1. Who we are
This Privacy Policy explains how Woosh ("Woosh", "we", "us", or "our") collects, uses, stores, and protects information about you when you use the Woosh application, website, and related services (collectively, the "Service").
Data controller: Woosh. The controller can be contacted at contact@woosh.no.
Data Protection Officer: Woosh is not currently required to appoint a Data Protection Officer under Article 37 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Privacy questions are handled by the contact above.
2. Scope and applicable law
Woosh is operated from Norway and is subject to the GDPR as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven). Where you access the Service from another country in the European Economic Area, the GDPR also applies directly. If you are outside the EEA, we still apply this Policy as a baseline standard.
3. Personal data we process
The table below describes every category of personal data the Service processes, the purpose for processing, and the legal basis under GDPR Article 6.
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account credentials | Username, email address (optional for guest accounts), password (stored as a one-way bcrypt hash, never in plain text) | Create and secure your account; authenticate sign-in; recover access | Performance of a contract (Art. 6(1)(b)) |
| Profile information | Display nickname, avatar, banner image, profile colours | Display your identity to other users you communicate with | Performance of a contract (Art. 6(1)(b)) |
| Messages and attachments | Text messages, image attachments (filename, MIME type, size), edit flag, replies, reactions, timestamps | Deliver messages to recipients; render message history; support edit/delete | Performance of a contract (Art. 6(1)(b)) |
| Social graph | Friendships, server memberships, direct-message participants, unread state | Operate the contact list, server, and DM features | Performance of a contract (Art. 6(1)(b)) |
| Voice and screen-share streams | Audio and video transmitted while you are connected to a voice channel | Real-time relay to other participants via a Selective Forwarding Unit (SFU). Streams are not recorded, persisted, or analysed by Woosh. Voice and video are not end-to-end encrypted. The relay server can technically observe the streams, but discards them after forwarding. | Performance of a contract (Art. 6(1)(b)) |
| Push-notification identifiers | Web Push endpoint, P-256 ECDH key, auth secret (web); FCM token + platform (Android); APNs token (iOS) | Deliver push notifications for new messages and activity | Performance of a contract (Art. 6(1)(b)); operating-system-level consent is collected separately at the device level |
| Terms-acceptance records | User ID, full HTML snapshot of the Terms accepted, acceptance timestamp | Demonstrate that you accepted the Terms in force at the time of registration | Legal obligation (Art. 6(1)(c)) and our legitimate interest (Art. 6(1)(f)) in being able to enforce the contract |
| Server and connection logs | IP address, request timestamp, HTTP method and response code, user agent | Security monitoring, abuse detection, debugging, rate limiting | Legitimate interests (Art. 6(1)(f)) in operating a secure service |
| Application telemetry | Crash reports, error traces, performance metrics, anonymised request paths, application version, OS version | Detect and diagnose bugs and outages | Legitimate interests (Art. 6(1)(f)) in maintaining a reliable service |
| Compliance records | Records of moderation actions, reports submitted, account suspensions, copyright notices, data-subject requests | Comply with the EU Digital Services Act, copyright law, and GDPR record-keeping duties | Legal obligation (Art. 6(1)(c)) |
We do not process special-category data (Art. 9) intentionally. If you choose to share such information in messages, we have no practical way to detect or prevent that, but we do not target the Service at any special-category processing.
We do not sell personal data. We do not use personal data for advertising, behavioural profiling, or automated decision-making with legal effect.
4. Microphone, camera, and screen access
Woosh requests access to your microphone, camera, and screen only when you actively join a voice channel or start a screen share. The operating-system permission dialog you see is the consent mechanism. We do not record, store, transcribe, or analyse the resulting streams. Access is released as soon as you leave the voice channel or stop sharing.
On Android, the RECORD_AUDIO permission is required by the operating system for any application that accesses the microphone.
5. How long we keep your data
| Data | Retention |
|---|---|
| Account profile | Until you delete your account, then erased within 30 days |
| Messages and attachments | Until you or another authorised user (e.g. server owner) deletes them, or until your account is deleted (then erased within 30 days) |
| Voice / screen-share streams | Not stored; discarded immediately after forwarding |
| Push-notification tokens | Until you uninstall, disable notifications, or delete your account, whichever is sooner |
| Terms-acceptance records | Up to 3 years after account deletion (limitation periods for contractual disputes) |
| Server and connection logs | Up to 90 days |
| Telemetry and crash reports | Up to 90 days |
| Moderation and DSA records | Up to 6 months after the action, longer if required for an ongoing investigation or legal dispute |
Where local law requires us to keep certain records longer (for example tax records), we will do so for the legally required period only.
6. Sub-processors and third-party services
We use the following providers to operate the Service. This list is kept up to date below; if a provider changes we will revise this section before the change takes effect.
- Microsoft Azure (Microsoft Ireland Operations Ltd.): cloud hosting, PostgreSQL database, file storage (Azure Blob Storage), and Application Insights telemetry. Resources are hosted in EU/EEA regions. Subject to Microsoft's Privacy Statement.
- Google Firebase Cloud Messaging (Google Ireland Ltd.): push-notification delivery on Android. Subject to Google's Privacy Policy.
- Apple Push Notification service (Apple Distribution International Ltd.): push-notification delivery on iOS. Subject to Apple's Privacy Policy.
- KLIPY: GIF, sticker, and clip search within the chat interface. When you search GIFs, KLIPY receives the search query and your IP address as part of normal HTTP traffic. Subject to KLIPY's own terms and privacy policy.
Each provider is bound by a Data Processing Agreement and may process personal data only on our documented instructions.
7. International transfers
Our primary infrastructure (Microsoft Azure) is configured to host data in EU/EEA regions. Some sub-processors, in particular push-notification providers, may transfer limited identifiers (e.g. device tokens, IP) to servers located outside the EEA, including the United States.
Where data is transferred outside the EEA, we rely on:
- The European Commission's Standard Contractual Clauses (Decision 2021/914) as incorporated into our agreements with each sub-processor; and
- For US recipients certified under it, the EU–US Data Privacy Framework adequacy decision.
A copy of the relevant safeguards is available on request from contact@woosh.no.
8. Your rights under the GDPR
Subject to the conditions in the GDPR, you have the right to:
- Access (Art. 15): request a copy of the personal data we hold about you.
- Rectification (Art. 16): ask us to correct inaccurate or incomplete data. Most profile fields you can edit yourself in-app.
- Erasure (Art. 17): delete your account at any time from in-app settings; the account and associated personal data are removed within 30 days, subject to the retention table above.
- Restriction of processing (Art. 18).
- Data portability (Art. 20): request a structured, machine-readable export of the personal data you provided to us. An in-app export is available at
Settings → Profile → Privacy & Data → Email me my data. The export is generated as a JSON file and emailed to the address on your account. Guest accounts without a registered email should convert to a full account first, or contact us to receive their export by another means. - Object to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time, where processing is based on consent.
- Not be subject to automated decision-making with legal effect (Art. 22): we do not engage in such processing.
To exercise any of these rights, contact contact@woosh.no. We will respond within one month of receiving the request and may extend the period by a further two months for complex requests, as permitted by Art. 12(3). Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.
Right to lodge a complaint: if you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. In Norway this is Datatilsynet. You may also complain to the authority in your EEA country of residence.
9. Children
The Service is not directed at children under 13 and we do not knowingly collect personal data from them. Where required by your country's implementation of GDPR Article 8, a higher age may apply: most EEA member states set the digital-consent age between 14 and 16. If you are below the digital-consent age in your country, you must have a parent's or guardian's consent to use the Service. If you believe a child has provided us with personal data without that consent, contact us and we will erase it promptly.
10. Security
We use industry-standard measures including TLS in transit, encryption at rest provided by Azure Storage and Azure Database for PostgreSQL, bcrypt password hashing, JWT-based session management, role-based access control on the production environment, and audit logging of administrative actions. No system is perfectly secure, and we cannot guarantee absolute security.
If we become aware of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (Art. 33) and, where the risk is high, notify affected users without undue delay (Art. 34).
11. Cookies and local storage
The Woosh web and desktop clients use only strictly necessary browser storage and do not require consent under Norwegian electronic-communications law. Specifically we store:
woosh.auth: your JWT access token so you stay signed in (localStorage, cleared on sign-out).- Zustand state keys (
app-store,settings-store,profile-store,social-store,server-store,voice-store): remember UI preferences, the last server/channel you viewed, microphone sensitivity, noise-suppression toggle, native-capture toggle, per-peer volume. theme: your selected colour theme.- Service Worker cache and Web Push subscription (push only if you opt in at the operating-system level).
We do not use advertising cookies, tracking pixels, third-party analytics cookies, or cross-site identifiers. Application Insights telemetry runs server-side only and does not place storage in your browser. You can clear cookies and local storage at any time from your browser settings; doing so will sign you out of the web client.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced in the application or by email at least 14 days before they take effect. The "Effective date" and "Version" at the top of this page will always reflect the latest version. Earlier versions are kept on file and can be requested.
13. Contact
Questions about this Privacy Policy or your data? Reach out and we'll get back to you.
Contact Us →