Privacy Policy

Last updated: 2026-10-03

1. Who We Are and How to Contact Us

Wisprs is an AI transcription and content workspace operated from the United States. In this policy, “Wisprs”, “we”, “us”, and “our” mean the service at wisprs.co and the team that operates it. We are the controller of personal data we process to provide the service, unless we tell you that we are acting only as a processor for a business customer. For privacy questions, rights requests, or complaints, email tosh@getwisprs.com. Please do not send passwords, access tokens, or unnecessary sensitive information in an email.

2. Personal Information We Collect

Depending on how you use Wisprs, we collect the following categories of information: (a) account identifiers such as your name, email address, account ID, authentication and session records, and preferences; (b) billing and commercial information such as plan, subscription, invoices, payment status, usage totals, and refund history; (c) content you choose to upload or create, including audio, video, filenames, transcripts, translations, summaries, chapters, action points, speaker labels, text-to-speech inputs, generated audio, and other outputs; (d) support information such as ticket messages, attachments, and replies; (e) connected-account and integration information such as OAuth grants, scopes, client and workspace identifiers, operation receipts, and revocation state; (f) technical and usage information such as IP address, user agent, browser and device details, approximate location derived from an IP address, page and feature interactions, error and performance measurements, and security or abuse signals; and (g) information you provide in a public share link or meeting capture, including access logs. Audio or transcript content can contain sensitive information about you or other people. We do not use it to infer biometric identity. We receive information from you, your browser or device, authentication and billing providers, connected tools, support communications, and service providers that help us detect fraud, protect the service, and deliver features. We do not intentionally collect more information than is needed for these purposes, but content you upload may contain anything recorded in that content.

3. Why We Use Information and Our Legal Bases

We use information to create and secure accounts; authenticate users; upload, store, transcribe, translate, summarize, search, export, share, and convert content; operate meetings and connected tools; calculate usage and enforce plan limits; process subscriptions, refunds, and support requests; send service and account emails; monitor reliability, performance, security, and abuse; improve the product and its accessibility; measure marketing and product journeys; comply with law; and establish, exercise, or defend legal claims. For people covered by the GDPR or UK GDPR, our legal bases are: performance of a contract for account, billing, storage, transcription, and requested outputs; legitimate interests for security, fraud prevention, service reliability, support, product improvement, and limited product analytics, balanced against your rights; consent where we ask for it, including where optional analytics or cookies require consent; and legal obligation for tax, accounting, safety, and lawful requests. You can object to processing based on legitimate interests at any time. If we need information to perform a contract or comply with law, we will explain the consequence of not providing it.

4. Content, AI Processing, and Connected Tools

We process your content only to provide the features you request, keep the service secure, support you, and maintain the service. We do not sell your content and do not use your content to train general-purpose AI models. AI outputs can be inaccurate and should be reviewed before you rely on them. You remain responsible for having the right to upload recordings, for giving any notice or consent required for recording other people, and for reviewing outputs before sharing or using them. When you connect Wisprs to an AI host or other tool, that tool receives only the inputs, excerpts, files, results, or operation data needed for the action you approve. To operate connected tools, we store the authorization grant, scopes, client or workspace identifiers, revocation state, and security, operation, usage, and cost records; raw OAuth access tokens are not stored in tool-operation records. A requested tool result may include a bounded transcript excerpt, search result, generated output, or a short-lived private export resource. The connected provider may retain information under its own terms. Revoking a grant stops new access through Wisprs but does not erase information already sent to or retained by that provider.

5. Service Providers and Disclosures

We disclose information to service providers that process it on our instructions or as needed to deliver a feature. These include Clerk for authentication and OAuth; Polar for subscriptions and billing; Resend for email delivery; ElevenLabs and OpenAI for speech-to-text or text-to-speech when routed to them; OpenAI, Anthropic, Google, or Ollama Cloud for requested AI features when enabled by the applicable product configuration; database, object-storage, hosting, queue, cache, monitoring, security, and support providers; and analytics providers such as PostHog, Mixpanel, Google Analytics, and Google Tag Manager where those tools are enabled. Providers receive the minimum data needed for their function and must protect it under their own agreements or applicable law. We may also disclose information to a buyer or successor in a merger, acquisition, financing, or sale of assets; to professional advisers; or to courts, regulators, law enforcement, or other parties when required by law or reasonably necessary to prevent fraud, protect people, enforce our terms, or protect our rights. We do not sell personal information for money and do not intentionally configure Wisprs analytics for cross-context behavioral advertising. A tag enabled through Google Tag Manager may have its own data practices, so review that provider’s policy when a tag is enabled. Service-provider disclosures may still be treated as “sharing” under a state privacy law, so the categories and purposes above are the complete description of those disclosures.

6. Wisprs Chrome Extension

The Wisprs Chrome extension works with your own Wisprs account. To connect it, you approve the connection on wisprs.co and the extension receives a scoped account key, which it keeps in extension storage that web pages and content scripts cannot read. The extension sends to Wisprs only what you choose to send: audio and video files you upload, links you submit (including the current tab's address when you click "Use this tab's link"), text you turn into speech, and recordings you start. Recording is optional and off until you enable it; it captures the audio of the tab you choose and, if you allow it, your microphone, only after you click Start and confirm that everyone on the call knows they are being recorded. When you record, the tab title and address are used to name the transcript. Once your account is connected, the extension also sends basic usage events (such as a transcription starting or failing) with a random installation ID and the extension version, and our servers log your IP address with each request, from which an approximate location may be derived. The extension does not read page content, browsing history, or other tabs, and does nothing in the background that you did not start. Short-lived recording chunks may remain in browser storage until upload completes and are then removed. You must follow all recording and consent laws that apply to the people and meetings you record. Our use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements: we use it only to provide and improve the features you use, we do not sell it, we do not use or transfer it for advertising or to determine creditworthiness or for lending purposes, and humans do not read it except with your permission, for security or abuse investigations, or where the law requires.

7. Analytics, Session Recordings, and Performance Data

We use first-party event and performance telemetry to understand navigation, feature use, errors, web vitals, and conversion paths. Depending on the environment and configuration, Google Analytics, Google Tag Manager, PostHog, and Mixpanel may receive page, device, interaction, and performance data. PostHog may also provide session replay and page snapshots for product debugging and UX improvement when enabled for the project. We do not intentionally put transcript text, audio bytes, access tokens, or passwords in analytics event properties. Session replay is a separate recorder: if it is enabled for a surface, it may capture rendered UI state, so sensitive content must be masked or that surface excluded before replay is enabled there. We defer non-essential analytics until the page is interactive, you interact with it, or the idle delay expires, but a browser may still load required tags or cookies. Internal staff browsers are opted out of product analytics. The current product does not expose a separate analytics consent preference center. If the law where you are requires prior consent for an optional technology, do not treat our load delay as consent: block optional cookies or contact tosh@getwisprs.com before using the service so we can handle the request. We are tracking this consent-control gap as a product compliance requirement.

8. Cookies and Similar Technologies

We use strictly necessary authentication, security, session, and abuse-prevention cookies. We also use preference storage such as the Wisprs theme and dashboard mode, first-party attribution and client identifiers such as wisprs_attr and wisprs_cid, and a short rolling session identifier such as wisprs_sid. Some analytics providers may set their own cookies, including Google or PostHog cookies when enabled. Our Cookie Policy describes these technologies and how to control them. Blocking necessary cookies can prevent sign-in or core product features from working.

9. Retention and Deletion

We keep account, content, usage, support, and security data for as long as needed to provide the service, meet the purpose for which it was collected, resolve disputes, enforce agreements, comply with tax and legal duties, and protect the service. Retention varies by data type and plan. Active account content remains available until you delete it or request account deletion. Operational logs, support records, billing records, and legal records may be kept longer where necessary. Deleted content is removed from active systems through our deletion process; encrypted backups and disaster-recovery copies may persist for a limited period until their normal overwrite cycle. We do not promise that deletion from a connected third-party tool or a public share recipient is possible, so revoke connected grants and share links as well as deleting content in Wisprs.

10. Your Privacy Rights and How to Exercise Them

Depending on where you live, you may have the right to know or access the personal information we hold, obtain a copy, correct inaccurate information, delete it, restrict or object to processing, withdraw consent, and receive portable information. You can export transcripts from Account Settings, delete content in the product, or start a verified account deletion request at Account Settings > Data & Privacy > Request account deletion. For any other request, email tosh@getwisprs.com from the account email and describe the request. We may ask for information needed to verify your identity and protect your account. We normally respond to a GDPR or UK GDPR request within one month, and to a California request within 45 days unless a lawful extension applies. We will not discriminate against you for exercising a privacy right. You may complain to the data-protection authority in the country where you live or work, or where you believe an infringement occurred. We have not appointed a data-protection officer; our privacy contact is tosh@getwisprs.com.

11. California and Other US State Privacy Rights

If a US state privacy law applies to you, the categories we may have collected in the preceding 12 months include identifiers and contact details; commercial and subscription information; internet, device, and interaction data; audio, video, transcript, and other user content; support and integration data; approximate location; and inferences from requested outputs. Sources are you, your device, authentication and billing services, connected tools, and service providers. Business purposes are the service, security, support, analytics, product improvement, billing, legal compliance, and transactions described above. We do not sell personal information. We do not knowingly use sensitive personal information to infer characteristics or for advertising. You may request access, correction, deletion, information about disclosures, or an opt-out where a law provides one. Send requests to tosh@getwisprs.com. We may verify a request, use an authorized agent where allowed, and explain any denial and appeal route required by the applicable law.

12. International Transfers

Wisprs and our service providers may process information in the United States and other countries. When personal data is transferred from the EEA, UK, or Switzerland, we use an adequacy decision, standard contractual clauses, or another lawful transfer mechanism when required. You can ask for more information about the applicable safeguard by contacting us.

13. Security

We use access controls, encryption in transit, encryption at rest where supported by the relevant system, scoped credentials, logging, rate limits, backups, and other technical and organisational measures appropriate to the risk. No online service can guarantee absolute security. Tell us promptly if you believe an account or share link has been compromised.

14. Children

Wisprs is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child provided information to us, contact tosh@getwisprs.com so we can investigate and remove it where appropriate.

15. Changes to This Policy

We may update this policy when our service, providers, or legal obligations change. We will post the new version with a new “last updated” date and, where appropriate, provide additional notice. Your continued use after the effective date means the updated policy applies to future processing. Contact tosh@getwisprs.com with questions.

Wisprs | Transcribe Audio & Video at the Speed of AI