Communications Privacy

WIGGWIGG uses zero-knowledge encryption for your vault and identity data. Phone communications cross carrier networks, and we choose to run limited safety checks. Here's exactly what we do, what the law requires after confirmed illegal content, and how we minimize data collection.

Rules and Choices

How Phone-Service Safety Works

Carrier rules and Canadian law shape parts of the service, but running our automated checks is a WIGGWIGG product decision. Confirmed-illegal matches carry legal preservation and reporting duties. Other harmful matches are preserved by our choice and reported only if review concludes they are criminal in Canada.

Prevent Illegal Content

CSAM Detection

Everyone

We choose to compare media fingerprints with known child sexual abuse material before storage. Matches are blocked and preserved. Confirmed-illegal matches carry legal preservation and reporting duties. Other harmful matches are preserved by our choice and reported only if review concludes they are criminal in Canada.

Fraud Prevention

Everyone

Spot bulk sending and abnormal message rates in SMS.

Spam & Abuse Prevention

SMS Spam Filtering

Personal (P2P)

Identify bulk messaging and commercial spam patterns.

SHAFT Content Rules

Business (A2P) - Future

SHAFT (Sex, Hate, Alcohol, Firearms, Tobacco) keyword filtering required by carriers for business messaging. Will apply when we launch business features.

What We Keep

Metadata Retention

Everyone

Call/SMS timestamps and phone numbers are used for billing disputes and responses to valid legal requests. Your call history remains until your account closes. Deleting a message removes it from your apps, but its row remains with us until account closure; there is no call-history deletion control yet.

Emergency Services (911)

911 calls only

Free built-in E911 on every WIGGWIGG number. Your registered E911 address (held by the carrier) is passed to dispatchers during emergency calls only; we keep only a sealed copy. See how E911 works on WIGGWIGG.

Personal (P2P)

Person-to-Person

Light filtering for personal messages only

Business (A2P) - Future

Application-to-Person

Stricter rules for business/automated messages only. NOT your personal texts

Legal Duties and Product Choices

These checks are WIGGWIGG product choices. When a match is confirmed illegal, applicable law requires us to preserve and report it. We preserve the broader harmful-to-children match class by choice and report it only if review concludes the material is criminal in Canada.

Privacy-First

How We Minimize Data Collection

We choose to run narrow safety checks and minimize what we keep. Confirmed-illegal matches carry legal preservation and reporting duties. Other harmful matches are preserved by our choice and reported only if review concludes they are criminal in Canada.

Zero-Knowledge Storage at Rest

SMS Messages

Messages transmitted through standard phone networks (visible to carriers like all SMS, unavoidable for any phone service that interoperates with the public network). Under our current method, the received message body is encrypted under a one-time key, then that key is sealed on Canadian servers to the account communication key. A supported client opens it after sign-in and unlock. We discard our copy of the sealing key the instant the message is stored, so we keep no key that can read a copy sealed this way: not at rest, not later, not under a warrant. A small set of communications retained from the private beta remains readable under our older server-side encryption. A supported web sign-in and unlock automatically starts a separate bounded pass that can re-seal up to 50 eligible SMS rows. It does not migrate private-beta voicemail, legacy call-log numbers, MMS attachments, retained object versions, or every remaining SMS row in one pass. Those excluded copies remain server-readable until later passes or separate maintenance.

MMS Images

Images are screened for illegal content (CSAM detection) before storage. To deliver your picture, we drop a readable copy behind a secret link that expires within minutes, just long enough for our carrier to pick it up, then we erase it. Our carrier keeps its own copy for a while: a picture message is never end-to-end encrypted. Under our current method, the copy kept in your account is sealed the same way as SMS, to the account communication key that a supported client opens after sign-in and unlock. We discard our copy of the sealing key the instant the picture is stored, so we keep no key that can open a copy sealed this way. A small set of communications retained from the private beta remains readable under our older server-side encryption until a separate re-sealing process.

Voicemail Audio

Recorded on Telnyx servers, then pulled to our Canadian servers and, under our current method, sealed to the account communication key that a supported client opens after sign-in and unlock, then deleted from Telnyx. We keep no key that can read a copy sealed this way. Voicemail remains server-readable, however, while Listen-by-phone is on or if the account has no usable communication key. A small set retained from the private beta also remains readable under our older server-side encryption until a separate re-sealing process.

Limited Human Review

No Routine Reading

WIGGWIGG staff don't routinely read your texts or listen to your calls. When review is needed, authorized staff may inspect safety-filter flags, abuse reports, appeals, and information you submit to support.

No AI Training

We don't use your data to train machine learning models.

No Marketing Analysis

Zero profiling, targeting, or behavioral tracking.

What We Don't Do With Your Communications

No Live Call Recording

We never record your calls. A call-recording add-on is on the roadmap; if it ships, recordings will use account-key sealing when a usable key resolves, as current voicemail does. Voicemail is only saved when you choose to enable it, and you can delete a voicemail.

Contacts Only If You Import Them

We only read your device contacts if you choose to import them, and they are encrypted before upload.

No Location Tracking

During a 911 call, your registered E911 address (held by the carrier) is passed to dispatchers. We don't track where you are.

No Behavioral Profiling

No marketing analytics, ad targeting, or behavioral tracking. We don't profile your communication patterns or sell your data.

No Third-Party Sharing

Your communications content is never shared with advertisers, data brokers, or analytics companies. We only share what's legally required (court orders, emergency services).

Our Commitment

What Remains Zero-Knowledge

Your vault and the personal content of your identities and contacts use zero-knowledge encryption. Phone-service fields do not all have that protection; the exceptions are named below.

Identity Information

Names, birthdates, addresses, notes--all encrypted client-side.

Saved Passwords

Your password vault is encrypted with keys only you control.

Personal Details

Organizational data, tags, highlights--encrypted before upload.

Account Settings

Your personal preferences are zero-knowledge; phone-line settings that our servers act on (routing, voicemail, greetings, spam filter) are server-readable by necessity.

Privacy Commitment

Your identity data and vault use zero-knowledge encryption at rest. Communications protected at rest by our current sealing method are encrypted under a one-time key that is sealed to the account communication key, which a supported client opens after sign-in and unlock. We discard our copy of the sealing key the instant the message is stored, so for a message sealed this way we hold no key that can read it, not even later or under a warrant. A small set of communications retained from the private beta remains readable under our older server-side encryption. A supported web sign-in and unlock automatically starts a separate bounded pass that can re-seal up to 50 eligible SMS rows. It does not migrate private-beta voicemail, legacy call-log numbers, MMS attachments, retained object versions, or every remaining SMS row in one pass. Those excluded copies remain server-readable until later passes or separate maintenance. Some things are deliberately server-readable, and we name them rather than bury them: voicemail while Listen-by-phone is on or when an account has no usable communication key, the other party's number in a call log when the account has no usable key or key lookup fails, the intros your callers record, automatic-reply text, the picture in a message you send (only while it is being delivered), the text and audio of your voicemail greeting, of the announcement we play to you on pickup, and of the prompt your callers hear before they identify themselves, the personal number you verify for call forwarding, a keyed fingerprint of your contacts' numbers while Contact recognition on calls is on (off by default), support tickets, which you and WIGGWIGG support can read, your phone numbers (for billing and placing calls), your calling credentials (so your device can connect), and your call and message records (date, time, duration, your own line). Your 911 address is sealed with your key; emergency routing uses the readable copy our carrier keeps from setup. (The account communication key can decrypt the history sealed to it and becomes available to each supported client after sign-in and unlock.) We choose to run limited automated safety checks on sending patterns and media fingerprints, never on your message text after it is stored. Preservation or reporting duties can apply if review confirms that content is illegal. Carrier-network transit (SS7/SIP) is unavoidable for phone services and is visible to carriers like all SMS. We minimize what we collect.

Learn more about how we protect your data at rest: Application Security

See how the inbound spam filter works (and how you control it): Spam Filter

Wondering how we use AI, and what it does (and doesn't) do with your data? How We Use AI

Common Questions About Communications Privacy

Why do carriers need my call metadata?

Carriers (like Bell, Rogers, and AT&T) need call detail records to route calls and support billing. They cannot deliver a call without processing the origin and destination numbers. This is inherent to interoperating with the public telephone network, not unique to WIGGWIGG.

Can I avoid carrier data collection?

No. Call detail records are inherent to how telephony works (SS7/SIP protocols). Even end-to-end encrypted messaging apps like Signal must use carrier infrastructure to send data, meaning carriers see connection metadata. The best you can do is choose services (like WIGGWIGG) that minimize what the application layer stores, but carrier routing is unavoidable for phone calls and SMS.

Why can't you make phone services fully zero-knowledge?

No content check is imposed on us by law. We choose to compare image fingerprints with known child sexual abuse material before storage. Confirmed-illegal matches carry legal preservation and reporting duties. Other harmful matches are preserved by our choice and reported only if review concludes they are criminal in Canada. Carrier rules also address sending volume and rate for spam and bulk messaging. We can't end-to-end encrypt SMS in transit because public telephone protocols predate that. Under our current method, the stored copy is sealed to the account communication key, which a supported client opens after sign-in and unlock. A small set retained from the private beta remains readable under older server-side encryption until a separate re-sealing process. For end-to-end privacy in transit too, use Signal or WhatsApp with your WIGGWIGG phone number.

Do CASL and SHAFT rules apply to my personal texts?

No. CASL and SHAFT are A2P (Application-to-Person) rules for businesses sending automated or marketing messages. If you're using WIGGWIGG for personal calls and texts (P2P), these don't apply to you. We choose to check basic spam patterns and image fingerprints on personal messages. Those checks run in memory at receive time and persist no ordinary plaintext copy. Confirmed-illegal matches carry legal preservation and reporting duties. Other harmful matches are preserved by our choice and reported only if review concludes they are criminal in Canada. When we launch business features, those identities will be subject to A2P rules including CASL opt-in requirements and SHAFT content restrictions.

Do you read my messages?

No one routinely reads your messages. Automated checks run in real time on sending patterns and image fingerprints, not on message text after storage. A person may review content that a safety filter flags, an abuse report you submit, or material you send to support. Confirmed-illegal matches carry legal preservation and reporting duties. Other harmful matches are preserved by our choice and reported only if review concludes they are criminal in Canada.

Does Telnyx see my message content?

Telnyx is our telecommunications infrastructure provider. As a carrier, they process calls and messages for routing and delivery. Content moderation (spam and safety checks) happens on our servers before delivery, image safety included: we compute each picture's perceptual fingerprint on our own servers and send only that fingerprint to the two detectors, the Canadian Centre for Child Protection and Microsoft PhotoDNA. No detector ever receives the picture.

What happens if I delete my identity?

When you delete an identity from WIGGWIGG, its identity record is removed from your account and its contacts stay in your encrypted contact list. Associated call and message history follows the retention described below and remains with us until account closure. Data already sent to carriers, including their call detail records, remains with them under their own retention policies.

How long do you keep my call and message history?

Your call and message history remains with us until your account closes. Deleting a message removes it from your apps, but its row remains with us until then. There is no call-history deletion control yet. Deleting an identity removes its record from your account; its contacts stay in your encrypted contact list, and associated history follows the same retention. Data already with carriers follows their own retention policies.

Can law enforcement access my communications?

With a valid warrant, law enforcement can request metadata from us, including your call history and message rows removed from your apps, which remain until account closure, and from carriers and Telnyx under their own retention policies. We do NOT store call audio. Under our current method, SMS, MMS, and voicemail content is sealed to the account communication key, which a supported client opens after sign-in and unlock. A small set retained from the private beta remains readable under older server-side encryption. A supported web sign-in and unlock automatically starts a separate bounded pass that can re-seal up to 50 eligible SMS rows. Private-beta voicemail, legacy call-log numbers, MMS attachments, retained object versions, and additional SMS rows remain server-readable until later passes or separate maintenance. The other exceptions, where our servers can read the content and a valid order reaches it, include voicemail while Listen-by-phone is on or when an account has no usable communication key, the other party's number in a call log when the account has no usable key or key lookup fails, the intros your callers record, automatic-reply text, the picture in a message you send while it is being delivered, the text and audio of your voicemail greeting, of the announcement we play to you on pickup, and of the prompt your callers hear before they identify themselves, the personal number you verify for call forwarding, a keyed fingerprint of your contacts' numbers while Contact recognition on calls is on (off by default), and support tickets, which you and WIGGWIGG support can read. We can produce the sealed bytes under legal compulsion, but a warrant served on us cannot compel a key we do not hold. The account communication key can decrypt the stored history sealed to it and becomes available to each supported client after sign-in and unlock, so a court that compels you directly is a different matter. If carriers or providers stored content during transit, it may be accessible through them separately. We comply with lawful requests but fight overly broad warrants.

What about emergency services (911)?

Emergency calls (911) are routed with your registered E911 address and are never blocked. Your registered E911 address (held by the carrier) is passed to dispatchers. This is a safety feature: lives come first. Emergency calls appear in your call history like any other call. That history remains with us until your account closes; there is no deletion control for it yet.

Ready for Secure Communications?

Get started with WIGGWIGG and keep your personal life separate with zero-knowledge encryption.