wiwi Terms of service

Privacy policy

Last updated 29 August 2026

This explains what we do with personal information when you use wiwi. It covers wiwi.ws, the WhatsApp number you message to use the service, my.wiwi.ws, and the pages wiwi publishes for you.

1. Who we are

wiwi is operated by Wisepunk LLC, a limited liability company formed in Wyoming, United States. We are the company responsible for the information described below.

2. Two different roles, and which one we are

This decides who you should ask about what, so it comes before everything else.

  • When you use wiwi yourself — you message our WhatsApp number and we build you a page — we are the controller of your information. This policy governs it, and you can ask us directly about any of it.
  • When you fill in a form on a page somebody built with wiwi, we are a processor. The person who built that page is the controller of what you submit. We hold it for them, we do not use it for our own purposes, and requests about it belong to them first. Section 11 says what to do if you cannot reach them.

Below, owner means somebody with a wiwi account, and visitor means somebody who opens or submits something to a page an owner published.

3. What we hold about owners

WhatDetail
Your WhatsApp identityThe phone number you message us from, and the identifier WhatsApp gives us for you.
Your messagesEverything you send to our WhatsApp number — text, photographs, voice notes, video, documents and links.
What we builtYour pages, their titles, what you asked for in your own words, and every revision ever published.
MediaThe photographs, audio and video you sent, and images produced for your pages.
Your conversationA record of each exchange: what arrived, what we answered, whether it worked and how long it took.
Your accountWhen it opened, the language you write in, and a brand colour if you chose one.
MoneyYour credit balance and every charge against it. If you subscribe: a Stripe customer reference, your plan, and whether it is paid.
Sign-inIf you open my.wiwi.ws, a hashed session token in a cookie, valid for 14 days.

We never see or hold your card details. Stripe takes the payment and holds the card.

We do not ask for your name, your postal address or your email address, and there is no field anywhere in wiwi that collects them.

4. What we hold about visitors to a published page

  • What you submit. If the page has a form, what you type is stored — that is what the form is for. What it asks for is the page owner's choice, not ours: it may be a name, an email address, a phone number, or anything else they decided to ask.
  • Files you attach, where the page accepts them.
  • A short-lived rate-limiting record. When you submit a form or upload a file we store a hash of your IP address with a counter, to stop one machine flooding a page. These rows are swept continuously and one lives about two minutes.

Being straight about that hash: it is mixed with a secret key of ours before hashing, so somebody who obtained it could not work back to your address by trying every possibility. It is still information about you rather than anonymous data — we hold that key — and it is used for nothing except rate limiting and deleted within minutes.

There is no analytics script and no advertising cookie on wiwi.ws or on any page wiwi publishes.

5. Why we hold it

WhyOur lawful basis
To build what you asked for and keep your pages onlinePerformance of our contract with you
To take payment and keep an accurate ledgerPerformance of our contract, and our legal obligation to keep records
To keep the service working, and to stop abuse of itOur legitimate interests in a service that stays up and is not used to harm people
To answer youPerformance of our contract

For what a visitor submits to an owner's page, we act on that owner's instructions. The lawful basis for collecting it is theirs to have and to state.

6. What happens when a model reads your messages

wiwi works by sending what you write, and what you send, to large language models run by specialist providers.

We use paid, business-tier services, and we contract on terms that forbid training on your content. Your prompts and the responses are not used to improve anybody's models, and they are not read by human reviewers for that purpose. Your messages — and anything a visitor submitted that gets read back to you — are not training data.

We do not train any model of our own on your content, and we do not sell it to anybody.

Which providers we use changes as the field does, and we choose on quality, cost and availability. The commitment above travels with the change: we will not move to a provider, or to a cheaper tier of one, whose terms allow customer content to be used for training. Ask us and we will tell you who we are using today.

7. Who else touches it

We use other companies to run wiwi, and each one only receives what it needs for its part. These are the kinds of service involved:

Kind of serviceWhat it does
Cloud hosting and storageRuns the service and stores the database, the files and the images
MessagingCarries every message between you and us
AI model providersRead what you send and build your page — section 6
PaymentsTakes payment and manages subscriptions. Stripe holds your card; we never see it
Email deliverySends the email we send
Media and mapping servicesReads a video link you send so a page can use what is in it, and turns an address into coordinates when your page has a map on it

We will name the specific companies if you ask — write to privacy@wiwi.ws and we will tell you. They are not listed here because the list changes, and asking gets you the current answer rather than a page that has quietly gone out of date.

We also disclose information where the law requires it, and to professional advisers where we need to. If wiwi is ever sold or merged, information moves with it and this policy continues to apply until you are told otherwise.

8. Where it goes

We are a United States company and several of the companies behind those services are too, so information about people in the EEA, the United Kingdom and Switzerland is transferred outside those areas.

Where it is, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, or on the recipient's own adequacy decision or framework certification where it holds one. You can ask us which applies to a particular company.

9. How long we keep it

WhatHow long
A submission an owner has binnedDestroyed 30 days later — the entry and any file attached to it, permanently
A file a visitor attached but never submittedDestroyed after 7 days
Rate-limiting recordsAbout two minutes
Expired sign-in sessionsSwept automatically once they expire
Everything else about an open accountWhile the account is open

One thing worth knowing: our database keeps a rolling 30-day point-in-time history that we cannot switch off. So for up to 30 days after something is deleted it may still exist in that history, and after that it is gone.

10. Your rights

Depending on where you live, you have some or all of these rights over information about you:

  • to get a copy of it
  • to have it corrected
  • to have it deleted
  • to restrict or object to what we do with it
  • to receive it in a portable form
  • to complain to a data protection authority

If you are in the EEA you can complain to the authority where you live — in Spain the AEPD, in Sweden the IMY. In the UK it is the ICO. You do not have to come to us first, though we would rather you did.

11. How to ask

Email privacy@wiwi.ws, or just say so in your WhatsApp thread. We answer within one month.

Deleting your account. There is no button for this, deliberately. Closing an account destroys every page, every file and every record it owns and cannot be undone, so a person here does it rather than a model or a mis-tap. Ask, and we do it, and we tell you when it is done.

Getting your data out. If you are an owner, you can export what people submitted to your pages as a spreadsheet from my.wiwi.ws at any time, without asking us.

If you submitted something to somebody else's page and you want it removed, ask the person whose page it is — they control it and can delete it themselves. If you cannot reach them, write to us and we will act.

12. How we protect it

  • Everything travels over TLS.
  • Session tokens and upload tokens are stored as hashes, never as the token itself.
  • There is no password anywhere in wiwi. You reach your dashboard through a single-use link sent to your WhatsApp thread, valid for 15 minutes. There is no password to guess, to reuse or to leak.
  • Keys and secrets are held as platform secrets, not in our code.

No system is perfectly secure. If something happens to information about you that is likely to put you at risk, we will tell you and the relevant authority as the law requires.

13. Age

wiwi is not for anybody under 18. We do not knowingly collect information about anybody under that age. If you think we have, write to us and we will delete it.

14. Changes to this policy

When this policy changes we publish the new version here and change the date at the top. That date is how you can tell. It last changed on 29 August 2026.