$ .../terms

terms of use

effective: june 2025 · version 1.0

what whispr is

whispr is a free, open-source, browser-based tool for anonymous, ephemeral, end-to-end encrypted peer-to-peer communication. it was built with a single purpose: to give people who need privacy a way to communicate without leaving a trace.

whispr has no accounts, no servers storing your messages, no logs, and no visibility into what you say. by design, we cannot read your conversations, we cannot recover them, and we do not want to.

this tool is free. it will remain free. it is not a product. it is not a business. it is infrastructure for people who believe private communication is a right, not a feature.

support whispr

keeping the lights on

whispr runs entirely on free-tier infrastructure: cloudflare workers for signaling, durable objects for ephemeral room state, and a turn relay service (metered.ca) to help peers connect across different networks.

these free tiers cover normal usage, but they are not unlimited. turn relay in particular consumes bandwidth on every relayed message and image — the more people use whispr, the more this costs to keep running smoothly.

whispr does not show ads, sell data, or charge for access. it never will. if you find this tool useful and want to help keep it free, fast, and ad-free for everyone, you can send a small donation in sol using the donate button in the corner of the screen.

donations are completely optional and go directly toward covering cloudflare worker usage, the turn relay subscription, and domain/hosting costs. there is no obligation, no tiers, and no features locked behind payment — whispr's full feature set is free for everyone regardless.

donations go directly toward cloudflare worker usage, turn relay, and domain costs.

your responsibilities

by using whispr, you agree that:

  • you are using this tool for lawful purposes only.
  • you understand that end-to-end encryption does not make illegal activity legal. the encrypted nature of this tool does not shield you from applicable laws in your jurisdiction.
  • you are solely responsible for the content you send and receive through whispr.
  • you will not use whispr to harass, threaten, or harm other individuals.
  • you will not use whispr to distribute illegal content, including but not limited to material that exploits minors, facilitates violence, or violates any applicable law.
  • you understand that whispr is a communication channel, not a shield for illegal conduct. if you are investigated by law enforcement for activity on your own device, the ephemeral nature of whispr does not constitute obstruction of justice on our part.

disclaimer of liability

whispr and its developer(s) expressly disclaim all responsibility for how this tool is used.

we have no visibility into, and bear no responsibility for:

  • ×the content of any conversation conducted through whispr
  • ×any illegal, harmful, or unethical use of this tool by any party
  • ×any consequences — legal, civil, personal, or otherwise — arising from the use or misuse of whispr
  • ×any decisions made based on communications through whispr
  • ×any data loss, session interruption, or technical failure

if whispr is used by irresponsible or malicious parties to conduct harmful activity, the developer(s) of whispr bear no liability for such use. the tool is provided as-is, as infrastructure. responsibility for use lies entirely with the user.

this is not a loophole. this is the nature of building privacy tools: we believe privacy is a right and we build for the responsible majority. we cannot and will not be held accountable for the irresponsible minority.

no warranty

whispr is provided "as is" without warranty of any kind, express or implied. we make no guarantees regarding:

  • uptime or availability
  • the security of your specific device or network
  • compatibility with all browsers or operating systems
  • the behavior of third-party infrastructure (Cloudflare, Vercel) that whispr depends on

use whispr at your own risk. for highly sensitive communications, we recommend combining whispr with additional operational security practices (VPN, secure devices, etc.).

encryption — honest disclosure

whispr uses ECDH P-256 key exchange and AES-256-GCM message encryption, implemented entirely in your browser via the WebCrypto API. keys never leave your device.

what this protects against:

  • server-side interception — we cannot read your messages
  • passive surveillance — no plaintext passes our infrastructure
  • data breaches — we store nothing to breach

what this does not protect against:

  • !a compromised device — if your phone or computer is compromised, encryption does not help
  • !the other person — once they receive your message, they can screenshot or copy it
  • !your own network — use a trusted network for sensitive communications

open source

whispr is open source. the code is available at github.com/vvarl0cks/whispr for review, audit, and contribution.

we believe transparency is part of security. if you find a vulnerability, please open an issue on GitHub.

contact & changes

whispr is maintained by an independent developer.

these terms may be updated without notice. the effective date at the top of this page reflects the most recent revision. continued use of whispr after any change constitutes acceptance.

for questions: open an issue at github.com/vvarl0cks/whispr