Privacy Policy

Last updated: August 25, 2026

Who We Are

Wasper is developed by an independent developer based in Lisbon, Portugal. For any privacy-related questions, contact us at privacy@wasper.app.

The Short Version

Wasper is designed with privacy at its core. By default, transcription happens on your Mac and your audio stays on your device. We collect the minimum data needed to provide the features you choose, run our business, and support customers.

What Data We Collect

Wasper Application

  • When you use local transcription, audio is processed on your Mac using a bundled on-device speech-recognition model. No audio data is transmitted to a server.
  • Transcriptions are stored locally on your device in a SQLite database. We have no access to them.
  • The app does not collect analytics or usage data. Optional anonymous crash reports may be sent (see Crash Reporting below). You can disable this in Settings.
  • No account is required to use the app.

Browser Extension

  • The extension may show a Wasper action on supported browser pages. It does not send page data until you choose to transcribe a video or start recording a tab.
  • When you use the extension, it handles the selected tab audio, selected page title, and selected page URL. It accesses microphone audio only after Chrome grants permission and you enable the microphone option.
  • When you start an Instagram Saved import, the extension collects the titles and URLs of the saved items you select, keeps the pending batch in Chrome session storage, and sends those selected items to the local Wasper app.
  • The extension sends this data only to the Wasper app on the same Mac at 127.0.0.1. Wasper processes audio locally and stores the resulting transcript in local History until you delete it.
  • The extension keeps activity records, including transcript text, titles, and URLs, in Chrome session storage. This survives closing the popup but is cleared when the Chrome session ends.
  • If you enable automatic summaries in Wasper and confirm the selected AI provider, the app may send the completed transcript, title, source URL, and source context to that provider to create a summary. This happens under that provider's policy and is separate from the extension's transfer to the local Wasper app.
  • We do not sell or rent browser-extension data, use it for advertising or cross-site tracking, or transfer it to third parties except when you explicitly enable and confirm an AI summary provider.
  • Wasper uses browser-extension data only to provide transcription and optional summaries that you request. This use complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Optional Cloud Transcription

  • If you enable cloud transcription, audio is sent to our server for processing and immediately deleted after transcription.
  • We do not store, log, or retain any audio data from cloud transcription.
  • Cloud transcription is entirely optional. Local processing is always available at no additional cost.

AI Rewrite Feature

  • Default: AI Rewrite runs on a bundled local model on your Mac (Apple Silicon only). Your selected text, voice command, and the rewritten output all stay on your device. No network request is made.
  • Optional AI providers: If you choose to configure Claude, OpenAI, Gemini, Grok, or a self-hosted OpenAI-compatible server on the AI Assistant page, your selected text and voice command are sent directly from your Mac to the service you configured. You supply any required credentials; Wasper does not have access to your account with these providers. Data stays on your device only when the server is hosted on your device.
  • If you use Anthropic (Claude): Anthropic does not use API inputs or outputs for model training. See Anthropic's API Terms for details. Each cloud provider has its own data-handling policy; please review theirs before opting in.
  • You can switch between local and cloud at any time on the AI Assistant page, or disable AI Rewrite entirely.

Crash Reporting

  • If enabled (default on, can be turned off in Settings → System), anonymous crash reports are sent to Sentry when the app encounters an error.
  • Reports contain: error message, stack trace, app version, and operating system version. No personal data, audio, or transcription content is included.
  • Sentry's servers are located in the EU (Germany). See Sentry's privacy policy.
  • You can disable crash reporting at any time in Settings → System → Crash Reports.

Update Checks

  • The app periodically checks for updates via GitHub Releases. This sends a standard HTTPS request containing your current app version. No personal data is transmitted.

License Validation

  • If you activate a license, your license key and a hardware identifier (macOS platform UUID) are sent to LemonSqueezy for validation. This is cached locally and re-checked periodically.
  • A local timestamp is stored on your device to manage the trial period. This data never leaves your Mac.

Website & Waitlist

  • Email address: Collected when you join our waitlist. Stored in Supabase (hosted in the EU). Used solely to notify you about product updates and launch.
  • Form source: Which form you used (hero or footer) — helps us understand our page layout, nothing more.
  • Analytics: We use cookieless analytics to understand aggregate traffic — Vercel Analytics plus a first-party page-view counter that records coarse, non-identifying signals (page, referrer, approximate country, screen size, browser language, device type, campaign source) to our own database. We do not store IP addresses or user-agents, neither uses cookies, and we never sell or share it.
  • We use no cookies and no advertising or cross-site trackers on this website.
  • Fonts are self-hosted. No requests are made to Google or other third parties when you visit this site.
  • Every email we send includes an unsubscribe link. Unsubscribing is instant and permanent — you can also email privacy@wasper.app to be removed.

Purchases

  • Purchases are processed by LemonSqueezy, who acts as the merchant of record.
  • LemonSqueezy collects payment information (card details, billing address) directly. We never see or store your payment details.
  • We receive your name, email, and license information from LemonSqueezy to deliver your license and provide support.

Why We Process Your Data

  • Waitlist emails: Based on your consent (you submitted the form). You can withdraw consent at any time.
  • Purchase data: Necessary to fulfill our contract with you (deliver license, provide support).
  • Support requests: Based on our legitimate interest in helping you and improving the product.
  • Crash reports: Based on our legitimate interest in maintaining app stability and fixing bugs (Art. 6(1)(f)). You can opt out in Settings.
  • License validation: Necessary to fulfill our contract with you (deliver and manage your license).

Third Parties

  • Supabase — Hosts our waitlist database (EU region).
  • LemonSqueezy — Processes payments as merchant of record. Their privacy policy.
  • Vercel — Hosts this website.
  • Optional AI providers — AI Rewrite runs on a bundled local model by default and sends nothing externally. If you explicitly configure another provider on the AI Assistant page, your selected text and voice command are sent to the service you chose: Anthropic (Claude), OpenAI (GPT), Google (Gemini), xAI (Grok), or a self-hosted OpenAI-compatible server. You supply any required credentials. Data stays on your device only when the server is hosted on your device.
  • Sentry — Receives anonymous crash reports (EU servers, Germany). Their privacy policy.

We do not sell, rent, or share your personal data with anyone else.

Data Processing Agreements

We have Data Processing Agreements (DPAs) in place with all third-party processors that handle personal data on our behalf:

  • SupabaseDPA
  • LemonSqueezyDPA
  • VercelDPA
  • Cloud AI providers — Only if you opt into one on the AI Assistant page. Each provider has its own terms: Anthropic, OpenAI, Google, xAI. You supply your own API key and Wasper is not a party to your agreement with any of these providers.
  • SentryDPA
  • ResendDPA

Data Retention

  • Browser extension state: Activity records, including transcript text, titles, and URLs, remain in Chrome session storage until the Chrome session ends.
  • Browser extension transcripts: Stored in Wasper History on your Mac until you delete them.
  • Waitlist emails: Kept until you unsubscribe or we complete the launch campaign, whichever comes first.
  • Purchase records: Kept as long as required by Portuguese tax law (typically 10 years for financial records).
  • Support emails: Kept for 2 years after last contact, then deleted.

Your Rights (GDPR)

If you're in the EU/EEA, you have the right to:

  • Access your personal data we hold
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Restrict processing of your data
  • Port your data to another service
  • Object to processing based on legitimate interest
  • Withdraw consent at any time (for waitlist emails)

To exercise any of these rights, email privacy@wasper.app. We'll respond within 30 days.

You also have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) at cnpd.pt.

Identity verification: To protect your privacy, we verify your identity before fulfilling data access, correction, or deletion requests. We will ask you to confirm the email address associated with your purchase or waitlist subscription. If we cannot verify your identity, we may ask for additional information. We will never ask for government ID or sensitive documents.

California Residents

While Wasper does not currently meet the thresholds requiring CCPA compliance, we respect your privacy rights. California residents may contact us at privacy@wasper.app for information about data we hold. We do not sell personal information.

Children

Wasper is not directed at children under 16. We do not knowingly collect personal data from children.

Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via email to waitlist subscribers or through the app. The "last updated" date at the top reflects the most recent revision.