Transparency

How WIGGWIGG Uses AI

Two honest answers. What AI does with your data: almost nothing, and zero-knowledge means we can't read most of it anyway. How we use AI to build the product: a lot, and a human is always accountable.

AI & Your Data

What AI Does With Your Data

We don't profit from your data, and we built WIGGWIGG so we can't read the parts that matter most.

We never train AI on your data

Your messages, contacts, and identity details are never used to train machine-learning models. We don't do it, and the providers we rely on are contractually barred from using your data for their own ends.

No routine human reading

WIGGWIGG staff don't routinely read your texts or listen to your calls. We choose to run narrow automated safety filters. When review is needed, authorized staff may inspect safety-filter flags, abuse reports, appeals, and information you submit to support. Confirmed-illegal matches carry legal preservation and reporting duties. Other harmful matches are preserved by our choice and reported only if review concludes they are criminal in Canada.

No profiling, no ad targeting

We don't build a profile of you, target ads, or sell anything to data brokers. There's no surveillance business here to feed.

Zero-knowledge by design

Your vault (password manager) and identities are encrypted on your device before they ever reach us. We hold no key to read them, so no AI of ours can either. Your messages pass through our servers briefly to be delivered and safety-checked. Under our current method, they are then sealed to the account communication key so we cannot read the sealed copy. A small set retained from the private beta remains readable by our servers under older encryption until a separate re-sealing process.

The safety checks, and where we explain them

Naming what isn't zero-knowledge matters. We choose to run a few narrow, automated safety checks: none of them is AI we built to learn about you, and none reads the words in your messages. Confirmed-illegal matches carry legal preservation and reporting duties. Other harmful matches are preserved by our choice and reported only if review concludes they are criminal in Canada. We set out the checks, what stays readable on our servers and for how long on the pages below.

AI & How We Build

How We Use AI to Build WIGGWIGG

WIGGWIGG is built independently, with AI assistance. A person stays accountable for every change, anything security-sensitive gets extra review, and none of it ever touches your data or weakens encryption.

The coding AI works on code, not your data

The AI that helps us write WIGGWIGG works on our source code, not your account. Your vault is encrypted with keys derived on your device. Under our current method, your stored messages are sealed to the account communication key, which a supported client opens after sign-in and unlock. Our build tools do not see your actual data. A small set retained from the private beta remains readable by our servers under older encryption until a separate re-sealing process.

Built and tested on synthetic data

Development and testing run on local, made-up data, never your real account. Because your vault and identities are encrypted with your key, direct access to our production database would reveal only their ciphertext. For communications protected by our current method, the stored copy is also sealed. A small set retained from the private beta remains readable by our servers under older encryption until a separate re-sealing process.

A human is always accountable

AI is a tool we own the output of, not an excuse. Nothing ships without a person reviewing it and taking responsibility for it. There is no "the AI did it."

Security-reviewed, not just fast

Anything that touches encryption or sensitive data gets an explicit zero-knowledge and security review, including adversarial "red-team" checks, before it's released.

AI is not only for code

AI also drew our mascots and wrote part of our public copy: marketing, blog, social posts, newsletters. As with the code, a person reads it over and approves it before it goes out. For Patch and the Wiggs we looked for an illustrator first, did not find one, and started with AI instead. We still intend to hire someone for that work when the project can pay for it. None of it touches your data.

Our line in the sand

AI helps us build WIGGWIGG. It never gets to weaken the zero-knowledge guarantee. If a faster path required us to read your data, we don't take it.

Common Questions About AI at WIGGWIGG

Does an AI read my texts or listen to my calls?

No general-purpose AI reads your communications. Narrow, automated safety filters (spam screening and illegal-content detection) run in memory the moment a message arrives. WIGGWIGG staff don't routinely read your texts or listen to your calls, but authorized staff may review safety-filter flags, abuse reports, appeals, and information you submit to support. Under our current method, stored content is then sealed to the account communication key, which a supported client opens after sign-in and unlock, and we never train any model on it. A small set retained from the private beta remains readable by our servers under older encryption until a separate re-sealing process.

Do you send my data to AI companies like OpenAI or Anthropic?

No. Your encrypted vault and messages are never sent to any third-party AI service. The AI assistance we use goes into writing our own code, drawing our mascots, and writing part of our public copy: it works on our own content, never on your account data.

Is WIGGWIGG's code written by AI?

We use AI coding assistants as part of how we build. But a person reviews and is accountable for every change, and security-sensitive code gets extra adversarial review before it ships. AI speeds us up; it doesn't get the final say.

Could a bug in your code expose my data?

Yes, client-side security still depends on trusted client code. When an authentic, uncompromised client runs correctly, your vault and identities are encrypted before leaving your device, so a database or API compromise should reveal only ciphertext. A compromised device, malicious browser extension, or tampered web client could expose data after you unlock it. Under our current method, your stored messages are instead sealed to the account communication key, and we keep no key that can read the sealed copy. A small set retained from the private beta remains readable by our servers under older encryption until a separate re-sealing process. A message also passes through our servers in plaintext for the moment it takes to deliver and check it.

Communications Privacy

Exactly what we check on calls and messages, and what we keep.

Communications Privacy

Zero-Knowledge Encryption

How your data is encrypted on your device, so we can't read it.

Zero-Knowledge Encryption

Privacy Policy

The full, legal detail on how we handle your information.

Privacy Policy

Last updated September 2026