This Privacy Statement describes how WIGGWIGG INC. (“we”, “WIGGWIGG”) collects, processes, uses and shares personal information and/or personal information about individuals browsing the WIGGWIGG website (“Website”) and about individuals using the WIGGWIGG web application or mobile application (collectively the “WIGGWIGG Service”).
The use of the second person (“you”, “your”, “yours”) refers to a visitor of the Website or user of the WIGGWIGG Service.
The contact details of the person responsible for processing personal information under this Privacy Statement are as follows:
Privacy Officer WIGGWIGG INC. 100-394 boulevard Maloney Ouest, Gatineau, Quebec J8P 6W2, Canada privacy@wiggwigg.ca (For any inquiry concerning the WIGGWIGG Service, please contact us through the WIGGWIGG Service)
What we corrected on September 9, 2026
The previous Privacy Statement incorrectly said that the stored copy of your message bodies and voicemail audio was sealed to a key specific to your device. We corrected that description and the related security boundaries:
- Under our current method, that copy is sealed to the account communication key. Supported clients open that key after you sign in and unlock. It is tied to the account, not to one device.
- Some communications retained from the private beta remain readable by our servers. Today, only signing in and unlocking with a supported web client automatically starts a bounded pass, for up to 50 eligible SMS rows. Mobile sign-in does not start that pass. The pass does not re-seal private-beta voicemail, legacy call-log numbers, MMS attachments, retained object copies, or every remaining SMS row at once. Those excluded copies remain server-readable until later passes or separate maintenance.
- On iOS, the notification extension currently receives a copy of the raw account communication key after the device’s first unlock, even when notification previews are hidden. That copy remains available when the vault or device locks and can open account history sealed to that key, not only a notification preview. The app attempts to erase it at sign-out, but sign-out does not fail closed or retry if erasure fails. Android instead uses a separate key limited to notification previews.
The communications corrections describe how the current system works. This version also covers the information requested to calculate taxes on a purchase or renewal. It is encrypted separately from your vault and remains readable by WIGGWIGG. Necessary tax records are generally kept for six years after the end of the last relevant year, including after account deletion. A specific legal requirement may extend that period. You confirm where you live at checkout, or when you update it for renewals.
1. Collection of personal information
1.1. User Information
We minimize our collection of personal information as much as possible. We process information you choose to provide and operational information generated by the features you use. The applicable categories, purposes, and retention periods are described in this Statement.
WIGGWIGG does not hold the keys needed to read your password, zero-knowledge-encrypted identity details and contacts, or message content in the default sealed-storage path. Your password is not uploaded. Identity details and contacts are encrypted on your device before upload. Calls and messages pass through WIGGWIGG and telecommunications providers in plaintext so they can be routed. Message content is also checked as described below. After that transit and those message checks, stored message bodies and voicemail audio in the default path are sealed server-side under one-time keys WIGGWIGG does not hold. This statement does not cover operational data needed for phone routing, billing, and support, optional features that require server-side processing, the illegal-content check we run on picture messages, or copies preserved when content is flagged. Server-readable data and the exceptions you choose to enable are described below.
The app includes a performance telemetry switch, off by default. If you turn it on yourself in settings, the app sends performance measurements and error reports to our own observability server, with no cookies or account identifier. On mobile, a random code groups ordinary traces from one app launch without being tied to your account; the incoming-call wake diagnostic omits it. Separately and regardless of this switch, the mobile app reports startup failures, uncaught global errors, and unhandled promise rejections so we can diagnose an app that will not open. Those reports contain a truncated error message, name and stack, whether the error was fatal, the build commit, app version, operating-system summary, time, and a random per-launch code. They contain no account identifier or form values, and query strings are removed from web addresses in stacks. An error message or stack can still contain personal information if the error itself includes it. The setting is synced with your account, so it applies to all your devices.
Registration asks for no billing country, province, or address, and those details do not determine your account tier. When you make a digital purchase or update your residence information for a digital subscription’s renewals, we separately ask for your country and province, territory, or state, and your confirmation that this is where you live. Checkout for Canadian phone service asks for a Canadian province. Phone-trial activation validates the province without adding it to the trial payment session or the record used to enforce one trial per account.
To enforce one phone trial per account, we retain the link between your account, the trial payment session, and the time its $0 checkout was accepted. If a verified permanent failure occurs while activating the number, this same record retains the time when your first and only replacement attempt was authorized. The next accepted attempt replaces the failed-session link with the new session; the authorization time remains on the record to prevent another replacement. The record is deleted with your account. We also count total accepted $0 phone-trial checkouts per UTC day, without an account identifier, to monitor cost and abuse and to stop new activations if necessary. That stop does not disable activated numbers or 911 service.
1.2. Calls and Messages
Calls, SMS and voicemails travel over the public telephone networks. That transit is not encrypted and stays visible to carriers, as it does for any phone service that interoperates with the public network. No phone provider can encrypt that segment. For a conversation that needs to stay end-to-end encrypted, use a service built for it, such as Signal.
Carrier and telecommunications rules require automated checks on SMS and MMS traffic. We go further than those rules require and also check picture messages for known illegal content; running that check is our decision. Those checks run in transit, on the plaintext, before encryption. When nothing is flagged, we keep no fingerprint of the content at all, only the result of the check and minimal metadata, and a 90-day sweep deletes those records. For images, when something is flagged, we also keep a keyed one-way fingerprint, so the same image is recognised if it comes back. We keep no fingerprint of the text of your messages, flagged or not. One exception applies: when content is flagged as illegal, we preserve a copy, as the law requires. We also preserve a copy when a detector flags a picture as harmful to children without placing it in its confirmed-illegal category; that is our decision rather than a legal obligation. That category is not a finding that the picture is legal: nothing is reported automatically, but if a review concludes the material is criminal in Canada, we report it. Neither copy can be deleted at your request.
We save a copy of your messages and voicemails in your account, and we do not use them for any purpose other than providing our services. Under our current sealing method, stored message bodies (SMS, MMS) and voicemail audio are encrypted at rest under a one-time key, which is itself sealed to the account communication public key. Supported WIGGWIGG clients open the corresponding private key after you sign in and unlock. The key is tied to the account, not to one device, and we keep no key that can decrypt the sealed copy. This is not end-to-end encryption: it protects what is stored, not what is in transit.
Some communications retained from the private beta still use our older server-side encryption and remain readable by our servers. Today, only signing in and unlocking with a supported web client automatically starts a bounded pass that can re-seal up to 50 eligible SMS rows. A mobile sign-in can provision the account key but does not start that pass. The pass does not re-seal private-beta voicemail, legacy call-log numbers, MMS attachments, retained object copies, or every remaining SMS row at once. Those excluded copies remain server-readable until later passes or separate maintenance.
The exceptions, which we state explicitly:
- Listen by phone. If you turn this on for a number, new voicemails on that number are kept in a form our servers can read, so you can hear them by calling your voicemail. The option is off by default. Turning it off returns new voicemail to account-key sealing, but does not automatically re-seal older server-readable voicemail from the private beta. That older voicemail remains server-readable until separate maintenance.
- The intros your callers record. If you use call screening, the short recording in which the caller says who they are is kept in a form our servers can read, because the phone network has to play it to you when the call rings. The caller has no account and no key with us.
- Automatic replies. The text of your automatic replies is kept in a form our servers can read, because our server is what writes and sends them on your behalf.
- Contact recognition on calls. If you turn it on, a keyed fingerprint of each contact’s number is stored so we can recognize a known caller on incoming calls and a known sender on incoming texts; while it is on, those numbers are recoverable by our servers. Off by default; turning it off erases the fingerprints from our live systems, and encrypted backups age out within about a month.
- Calling devices. After you accept the current Privacy Statement, official WIGGWIGG clients automatically register up to 10 active browsers or mobile devices on your account when you sign in and unlock your data so they can receive your calls. The random recognition code stays on the device that created it and is sent to us only transiently for recognition; we neither log nor store the raw code. We retain a keyed, account-scoped fingerprint. While the registration is live, we can read the account link, a random internal device id, browser-or-mobile class, account-local display number, associated phone ids, lifecycle state, and registration, readiness, and lifecycle activity timestamps. For each phone number, we can also read whether all devices or only the devices you choose may ring and infer the selected device links. A custom device name is encrypted on your device and is not readable by us. A historical calling-device decline or withdrawal remains a server-readable paused routing state until you explicitly turn calling devices back on after recent authentication; we do not retain a separate date for that state change. Removing a device immediately stops new calls to its registration, but provider cleanup may take time. After cleanup is confirmed, we erase the active metadata and encrypted name. We retain only the account link, random internal id, keyed fingerprint with its key version, and revoked status. While that minimal record exists, it blocks reuse of the old code. The record is deleted with your account or earlier when its fingerprint key is retired. The WIGGWIGG app creates a new recognition code when it registers again. A separate account-scoped event ledger, containing only a random internal id, the account link, and the attempt time, enforces rolling registration limits and is swept after its 24-hour window.
- iOS notification decryption. After the device has been unlocked once, the current iOS app copies the raw account communication keypair into a device-only shared keychain so its notification extension can decrypt notification content. It does this even when your notification display setting is Nothing. The copy survives vault lock and device lock, and it can open all history sealed to the account key, not only notification previews. The app attempts to erase the copy when you sign out, but sign-out does not fail closed or retry if erasure fails. The copy is not uploaded to WIGGWIGG. Android uses a separate display key whose scope is limited to notification previews.
- Your phone lines. Your WIGGWIGG numbers, the personal number you verify for call forwarding, and the greetings, pickup announcements and caller prompts for a line, whether you write them or record them, are readable by our servers, because they are what the phone network runs on.
- Support requests. The content of your support tickets is encrypted, but the ticket text is readable by you and by WIGGWIGG support, so we can handle your request; files you attach are stored readable by our servers, so support can open them to help you. You can also choose to attach technical details about your device, your app or your browser, to help us reproduce the problem: this is optional, you decide when you send the request, and those details are readable by WIGGWIGG support too. No one else can access it.
- Call metadata. Call detail records (date, time, duration, your own line’s number) are encrypted under a server key: we need to be able to read them for billing and for our regulatory obligations.
Our servers and the data we hold are in Canada. Our providers and the third parties the service must work with run their own infrastructure, including in the United States: telephone traffic passes through our carrier and payments through our payment processor. What they retain, where, and for how long is governed by their policies, not ours.
1.3. Information collected through the Website
We only collect information you provide voluntarily: if you subscribe to our newsletter, your email address and the language and country you pick. We encourage you to use an email address that does not identify you. Newsletter signup forms no longer send campaign parameters, the previous page’s address, or technical details about your device to our subscription service. We do not collect any other information nor use any analytics tools on the Website.
1.4. The community forum
WIGGWIGG operates an optional community forum (community.wiggwigg.ca), hosted on cloud infrastructure we operate in Canada and not on a third-party community platform. Access is only through your WIGGWIGG account; the forum creates no separate password and sends no email.
You take part under a display name that you choose. We send the forum this display name, a pseudonymous identifier irreversibly derived from your account, and a synthetic email address, never your real name, your account identifier, or your real email address. We do not publicly link your identity to your messages, but if you reveal personal information in what you post, it may be associated with you.
The forum does not receive your real IP address: it is replaced with a constant value before reaching the forum. As with the rest of the WIGGWIGG Service, our load balancer briefly logs connection IP addresses for security purposes, retained for at most 90 days. Security records keep a keyed one-way fingerprint of the IP (not the address) for up to seven years.
The forum offers an anonymous mode that hides your display name from other members, but not from the system: the technical link between the anonymous profile and your membership still exists. After roughly a week without anonymous activity, the forum issues you a new anonymous profile, and posts made under the previous one are not tied to the new one.
Unlike data subject to our zero-knowledge architecture (section 1.1), the content you post on the forum is readable by the forum software and visible to the public or to members, depending on the category. Post accordingly.
2. Processing of personal information
We process personal information collected through WIGGWIGG Service for the sole purpose of operating the WIGGWIGG Service and for no other purpose.
Automated checks run on message content in transit (section 1.2). We have no access to the content of your calls.
3. Personal Data storage and retention
Our databases and file storage are in Canada (AWS ca-central-1). Two exceptions: DNS query logs (no account data) are held by AWS in the United States for 90 days, and our content delivery network caches encrypted files at edge locations in North America and Europe.
Any information transmitted on telecommunication networks transits through infrastructure located in the United States and operated by Telnyx, our telecommunication services provider. We do not store any User Data at rest in the United States.
We retain User Data while the relevant User has an active account on the WIGGWIGG Service, subject to the shorter periods described in this Statement. Account deletion has a 30-day grace period during which signing back in cancels the request. After that, personal data is permanently deleted except for invoices and necessary tax records; verdicts for content checks that flagged something and the preserved copy for either match class described in section 1.2, only one of which is legally compelled; and security audit logs kept up to seven years for service security.
Retained billing records include amounts, dates, taxes, payment-method type, and the product billed. They also include the information needed to support the tax treatment: the country and province, territory, or state you selected, and your confirmation that this is where you live. The information collected to support the tax treatment is encrypted separately from your vault and remains readable by WIGGWIGG. It does not include your vault contents or communications.
We keep these tax records for the period required by law, generally six years after the end of the last relevant year. A specific legal requirement may extend that period. Account deletion does not end this obligation.
4. Security Measures
User data is hosted on servers operated by our service providers and are protected by industry standard security measures. Our zero-knowledge protections cover the specific data classes identified in section 1.1: your master password is not uploaded, and WIGGWIGG does not hold the keys needed to decrypt password entries in your zero-knowledge vault, encrypted identity details and contacts, or the default sealed storage copy of your message content. Other account, billing, routing, safety, audit, and opt-in feature data remains server-readable as described in this Statement.
Our employees and suppliers are informed of the confidential nature of personal information collected through the WIGGWIGG Service and are made aware of the appropriate security measures to prevent unauthorized access to personal information.
5. Disclosure of Personal Information
We only share or disclose personal information in the manner described in this Privacy Statement or when we have obtained your express consent. Your personal information may be disclosed to the categories of persons described below for the following purposes.
5.1. Employees
Personal data is accessible to our officers and employees who must access it in order to use the same as set forth in this Privacy Statement and to provide our services to our Customers.
5.2. Service Providers
We process encrypted personal information through our service providers, who undertake to keep this information confidential and to limit its use to what is necessary to support our services.
Our current service providers (subprocessors) are:
- Amazon Web Services (AWS): cloud hosting of our databases, encrypted media storage and application servers, located in Canada.
- Telnyx: voice, SMS/MMS and 911 (E911) connectivity, located in the United States.
- Stripe: payment and subscription processing, in the United States and globally.
- Blockonomics: cryptocurrency payment processing (Bitcoin), for subscription and donation payments, global.
- Resend: delivery of our newsletter (and unsubscribe confirmations) to addresses subscribed on the Website, located in the United States.
- Canadian Centre for Child Protection (Arachnid Shield): automated scanning of media messages for child sexual abuse material (CSAM). The picture’s perceptual fingerprint is computed on our servers and only that fingerprint is sent; no detector ever receives the picture. Confirmed matches are preserved and reported as the law requires. Located in Canada.
- Microsoft (PhotoDNA): automated scanning of media messages for child sexual abuse material (CSAM), alongside Arachnid Shield. The PhotoDNA hash is computed on our own servers using Microsoft’s edge-hashing library and only that hash is sent; no detector ever receives the picture. Confirmed matches are preserved and reported as the law requires. Located in the United States.
- Apple (APNs): push notification delivery to iOS devices (device tokens and encrypted notification payloads).
- Google (FCM): push delivery for the Android app installed from Google Play (device token, encrypted payload). Our de-Googled build uses our own relay instead.
- Vercel: hosting for our marketing website only, not the WIGGWIGG application.
We may update this list as our services evolve. The current, detailed list is available on our Subprocessors page.
The content of calls and SMS sent through telephone or mobile networks may be monitored by our telecommunication services providers and telecommunication carriers. This is not specific to WIGGWIGG and happens with all audio calls and SMS transmitted through the telephone or mobile networks. We hold no real-world identity to associate with them; call and message records are linked only to your account ID. If you reveal personal information in your messages or calls, it may be associated with you.
5.3. Legal obligations
We may also disclose personal information to third parties if we are required to do so by law, or if we are compelled to do so by a competent authority. We may disclose personal information in connection with legal proceedings if absolutely necessary to protect our rights.
6. What are your rights regarding your personal information?
6.1. Access your data
You may access your data through your user account on the WIGGWIGG Service. Any personal information we have about you is only accessible through the WIGGWIGG Service. We do not collect your email address, so you cannot request access to your personal information through email.
6.2. Withdrawal of Consent
You may withdraw your consent to our processing of your personal information by unsubscribing from our newsletter, by withdrawing consent for an optional feature that offers this choice in settings, by removing a calling device, by removing information from your WIGGWIGG account, or by deleting your WIGGWIGG account altogether.
6.3. Deletion
You may request deletion of your account through the WIGGWIGG Service. The request begins a 30-day grace period; signing back in during that period cancels it. After the grace period, we permanently delete personal data except for the limited records described in section 3: billing records retained under Canadian tax law, flagged content-check records and preserved match copies, and security audit logs retained for service security.
6.4. Complaint
Depending on your jurisdiction of residence, you may have the right to file a complaint regarding the processing of your personal information with a supervisory authority responsible for the protection of privacy.
7. Modifications
We may modify this Privacy Statement from time to time to reflect changes in our personal information processing practices or applicable law. If a modification is made, we will notify you through the WIGGWIGG Service and the modified statement will be available through the WIGGWIGG Service and on the Website at the following address https://wiggwigg.ca/en/privacy-policy/. We will not do any additional processing of your personal information without your express consent.
8. Additional Information
For any additional information with respect to our processing of personal information, please contact us through the WIGGWIGG Service. Any inquiry made by email should concern information collected through the Website only.