Legal

Privacy Policy

Last updated: July 13, 2026

Whisply is a Mac-only assistant that helps you answer, listen, write, search, remember, and complete bounded actions. We’ve built it to keep each data flow tied to a feature you choose. This policy explains what we collect, why, who processes it, how long we keep it, and the controls you have. It applies to the Whisply app and whisply.net.

What we collect

We collect only what we need to operate your account and the product:

  • Account and profile data— your email, display or preferred name, authentication identities, response preferences, and settings. Locale and timezone help format responses and current time correctly.
  • Subscription status— your plan, billing state, and renewal dates, so we know which features to enable.
  • Device identifiers— a per-device ID for your Mac to manage active sessions and enforce plan limits.
  • Chats, transcripts, and shared context— text, audio-derived transcripts, screen or browser context, attachments, and saved session outputs you choose to use with Whisply. Relevant content may be sent to an AI model or retrieval provider to fulfill the request. Saved chats and transcripts remain in your account until you delete them; approved raw captures follow the shorter periods listed below.
  • Personalization and memory— facts you ask Whisply to remember, approved preference updates, correction history, and the source needed to explain or remove a memory. Memory can be disabled, reviewed, corrected, exported, or deleted.
  • Optional general location— a coarse place such as a city, region, or country that you enter and explicitly enable. It is off and blank by default. Whisply does not request precise location permission or infer a conversational location from your IP address. The enabled value is used only where location context is relevant to your request.
  • Connected-account data— the provider account, granted scopes, connection health, and content returned by a connected service when you ask Whisply to search, read, draft, or act there. OAuth credentials are encrypted and brokered to typed provider calls; they are not placed in model prompts.
  • Task, source, and action records— bounded task state, source metadata, confirmations, safe outcome receipts, and provider references needed to resume work, prevent duplicate actions, show what happened, and investigate failures. Receipts do not contain raw credentials or hidden model reasoning.
  • Usage and security records— metered feature consumption, reservations, reset windows, minimized authorization and abuse-prevention events, and diagnostic data needed to operate the service safely and enforce plan limits.

How we use it

We use this information to authenticate you, deliver and improve Whisply’s features, personalize responses you request, synchronize settings, execute and verify bounded actions, process payments, account for usage, maintain security, prevent abuse, and provide support. We do not sell your personal data. We do not use conversation, transcript, connector, memory, screen, or teaching content for advertising or to train a Whisply model.

Third parties and subprocessors

We rely on a small set of trusted providers to run Whisply. Each processes data only as needed to deliver their service:

  • Supabase— authentication and database storage for your account.
  • Lemon Squeezy (Sold through Link, LLC, formerly known as Lemon Squeezy LLC)— merchant of record. Lemon Squeezy handles all payment processing, subscription billing, tax collection, and remittance on our behalf. See lemonsqueezy.com/privacy.
  • Cloudflare— hosting and content delivery.
  • Composio— connected-account authorization, encrypted credential storage, token refresh, and on-demand provider API brokering for managed connectors you choose to connect. GitHub is the exception: it uses Whisply's direct, strictly read-only GitHub App rather than Composio.
  • AI and retrieval providers— providers such as OpenAI, Anthropic, Google, and xAI process the request content routed to the model or search service you use. Whisply uses business/API offerings and settings intended for inference rather than generalized model training.

A service you connect — such as Google, GitHub, Microsoft, Notion, Slack, Zoom, or Calendly — also processes your data under its own terms and privacy policy. Whisply requests the access shown in the connection flow and does not treat a connection as permission to use unrelated products or accounts. Connector access is on demand; Whisply does not continuously index these accounts or create connector webhooks.

Diagnostics & crash reports

To keep Whisply stable, the Mac app may send us diagnostic and crash reports when something goes wrong. These reports are limited to technical signals: the app version, your macOS version and device architecture, the error message and stack trace, and standard network request metadata processed by our hosting provider. They do not include raw conversation, connector, memory, or screen content by default, and we make no attempt to reconstruct that content from diagnostics.

We use these reports solely to diagnose bugs, prioritize fixes, and improve reliability — never for advertising. We retain ordinary diagnostic and metric events for up to 90 days, after which they are deleted or aggregated into non-identifying statistics. Minimized security and billing evidence may be retained for the longer audit period below.

Data retention

Our published default periods are:

  • account profile, saved chats and transcripts, memories, private skills, and plugin settings: until you clear or delete them;
  • approved raw screen, browser, audio, and teaching captures: up to 24 hours by default; an explicitly approved repair recording may be kept for up to 30 days;
  • encrypted exact source links and task source metadata: up to 30 days;
  • safe action receipts and skill-run receipts: up to 90 days;
  • encrypted connected-account credentials: only while that exact connection remains active;
  • prepared account exports and authenticated download links: 24 hours;
  • minimized security, authorization, usage, and billing audit evidence: up to 365 days where needed for integrity, fraud prevention, legal, tax, or accounting obligations; and
  • encrypted disaster-recovery backups: a rolling maximum of 30 days.

Deleting data makes it unavailable to product retrieval immediately. Active copies are then removed by the applicable deletion workflow; encrypted backup copies age out within 30 days. Legally required billing or security exceptions contain minimized metadata rather than raw task content. The authenticated Privacy & Data page shows category-level periods, derivative effects, and the live status of export or deletion requests.

Connected-account controls

You can reconnect, revoke, or disconnect each provider account. A disconnect blocks new Whisply access immediately, removes Whisply’s credential reference, and requests provider revocation where supported. You can separately choose whether memories derived from that source are deleted, redacted, or retained as stale summaries. The provider may keep its own records under its policy.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise these rights at any time by using the authenticated Privacy & Data controls or contacting us at the address below. We will respond within the timeframe required by applicable law.

Security

We protect your data with encryption in transit and at rest, scoped access controls, and reputable infrastructure providers. While no system can be guaranteed perfectly secure, we work continuously to safeguard your information and to limit what we collect in the first place.

Contact

Questions about this policy or your data? Email us at dynamicgpt@pm.meand we’ll be glad to help.