Skip to content
whisk
FeaturesGuidesDocsPricingStatus
Sign in
whisk
FeaturesDocsGuidesComparisonsLearnSkillStatusSecurityContact
TermsAcceptable usePrivacyData processingTakedown
  • Terms of service
  • Acceptable use policy
  • Privacy policy
  • Data processing agreement
  • Takedown process
  • Security disclosure policy

Privacy policy

Last updated 9 October 2026.

This policy explains what personal data Whisk ("we") collects about the people who use the Whisk platform at whisk.run, why, where it is kept, who else sees it, and what you can do about it. It is written to meet the GDPR, the UK GDPR and the New Zealand Privacy Act 2020, and it gives Californian residents the rights the CCPA as amended gives them; where another law gives you more rights, you have them.

The short version

We collect what running your account needs and nothing else. We do not sell your data, we do not advertise, and we set no tracking cookies. We count visits to our website without cookies, in a way that cannot identify you unless you are signed in to your account. Your data and its encrypted backups live on servers in Europe. Six companies help us run the Service, and a seventh only if you turn its feature on, and each sees only its own slice. Nobody here can read a secret value without leaving a record you can see. You can export everything and delete everything yourself, and a deleted organisation is destroyed 30 days later by throwing away the key. The rest of this page is the detail, and it is worth reading.

There are two kinds of personal data on Whisk, and this policy is about the first:

  • Data about you as a user of the platform: your account, your sign-ins, what you did in the dashboard, your billing. We are the controller of this data. This policy covers it.
  • Data inside your apps: the people your apps are about, the customers your apps sign in, the records in your databases. Your organisation is the controller of this data and we process it only on your instructions, under the Data processing agreement. Questions about that data go to the organisation that runs the app. If you reach us instead, we pass your request to them within 5 business days and tell you we have.

1. Who we are and how to reach us

Whisk, Auckland, New Zealand, is the controller of the data this policy covers. Write to support@whisk.run about anything in it, including a request under section 7. We have not appointed a data protection officer, because the law does not require one of us. If that changes we will appoint one and name the contact here. We have also not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR; if one becomes necessary we will appoint one and publish its details here. Until then, support@whisk.run reaches us for every purpose in this policy.

2. What we collect and why

DataWhere it comes fromWhy we use itLegal basis (GDPR)
Name, work email and organisation nameYou, when an account is created or confirmedTo run your account, tell you what needs you, and know which business an organisation isContract
Sign-in credentials: passkeys (public keys only), one-time sign-in codes (stored hashed, ten minutes), sessionsWhisk's own sign-in serviceTo sign you in and keep others outContract; legitimate interest in security
Sessions and tokens: device, IP address, user agent, when each was usedYour browser and your agent's CLITo show you your active sessions, let you revoke them, and detect misuseLegitimate interest in security
The audit log: every login, permission change, secret set or read, deploy, and who did it, including which coding agent acted for whomThe platform, as you and your agent use itSo your organisation can see who did what, foreverContract; legal obligation where one applies
Billing: plan, invoices, payment status; the last digits of a card and its expiryStripeTo charge you and send invoices. Full card details never reach us.Contract
Notification preferences and time zoneYouTo send you the notifications you asked for, at times that make senseContract
Support requests and the emails you send usYouTo answer youContract; legitimate interest
Request logs at the edge: IP address, the address asked for without its query (on whisk.run's own pages, only a link's source and campaign tags are kept), the referring page without its query, browser name and version, time, status, request IDYour browserTo keep the platform secure and find faultsLegitimate interest in security and operation
Visit counts on the public site: the page, where the visit came from (the referring page's address without its query, or the source and campaign a link names), the browser's name and version, the time, whether the page was found, the country and network your IP address belongs to (looked up when the visit is recorded; the address itself is not kept), the kind of device, screen width and language your browser reports, how long a page was in view, how far down it was read and how fast it showed, links you followed to other sites, a visitor number that changes every day, and your account if you are signed inYour browser, when you open a page on whisk.run, and our request log of the same page loadsTo count how many people visit and which pages and links bring them, so we can tell whether a change to the site helped. Section 10 says how it worksLegitimate interest in understanding how the site is used
Abuse signals: the records in section 5 of the Acceptable use policyThe platform, measuring behaviourTo protect other tenants, our sending reputation and people outside the platformLegitimate interest; legal obligation where one applies
Abuse holds: the IP addresses an account first signed in from and the public keys of the computers its coding agents useThe platform, when a business is held under the Acceptable use policyTo stop a person whose business was held for abuse from starting the same thing again under a new nameLegitimate interest in protecting other tenants and people outside the platform
Feedback you send from the dashboard, with the IP address it came fromYouTo read and answer it, and to spot abuse of the formLegitimate interest

Where we rely on a legitimate interest we have weighed it against your rights, and we will explain the reasoning on request. You may object: see section 8.

3. What we do not collect

Saying what we hold is only half of it. We do not collect, and do not want:

  • health data, biometrics, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, trade union membership or criminal records about you as a platform user;
  • your precise location, or anything derived from it;
  • advertising identifiers, cross-site tracking data or a profile of your behaviour off Whisk;
  • your card number, which goes to Stripe and never reaches our servers;
  • the contents of your databases, files or secrets, which we store and cannot read as a matter of ordinary operation.

We do not sell personal data, share it for cross-context behavioural advertising, use it for advertising, or train a model on it. One decision is automated: when an automatic check finds an app serving scams or malware, or a new business matches the addresses or computers of one already held for abuse, every app of that business is taken offline at once and held for a person to review. A person reviews every hold, releases or removes it, and tells the owner. You can contest a hold by replying to the email about it or writing to support@whisk.run. We make no other decision about you by automated means that has a legal or similarly significant effect.

4. Where data is kept

The platform runs on servers we rent from Hetzner. Backups go to Backblaze B2, a second provider in a different country, held with versioning and a deletion lock so that a stolen credential cannot erase them.

5. Who else sees it (subprocessors)

We use these companies to run the Service. Each sees only what its job needs, is bound by a written contract with data protection terms no weaker than ours, and may not use the data for anything but our instructions.

SubprocessorWhat forWhat it sees
Hetzner Online GmbH (Germany)The servers and object storage the platform runs onEverything the platform stores, encrypted at rest
Backblaze, Inc. (United States)Off-site backupsEncrypted backups of databases and platform state
Amazon Web Services (AWS SES and AWS KMS)Sending platform email; holding the master key that wraps each organisation's encryption keyEmail addresses and message contents we send; key operations, never the data the keys protect
Resend, Inc. (United States)Sending email from the platform and from the apps on itEmail addresses and the contents of the messages sent
Stripe, Inc.Payments and invoices, and the card form on our payment pagesBilling contact details, payment method, invoices; on a payment page, what Stripe's own script collects to prevent fraud
Cloudflare, Inc.DNS for the platform's domainsDNS queries
BunnyWay d.o.o. (Slovenia)The CDN for a hostname, only when a business turns it onFor CDN-fronted hostnames, the public traffic to them

A subprocessor that will see personal data is listed on this page at least 30 days before it starts, and the current list is always this page. On the Business and Enterprise plans we also tell organisation owners by email when it is listed. You may object during that time on reasonable data protection grounds, as the Data processing agreement section 8 sets out.

Apart from subprocessors, we disclose personal data only:

  • to you, and to the people in your organisation who are entitled to see it;
  • to professional advisers under a duty of confidence;
  • to an authority or a court where the law requires it, in the narrowest way the request allows, and we tell you first where we may;
  • to a buyer or successor if the Service is sold or merged, under the same obligations, and we tell you before your data moves.

6. Who at Whisk sees it

Our staff access your organisation's data only at your request, such as to help with a support question, and that access is logged.

Everyone at Whisk with access to personal data is bound by confidentiality and gets only the access their job needs.

7. How long we keep it

DataKept for
Account, membership and organisation detailsWhile the organisation exists, then as a tombstone (the slug and the fact it existed) so a name is never reused
SessionsUntil they expire or are revoked; the record of each, with its IP address and browser, is deleted 30 days after that
Agent tokens30 days, refreshable, or until revoked; deleted 30 days after they expire or are revoked
Audit logIndefinitely, including after the organisation is deleted, because it is the record of who did what. The IP address on each entry is removed after 12 months
Edge request logs, platform logs and app logs14 days
Visit counts on the public site400 days; the daily number that groups one visitor's pages is useless after its day, because what made it is deleted the day after
Abuse signal records12 months
The IP addresses and computer keys kept with an abuse hold12 months after the hold is decided; the record that the hold happened stays
FeedbackThe message is kept; the IP address it came from is removed after 90 days
Records of the notifications we sent you12 months
Your own accountUntil you delete it from /me (section 8)
Support correspondence2 years from the last message
BackupsPoint-in-time recovery covers 30 days; backups roll out of retention after that
Billing recordsAs long as tax law requires, normally seven years

When an organisation is deleted it is shredded 30 days later (sooner on request): its encryption key is destroyed, which makes every backup that ever held its secrets unreadable, and its apps, databases, files and customer sign-in pools are removed. Backups of its databases and files roll out of retention within a further 30 days.

8. Your rights

You may ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or move it to another provider in a machine-readable form, and you may withdraw consent where consent is the basis without affecting what we did before. You will never be treated worse for exercising a right.

Most of this you can do yourself. Under /me you can see and revoke your sessions and tokens, download a copy of your own account (your profile, memberships, sessions, passkeys, tokens, your entries in the audit log and the feedback you sent), and delete your account, which signs you out everywhere and leaves no name or email behind. An owner can export the whole organisation from its trust page and delete it from the organisation's settings. If you are the last owner of a business you must hand it to someone else, or delete it, before you can delete your account. For anything else write to support@whisk.run. We answer within one month, and tell you if we need a further two months because the request is complex. We may ask you to confirm who you are before we act, and we will not ask for more than we need to do so.

If you are in California. You may ask what we collected about you in the last 12 months and where it came from, ask for a copy, ask us to correct or delete it, and limit our use of sensitive personal information. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of, and we do not use sensitive personal information for anything beyond running the Service. An authorised agent may act for you with written proof.

If you are unhappy with our answer you may complain to the data protection authority where you live. In New Zealand that is the Office of the Privacy Commissioner; in the EU your national supervisory authority; in the United Kingdom the Information Commissioner's Office. We would rather you told us first at support@whisk.run and gave us the chance to fix it.

9. Security

Every app runs in a sandboxed, non-root, read-only container on a network that reaches only its own database and the platform's services. Secrets are envelope-encrypted with a key per organisation, wrapped by a master key in AWS KMS that our servers never hold. Data is encrypted in transit everywhere. Images are scanned for known vulnerabilities on every build. Annex 2 of the Data processing agreement lists the measures in full, and our Security disclosure policy says how to report a weakness.

No system is perfectly secure. If a breach affects your personal data we tell you without undue delay, and the authority within 72 hours where the law requires, with what we know and what we recommend you do.

10. Cookies and tracking

whisk.run sets two cookies of its own, both necessary for the Service to work: the session, which keeps you signed in, and __Host-whisk_signin, a random value kept for 7 days that lets the sign-in page tell repeated attempts from one browser apart from attempts by many. On the payment pages, Stripe's card form sets Stripe's own cookies, which Stripe uses to prevent fraud and which the payment needs. There are no analytics, advertising or cross-site tracking cookies, so there is no consent banner. The payment pages load their font from our own servers, not from Google.

We count visits to the public pages of whisk.run ourselves, without cookies and without any other company, in two ways. Our servers' request log already records each page your browser asks for, and we read the page loads of whisk.run from it. And each page you open tells our own servers its address and, for the first page, the address of the page that sent you there. For each visit we keep the page, where you came from (that page's address without anything after a ?, or the source and campaign a link names), your browser's name and version as your browser sends it, the time, and, for page loads, whether the page was found. When you click one of the site's main buttons (Sign in, Start free, a plan's button) or copy the command that installs our command-line tool or the address of our instructions for coding agents, the page tells our servers which, on the same terms, and so does following a link to another site, with the address of the page it leads to. Each page also tells our servers your screen's width and your browser's language, and, only to tell automated browsers apart and without keeping them, your screen's height and whether software is controlling your browser. When you leave or hide a page, it tells them how many seconds it was in view, how far down you scrolled and, for the first page, how long it took to show. We work out from your browser's name whether you are on a phone, a tablet or a computer. When you sign up, we note which source the first page you opened that day came from, using the same daily visitor number. From the same request log we also count downloads of the install script and reads of those instructions, keeping the time, the address asked for and the program's name as it sends it. To count you once a day rather than once a page, the server combines your IP address and browser name with a random value and keeps only the result; it also keeps the result of combining your IP address alone with that value, so a download from your terminal can be told apart from one by our own team on the same connection. Your IP address is never stored with a visit, the random value is deleted the day after its day ends, and so nobody, including us, can work out who you are or follow you from one day to the next. At the moment a visit or a download is recorded, your IP address is also used to look up the country it is registered in and the network it belongs to (your internet provider, or the company or hosting provider that runs the connection), and we keep those two with the visit and then discard the address. The lookup is in a copy of DB-IP's free database that we download to our own servers each month, so your address is never sent to DB-IP or anyone else. If you are signed in, the visit also records your account, so that our own team and our customers can be left out of the numbers. If your browser sends a Global Privacy Control or Do Not Track signal, the visit is still counted and marked as such; it holds nothing that identifies you. Nothing is stored in your browser. We also read from Google Search Console how often whisk.run appeared in Google's search results and was clicked, for which searches and pages; Google gives these as totals per day, leaves out rare searches, and tells us nothing about who searched. Apps on whisk.page set their own cookies, which are theirs and are covered by their own operator's policy.

We send you service email you cannot opt out of while you have an account (security notices, billing) and product email you can, from the notification settings or the link in the message.

11. Children

Whisk is sold to businesses and no part of it is aimed at children. Nobody under 18 should be a platform user, and we do not knowingly hold data about one. If you believe a child has given us personal data, write to support@whisk.run and we will delete it. Whether an app on whisk.page is suitable for children is the responsibility of the organisation that runs it.

12. International transfers

Backups are kept by Backblaze, a United States company, email goes through Resend (United States) and AWS, and key operations go through AWS. Where personal data leaves the EEA, the United Kingdom or Switzerland, the transfer relies on the European Commission's 2021 standard contractual clauses with the UK Addendum and the Swiss amendments where they apply, on an adequacy decision, or on the subprocessor's certification under the EU-US Data Privacy Framework, as Annex 3 of the Data processing agreement records for each one. You may ask us at support@whisk.run for a copy of the clauses with commercial terms removed.

13. Links to other sites

Our pages link to documentation, providers and status pages we do not run. Their privacy practices are theirs, and we suggest you read them before you hand them anything.

14. Changes

We may change this policy. A change that reduces your rights is emailed to organisation owners 30 days before it takes effect, and posted on the dashboard. A new subprocessor is listed 30 days before it starts, and emailed to owners on the Business and Enterprise plans. Other changes take effect when published. The date at the top is the date of the current version, and we keep the previous versions available on request.

15. Contact

Whisk, Auckland, New Zealand, support@whisk.run.

See also: Terms of service · Acceptable use policy · Data processing agreement · Takedown process · Security disclosure policy