Privacy policy
Last updated: 24 September 2026
Hushpiper is a messenger built so that we know as little about you as possible. This policy explains what we do hold, why, how long we keep it, who helps us run the service, and your rights.
Who we are
Hushpiper is run by Hushpiper Ltd (company number to follow, registered address to follow), which is the "controller" of your personal data under UK data protection law (the UK GDPR and the Data Protection Act 2018). You can contact us about privacy at privacy@hushpiper.com.
The short version
- Your messages, calls, photos, videos, voice notes, files, stickers, locations and statuses are end-to-end encrypted. We can't read or hear them, and neither can anyone else who gets into our servers.
- You don't need a phone number or an email address to use Hushpiper, and we never upload your address book.
- We keep what we need to run the service and keep it safe: your username, which chats you're in, when messages are sent, and short-lived security data.
- We don't sell your data, show ads or use trackers. Our website sets no cookies.
- You can delete your account at any time from the app. Accounts nobody uses for 4 months are deleted, after a warning.
What we can't see
When you send something, your device encrypts it before it leaves, and only the devices of the people in the chat can open it (see Security for how). Our server stores these sealed messages only until every recipient device has collected them. Photos and files are deleted after 7 days at the latest, and messages waiting for a device that hasn't connected for 30 days are deleted. Encrypted backups are files you keep yourself, locked with a password we never see.
What we collect and why
For each kind of data: what it is, why we need it, our lawful basis under the UK GDPR, and how long we keep it.
Your account
- What: your username; your password and your 12-word recovery phrase, stored only as one-way scrambled "hashes" we can't reverse; and, if you add them, a display name, a short "about" line, a profile picture and an email address. We ask the year you were born when you sign up but don't keep it: if you're under 18, we keep only the date your under-18 protections end (1 January of the year you're sure to be 18); otherwise nothing.
- Why: to create your account, let you sign in and recover it, show your profile to the people you choose (profile pictures can be limited to your contacts), and protect people under 18 (see "Children" below).
- Lawful basis: performing our contract with you (our terms).
- How long: until you delete your account, or until it goes unused for 4 months (no signed-in device opens Hushpiper): we warn you in the app 14 days before, and using any of your devices cancels it. Accounts with panic recordings or trusted contacts are kept. When an account is deleted, we delete its profile, email, phone number and picture straight away. We keep your username reserved, with nothing else attached, so nobody can take it over and pretend to be you.
Your phone number (optional)
- What: your number, if you add one, and a scrambled copy used to look it up.
- Why: so you can sign in with it and, only if you switch it on, so people who already have your number can find you. To prove the number is yours, you send us a code: either by WhatsApp (WhatsApp, operated by Meta, then processes that message as part of its own service) or by text message to our own receiving phone.
- Lawful basis: your consent. You can remove the number at any time.
- How long: until you remove it or delete your account. Verification codes expire after 15 minutes.
Your devices
- What: for each signed-in device: its name and type, its public encryption keys, a sign-in token, when it was last active, a random ID for the app installation, and, on phones, a notification token from Google. You can turn notifications while the app is closed off in Settings ("Get messages when the app is closed"); the token is then removed.
- Why: to deliver messages to the right devices, let you see and sign out your devices, and wake your phone when something arrives.
- Lawful basis: contract.
- How long: until the device is signed out or your account is deleted.
Chats, groups and delivery
- What: which chats and groups you're in and your role; each chat's privacy settings; the time, size and ID of messages (not their contents) while they wait for delivery; delivery receipts, where a chat's settings allow them; people you've blocked; your contact PIN and contact link if you set them.
- Why: to deliver messages and apply each chat's privacy rules.
- Lawful basis: contract.
- How long: chat membership until you leave the chat or delete your account; sealed messages until delivered (at most 7 days for files, 30 days for a device that stays offline).
Channels
- Posts in public channels are public: anyone can read them, and they are stored on our server unencrypted, like a website.
- Posts in encrypted channels are sealed with a key that is only in the channel's link; we store them but can't read them.
- We keep a list of channels you follow and your notification choice for each.
- Lawful basis: contract. Posts stay until the channel's owner or an admin deletes them or the channel.
Calls
- Call set-up messages are end-to-end encrypted.
- Calls connect directly between devices where possible. To find a route, devices ask public "STUN" servers run by Google and Cloudflare for their own network address, so those companies see your address when a call starts.
- When a direct route isn't possible, the call is relayed through our own servers (a relay for one-to-one calls and a media server for bigger group calls). They see network addresses and pass on encrypted audio and video they can't decode.
- Lawful basis: contract. We don't record calls or keep call contents; our servers only keep temporary connection details while a call is running.
Safety features: panic recording, trusted contacts and check-ins
- What: your trusted contacts; your check-in schedule and whether a check-in was missed; alerts you send; and panic recordings, which are encrypted on your phone in small pieces before upload.
- Why: to alert the people you chose, and to keep a recording safe even if your phone is taken.
- Lawful basis: contract; and, where an alert protects someone's life, vital interests.
- How long: recordings stay on our server (within a storage limit per person) until enough of your devices and trusted contacts hold copies, or until you delete them. Deletion takes effect after 24 hours, so someone who takes your phone can't destroy a recording at once.
The AI assistant (optional)
- If you use it, the text you send to the assistant, including any messages you choose to share with it, goes through our server to Groq, Inc. in the United States, which generates the reply. This is not end-to-end encrypted. Groq's terms say it doesn't use this data to train models and doesn't keep it by default.
- In a chat, members can only share its messages with the assistant if the chat's settings allow it (they don't by default).
- We keep only a daily count of your requests, to apply a fair-use limit.
- Lawful basis: contract, for a feature you choose to use.
Keeping Hushpiper safe
- Reports: when you report someone, we receive what you write and the messages you choose to include, so we can review them. We keep reports and our decisions for as long as needed to handle them and any appeal, and to deal with repeat abuse.
- Stopping banned people returning: we keep one-way scrambled versions (HMAC hashes) of the network address and app installation ID used by each account, never the address itself, for 30 days after they were last seen, and compare them when a new account is created.
- Sign-up checks: to stop automated sign-ups we may use Cloudflare Turnstile, which checks your browser or device and network address.
- Error logs: our web server keeps no access logs. Error logs, which can include a network address, are kept for up to 14 days.
- Lawful basis: our legitimate interests in keeping the service and its users safe and secure, and our legal duties, including under the Online Safety Act 2023.
Bug reports
- If you send one, we receive what you write, any screenshot you attach, and technical details about the app and device. Screenshots are deleted 90 days after the problem is closed (sooner if our storage runs short), and the report itself 12 months after.
- Lawful basis: legitimate interests (fixing problems you tell us about).
Our website
This website sets no cookies, uses no analytics and loads nothing from other companies. See "Error logs" above.
Who we share data with
We don't sell your data or share it with advertisers. These companies help us run Hushpiper and may process data for us, only as we instruct:
| Company | What they do | Where |
|---|---|---|
| IncogNET | Hosts our servers | Sweden (Stockholm) |
| Cloudflare, Inc. | Network security, delivery of our website and app traffic, sign-up checks, a STUN server | Worldwide, including the United States |
| Google LLC | Firebase Cloud Messaging wakes your phone when something arrives: it gets a device token and a one-letter signal, never who sent what. Also a STUN server for calls | United States |
| Groq, Inc. | The optional AI assistant | United States |
| Meta Platforms (WhatsApp) | Only if you verify your phone number by WhatsApp | Worldwide |
We may also disclose data if the law requires it, for example a valid court order, or to protect someone from serious harm. Because of end-to-end encryption, we can't provide the contents of messages, calls or files, because we don't have them.
International transfers. Some of these companies are in the United States or elsewhere outside the UK. When data goes there, we rely on the UK's adequacy regulations (including the UK-US "data bridge" for certified companies) or the UK International Data Transfer Addendum to the EU standard contractual clauses.
Your rights
You have the right to:
- access the personal data we hold about you and get a copy;
- correct it if it's wrong (most of it you can change in the app);
- delete it (Settings, tap your name, Delete my account);
- restrict or object to how we use it, including where we rely on legitimate interests;
- data portability: receive the data you gave us in a common format;
- withdraw consent at any time where we rely on it (for example, remove your phone number).
To use any of these rights, email privacy@hushpiper.com. We'll reply within one month. If you're not happy with our answer, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.
Children
You must be at least 13 years old to use Hushpiper. We ask the year you were born when you sign up, and we don't create an account for anyone who is clearly younger. If you're under 18, people you don't know can't find you by your username or phone number, message you or add you to groups; your contact link and invite links still work, because you choose who gets them. For this we keep only the date these protections end, never your year or date of birth, and nobody else can see it. If we learn that someone under 13 has an account, we'll delete it. If you think a child under 13 is using Hushpiper, please tell us at abuse@hushpiper.com.
If you live outside the UK
Hushpiper is available worldwide and we give everyone the rights above, wherever they live. In addition:
- European Union and EEA: the EU GDPR gives you the same rights, and you can complain to the data protection authority where you live, work or where you think the law was broken. International transfers use the EU's adequacy decisions (including the EU-US Data Privacy Framework for certified companies) or standard contractual clauses. Our representative in the EU is to be appointed; until then, write to privacy@hushpiper.com.
- South Africa: under the Protection of Personal Information Act (POPIA) you have the same rights to access, correct and delete your information and to object, and you can complain to the Information Regulator (inforegulator.org.za).
- Elsewhere: if your country's law gives you further rights, write to privacy@hushpiper.com and we'll honour them.
Changes to this policy
If we change this policy in a way that matters, we'll tell you in the app before the change takes effect. The date at the top shows when it last changed.