In plain language
- Your browsing, voice and game data stay on your PC. We never receive your history, cookies, recordings or transcripts.
- Free needs no account. If you create one, we keep only what it needs: your email, your consent, your plan, your PCs and, if you use Sync with Pro, a copy of your setup.
- No ads, no analytics, no tracking. This website sets a sign-in cookie only once you sign in.
- Paddle sells Pro as the merchant of record and handles your payment. We never see your card.
- You can download your account data or delete the account yourself, at any time.
#1. Who we are
Side Whisper is run by Crăciun Cosmin Viorel PFA (“we”, “us”), a sole trader registered in Romania. We are the controller of the personal data this policy describes.
For anything about your data, write to support@sidewhisper.app. We answer within one month, and usually within a few days.
#2. What this policy covers
The Side Whisper app for Windows, this website (sidewhisper.app) and the account service behind both.
Websites you open inside Side Whisper are run by others and follow their own privacy policies. So do the Microsoft Store, where you install the app, and Paddle, which handles payments for Pro.
#3. What stays on your PC
The app keeps its data on your PC, and we have no access to it: browsing history, open tabs, website sessions and cookies, site permissions, saved links and their icons, settings, themes, templates, voice transcripts, Dictionary, Snippets, game profiles and HUD readings.
Dictation is recorded and transcribed on your PC, and its temporary audio files are removed during normal operation. Recent address-bar searches are kept for up to 90 days, at most 100 of them. You can clear them, and your browsing data, under Settings, then Advanced. Uninstalling the app removes its data from the PC.
#4. What the app sends on its own
Side Whisper has no analytics, no crash reporting and no ads. Apart from the websites you open, it connects to these services:
- DuckDuckGo receives what you type in the address bar, in Add link and in Quick Search, to suggest searches and sites, and serves the icons of suggested sites. There is no setting to turn this off.
- GitHub serves the ad-blocking filter lists, which the app downloads each time it starts.
- Hugging Face serves the voice models, only when you choose to download one.
- The sites in your sidebar provide their own icons, which the app fetches from each site.
- The Microsoft Store installs and updates the app.
- Our account service, only if you sign in, as described below.
Each of these services sees your IP address, as any server you connect to does, and handles it under its own privacy policy.
#5. Your account and the data it holds
You need an account only for the Pro trial, Pro and Sync. When you have one, we process:
- Identity. Your email address. If you sign in with Google, also the name, profile picture and account ID that Google shares. We do not keep the access tokens Google issues.
- Sign-in. Six-digit codes, stored only as a one-way hash and valid for 10 minutes, and sessions, with the IP address and browser details they were opened from, which end 30 days after you last use them.
- Your PCs. For each connected PC, the name Windows gives it, its platform, a one-way hash of a device identifier, and when it was added and last seen.
- Consent. Which versions of the Terms and of this policy you accepted, when, and whether you want product news.
- Plan. Free, trial or Pro, when it ends, and the customer, subscription and transaction IDs that Paddle gives us. We never receive card details.
- Trial checks. One-way hashes of your email address and of your PC’s identifier, so that each person and each PC gets one trial.
- Sync. With Pro and Sync on, your sidebar links and their icons, templates, themes, Dictionary, Snippets and portable settings, so that your PCs match. Cookies, sign-ins, open tabs, shortcuts, game profiles and voice models never sync.
- Messages. The emails you send us and our replies.
- Security. Short-lived counters per IP address that limit sign-in attempts, and a log of administrative changes to accounts, such as granting Pro or suspending an account, with the date and the reason.
#6. Why we use it, and on what legal basis
- To provide what you signed up for: sign-in, your PCs, the trial, Pro and Sync. This is necessary for our contract with you (Article 6(1)(b) GDPR).
- To keep the service secure and fair: rate limits, one trial per person and PC, suspending accounts that abuse the service, and logging administrative changes. This rests on our legitimate interest in protecting the service and the people who use it (Article 6(1)(f)).
- To keep the records the law requires, such as accounting records (Article 6(1)(c)).
- To send product news, only if you asked for it (Article 6(1)(a)). You can change your mind at any time under Account, then Profile.
- To answer you when you write to us, as part of our contract with you or in our legitimate interest in helping you.
We do not sell personal data, we do not use it for advertising, and we make no decisions about you by automated means that have legal or similarly significant effects.
#7. Who processes it for us
A few providers run parts of the account service. They process personal data only on our instructions, under data processing agreements:
- Convex (Convex, Inc.) hosts the account database and the sign-in service, in the EU (Ireland).
- Cloudflare (Cloudflare, Inc.) hosts this website and passes requests on to the account service.
- Resend (Plus Five Five, Inc.) sends sign-in codes and service emails.
Others decide for themselves how they handle data, under their own policies: Paddle (Paddle.com Market Limited), the merchant of record for Pro, which processes your payment, tax details and invoices, and to which we pass your email address and account ID when you check out (Paddle’s privacy notice); Google, if you choose to sign in with Google; and the services the app connects to, listed in section 4.
We may also disclose data when the law requires it, for example to answer a valid request from a public authority.
#8. Transfers outside the EU
The account database stays in the EU. Cloudflare, Convex and Resend are US companies, and some processing, such as delivering an email or serving a page through Cloudflare’s network, can take place outside the European Economic Area. Where it does, we rely on the EU–US Data Privacy Framework for providers certified under it, and otherwise on the Standard Contractual Clauses approved by the European Commission.
Paddle is based in the United Kingdom. Transfers to it rely on the European Commission’s adequacy decision for the UK or, failing that, on Standard Contractual Clauses.
#9. How long we keep it
- Account data: for as long as you keep the account.
- Sign-in codes and PC connection codes: 10 minutes. Sessions: until 30 days after their last use, or until you sign out.
- Sent emails: 24 hours on our side. Resend keeps delivery logs for a limited time under its own policy.
- Rate-limit counters: deleted within a day.
- Synced copies: until you delete your account.
When you delete your account, we delete it at once with its sessions, PCs, consents, plan records and synced copies. We keep only what prevents abuse or what the law requires: the one-way trial hashes, a record of billing events that no longer points to you, and the log of administrative changes with your email address removed. Paddle keeps its own records of your purchases, as tax law requires.
#10. Your rights
You can ask us for access to your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on your consent, you can withdraw it at any time; that does not affect what we did before.
Much of this is self-service. Under Account, then Profile, you can download your data as a JSON file, change your product news choice and delete your account. For anything else, write to support@sidewhisper.app. We may ask you to confirm the request from your account’s email address.
If you think we have not handled your data properly, you can complain to the Romanian data protection authority, ANSPDCP (B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, Bucharest, dataprotection.ro), or to the authority where you live or work. We would appreciate the chance to put it right first.
#11. How we protect it
Connections to this website and the account service are encrypted. Sign-in codes and device identifiers are stored only as one-way hashes, sign-in attempts are limited, and a suspended account cannot sign in. Administrative access is limited to the owner, needs a recent sign-in for destructive actions, and is logged.
No system is perfectly secure. If a breach puts your data at risk, we will inform you and the authority as the law requires. To report a vulnerability, see our security contact.
#12. Children
Side Whisper is not meant for children under 16, and we do not knowingly hold their data. If you believe a child has created an account, write to us and we will delete it.
#13. Cookies and similar storage
This website sets a cookie to keep you signed in, a short-lived one while you sign in with Google, and a few values in your browser’s storage. None of them track you. The Cookies page lists each one.
#14. Changes to this policy
When this policy changes, we update the date and the version at the top. If a change affects how we use your data, we tell you in advance, by email or when you next sign in.