Your data in a shared world
Privacy Policy
This Policy explains what personal data Whisp handles, why we need it, who can see it, how long we keep it and the choices available to you.
We use data to run accounts, live rooms, games, messages, social and creator features, keep Whisp secure, and meet legal duties. We do not sell personal data. Public content is public; private communications are processed to deliver and protect the Service.
1. Who is responsible for your data
Ceres Emil is the operator of Whisp.online (“Whisp”, “we”, “us”) and the controller for the processing described here. Ceres Emil is registered with the Dutch Chamber of Commerce under number 77146123 and has VAT number NL003160913B16.
For privacy questions or rights requests, use the Privacy and data rights channel or email [email protected]. We handle these requests in writing so there is a clear record. Do not send passwords, passkeys or unnecessary identity documents.
This Policy applies to the Whisp website and Service. A linked third-party site or service controls its own processing and should provide its own privacy information.
2. Personal data we collect
Data you provide
- Account and authentication: username, email address, password hash if you choose a password, email-verification state, passkey public credential data, account recovery and magic-link records, consent records and account settings.
- Profile and social: display name, avatar, profile picture, biography, status, friendships, follows, blocks, groups, room memberships, comments, wall posts and social activity.
- Communications: room chat, private messages, mail, reports, appeals, support requests and correspondence.
- Creations and uploads: room layouts, games, drawings, item metadata, images, audio, thumbnails, avatars, profile and group art, SWF files and related ownership or publishing data.
- Economy and gameplay: inventory, coins, bars, stamps, ledger entries, purchases, creator transactions, game sessions, scores, trophies, awards, prizes and progress.
Data collected during use
- Technical and activity data: IP address, browser and device information, user agent, timestamps, requested routes, session identifiers, room presence, actions, errors, diagnostics and security events.
- Approximate location: country or region inferred from an IP address where needed for security, localization or legal compliance. We do not require precise device location for ordinary use.
- Derived records: moderation state, abuse signals, rate-limit events, content-safety results and records needed to reconcile inventory or transactions.
Please do not submit sensitive personal data that Whisp does not ask for. Content you share about another person must have a lawful basis and respect their rights.
3. Why we use data and our legal bases
| Purpose | Typical data | Legal basis in the EEA |
|---|---|---|
| Create and operate accounts; authenticate users; provide rooms, games, chat, social, store, inventory and creator tools. | Account, profile, content, messages, sessions, gameplay and economy records. | Performance of our contract with you. |
| Keep the Service reliable, prevent fraud and abuse, moderate content, enforce rules and protect users. | Technical logs, security signals, content, reports, moderation and transaction records. | Legitimate interests in safety, integrity and service protection; legal obligation where applicable. |
| Verify email, deliver magic links, recovery, receipts, service messages and support. | Email, account status and correspondence. | Contract, legitimate interests and legal obligation, depending on the message. |
| Remember security, login, accessibility, interface and room preferences. | Session cookie and browser storage. | Contract or legitimate interests for strictly necessary storage; consent if non-essential storage is introduced. |
| Comply with law, valid authority requests, accounting duties and legal claims. | Relevant account, content, transaction, audit and communication records. | Legal obligation and legitimate interests in establishing, exercising or defending claims. |
| Measure aggregate reliability and improve features. | Usage, errors and aggregated or minimized activity data. | Legitimate interests; consent where the law requires it for device storage or tracking. |
Where we rely on legitimate interests, we consider necessity, proportionality and your rights. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
4. What other users can see
Whisp is social. Usernames, display names, avatars, profiles, public rooms, published items, public groups, comments, scores and other public activity may be visible to logged-in users or the public, depending on the feature and settings. People in the same room can receive live presence, movement, chat, drawings, game actions and shared media.
Private messages and mail are visible to their participants. They are not public, but our systems process them for delivery, abuse prevention, support and legal compliance. Authorized personnel may access content only when reasonably needed for these purposes. Recipients can save or share what you send, so do not send content you cannot safely disclose.
6. Cookies, browser storage and analytics
Whisp uses a strictly necessary session cookie to keep you signed in and protect authenticated requests. Local storage or similar browser storage may remember interface state, accessibility choices, room or window preferences, and temporary game state. Essential storage expires or is replaced according to its function; deleting it can sign you out or reset preferences.
With your consent, Whisp uses the following optional analytics services. They load only after you choose to accept analytics. Refusing them does not block ordinary access to Whisp.
- Google Analytics (measurement ID G-BKLHQ5GW3G): helps us understand visits, feature use, device and browser categories, approximate location, navigation and performance. Google may receive online identifiers, IP-derived information and usage events as our analytics processor.
- Microsoft Clarity (project kk9lhljbil): helps us find usability and reliability problems through aggregated interaction measurements such as navigation, clicks, scrolling, device information and session replays. Sensitive fields should be masked, but you should still avoid entering sensitive information that Whisp does not request. Microsoft may receive online identifiers, IP-derived information and interaction events as our analytics processor.
The legal basis for these optional services is consent. You may refuse them or withdraw consent at any time through Manage privacy on the site. Withdrawal stops future optional collection but does not undo processing that was lawful before withdrawal. Your preference is stored on your device so Whisp can honor it.
Google and Microsoft may process analytics data in the United States or other countries outside the EEA. Where required, transfers are covered by a valid adequacy mechanism, the European Commission’s Standard Contractual Clauses and supplementary safeguards. Their own privacy notices provide more detail about their processing. We do not use these analytics services to sell personal data or for third-party cross-context behavioral advertising.
7. How long we keep data
We keep personal data only for as long as needed for the purpose collected, then delete or anonymize it unless law or a legal claim requires longer. The exact period depends on the record:
- Account and profile: while the account is active, then during the short period needed to complete deletion and resolve restoration, fraud or legal issues.
- Sessions, passkey challenges and magic links: until expiry, logout, replacement or the security purpose is complete. Passkey credentials remain until removed or the account is deleted.
- Public and social content: while published or needed for the feature. Deletion may not remove copies made by recipients or material lawfully retained as moderation evidence.
- Security and moderation: for a proportionate period based on severity, recurrence, appeal windows and legal limitation periods.
- Transactions and accounting: for the period required by tax, accounting, fraud-prevention and consumer law.
- Backups: until overwritten in the protected backup cycle. Restored data is subject again to the live deletion process.
We periodically review whether retained data is still necessary. A lawful preservation request, dispute or investigation may temporarily extend a period for the relevant records.
8. Processors and international transfers
Service providers may process data in countries other than yours. When EEA personal data is transferred outside the EEA, we use a lawful transfer mechanism where required, such as an adequacy decision, the European Commission’s Standard Contractual Clauses with supplementary measures, or a limited statutory exception. You may ask for information about the applicable safeguard through our privacy contact.
9. Security and data incidents
We use measures designed for the risks of a live social service, including encrypted transport, password hashing, passkey support, access controls, request protection, rate limits, upload isolation and validation, logging, backups and restricted administrative tools. No system is perfectly secure. Keep your account credentials private and report suspicious activity promptly through Security.
If a personal-data breach is likely to create a legally relevant risk, we will investigate, document and notify the competent authority and affected people as required by law.
10. Your privacy rights
Under the GDPR, where applicable, you may ask for access, correction, deletion, restriction or portability of your personal data; object to processing based on legitimate interests; and withdraw consent. You also have the right not to be subject to a solely automated decision with legal or similarly significant effects where Article 22 applies. Whisp does not describe such automated decision-making as part of ordinary account use.
Submit a request through Privacy and data rights. State the account and request clearly. We may verify identity and ask for information needed to find the data, but will not ask for more than necessary. We normally respond within one month; complex or numerous requests may lawfully take up to two additional months, with notice. Rights can have exceptions, including the rights and freedoms of others, legal obligations and legal claims.
You may complain to your local supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens. We would appreciate the chance to resolve the concern first.
11. Children, changes and contact
Whisp is not intended for children under 13. Where local law requires parental consent for a user who is 13 or older, the user may register only after that requirement is met. If you believe a child used the Service contrary to this rule, contact Safety so we can investigate and delete data where appropriate.
We may update this Policy when our processing, Service or law changes. We will post the new version and effective date and provide additional notice for material changes where required. Earlier handling remains governed by the version then in effect.