Privacy Policy
Last updated: 2026-08-30
Woosh ("we", "us") is operated by ViVeCo BV (enterprise number BE 0797.030.687, Belgium). This policy explains what personal data we collect, why, and how it is used.
Data we collect
• Phone number. Used to authenticate your account and deliver a one-time login code over WhatsApp or SMS, and — if no Woosh app is installed on your phone — to send notifications and occasional reminders as text messages.
• Contacts you choose to import. If you grant permission — from your device address book or by connecting Google Contacts — the contact details themselves (names, email addresses, phone numbers, and photos) stay on your device. To show you which of your contacts are already on Woosh, we send their phone numbers to our server, which keeps only a salted, irreversible hash of each number — never the raw number, name, email address, or photo.
• Calendar events you choose to share. If you connect Google Calendar (web) or grant calendar access (mobile), Woosh reads upcoming events from your primary calendar so it can suggest plans you might want to share with a group. Calendar read data is processed on your device and is not stored on our servers; only events you explicitly attach to a Woosh event are saved server-side.
• Approximate and precise location. If you grant permission, we use your location so friends can see you on the map. You can revoke this in your device settings at any time.
• Email address. Optional, and only if you give us one. We store it as a backup way to reach you when your phone number cannot be used — for example where we are unable to send a text message. It is never shown to other people, never sold, and you can remove it at any time from your profile.
• Technical data. Standard request logs (IP, user agent, timestamps) for security and abuse prevention.
• Device diagnostics. To find out how much battery Woosh's location tracking really uses, the app records — at the moment it sends a location update — your battery percentage, whether the device is charging, whether it is in a power-saving mode, and which tracking-accuracy setting is active. This is never linked to a position, is kept for 90 days, and is used only to improve the app.
How we use it
We use this data to provide the service: log you in, match you with friends from your contacts, show real-time presence, and operate the app securely. We do not sell your data.
WhatsApp messaging
Woosh uses the Meta WhatsApp Business Cloud API only to deliver one-time login codes to the phone number you enter on the sign-in screen. By entering your number and tapping "Send Code" you consent to receive that single message. We do not send marketing or promotional WhatsApp messages.
Text-message notifications
If no Woosh app is installed on your phone, a notification that has nowhere else to go may be sent to your phone number as a text message, through Twilio — and so may reminders we send on our own initiative, including a single one, once ever, if you made an account and never installed the app. To deliver it, Twilio receives your phone number and the text of the message, which for a notification can include a sender's name, a preview of what they sent, or where a friend is. These sends are limited: we cap how many you can receive in a day, we do not send during night hours in the timezone we have on record for you (UTC if we have none), and we never send to someone who has switched them off — in Settings under Notifications, or by replying STOP. We keep a record of each message: when it was sent, what kind it was, and the provider's reference, which is what lets us enforce those limits, see whether delivery worked, and understand how notifications are delivered overall; we do not keep the message text. Safety alerts are exempt from the daily limit and the night window, as they are in the app.
Email
Woosh sends email only where it is needed to run your account — confirming an address you gave us, or delivering a notification that could not reach you any other way. Those messages go through Resend, which receives your email address and the content of the message, and processes them on servers in the European Union. We do not send marketing email, and you can remove your address at any time from your profile.
Google user data
When you choose to connect your Google account, Woosh requests access to specific Google APIs to power features you have explicitly enabled.
• Google Contacts (contacts.readonly scope). If you connect Google Contacts, we read your contact list — names, phone numbers, email addresses, and profile photos — to (a) suggest which of your contacts are already on Woosh, (b) let you invite friends by email, (c) surface mutual connections within your groups, and (d) display each contact's photo as their avatar in the friend-picker so you can recognise them at a glance. The contact details stay on your device. To match against existing members, we send phone numbers to our server (hosted in the European Union), which stores only a salted, irreversible hash of each number — never the raw number, name, email address, or photo. You can delete the stored hashes at any time from Settings → Google connections, or by deleting your Woosh account.
• Google Calendar (calendar.events scope). If you connect Google Calendar, we read upcoming events from your primary calendar so we can suggest plans you might want to share with a Woosh group. We do not store this read data on our servers — it is held only in your browser session and is discarded when you close the tab. When you RSVP "going" to a Woosh event, we create a corresponding event on your Google Calendar; if you later decline, we delete that event. We do not read, modify, or delete any other events on your calendar.
Limited Use disclosure. Woosh's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
• We do not use Google user data to serve advertisements.
• We do not sell Google user data.
• We do not transfer Google user data to third parties except as necessary to provide or improve the features above (e.g. our hosting providers), for security purposes, or to comply with applicable law.
• We do not allow humans to read Google user data, except (a) with your affirmative consent for specific messages, (b) for security purposes (such as investigating abuse), (c) to comply with applicable law, or (d) where the data is aggregated and used for internal operations in accordance with applicable privacy and other laws.
• We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine learning models.
Revoking access. You can revoke Woosh's access to your Google account at any time at myaccount.google.com/permissions. Revoking access on Google's side does not automatically delete data already imported into Woosh — use Settings → Google connections to delete imported contacts, or delete your Woosh account to remove everything.
Storage and security
Data is stored on Supabase (PostgreSQL) inside the EU. Authentication tokens are stored on your device in the platform secure storage (Keychain on iOS, EncryptedSharedPreferences on Android). Transport is TLS-encrypted end-to-end between your device and our servers.
Your rights (GDPR)
You may request access, correction, or deletion of your personal data at any time by writing to hello@woosh.social. Deleting your account removes your user record and all imported contacts.
Deleting your account
You can delete your account and all associated data at any time from the app, or read the full steps on our account deletion page.
Contact
ViVeCo BV
Rozenhoed 46, 9921 Lievegem, Belgium
Enterprise number: BE 0797.030.687
Email: hello@woosh.social
← Back to Woosh