Privacy Policy
Effective and last updated: July 25, 2026
1. Scope and acceptance
This Privacy Policy explains how Whisser.com and the person or entity operating it (collectively, "Whisser," "we," "us," or "our") collect, use, store, disclose, transfer, and protect personal data when you visit Whisser.com, create an account, communicate with us, or use any Whisser website, application, classroom, artificial-intelligence feature, writing tool, media tool, coding environment, database feature, community feature, administrative service, or related product that links to this Policy (collectively, the "Services").
This Policy applies to account holders, visitors, students, educators, administrators, creators, developers, contributors, and other users. It does not replace any rights that cannot lawfully be waived. By using the Services, you acknowledge that you have read this Policy. Where consent is legally required, we will request it separately or through the relevant feature.
2. Privacy roles and responsibility
Depending on the feature and circumstances, Whisser may act as a personal information controller because it determines why and how personal data is processed, or as a personal information processor acting on documented instructions from a school, organization, account owner, or another authorized controller.
Schools, teachers, organizations, workspace owners, and users who collect or upload information about other people are independently responsible for having a lawful basis, providing required notices, obtaining required permissions, limiting access, and using the Services in accordance with applicable privacy, education, employment, consumer, and communications laws.
3. Personal data we may collect
3.1 Account and profile information
- Name, username, email address, password hash, profile image, biography, preferences, language, role, organization, class membership, and account identifiers.
- Age or date-of-birth information when needed to determine eligibility, obtain appropriate authorization, or provide age-appropriate experiences.
- Subscription, transaction, invoice, entitlement, and payment-status information. Complete payment-card details may be handled directly by a payment provider rather than stored by Whisser.
3.2 Content and activity
- Prompts, messages, documents, assignments, answers, comments, posts, code, databases, files, images, audio, video, projects, feedback, reports, moderation appeals, and other material you submit, generate, save, publish, or transmit.
- Classroom information such as class membership, submissions, grades, scores, teacher feedback, attendance-related records, and learning activity where the relevant feature supports them.
- Interaction data such as features opened, actions taken, dates and times, search terms, model or tool selections, sharing settings, and collaboration history.
3.3 Device, network, and security data
- Internet Protocol address, browser, device type, operating system, language, approximate location derived from IP, referring page, session identifiers, cookie or local-storage identifiers, and application diagnostics.
- Authentication events, login history, failed login attempts, security alerts, abuse signals, rate-limit events, device or network indicators, audit logs, and records reasonably necessary to protect users and the Services.
3.4 Communications and support
We may retain support messages, privacy requests, legal notices, survey responses, bug reports, and other communications, together with information needed to verify identity, investigate the request, and document our response.
3.5 Sensitive or regulated information
Some user content may contain sensitive personal information because a user chooses to enter it. Unless a feature specifically requests it, do not submit government identifiers, financial credentials, medical records, precise location, biometric data, passwords, confidential legal material, or information about another person that you are not authorized to provide.
4. Sources of personal data
We may receive personal data directly from you; automatically from your device and use of the Services; from a school, teacher, administrator, organization, collaborator, or account owner; from authentication, hosting, analytics, security, payment, communications, AI, media, storage, and infrastructure providers; from integrations you choose to connect; and from publicly available or lawfully provided sources when needed for security, rights protection, or service operation.
5. Why and on what basis we process data
Subject to applicable law, Whisser processes personal data for one or more of the following purposes and legal bases:
- Providing the Services and performing our agreement: creating accounts, authenticating users, storing requested content, operating classroom and collaboration features, processing transactions, and delivering requested functions.
- Legitimate interests: maintaining, securing, troubleshooting, measuring, improving, and developing the Services; preventing fraud and abuse; enforcing our Terms; protecting users, Whisser, and the public; and supporting business operations where those interests are not overridden by applicable rights.
- Consent: where required for optional cookies, particular integrations, marketing, sensitive processing, or other activities for which the law requires consent. You may withdraw consent prospectively, subject to lawful exceptions.
- Legal obligations and public-interest requirements: complying with valid legal process, regulatory duties, tax and accounting requirements, safety obligations, and lawful requests.
- Protection of vital interests and legal claims: responding to urgent safety issues and establishing, exercising, or defending legal claims.
We may use aggregated or de-identified information for analytics, research, security, and product improvement where the information is not reasonably capable of identifying an individual. We will not attempt to re-identify de-identified data except as permitted to test our safeguards or comply with law.
6. AI features and third-party services
Some Whisser features may rely on third-party artificial-intelligence models, cloud infrastructure, authentication systems, payment processors, content-delivery networks, analytics services, communications providers, databases, storage providers, media processors, moderation tools, or external websites. When you use such a feature, the information needed to perform your request may be transmitted to and processed by the applicable provider.
Third-party providers may process information as Whisser's service providers, as independent controllers under their own terms and privacy policies, or in both capacities depending on the integration. Your use of an external or connected service may therefore be governed by that provider's separate terms, privacy notice, acceptable-use rules, retention practices, location, and security controls. Review those terms before enabling or using an integration.
Do not submit confidential, privileged, regulated, or highly sensitive information to an AI or external-service feature unless the feature expressly supports that use and you have authority to do so. AI-generated content can be inaccurate, incomplete, biased, or unsuitable. Whisser may log prompts, outputs, safety signals, and technical metadata to provide the feature, investigate abuse, improve reliability, and meet legal obligations, subject to applicable settings and provider arrangements.
7. Cookies, local storage, and local processing
Whisser may use cookies, local storage, session storage, cache, and similar technologies to authenticate users, maintain security, remember settings, preserve drafts, measure reliability, and operate requested features. Some tools may process or store data only or primarily on your device. Data stored locally may remain until you clear browser data, uninstall an application, delete the files, or use the feature's deletion control.
You can restrict certain technologies through browser or device settings, but blocking essential storage may prevent login or cause features to stop working correctly. Whisser does not represent that a browser "Do Not Track" signal has a uniform legal or technical meaning across all jurisdictions.
8. Classroom, educational use, and minors
Whisser Classroom and related learning features may process class membership, assignments, submissions, grades, feedback, and educational activity. Students should ordinarily access only information made available to them and their own personal records, while teachers and authorized administrators may access information needed to administer classes, review work, provide feedback, maintain integrity, and meet institutional obligations.
Schools, teachers, parents, guardians, and institutions are responsible for determining whether use is appropriate, obtaining permissions required by law or policy, configuring access correctly, and avoiding unnecessary collection. They must not use educational data for unrelated profiling, discrimination, or commercial exploitation.
Users who are below the age at which they can independently consent to data processing or enter a binding agreement may use the Services only with authorization from a parent, guardian, school, or other legally authorized person. If we learn that personal data was collected without required authorization, we may restrict the account and delete or otherwise handle the data as required by law.
9. When we disclose information
Whisser does not sell personal data for money. We may disclose personal data only as reasonably necessary:
- to vendors and processors that provide hosting, storage, security, authentication, analytics, communications, customer support, payment, AI, moderation, media processing, or other operational services;
- to a school, teacher, organization, workspace owner, administrator, collaborator, or recipient according to the feature, account configuration, sharing choice, or applicable agreement;
- to third-party services that you direct us to connect with or send information to;
- to investigate fraud, security incidents, abuse, intellectual-property complaints, threats, unlawful activity, or violations of our Terms;
- to comply with law, court orders, subpoenas, warrants, preservation requests, regulatory obligations, or other valid legal process;
- to protect the rights, property, safety, and security of Whisser, users, third parties, or the public;
- in connection with a financing, merger, acquisition, reorganization, insolvency, sale of assets, or similar transaction, subject to appropriate confidentiality and notice where required; or
- with your consent or at your documented direction.
Public posts, shared links, published projects, community content, and information you make publicly accessible can be viewed, copied, indexed, redistributed, or retained by others. Whisser cannot control information after another person lawfully receives or independently copies it.
10. International processing and transfers
Whisser and its providers may process data in the Philippines and in other countries where infrastructure, personnel, or vendors operate. Those countries may have different privacy laws. Where required, we use contracts, assessments, consent, or other legally recognized safeguards intended to provide appropriate protection for transferred personal data.
11. Retention and deletion
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing requested Services, maintaining account and transaction records, supporting security, preventing abuse, resolving disputes, enforcing agreements, meeting legal obligations, and defending claims. Retention varies by data category, feature, account status, legal requirement, risk, and technical architecture.
Deleted content may be removed from active systems but remain temporarily in backups, security records, fraud-prevention systems, or legally required archives. We may retain limited information after account deletion where necessary to document consent or transactions, prevent repeat abuse, comply with law, protect users, or establish or defend legal rights. Locally stored data remains under the user's control and may not be accessible to Whisser.
12. Security and incident response
We use reasonable and appropriate administrative, organizational, physical, and technical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures may include access controls, password hashing, secure sessions, logging, monitoring, backups, encryption where appropriate, least-privilege practices, vendor review, and incident-response procedures.
No online service is completely secure. You are responsible for securing your account, device, email, integrations, API keys, and local files; using a strong and unique password; signing out of shared devices; and promptly reporting suspected compromise. If a breach requiring notice occurs, Whisser will take reasonable steps to investigate, mitigate, and notify affected persons or authorities as required by applicable law.
13. Your privacy rights
Subject to applicable law and lawful limitations, you may have the right to:
- be informed about processing and obtain access to personal data;
- correct inaccurate or incomplete information;
- object to or restrict certain processing;
- withdraw consent for future processing that depends on consent;
- request erasure, blocking, or deletion where legally available;
- receive portable data in an appropriate format where applicable;
- request information about significant automated decision-making;
- complain to the National Privacy Commission or another competent authority; and
- seek damages or another remedy where provided by law.
To protect users, we may require reasonable verification before fulfilling a request. We may deny or limit requests where permitted by law, including when a request would expose another person's data, compromise security, interfere with an investigation, be manifestly unfounded or excessive, or conflict with a legal retention duty. Authorized agents must provide proof of authority.
14. Service and marketing communications
We may send essential account, security, transaction, classroom, policy, or operational messages that are necessary to provide the Services. Where permitted, we may send optional product or promotional messages. You may unsubscribe from marketing communications using the provided control, but you may continue to receive non-promotional service messages.
15. Automated processing
Whisser may use automated tools to detect spam, malware, fraud, unauthorized access, policy violations, account abuse, or technical failures. Automated signals may lead to rate limits, content review, security challenges, or temporary restrictions. Where a decision has a significant legal or similarly significant effect and applicable law grants review rights, you may contact us to request appropriate human review.
16. External links and independent services
The Services may link to websites, downloads, advertisements, repositories, or services that Whisser does not control. Their operators are responsible for their own privacy practices. A link or integration does not mean Whisser endorses or guarantees the third party. Review the third party's privacy notice and security practices before providing information.
17. Changes to this Policy
We may update this Policy to reflect changes in law, technology, vendors, risks, or the Services. We will post the revised Policy and update the effective date. Where required, we will provide additional notice or request consent. Continued use after an update takes effect means you acknowledge the revised Policy, but does not eliminate rights that require separate consent.
18. Philippine privacy framework
Where applicable, Whisser handles personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and relevant issuances of the National Privacy Commission. Other privacy and consumer laws may also apply based on the user's location, the relevant service, and the circumstances.
19. Contact and complaints
For access, correction, deletion, objection, consent withdrawal, portability, or other privacy requests, email [email protected]. For general support, email [email protected].
Please include enough information to identify the relevant account and describe the request, but do not email passwords or unnecessary sensitive data. You may also file a complaint with the Philippine National Privacy Commission or another competent authority where applicable.