Last Updated: October 1, 2026
Product status: Hardened Whisper v3 Preview (not GA)
Related: Privacy Policy §6 · Terms §7 · Product about: about/whisper.md
Not legal advice. This notice explains how Whisper private chat (QR sessions) handles data today. It does not cover Whisper Questions (anonymous Q&A links) — that is a separate product with a different privacy model (see Privacy Policy §7).
1. Purpose — true privacy for lawful conversation
Hardened Whisper private chat exists so people can have lawful, time-limited, private conversations with strong privacy engineering (on-device encryption, ephemeral rooms, Tor/onion relay path, optional Chat Lock).
Whisper is not a crime tool. It is not designed, offered, or permitted as a way to commit, plan, conceal, or facilitate illegal activity — including CSAM or child exploitation, terrorism or violent extremism, trafficking, illegal drugs or weapons trade, fraud, scams, phishing, non-consensual intimate imagery, credible threats, or any other crime.
There is no safe harbor for crime. Abuse of Whisper for illegal ends violates the Terms (§7.1 and §17) and may result in account bans and, where Buzzio holds reportable account or safety data, referral to authorities. Because message bodies are end-to-end encrypted, Buzzio generally cannot read Whisper content — that technical limit does not authorize illegal use. Participants remain solely responsible for what they say and do.
2. What Whisper private chat is
Whisper private chat is Buzzio’s time-limited, QR-started, end-to-end encrypted meet-and-vanish mode. It is designed so that:
- you can talk without adding someone as a permanent contact;
- participants appear as ephemeral slots (
creator/scanner), not as Buzzio IDs in the chat stream; - after the room expires or is ended, session material and relay paths are scrubbed — we do not keep a durable Whisper “who talked to whom” archive for new Hardened rooms.
We do not sell Whisper private chat data. Never. Not messages. Not session metadata. Not who scanned your QR.
3. Preview honesty (read this)
Hardened Whisper is offered as a Preview until our published verify gates and an independent audit summary support GA claims.
We will never market Whisper as:
- “untraceable,” “undetectable,” or “impossible to find”;
- “spyware-proof” or “perfect anonymity”;
- free of residual network or device risk.
Residual risks that remain even when Whisper works as designed:
| Risk | Honest answer |
|---|---|
| Peer | The other person can see what you send, screenshot (where not blocked), or record outside the app. |
| Your device | Malware, a compromised OS, or someone watching the unlocked screen can see content while Whisper is open. |
| ISP / network | Observers may see that you used Tor (or an optional mixnet path when enabled) — not message plaintext. |
| Global correlation | A powerful passive adversary may attempt traffic correlation. We do not claim Tor-grade certainty against that. |
| Hop operators | Relay hops see fixed-size ciphertext cells and timing/volume — not message plaintext and not Buzzio account IDs for Hardened rooms. |
4. Encryption & keys
- Message bodies and media are encrypted on your device before they leave it.
- Session crypto is ephemeral per room — not your long-lived 1-to-1 identity keys.
- Join material for new Hardened rooms is carried in an offline QR payload. New sessions are not minted on Firebase.
- Production Hardened rooms use a post-quantum hybrid wire (ML-KEM hybrid) as shipped in current builds.
- Buzzio operators cannot decrypt Hardened Whisper message bodies.
5. Network path (Hardened v3)
For live Hardened Whisper rooms:
| Layer | Role |
|---|---|
| Your device | Keys, local messages/media, nicknames; optional Chat Lock vault |
| Tor + onion hops | Fail-closed design: entry → middle → mailbox (multi-vendor when configured) |
| Opaque mailbox | Stores sealed cells with TTL scrub and rotating epoch identifiers — not readable chat archives |
| Not used for new rooms | Firebase createQrSession, RTDB qr_chats chat path, Whisper FCM wake for new Hardened create/join/chat |
Optional Maximum privacy routing (for example mixnet / Nym when linked in a build) is an additional privacy path when available. Mixnet is not claimed as GA until published verify criteria pass. Do not assume every build includes mixnet.
Keep the app available as the product requires while a room is live (for example Android foreground guidance) so the Tor path can stay healthy.
6. Session lifetime & controls
| Control | Current Hardened design |
|---|---|
| Duration | You choose 1 hour up to 48 hours (hard cap). Then delete. |
| Join | Offline QR only for new rooms (no HTTPS deep-link mint for new Hardened sessions). |
| Identity in chat | Ephemeral creator/scanner slots — not durable Buzzio IDs in the stream. |
| Seen / presence | Designed for seen-only style signals; no durable delivery/typing/online social graph on the Whisper wire. |
| Once-view / view-once media | Available where the product exposes them for Whisper lanes. |
| Cover traffic | Constant-rate cover while the room is live (as shipped) to raise the cost of simple traffic analysis. |
| Screenshot / secure surfaces | Platform secure-flag / screenshot restrictions apply on Hardened surfaces where implemented. |
7. Optional Chat Lock (on-device)
Optional Chat Lock (6-digit PIN, with biometric / device-credential presence when available) can put Whisper data in a separate SQLCipher vault with field-level AEAD (including media under the vault DEK).
- The vault seals when you leave Whisper or background the app (keys zeroed in RAM as designed).
- Wrong PIN: limited attempts + escalating wait.
- 10 wrong attempts, or an optional Fail-safe wipe PIN, erase Whisper data on this phone after clear confirmation (panic wipe — not stealth unlock).
Honesty: Chat Lock protects sealed data on a stolen or unlocked phone. It does not stop a live debugger while Whisper is open, and it is not a network “untraceable” claim.
8. What we store — and what we do not (Hardened rooms)
What Buzzio / Firebase hold for new Hardened rooms
For create / join / chat of new Hardened Whisper rooms, Buzzio’s Firebase paths are designed to hold no durable Hardened Whisper session graph. Session establishment and chat traffic go through the Hardened relay path described above.
What hop operators may process
Independent hop operators (for example Fly entry and Cloudflare middle/mailbox when configured) may process:
- fixed-size ciphertext cells;
- timing / volume metadata needed to forward cells;
- operational health metrics for the hop.
They do not receive message plaintext or Buzzio account IDs as part of the Hardened Whisper chat payload.
Multi-vendor hops are intentional: a single-vendor subpoena is less likely to yield every hop key.
On-device only (typical)
- Readable Whisper history for the live room
- Session keys and Chat Lock vault material
- Local nicknames / UI state for the room
Legacy rooms
Legacy Firebase-backed Whisper rooms created before create-retirement may still exist until the documented sunset / hard-delete window (earliest operator hard-delete after 2026-10-06 UTC). Those legacy paths are retired for new create. Privacy for legacy rooms follows the older operational fields until they expire or are deleted.
9. Compelled disclosure (honest table)
| Party | What they can get for Hardened Whisper |
|---|---|
| Buzzio / Firebase | No Hardened Whisper create/join/chat graph for new rooms. Account-level Buzzio data still exists if you have a Buzzio account for other features — that is separate from the Hardened Whisper room graph. |
| Hop operators | Ciphertext cells + timing/volume — not plaintext, not Buzzio IDs in the Hardened chat path. |
| Still residual | Peer content; ISP can see Tor/mixnet use; global correlation risk; compromised-device risk. |
We cannot decrypt Hardened Whisper message bodies. We cannot reconstruct an expired Hardened room after scrub.
10. Device integrity & backups
- Hardened create/session may warn on rooted, jailbroken, or emulator environments (warn-only unless product enforcement says otherwise).
- Whisper-sensitive local data is designed for exclusion from iOS backup and Android backup-off posture where implemented.
- Hardware-backed wrapping (StrongBox/TEE / Keychain) may protect mnemonic / key material on supported devices — this is key custody, not a claim that ECDH runs inside the secure element for every operation.
11. Analytics & telemetry
Whisper private chat is designed to avoid shipping private message contents to analytics. Product reliability telemetry that applies to the whole app (for example Firebase Analytics events configured for the app) is described in the main Privacy Policy §23. We do not use Whisper content to build advertising profiles. We do not sell analytics. Never.
12. Your responsibilities
- Use Whisper only for lawful private conversation (§1).
- Share QR codes only with people you intend to meet. Anyone who scans can join within limits.
- Do not use Whisper for CSAM, terrorism, trafficking, drugs/weapons trade, fraud, NCII, credible threats, or any other illegal activity.
- End or let expire rooms that should not keep living on devices.
- Protect your phone and optional Chat Lock PIN.
Buzzio is not responsible for misconduct by participants inside a Whisper private session we cannot read.
13. Whisper Questions (different product)
Whisper Questions (whisper.buzzio.dev and related pages) is not this notice. Answers are stored so the link owner can read them; that surface is not Hardened Whisper E2E. See Privacy Policy §7.
14. Changes & contact
We may update this notice when Hardened Whisper ships material privacy changes. The Last Updated date will change. Material changes are also reflected in the main Privacy Policy.
Privacy contact: founder@buzzio.dev (subject: Privacy Request)
Website: https://buzzio.dev
Full Privacy Policy: https://buzzio.dev/privacy
Effective as of October 1, 2026.
© 2026 Buzzio. All rights reserved.