Privacy Policy
Last updated: 7 September 2026
The short version
- Your data stays in Europe. Recordings and content are stored on servers in Belgium, inside the European Union. That was a deliberate choice, not the default setting.
- We don't sell anything to anyone. No advertising, no ad profiles, no sharing with third parties.
- This website doesn't follow you. No analytics cookies, no measurement tools, nothing loaded from someone else's servers.
- The person being recorded gets a say. The consent of whoever is holding the phone isn't enough — we also need the consent of the person speaking, and they can withdraw it whenever they like.
- Everything can be deleted, even if you don't have an account and never install the app. Here's how.
WhisperTree exists to keep the voices of the people you love. That is intimate material: your grandmother telling a story is not just another file. This page explains, without the usual formulas, what we do with it.
1. Who we are and how to reach us
WhisperTree is not a company: it is the name one person works under. The data controller — who decides what happens to your data and answers for it personally — is [full name], trading as a sole trader in the United Kingdom, contactable at [UK address].
The controller is established in the United Kingdom. WhisperTree also serves people living in the European Union, so both UK and EU data protection law apply, and the rights set out below are the same either way.
For anything concerning your data, write to whispertree@mail.com. A person answers, not a form.
2. What we collect
What you give us
- Your name, or whatever you'd like to be called.
- Your email address, which the account needs.
- A profile photo, if you choose to add one. It's optional.
- Audio recordings and whatever you write alongside them: titles, descriptions, who they're about.
- Photos of family members shown in the app, if you upload them.
What comes from using the app
- An account identifier and technical device identifiers, needed to run the app and keep you signed in.
- Date, time, length and size of recordings.
- Who you shared a memory with, and whether it has been listened to.
- Technical logs: errors, crashes, diagnostic information.
What we never ask for
The app asks the phone for one permission: the microphone. It doesn't ask for your location, your contacts, your photos or your calendar. If another permission were ever needed, the phone would ask you, and you would know why.
Payments go through Google Play. Your card number never reaches us: we only receive confirmation that a subscription is active, or that it isn't any more.
3. Why we process it, and on what basis
- Voice recordings: on your consent (Art. 6(1)(a) GDPR) and on the consent of the person recorded. You can withdraw it whenever you like, and withdrawing it means the recordings are deleted.
- Account and subscription: to perform the contract (Art. 6(1)(b) GDPR). Without an email and an identifier we can't give you access to what you saved.
- Accounting records: legal obligation (Art. 6(1)(c) GDPR).
- Keeping the service safe: legitimate interest (Art. 6(1)(f) GDPR), limited to what is needed to prevent abuse and unauthorised access.
One clarification about voice. Today we treat recordings as content, not as biometric data: we don't use them to recognise or identify anyone. There is no voice recognition, and there will not be. When a recording is attributed to a person, it's because someone said so — not because a system compared their voice against anything. Comparing voiceprints to identify someone is precisely what would make this biometric data under Art. 9, and that is a door we decided not to open. If we ever introduce features that reconstruct or imitate a voice, that will be a different and far more delicate kind of processing, and it will not start without separate, specific consent asked for in advance.
4. The consent of the person being recorded
This is the unusual part of WhisperTree, and it's worth reading carefully: the person speaking in a recording is almost never the person using the app. The voice is theirs, and so are the rights over it.
Here is how it works:
- Whoever records declares that they have the consent of the person being recorded. This isn't a box you tick to clear your conscience — it's a responsibility you take on.
- When the person being recorded is present — and in normal use of WhisperTree they are, because they're the one talking — the app asks them directly. It's a screen built to be read out loud: few words, large type. There they choose separately whether to accept the recording, and whether to accept that one day their voice might be used by an artificial intelligence system. They can also set a veto that overrides everything else.
- The person recorded can change their mind at any time, even years later, without an account and without installing anything.
Withdrawing consent means deletion. If you are the person recorded and you ask for your voice to be deleted, we remove the recordings that concern you from every part of WhisperTree they sit in — including copies other users have received. It isn't negotiable and it doesn't depend on whoever made them: it is your right. How to ask.
5. Recordings involving children
A WhisperTree account is for adults.
A child may appear in a recording — and it's natural that they do, these are family memories — but only with the consent of whoever holds parental responsibility. Anyone recording a child must have that consent.
A parent or guardian can ask us at any time to show or delete the recordings concerning their child, by writing to the address above. We don't ask for reasons.
6. Where the data is stored
Recordings, photos and your account data are stored on servers located in Belgium, in the europe-west1 region of Google Cloud, inside the European Union.
It's worth saying because it isn't what happens by default: the default sends data to the United States, and configuring everything in Europe was a deliberate decision made at the start of the project.
The controller is in the UK, the data is in Belgium. European law allows that movement without additional safeguards: on 19 December 2025 the European Commission renewed its adequacy decision for the United Kingdom, valid until 27 December 2031. The recordings themselves stay physically in Belgium.
Two honest caveats:
- Authentication. Email addresses and account identifiers go through Firebase Authentication, a service Google does not allow to be pinned to a single region. That data — the email, not the recordings — may therefore be processed by Google outside the Union, under the Standard Contractual Clauses approved by the European Commission.
- Technical support. In limited cases, to fix a fault, Google staff may access the systems from outside the Union. Here too the basis is the Standard Contractual Clauses.
7. Who else processes data for us
We rely on a single infrastructure provider, and we name it:
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), for the Firebase and Google Cloud services that host the app. It acts as a processor on our behalf, under a contract pursuant to Art. 28 GDPR.
- Google Play, for distributing the app and handling subscriptions.
- Firebase Crashlytics, also Google, which delivers technical reports when the app crashes. They contain the device type and the point in the program where it happened, not your content.
There are no other recipients. No ad agencies, no analytics platforms, no data brokers.
8. Who your memories are shared with
Only the people you choose. There are no public feeds, open profiles, shareable-with-anyone links, or search engines indexing recordings.
We don't listen to your recordings. Nobody here opens them out of curiosity, to moderate them, or to improve the service. The only case in which someone on our team can access a piece of content is if you ask us for help with that specific content, and only for as long as it takes to fix the problem.
We don't use your recordings to train artificial intelligence systems. If we ever do, it will be for a feature you chose, and we'll ask you first.
9. How long we keep things
| What | How long |
|---|---|
| Recordings, photos, content | As long as your account is active, or until you delete them |
| Account data (name, email, profile photo) | As long as your account is active |
| All of the above, after a deletion request | Removed within 30 days |
| Copies in backups | Overwritten within 90 days of deletion |
| Technical and diagnostic logs | 12 months |
| Accounting and tax records | 10 years, as the law requires |
One point deserves clarity, and it's the same one you'll find on the deletion page: if you close your account, the memories you already shared stay with the people who received them. You gave them to those people, and at that point they belong to them too. That is different from the case where the person recorded asks for their own voice to disappear: there, the recording is removed everywhere, shared copies included.
10. Your rights
European law gives you rights you can exercise whenever you want, free of charge:
- Know what data we hold about you and get a copy (Art. 15).
- Correct it if it's wrong or incomplete (Art. 16).
- Erase it (Art. 17).
- Restrict its use while a question is being settled (Art. 18).
- Take it elsewhere in a machine-readable format (Art. 20). For the recordings you don't even need to ask: from the "My recordings" screen you can export them all as a .zip archive whenever you like.
- Object to processing based on legitimate interest (Art. 21).
- Withdraw consent at any time, without explaining why (Art. 7(3)). Withdrawal doesn't make what happened before unlawful.
To exercise any of them, write to whispertree@mail.com. We answer within one month; if the request is complex we may take up to two months more, but we'll tell you within the first month and explain why.
If you think we've got it wrong, you can complain to a supervisory authority. Which one depends on where you live:
- In the European Union, the authority of your country. In Italy it is the Garante per la protezione dei dati personali — garanteprivacy.it.
- In the United Kingdom, the Information Commissioner's Office — ico.org.uk.
You can also go to court.
11. If you were recorded and have no account
It can happen that you end up on WhisperTree without choosing to: someone in your family recorded your voice. The rights listed above apply to you all the same, exactly as they do to account holders.
You don't need to install the app, you don't need to sign up, and you don't need permission from whoever made the recording. Write to whispertree@mail.com, or follow the second route on the deletion page.
12. Security
- Everything travelling between the app and our servers is encrypted (TLS).
- Files are also encrypted while at rest on the servers.
- Access to the systems is limited to the people who need it, with two-factor authentication.
- There are no public links to recordings: every access goes through a permission check.
Something we'd rather tell you than let you discover: recordings are not end-to-end encrypted. That means it would technically be possible to access them on our systems. We don't, access is restricted and logged, but we won't claim a level of security we don't have. No system is invulnerable: if a breach ever puts your data at risk, we'll tell you, and we'll report it to the supervisory authority within 72 hours as the law requires.
13. Cookies and tracking
This site uses no cookies and doesn't track you. There are no analytics tools, no advertising, and no social buttons telling anyone else that you came by. Even the typefaces are served from our own servers rather than someone else's, so no third party sees your IP address.
That's why there's no cookie banner: there's nothing here for you to accept.
One precise exception: your account page. To sign you in it has to load Firebase's connection software from Google's servers and keep on your device the token that keeps you signed in until you sign out. It isn't tracking, and it isn't a new supplier — Google already hosts WhisperTree — but it is the only page on this site that calls out, and we'd rather write that down than let you find it with developer tools.
On your phone, the app keeps some information in local storage to keep you signed in and to let you replay memories without a connection. Those aren't tracking tools and they aren't used to build profiles.
The app doesn't follow you either. It contains no analytics or behaviour-measurement tools: we don't record which screens you open, how long you stay, or what you tap. The only thing that reaches us on its own is a crash report when the app fails, and it exists to fix it.
14. Changes to this policy
If we change something, we update the date at the top of this page. If the change is substantial — a new kind of data, a new purpose, a new provider — we'll tell you by email or in the app before it takes effect, and if new consent is needed we'll ask for it.
Contact
For any question about this policy or your data: whispertree@mail.com.
WhisperTree