Privacy Policy
Last updated: 2026-08-15
⚠️ About this policy and our service
This policy describes how we handle your data when you use Wispic. We are committed to complying with the GDPR and best practices for data protection while providing our service.
1. Data Controller
Controller: Wispic UG (haftungsbeschränkt)
Represented by: Álvaro Rodríguez (Managing Director / Geschäftsführer)
Address: Salvador-Allende-Straße 20, 28203 Bremen, Germany
Commercial register: Amtsgericht Bremen, HRB 42924
VAT ID (USt-IdNr): DE463876042
Content responsible party (§18 (2) MStV): Álvaro Rodríguez
Residence: European Union (Germany)
Contact email: support@wispic.app
Applicable law: The EU General Data Protection Regulation (GDPR) and German data protection law.
Supervisory authority: You have the right to lodge a complaint with a data protection authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
2. Data We Collect
2.1 Account and Profile Data
- Email: For authentication and service communications (required)
- Display name or profile alias: Text other users will see on your profile (required)
- Date of birth: To verify the 18+ minimum age and show your age on your profile (required)
- Gender and sexual orientation: To personalize matching (optional)
- Photos: Up to 6 profile photos (at least 1 required)
- Bio: Free text, max. 160 characters (optional)
- Interests and prompts: Answers to predefined questions (optional)
2.2 Location Data
- Approximate location (city): To show nearby events and groups
- GPS coordinates: Only when you use the "Nearby events" feature (with your explicit permission)
Note: We never share your exact location with other users. We only show city or approximate distance (e.g. "5 km" without exact coordinates).
2.3 Usage Data
- Messages sent in 1-on-1 chats and groups
- Likes, superlikes, matches
- Groups you create or join
- Events you join or mark as interested/attending
- Reports of inappropriate content
- Logs of critical actions (login, email change, account deletion) for security auditing
2.4 Technical Data
- IP address (for fraud prevention and security analysis)
- User agent (browser/device)
- Push notification token (if you enable notifications)
- Error and crash logs (via Sentry on Android and Firebase Crashlytics on iOS, see section 4)
3. Legal Basis and Purpose of Processing
| Data |
Purpose |
Legal Basis (GDPR) |
| Email, name, age |
Contract performance (dating/groups service) |
Art. 6(1)(b) - Contract |
| Photos, bio, interests |
Contract performance (showing your profile to other users) |
Art. 6(1)(b) - Contract |
| Location (city) |
Core functionality (showing nearby events/groups) |
Art. 6(1)(b) - Contract |
| Location (precise GPS) |
Improving the experience (nearby events) |
Art. 6(1)(a) - Consent |
| Messages, matches |
Contract performance (matching/chat functionality) |
Art. 6(1)(b) - Contract |
| IP, security logs |
Fraud prevention, security |
Art. 6(1)(f) - Legitimate interest |
| Analytics (PostHog) |
Product improvement |
Art. 6(1)(f) - Legitimate interest |
4. Sharing Data with Third Parties
4.1 Infrastructure Providers
- Supabase (AWS EU-Central-1): Database hosting, authentication, photo storage. Servers in Frankfurt, Germany. Privacy policy
- PostHog (EU Cloud): Usage analytics (anonymized events). Servers in the EU. Privacy policy
- Sentry (Android): Error and crash monitoring on Android. Privacy policy
- Firebase Crashlytics (iOS): Crash monitoring on iOS. Privacy policy
- Hive AI: Automated content moderation (detection of inappropriate photos). Temporary analysis with no permanent storage. Privacy policy
4.2 Content Moderation
We use automated moderation services (Hive AI) to detect inappropriate content in photos. This service:
- Automatically scans photos to detect nudity, violence, illegal content
- Does not permanently store your photos (only temporary analysis during validation)
- Complies with the GDPR and has servers in the EU with appropriate transfer safeguards
- Automatically rejects photos with detected inappropriate content
- Our moderation team may review content reported by users or flagged by the automated system
4.3 Payment Processors (Future Implementation)
When we implement paid premium features, we will use secure, PCI-DSS-compliant processors (e.g. Stripe, RevenueCat). We do not store credit card data.
4.4 Data We NEVER Share
- ❌ We do not sell your data to third parties for marketing
- ❌ We do not share your exact location with other users (only city or approximate distance)
- ❌ We do not share private messages with third parties (except where legally required)
5. Data Retention
| Data Type |
Retention Period |
| Profile photos and media messages |
90 days after account closure |
| Text messages |
Until you delete your account or the chat |
| Audit logs (login, critical changes) |
90 days (security and compliance) |
| Banned user data |
Between 7 and 90 days depending on the severity of the violation; indefinitely in serious safety cases (sexual content involving minors, serious threats) so we can cooperate with authorities and prevent repeat offenses. After the applicable period, the data is automatically deleted. |
| Analytics (PostHog) |
12 months (anonymized data) |
6. Your Rights (GDPR)
As an EU user, you have the following rights:
- Access (Art. 15): You can request a copy of all your data. Available in Profile Settings → Help & Legal → "Export my data" (JSON format)
- Rectification (Art. 16): You can correct inaccurate data from Profile Settings → edit profile
- Erasure (Art. 17): You can delete your account from Profile Settings. See detailed instructions
- Portability (Art. 20): Data export in JSON format ("Export my data" feature)
- Objection (Art. 21): You can object to certain processing (e.g. analytics). Contact support@wispic.app
- Restriction (Art. 18): You can request that processing be temporarily restricted
Exercising your rights: Send your request to support@wispic.app. We will respond in accordance with the GDPR (within 30 days maximum, extendable to 90 days for complex requests; we will inform you of any extension).
Right to complain: If you believe we have violated your rights, you have the right to lodge a complaint with a data protection authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
7. Security
- Encrypted connections (HTTPS/TLS 1.3)
- Passwords hashed with bcrypt (never stored in plain text)
- Rate limiting to prevent spam and attacks
- Automated content moderation with Hive AI (detection of nudity, violence, illegal content)
- Daily encrypted backups (7-day retention)
- Audit logs for critical actions
8. Cookies and Similar Technologies
Wispic is a native mobile application and does not use web cookies. We store data locally on your device for:
- Session tokens (authentication)
- User preferences (language, notifications)
- Photo cache (performance)
This data is deleted when you log out or uninstall the app.
9. Minors
Wispic requires a minimum age of 18.
- We verify age at sign-up (date of birth)
- If we detect a user under 18, we close the account immediately
- If you are a parent/guardian and believe a minor has created an account, contact support@wispic.app
10. International Transfers
All our main providers (Supabase, PostHog, Sentry, and Firebase Crashlytics) have infrastructure in the European Union or comply with applicable GDPR safeguards for international transfers (e.g. Standard Contractual Clauses where applicable).
11. Changes to This Policy
We may update this policy from time to time. Significant changes will be notified via:
- Email to your registered address
- In-app notice, when available
- Push notification, if enabled and the change requires it
Last updated date: 2026-08-15
12. Contact
For any questions about privacy or exercising your rights:
- Email: support@wispic.app
- Suggested subject: "Privacy - [your request]"
- Response time: Maximum 30 days
Wispic – Connect with like-minded people at real events
© 2026 Wispic UG (haftungsbeschränkt). All rights reserved.