1. Who we are

This Privacy Policy explains how Woosh ("Woosh", "we", "us", or "our") collects, uses, stores, and protects information about you when you use the Woosh application, website, and related services (collectively, the "Service").

Data controller: Woosh. The controller can be contacted at contact@woosh.no.

Data Protection Officer: Woosh is not currently required to appoint a Data Protection Officer under Article 37 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Privacy questions are handled by the contact above.

2. Scope and applicable law

Woosh is operated from Norway and is subject to the GDPR as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven). Where you access the Service from another country in the European Economic Area, the GDPR also applies directly. If you are outside the EEA, we still apply this Policy as a baseline standard.

3. Personal data we process

The table below describes every category of personal data the Service processes, the purpose for processing, and the legal basis under GDPR Article 6.

CategoryExamplesPurposeLegal basis
Account credentials Username, email address (optional for guest accounts), password (stored as a one-way bcrypt hash, never in plain text) Create and secure your account; authenticate sign-in; recover access Performance of a contract (Art. 6(1)(b))
Profile information Display nickname, avatar, banner image, profile colours Display your identity to other users you communicate with Performance of a contract (Art. 6(1)(b))
Messages and attachments Text messages, image attachments (filename, MIME type, size), edit flag, replies, reactions, timestamps Deliver messages to recipients; render message history; support edit/delete Performance of a contract (Art. 6(1)(b))
Social graph Friendships, server memberships, direct-message participants, unread state Operate the contact list, server, and DM features Performance of a contract (Art. 6(1)(b))
Voice and screen-share streams Audio and video transmitted while you are connected to a voice channel Real-time relay to other participants via a Selective Forwarding Unit (SFU). Streams are not recorded, persisted, or analysed by Woosh. Voice and video are not end-to-end encrypted. The relay server can technically observe the streams, but discards them after forwarding. Performance of a contract (Art. 6(1)(b))
Push-notification identifiers Web Push endpoint, P-256 ECDH key, auth secret (web); FCM token + platform (Android); APNs token (iOS) Deliver push notifications for new messages and activity Performance of a contract (Art. 6(1)(b)); operating-system-level consent is collected separately at the device level
Terms-acceptance records User ID, full HTML snapshot of the Terms accepted, acceptance timestamp Demonstrate that you accepted the Terms in force at the time of registration Legal obligation (Art. 6(1)(c)) and our legitimate interest (Art. 6(1)(f)) in being able to enforce the contract
Server and connection logs IP address, request timestamp, HTTP method and response code, user agent Security monitoring, abuse detection, debugging, rate limiting Legitimate interests (Art. 6(1)(f)) in operating a secure service
Application telemetry Crash reports, error traces, performance metrics, anonymised request paths, application version, OS version Detect and diagnose bugs and outages Legitimate interests (Art. 6(1)(f)) in maintaining a reliable service
Compliance records Records of moderation actions, reports submitted, account suspensions, copyright notices, data-subject requests Comply with the EU Digital Services Act, copyright law, and GDPR record-keeping duties Legal obligation (Art. 6(1)(c))

We do not process special-category data (Art. 9) intentionally. If you choose to share such information in messages, we have no practical way to detect or prevent that, but we do not target the Service at any special-category processing.

We do not sell personal data. We do not use personal data for advertising, behavioural profiling, or automated decision-making with legal effect.

4. Microphone, camera, and screen access

Woosh requests access to your microphone, camera, and screen only when you actively join a voice channel or start a screen share. The operating-system permission dialog you see is the consent mechanism. We do not record, store, transcribe, or analyse the resulting streams. Access is released as soon as you leave the voice channel or stop sharing.

On Android, the RECORD_AUDIO permission is required by the operating system for any application that accesses the microphone.

5. How long we keep your data

DataRetention
Account profileUntil you delete your account, then erased within 30 days
Messages and attachmentsUntil you or another authorised user (e.g. server owner) deletes them, or until your account is deleted (then erased within 30 days)
Voice / screen-share streamsNot stored; discarded immediately after forwarding
Push-notification tokensUntil you uninstall, disable notifications, or delete your account, whichever is sooner
Terms-acceptance recordsUp to 3 years after account deletion (limitation periods for contractual disputes)
Server and connection logsUp to 90 days
Telemetry and crash reportsUp to 90 days
Moderation and DSA recordsUp to 6 months after the action, longer if required for an ongoing investigation or legal dispute

Where local law requires us to keep certain records longer (for example tax records), we will do so for the legally required period only.

6. Sub-processors and third-party services

We use the following providers to operate the Service. This list is kept up to date below; if a provider changes we will revise this section before the change takes effect.

Each provider is bound by a Data Processing Agreement and may process personal data only on our documented instructions.

7. International transfers

Our primary infrastructure (Microsoft Azure) is configured to host data in EU/EEA regions. Some sub-processors, in particular push-notification providers, may transfer limited identifiers (e.g. device tokens, IP) to servers located outside the EEA, including the United States.

Where data is transferred outside the EEA, we rely on:

A copy of the relevant safeguards is available on request from contact@woosh.no.

8. Your rights under the GDPR

Subject to the conditions in the GDPR, you have the right to:

To exercise any of these rights, contact contact@woosh.no. We will respond within one month of receiving the request and may extend the period by a further two months for complex requests, as permitted by Art. 12(3). Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.

Right to lodge a complaint: if you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. In Norway this is Datatilsynet. You may also complain to the authority in your EEA country of residence.

9. Children

The Service is not directed at children under 13 and we do not knowingly collect personal data from them. Where required by your country's implementation of GDPR Article 8, a higher age may apply: most EEA member states set the digital-consent age between 14 and 16. If you are below the digital-consent age in your country, you must have a parent's or guardian's consent to use the Service. If you believe a child has provided us with personal data without that consent, contact us and we will erase it promptly.

10. Security

We use industry-standard measures including TLS in transit, encryption at rest provided by Azure Storage and Azure Database for PostgreSQL, bcrypt password hashing, JWT-based session management, role-based access control on the production environment, and audit logging of administrative actions. No system is perfectly secure, and we cannot guarantee absolute security.

If we become aware of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (Art. 33) and, where the risk is high, notify affected users without undue delay (Art. 34).

11. Cookies and local storage

The Woosh web and desktop clients use only strictly necessary browser storage and do not require consent under Norwegian electronic-communications law. Specifically we store:

We do not use advertising cookies, tracking pixels, third-party analytics cookies, or cross-site identifiers. Application Insights telemetry runs server-side only and does not place storage in your browser. You can clear cookies and local storage at any time from your browser settings; doing so will sign you out of the web client.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be announced in the application or by email at least 14 days before they take effect. The "Effective date" and "Version" at the top of this page will always reflect the latest version. Earlier versions are kept on file and can be requested.

13. Contact

Questions about this Privacy Policy or your data? Reach out and we'll get back to you.

Contact Us →