Privacy policy
Last updated 29 August 2026
This explains what we do with personal information when you use wiwi. It covers wiwi.ws, the WhatsApp number you message to use the service, my.wiwi.ws, and the pages wiwi publishes for you.
1. Who we are
wiwi is operated by Wisepunk LLC, a limited liability company formed in Wyoming, United States. We are the company responsible for the information described below.
- 30 N Gould St Ste N, Sheridan, WY 82801, United States
- privacy@wiwi.ws
2. Two different roles, and which one we are
This decides who you should ask about what, so it comes before everything else.
- When you use wiwi yourself — you message our WhatsApp number and we build you a page — we are the controller of your information. This policy governs it, and you can ask us directly about any of it.
- When you fill in a form on a page somebody built with wiwi, we are a processor. The person who built that page is the controller of what you submit. We hold it for them, we do not use it for our own purposes, and requests about it belong to them first. Section 11 says what to do if you cannot reach them.
Below, owner means somebody with a wiwi account, and visitor means somebody who opens or submits something to a page an owner published.
3. What we hold about owners
| What | Detail |
|---|---|
| Your WhatsApp identity | The phone number you message us from, and the identifier WhatsApp gives us for you. |
| Your messages | Everything you send to our WhatsApp number — text, photographs, voice notes, video, documents and links. |
| What we built | Your pages, their titles, what you asked for in your own words, and every revision ever published. |
| Media | The photographs, audio and video you sent, and images produced for your pages. |
| Your conversation | A record of each exchange: what arrived, what we answered, whether it worked and how long it took. |
| Your account | When it opened, the language you write in, and a brand colour if you chose one. |
| Money | Your credit balance and every charge against it. If you subscribe: a Stripe customer reference, your plan, and whether it is paid. |
| Sign-in | If you open my.wiwi.ws, a hashed session token in a cookie, valid for 14 days. |
We never see or hold your card details. Stripe takes the payment and holds the card.
We do not ask for your name, your postal address or your email address, and there is no field anywhere in wiwi that collects them.
4. What we hold about visitors to a published page
- What you submit. If the page has a form, what you type is stored — that is what the form is for. What it asks for is the page owner's choice, not ours: it may be a name, an email address, a phone number, or anything else they decided to ask.
- Files you attach, where the page accepts them.
- A short-lived rate-limiting record. When you submit a form or upload a file we store a hash of your IP address with a counter, to stop one machine flooding a page. These rows are swept continuously and one lives about two minutes.
Being straight about that hash: it is mixed with a secret key of ours before hashing, so somebody who obtained it could not work back to your address by trying every possibility. It is still information about you rather than anonymous data — we hold that key — and it is used for nothing except rate limiting and deleted within minutes.
There is no analytics script and no advertising cookie on wiwi.ws or on any page wiwi publishes.
5. Why we hold it
| Why | Our lawful basis |
|---|---|
| To build what you asked for and keep your pages online | Performance of our contract with you |
| To take payment and keep an accurate ledger | Performance of our contract, and our legal obligation to keep records |
| To keep the service working, and to stop abuse of it | Our legitimate interests in a service that stays up and is not used to harm people |
| To answer you | Performance of our contract |
For what a visitor submits to an owner's page, we act on that owner's instructions. The lawful basis for collecting it is theirs to have and to state.
6. What happens when a model reads your messages
wiwi works by sending what you write, and what you send, to large language models run by specialist providers.
We use paid, business-tier services, and we contract on terms that forbid training on your content. Your prompts and the responses are not used to improve anybody's models, and they are not read by human reviewers for that purpose. Your messages — and anything a visitor submitted that gets read back to you — are not training data.
We do not train any model of our own on your content, and we do not sell it to anybody.
Which providers we use changes as the field does, and we choose on quality, cost and availability. The commitment above travels with the change: we will not move to a provider, or to a cheaper tier of one, whose terms allow customer content to be used for training. Ask us and we will tell you who we are using today.
8. Where it goes
We are a United States company and several of the companies behind those services are too, so information about people in the EEA, the United Kingdom and Switzerland is transferred outside those areas.
Where it is, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, or on the recipient's own adequacy decision or framework certification where it holds one. You can ask us which applies to a particular company.
9. How long we keep it
| What | How long |
|---|---|
| A submission an owner has binned | Destroyed 30 days later — the entry and any file attached to it, permanently |
| A file a visitor attached but never submitted | Destroyed after 7 days |
| Rate-limiting records | About two minutes |
| Expired sign-in sessions | Swept automatically once they expire |
| Everything else about an open account | While the account is open |
One thing worth knowing: our database keeps a rolling 30-day point-in-time history that we cannot switch off. So for up to 30 days after something is deleted it may still exist in that history, and after that it is gone.
10. Your rights
Depending on where you live, you have some or all of these rights over information about you:
- to get a copy of it
- to have it corrected
- to have it deleted
- to restrict or object to what we do with it
- to receive it in a portable form
- to complain to a data protection authority
If you are in the EEA you can complain to the authority where you live — in Spain the AEPD, in Sweden the IMY. In the UK it is the ICO. You do not have to come to us first, though we would rather you did.
11. How to ask
Email privacy@wiwi.ws, or just say so in your WhatsApp thread. We answer within one month.
Deleting your account. There is no button for this, deliberately. Closing an account destroys every page, every file and every record it owns and cannot be undone, so a person here does it rather than a model or a mis-tap. Ask, and we do it, and we tell you when it is done.
Getting your data out. If you are an owner, you can export what people submitted to your pages as a spreadsheet from my.wiwi.ws at any time, without asking us.
If you submitted something to somebody else's page and you want it removed, ask the person whose page it is — they control it and can delete it themselves. If you cannot reach them, write to us and we will act.
12. How we protect it
- Everything travels over TLS.
- Session tokens and upload tokens are stored as hashes, never as the token itself.
- There is no password anywhere in wiwi. You reach your dashboard through a single-use link sent to your WhatsApp thread, valid for 15 minutes. There is no password to guess, to reuse or to leak.
- Keys and secrets are held as platform secrets, not in our code.
No system is perfectly secure. If something happens to information about you that is likely to put you at risk, we will tell you and the relevant authority as the law requires.
13. Age
wiwi is not for anybody under 18. We do not knowingly collect information about anybody under that age. If you think we have, write to us and we will delete it.
14. Changes to this policy
When this policy changes we publish the new version here and change the date at the top. That date is how you can tell. It last changed on 29 August 2026.