have violated your rights, you have the right to lodge a complaint with a data protection authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.

7. Security

  • Encrypted connections (HTTPS/TLS 1.3)
  • Passwords hashed with bcrypt (never stored in plain text)
  • Rate limiting to prevent spam and attacks
  • Automated content moderation with Hive AI (detection of nudity, violence, illegal content)
  • Daily encrypted backups (7-day retention)
  • Audit logs for critical actions

8. Cookies and Similar Technologies

Wispic is a native mobile application and does not use web cookies. We store data locally on your device for:

  • Session tokens (authentication)
  • User preferences (language, notifications)
  • Photo cache (performance)

This data is deleted when you log out or uninstall the app.

9. Minors

Wispic requires a minimum age of 18.

  • We verify age at sign-up (date of birth)
  • If we detect a user under 18, we close the account immediately
  • If you are a parent/guardian and believe a minor has created an account, contact support@wispic.app

10. International Transfers

All our main providers (Supabase, PostHog, Sentry, and Firebase Crashlytics) have infrastructure in the European Union or comply with applicable GDPR safeguards for international transfers (e.g. Standard Contractual Clauses where applicable).

11. Changes to This Policy

We may update this policy from time to time. Significant changes will be notified via:

  • Email to your registered address
  • In-app notice, when available
  • Push notification, if enabled and the change requires it

Last updated date: 2026-08-15

12. Contact

For any questions about privacy or exercising your rights:

  • Email: support@wispic.app
  • Suggested subject: "Privacy - [your request]"
  • Response time: Maximum 30 days

Wispic – Connect with like-minded people at real events
© 2026 Wispic UG (haftungsbeschränkt). All rights reserved.