Whizi legal
Privacy Policy
How Whizi collects, uses, shares, stores and deletes information across its website and mobile apps, and the choices you have over your data.
Last updated: 2026-08-13
Account and guest information
Creating an account is optional in the mobile app. An account may include a name, email address, authentication identifiers, profile details, subscription status, and support communications. Continuing without an account creates an anonymous device-bound guest profile without requiring a name or email address. Whizi stores a one-way derived guest identifier to recognize the profile, synchronize its Whizi data, verify subscription access, and link it to an account if the user later chooses to create one.
Prompts and generated content
Whizi processes prompts, relevant conversation context, uploaded files and images, search context, active voice audio or transcripts, image-generation prompts, generated content, and feedback or reports when needed to provide a requested feature. Chats may be synchronized and the mobile app may keep a local cache of recent conversations.
Purchases and technical information
Apple or Google processes mobile purchases, and RevenueCat receives purchase receipts, product identifiers, entitlement status, and related identifiers so Whizi can verify and restore access. Whizi may also process IP address, device and app details, request timestamps, error and security events, usage counts, push tokens, and related operational information needed to run and secure the service.
Third-party AI processing
To generate a response, Whizi sends the information reasonably needed for the request to OpenRouter and the model provider selected by the user, Google for realtime voice or selected model features, or fal.ai for image generation. Provider retention and temporary caching vary by provider and endpoint. Whizi does not use prompts, files, conversations, voice transcripts, or generated content to train Whizi-owned AI models or sell that content as training data.
Other service providers
Whizi also uses Clerk for authentication; Cloudflare Workers, D1, R2, and Durable Objects for hosting and service data; RevenueCat, Apple, Google, and Stripe for purchase and subscription functions; and Expo for optional transactional push notifications. Providers process information for the functions for which they are used, subject to their terms and Whizi configurations.
Retention and security
Whizi retains information only as reasonably needed to provide and secure the service, meet legal obligations, and resolve disputes. Attachments and generated media are configured to expire after up to 30 days. Deleted database records may remain in protected Cloudflare recovery history for up to 30 days. Payment processors and AI providers may retain limited records or temporary caches under their own policies. Whizi uses administrative, technical, and organizational safeguards, but no networked service can guarantee absolute security.
Account and guest-data deletion
Registered users can permanently delete their account and associated Whizi data under Settings > Delete account and data. Anonymous users can permanently delete their guest profile and associated Whizi data under Settings > Delete guest data. Both actions require two confirmations. Deleting Whizi data does not cancel Apple or Google store billing. See the complete deletion instructions.
Choices and rights
Depending on location, a user may have rights to access, correct, delete, or receive a copy of personal information, or to object to or restrict processing. Users can control optional notifications, delete conversations, delete an account or guest data, manage subscriptions through the applicable store, and use available browser or consent controls.
Contact
For privacy questions, rights requests, or help deleting data, email [email protected]. Do not email passwords, authentication codes, full payment-card information, or sensitive prompts and files.