Privacy Policy
Last Updated: August 2026
1. Introduction
This Privacy Policy describes how WhistleCore ("we", "us", "our") collects, uses, stores, and protects your information when you use our whistleblowing compliance platform, website (whistlecore.com), and related services (collectively, the "Service"). This policy applies to all users of the Service, including Company Administrators ("Customers") and Whistleblowers who submit reports. We are committed to protecting your privacy and complying with the European Union General Data Protection Regulation (GDPR) and all applicable data protection laws.
2. Data Controller vs. Data Processor
Under GDPR, the classification of our role depends on the type of data:
For Admin/Account Data: WhistleCore acts as the Data Controller for Customer account information (e.g., email addresses, company names, team member profiles). We determine the purposes and means of processing this data for service operation, billing, and communication.
For Whistleblower Report Data: WhistleCore acts as the Data Processor. The Customer (Company) is the Data Controller. We process encrypted Report Data solely on behalf of and under the instructions of the Customer. We do not access, read, analyze, or make decisions based on Report Data, as it is encrypted end-to-end using Zero-Knowledge architecture and we do not hold the decryption keys.
3. Data We Collect
- Customer Account Data: When you register for WhistleCore, we collect your email address, full name, and company name. This data is necessary for account creation, authentication, and service delivery.
- Billing Data: All payment processing is handled exclusively by our Merchant of Record, Lemon Squeezy (Lemon Squeezy B.V.). Lemon Squeezy collects and processes your payment instrument details (credit card numbers, billing addresses, tax IDs). WhistleCore does NOT directly collect, store, process, or have access to your credit card numbers or sensitive payment details. We receive only a subscription identifier and billing status from Lemon Squeezy.
- Encrypted Report Data: Whistleblower reports are encrypted directly in the Whistleblower's browser using the Customer's public cryptographic key before being transmitted to our servers. We store only encrypted ciphertext blobs. We do NOT hold the private decryption keys and CANNOT access, read, or decrypt Report Data under any circumstances.
- Usage Metadata: We collect basic, non-personally-identifiable usage metadata such as page views, feature usage frequency, and error logs for the purpose of maintaining and improving the Service. This data is NOT linked to whistleblower identities.
4. Data We Do NOT Collect
WhistleCore has been architecturally designed to minimize data collection. Specifically, we do NOT collect or log the following during the whistleblower report submission process:
- IP addresses of Whistleblowers
- Device identifiers, fingerprints, or hardware information
- Browser User-Agent strings
- Email addresses, phone numbers, or any personally identifiable information (PII) of Whistleblowers
- Geolocation data
- Referral URLs or browsing history
This data minimization is by design and is enforced at the application level. Because this data is never collected, it does not exist in our systems and cannot be produced, disclosed, or surrendered to any party — including the Customer, law enforcement agencies, courts, or any governmental authority — under any circumstances, including pursuant to subpoena, court order, or legal process.
5. Cookies & Local Storage
WhistleCore uses the following browser storage technologies:
- Authentication Cookies (Strictly Necessary): We use Supabase authentication cookies (prefixed "sb-") to manage your login session. These are HttpOnly, secure cookies required for the Service to function. They are automatically deleted when you log out.
- Session Storage: We use browser sessionStorage to temporarily store your decrypted vault key during your active session. This data is automatically cleared when you close the browser tab and is never transmitted to our servers.
- Local Storage: We store your session mode preference ("persistent" or "standard") in localStorage so that your security preference is remembered across sessions.
No Tracking, Analytics, or Advertising Cookies: WhistleCore does NOT use any tracking cookies, analytics cookies (e.g., Google Analytics), advertising cookies, or any third-party cookies for profiling or behavioral targeting. We do not participate in any ad networks or data broker programs.
6. How We Use Your Data
We use Customer Account Data for the following purposes:
- Service Operation: To authenticate your identity, provide access to the dashboard, and deliver the Service.
- Billing: To manage your subscription status and communicate billing-related information via Lemon Squeezy.
- Transactional Communications: To send essential emails such as team invitations, new report notifications, reporting link rotation alerts, and subscription status updates. These emails are sent via Resend and are strictly transactional — we do NOT send marketing, promotional, or newsletter emails.
- Security: To detect and prevent fraud, abuse, and unauthorized access using Cloudflare Turnstile CAPTCHA verification.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
7. Third-Party Sub-Processors
We use the following trusted third-party service providers (sub-processors) to operate the Service. Each sub-processor processes data only as necessary for the specific purpose described below:
- Vercel Inc. — Web application hosting and edge network delivery. Vercel may process routing metadata (IP addresses at the infrastructure level for DDoS protection and CDN delivery). Vercel's infrastructure includes servers in the EU and US.
- Supabase Inc. — PostgreSQL database hosting, user authentication, and real-time infrastructure. Our Supabase project is hosted in the EU-Frankfurt (eu-central-1) region. All Customer and Report Data is stored within the EU.
- Lemon Squeezy B.V. — Merchant of Record for all payment processing, invoicing, tax calculation, PCI compliance, and subscription management. Lemon Squeezy handles all sensitive financial data. WhistleCore does not directly process payments.
- Resend Inc. — Transactional email delivery service. Used to send team invitations, report notifications, link rotation alerts, and subscription warning emails to Customer administrators. Resend processes only the recipient email address and email content for delivery purposes.
- Cloudflare Inc. — Content delivery network (CDN), DDoS protection, web application firewall (WAF), and Turnstile CAPTCHA verification. Cloudflare processes connection metadata (IP addresses, request headers) at the network level for security purposes. Cloudflare Turnstile is used to protect the reporting form from automated abuse without collecting personal data from Whistleblowers.
8. Data Storage & International Transfers
Our primary database (Supabase) is hosted in the European Union (Frankfurt, Germany, eu-central-1 region). All Customer Account Data and encrypted Report Data are stored within the EU. Report content is encrypted in the Whistleblower's browser before transmission — our servers never receive or store plaintext report data. Some of our sub-processors (Vercel, Resend, Cloudflare) operate global infrastructure that may route or process connection-level metadata (such as IP addresses for DDoS protection) through servers located outside the EU/EEA. Where international data transfers occur, they are governed by Standard Contractual Clauses (SCCs) or equivalent safeguards as required by GDPR Chapter V.
9. Data Retention & Destruction
Active Accounts: Customer Account Data is retained for the duration of your active subscription. You may delete your account and all associated data at any time using the "Delete Company" feature in your dashboard settings.
Report Auto-Deletion: WhistleCore provides configurable automatic report deletion. The default retention period for resolved reports is 60 days, which Customers can adjust between 30 and 365 days in their dashboard settings. It is the Customer's responsibility to configure retention periods that comply with applicable legal requirements.
Cancelled/Expired Accounts: When a subscription is cancelled or expires, the account enters a suspended state. We retain all data for a 30-day grace period to allow reactivation. After 30 days without reactivation, ALL data — including encrypted reports, messages, audit logs, team member profiles, cryptographic keys, and company settings — is permanently and irreversibly deleted from our production servers and all database backups. This deletion is automated and cannot be reversed.
Immediate Deletion: Customers may choose to permanently delete all company data immediately using the "Delete Company" button, without waiting for the 30-day grace period.
10. Artificial Intelligence
WhistleCore does NOT use artificial intelligence (AI), machine learning (ML), large language models (LLMs), natural language processing (NLP), or any form of automated decision-making to process, analyze, classify, summarize, prioritize, or make any determinations about whistleblower reports, Customer data, or any other information stored on the Platform. All report content is encrypted end-to-end and can only be decrypted and reviewed manually by the Customer.
11. Your Rights Under GDPR & Data Breach Notification
Depending on your role, you have the following rights:
Customer Administrators (Account Holders): As a data subject, you have the right to access, rectify, port, restrict processing of, or erase your personal account data at any time. To exercise these rights, contact us at whistlecore.support@gmail.com. We will respond to all valid requests within 30 days as required by GDPR.
Data Breach Notification (GDPR Article 33): In the event of a security breach that compromises encrypted Report Data or Customer Account Data, WhistleCore will notify affected Customers without undue delay in accordance with GDPR Article 33. The Customer is responsible for notifying the relevant supervisory authorities and affected Whistleblowers, if applicable.
Whistleblower Report Data: For personal data contained within whistleblower reports, the Customer (Company) is the Data Controller. Requests regarding report data should be directed to the relevant Company, not to WhistleCore.
Limitation of Disclosure: Because WhistleCore does not collect or log IP addresses, device identifiers, email addresses, or any personally identifiable information during the report submission process, we are technically unable to identify Whistleblowers. We cannot provide, produce, disclose, or surrender Whistleblower identity information — because it does not exist in our systems. This applies to requests from any party, including Customers, law enforcement, courts, regulatory authorities, or any governmental body, regardless of the legal basis for the request (including subpoenas, court orders, or warrants). We will respond to all legally valid requests by confirming that such data was never collected.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify registered Customers via email to the address associated with their account. The "Last Updated" date at the top of this policy indicates when the most recent revisions were made. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.
Contact: whistlecore.support@gmail.com