WI · Legal
Privacy Policy
WI (“WI”, “we”, “us”, “our”) is a short-form social product: Spark feed, Stories, Echoes, encrypted Chat and calls, and WI Coins. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and the rights you have. It is written to meet the expectations of major app platforms and privacy laws that apply to social apps — including the EU/UK GDPR, UK Data Protection Act, California CCPA/CPRA, and similar US state laws, and (where applicable) rules for users aged 13 and over.
If you do not agree with this policy, do not use WI. Using the app or websites means you understand how we handle information as described here.
1. Who we are
The WI services are operated under the WI brand at wivo.to (Spark / marketing / legal) and wivo.chat (messenger face of the same app). The mobile applications are published as WI, package com.wi.wi, with deep link scheme com.wi.app.
For privacy requests, the controller contact is privacy@wivo.to.
2. Information we collect
We collect information in three ways: you give it to us, we collect it automatically when you use WI, and we receive it from others (for example Apple, Google, or people who interact with you).
2.1 Information you provide
- Account. Username, display name, phone number and/or email, password or one-time codes, profile photo, bio, and sign-in via Apple, Google, or other supported providers.
- Profile & social graph. Who you follow, vibe with, block, or mute; lists and suggestions you interact with.
- Content you create. Clips, photos, captions, music tags, Stories, Echoes (comments), fire/pulse reactions, reports, and other text or media you upload or generate in WI.
- Messages & calls you choose to send. See Section 6. We design Chat so message bodies are end-to-end encrypted. We still process limited metadata needed to deliver the service.
- Support. Emails, reports, appeals, and attachments you send to support or privacy contacts.
- Purchases. When you buy WI Coins, Apple or Google process the payment. We receive purchase tokens, product IDs, and whether the transaction succeeded — not your full card number.
2.2 Information collected automatically
- Usage. What you watch, how long, swipe and tap events, fires, Echoes, follows, wallet actions (for example daily mining), crash and performance logs, and which screens you open.
- Device. Device type, OS version, app version, language, time zone, device identifiers needed for push notifications and fraud prevention, and approximate network information.
- Diagnostics & security. IP address, request timestamps, anti-abuse signals (including bot checks such as Cloudflare Turnstile on the web), and logs that keep accounts and payments safe.
2.3 Device permissions
WI asks for permissions only to run features you use. You can revoke them in system settings. Without a permission, that feature will not work.
- Camera — record clips and video calls.
- Microphone — record clips, voice notes, and audio/video calls.
- Photo library — upload videos and photos you choose.
- Notifications — alerts, chat, and calls.
WI does not require persistent background location to use Spark. We do not sell your precise location.
2.4 Information from others
- People who mention you, fire your clips, send you Echoes or messages, or report content.
- Sign-in and in-app purchase providers (Apple, Google, and similar).
- Service providers who host, send push, or help us stop spam and fraud.
3. How we use information
- Create and secure your account, and keep you signed in.
- Show Spark, Stories, profiles, Echoes, and the Create flow.
- Rank and personalize the feed (what you watch, fire, and follow helps us show clips that fit you).
- Deliver Chat, calls, and notifications.
- Run WI Coins: mining, balance, tips/gifts, and restoring purchases.
- Keep the community safe: detect spam, scams, underage use, copyright abuse, and other violations of our Terms.
- Measure product quality, fix bugs, and improve features.
- Comply with law, respond to valid legal process, and protect WI, users, and the public.
- Communicate about the product, security, and (where allowed) features you may care about. You can opt out of non-essential marketing emails.
We do not sell your personal information for money. We do not let third parties run their own advertising SDKs inside WI to build independent ad profiles of you. If that ever changes, we will update this policy and, where the law requires, ask for consent.
4. Legal bases (EEA, UK, and similar regions)
Where GDPR or the UK GDPR applies, we process personal data on these bases:
- Contract — to provide the app you signed up for (account, feed, chat delivery, coins you bought).
- Legitimate interests — safety, fraud prevention, product improvement, and showing a relevant feed, balanced against your rights.
- Consent — optional permissions (camera, microphone, photos, push) and any optional analytics or marketing we may add later. You can withdraw consent in settings or by contacting us.
- Legal obligation — tax, accounting, lawful requests, and child-safety duties where they apply.
5. How we share information
We share information only as needed to run WI:
- Other users. Profile, public or audience-limited clips, Stories, Echoes, and fires are visible according to the privacy setting you chose (for example Everyone, Friends, or Only you).
- Service providers. Hosting, databases, storage, push delivery, crash diagnostics, bot protection, and app-store billing. They may process data only on our instructions.
- Apple & Google. Sign-in and in-app purchases are governed by their policies as well as ours.
- Legal & safety. We may disclose information if we believe in good faith it is required by law, to protect someone from serious harm, or to defend WI’s rights. Encrypted Chat content that we cannot decrypt is not something we can turn over as readable text (see Section 6).
- Business transfers. If WI is merged, sold, or reorganized, information may move with the product under this policy or a successor notice.
We do not sell personal information as defined by the CCPA/CPRA. We do not share it for cross-context behavioral advertising. If you are a California resident you still have the rights in Section 10.
6. Chat, calls, and encryption
WI Chat (also described on wivo.chat) is built so that the body of 1:1 messages is end-to-end encrypted using a Signal-style session. If encryption cannot start, the message is not sent (“fail closed”).
- We cannot read the plaintext of successfully encrypted message bodies on our servers.
- We do process metadata required to operate Chat: that a conversation exists, participant IDs, timestamps, delivery/read-style events, and encrypted payloads or media pointers.
- Media (albums, voice notes, view-once) is stored in a private bucket with short-lived access, not a public CDN dump of your chat photos.
- Audio and video calls need camera and microphone on your device. Call signaling metadata is processed to connect the call.
- An optional messenger PIN can lock the inbox on your device; that PIN is stored in on-device secure storage, not in a form we can recover for you.
Encryption protects content in transit and at rest on our servers. It does not stop a person you chat with from screenshotting, forwarding, or reporting you. If you report a user, we may use available account and metadata to review the report.
7. WI Coins and payments
WI Coins are in-app virtual items. You can mine a daily amount, hold a balance, and use coins for features such as tipping or gifting where we offer them.
- Purchases go through Apple In-App Purchase or Google Play Billing. Those stores are the merchant of record. Refunds follow Apple or Google rules.
- We keep a ledger of balances and transactions so your wallet works across devices after you sign in.
- Coins have no cash value outside WI unless we expressly say so in writing. They are not a bank account, e-money wallet, or cryptocurrency exchange.
- We use purchase and mining signals to prevent fraud, duplicate claims, and abuse.
8. Safety, integrity, and public content
Like other large social apps, we use a mix of tools to keep WI usable and lawful:
- Reports, blocks, and post privacy (Everyone / Friends / Only you).
- Automated and human review of content that is reported or that our systems flag as spam, abuse, or illegal.
- Removal of content and restriction of accounts that break our Terms or the law (including child sexual abuse material, which we have a zero-tolerance policy for and will report as required).
Content you set to public can be viewed, shared, or downloaded by others. Think before you post. We are not responsible for what other people do with content you made public.
9. Storage, security, and retention
We use technical and organizational measures appropriate to a consumer social app: encryption in transit (HTTPS), access controls, and end-to-end encryption for Chat bodies as described above. No method is 100% secure.
We keep information only as long as needed for the purposes in this policy, including:
- Account and profile data — until you delete the account, plus a short period to complete deletion and handle disputes.
- Public clips and Echoes — until you delete them or the account is removed, unless we must keep a copy for safety or legal reasons.
- Wallet ledger — as needed for fraud prevention, accounting, and store rules.
- Security logs — for a limited time to investigate abuse.
- Legal holds — longer if required by law or a good-faith dispute.
Backup systems may retain residual copies for a limited window after deletion.
10. Your rights and choices
Depending on where you live, you may have some or all of these rights:
- Access and a copy of personal data we hold about you.
- Correction of inaccurate data (much of this you can edit in the app: profile, privacy of a clip, blocks).
- Deletion of your account and associated content, subject to legal exceptions (for example, we may keep records of a ban or a transaction).
- Portability of data you provided, in a common machine-readable format where technically feasible.
- Objection / restriction of certain processing, including profiling for feed ranking where GDPR gives you that right.
- Withdraw consent for optional permissions without paying a penalty. The related feature will stop working.
- California / similar US state rights: know, delete, correct, and opt out of “sale” or “sharing” for cross-context ads. We do not sell or share for those ads today. We will not discriminate against you for exercising privacy rights.
To use these rights, email privacy@wivo.to from the address on your account, or use in-app settings where we provide them. We will verify the request and respond within the time the law requires (generally 30–45 days, extendable as permitted).
EEA/UK users may also complain to their local data protection authority. US users may contact their state attorney general.
You can also: edit clip privacy, hide or delete your clips, block accounts, turn off notifications, and revoke camera / mic / photos / push in the operating system.
11. Children
WI is not directed at children under 13 (or the higher age required in your country, for example 16 in some GDPR states if we do not have a lawful basis for younger teens).
We do not knowingly collect personal information from children under 13. If you believe we have, contact privacy@wivo.to. We will delete the account and associated information as required by COPPA and similar laws.
Parents and guardians who need help with a teen’s account should use the same contact. We may require additional verification for under-18 users as child-safety rules evolve (including app-store age ratings and, where applicable, age-assurance duties).
12. International transfers
We may process and store information in countries other than where you live, including where our hosting and subprocessors operate. Those countries may have different data-protection laws. Where GDPR requires a transfer tool, we use appropriate safeguards such as Standard Contractual Clauses with our processors, plus supplementary measures where needed.
13. Cookies and similar technologies
wivo.to and wivo.chat are mostly static marketing sites. They may use strictly necessary cookies or similar storage for security (for example Cloudflare bot management / Turnstile) and to remember basic preferences. We do not run third-party advertising cookies on these sites today.
The mobile app uses local storage, secure storage, and push tokens as described above — not browser cookies.
14. Changes to this policy
We may update this Privacy Policy. The “Last updated” date will change. If a change is material, we will provide a more prominent notice (in the app, by email, or on wivo.to) as required by law. Continued use after the effective date means the updated policy applies.
15. Contact
Privacy requests: privacy@wivo.to
Support: support@wivo.to
Legal: legal@wivo.to
Web: https://wivo.to · Chat: wivo.chat
This document is provided so you can use WI with a clear picture of our practices. It is not legal advice to you. Platform rules (Apple, Google) and local law also apply.