This is the first published version, and a lawyer is still reviewing it. It describes the app and our server as they are on the date above. Where the review may change something, the text says so. If it changes what we keep or for how long, we will update this page and tell you in the app before the change takes effect.
Windpost is a private messenger for families and the people closest to a family. It is made by Crowner Technology Inc., a Canadian company (“we”, “us”), which is responsible for the personal information described here.
Under review: the name of our privacy officer will be added here.
Your account is a key made on your phone. The relay knows it by a random number and its public keys, never the private key. Your messages, photos, videos, voice messages and documents are kept on your phone, in Windpost’s own sealed store, and on the phones of the people you sent them to.
Because of end-to-end encryption, we cannot see: what you write, say or send; the names of your contacts, families, groups, circles or albums; your name or profile picture; your location, including Help me and SOS; what is said or shown in a call; what is in your backup; or anything in My documents, which never leaves your phone unless you send or export it.
The one exception is a report: if you report something, you choose to show it to us (section 9).
The relay runs on servers we rent in Toronto, Canada. Its database holds the following, and nothing else.
| What | What exactly | How long |
|---|---|---|
| Your account | A random account id and your public keys. When the account was made and last signed in. That it is for an adult. Your call settings, and whether notifications may name the kind of thing waiting. If we closed it after a report: when, and why. | While the account exists. Deleted with your account (section 10). An account that has not signed in for 24 months is deleted the same way, after one notification 30 days before; for that we also keep when the warning went, until the next sign-in. The 24 months are under review. |
| One-time keys | Public keys your phone publishes so others can start a sealed conversation. | Each is deleted when used. |
| Contacts | For each connection: the two account ids, when it was made, whether each side allows photos and documents, a block, an optional time limit, and whether a shared family made it. | Until either side disconnects, the time limit ends, or the two no longer share a family. A block is kept, so it stays permanent. |
| Invitations | The code, who made it, when, when it expires, and who used it. A family invitation also holds a sealed preview whose key is in the link and never reaches us. | Until it expires (one to one: 24 hours unless you chose otherwise; family: 72 hours; an event code: the event’s close) or is taken back. |
| Families, groups and circles | The id and kind of each family, group, event album or document collection, who made it and when; each circle’s keeping rule and key generation; for each member: account id, role, invited or in, who added them, when they joined, and the first key generation they may hold. No names. A co-host of a document collection sees only documents sent after joining. | While it exists. Your membership goes when you leave or are removed; guests leave an event album at its close. A note that someone was removed: 30 days; for an event album or document collection, or when an owner or admin chose “Don’t let … back in”, while it exists (or until that is lifted). |
| Family and group posts | Messages, names, receipts, shared lists, locations, Help me and SOS, as sealed posts: the circle, the sender’s account id, one of four kinds (message, quiet, help, SOS, so the relay knows whether to ring), the key generation, the size and the time; the account ids a post names with an @; and which members’ phones have collected it. A post sent later is held sealed with its chosen time, at most 30 days ahead. | Deleted once every member’s phone has it, and after 30 days at most. Sooner in a circle set to disappear, for a live location when the share ends, and at once when its sender deletes it. Someone who joins later is given what is said from then on, and anything still waiting for another member’s phone; the history stays on the phones of those already there. In an event album, until 30 days after the event closes. In a document collection, while it exists, so that someone who sends documents later still sees what its collector said. |
| Shared files in families and groups | Sealed photos, videos, voice messages and documents, up to 500 MB each, in sealed pieces: the circle, the uploader’s account id, the size, the time, and which members’ phones have collected it. | Deleted once every member’s phone has it, and after 30 days at most. A copy re-sent for one member: 7 days at most. An unfinished upload: 1 day. Event album photos: 30 days after the event closes, as the album says; guests can no longer fetch them once it closes. |
| One-to-one messages | The sealed message and a small sealed label, the contact it belongs to, sender and recipient ids, the number of pages, when it was sent and opened, how long each page was on screen, whether it is a photo or document, whether the sender let it be kept, and whether it was sent without sound. Only if the recipient turned on “say what is waiting”: one word (photo, voice, video or document). A message sent later: its chosen time, at most 30 days ahead. | Deleted the moment it is delivered, or when its window ends. It waits up to 30 days for a phone that is off (view-once and timed messages, up to 24 hours). The record that it was sent goes 6 hours after it closes. |
| Big files in one-to-one chats | Documents and videos up to 500 MB, in sealed pieces of 4 MB: the contact, both account ids, the total size and each piece’s size, and when it was started, last added to and finished. A big file is not padded, so the relay sees its size. Its key travels only inside the sealed message that names it. | Deleted when the recipient’s phone has it, or the sender deletes or stops it. An unfinished upload: 1 hour after its last piece. A finished file nobody fetched: 7 days. |
| Muted chats | For each chat you muted: its id and until when. Nothing that was said. The relay writes iPhone notifications and rings Android phones, so it has to know. | Until you unmute, the time runs out, you leave, the contact ends, or the account is deleted. |
| Notification routes | iPhone: Apple’s token for the app, and a second one if you turned on “Ring like a phone call”. Android: Google’s token, and a hashed secret for the phone’s own connection. The language notifications are written in. | Until you turn notifications off, Apple or Google says the token is dead, or the account goes. |
| Backups and recovery | The relatives you chose as helpers; one sealed backup (only the newest); if you set a recovery code, values made from it and your backup key sealed with it, never the code; during a recovery, the request, the new phone’s public keys and the helpers’ sealed pieces. | See section 6. |
| Reports | The one thing you chose to show us, encrypted with our own key; the reason; your account id and the reported one; which conversation or message. | 30 days, longer only if a legal preservation demand names it. A report outlives the deletion of either account for those 30 days. |
| Purchases | Windpost charges nothing today, so no store receipts are kept. | — |
What the relay does not hold: your name, phone number, email address, contact list, location, internet address, or any history of who talked to whom once the records above are gone. The front door of our server keeps no access log. Our host, Vultr, may see network traffic at its own level.
The relay sees when things are sent and when they are collected. Even where it is not told who wrote to whom, someone who watched the relay could match the moment a message goes in with the moment it comes out. We accept this, as every messenger that passes messages through a server must, and we keep no record of it.
Windpost reads your location only when you tap to send it: share where you are (once, or live for a time you choose while the app is open), Where is everyone?, Help me and SOS. Never in the background, never on a timer you did not start, and nobody can turn it on for you. It is sealed on your phone; the relay sees a sealed post and cannot tell it is a location. The relay knows a post is urgent (“help” or “sos”) so it can ring through Do Not Disturb, and limits each person to three SOS alerts an hour. Park my car stays on your phone unless you share it.
Windpost does not call emergency services. If someone is in danger, call your local emergency number.
Backups are off until you turn them on. A backup holds your identity key, your conversations and your families’ keys and history, sealed on your phone with a key the relay never sees. It does not hold family album photos (your family’s phones have them) or My documents (never backed up). Only the newest is kept; an unfinished upload goes after a day.
A recovery code is sixteen characters made on your phone; we never see it. With family recovery, two of the relatives you chose confirm on their own phones, then a 24-hour wait follows that you, the new phone or any helper can stop, and your old phone is told. We cannot recover your account alone, and neither can one relative. When a recovery moves your account, the relay keeps how and when for a week, so the old phone can be told. A recovery request goes about a week after it ends.
Turning off both the code and family recovery deletes the backup from the relay. Windpost’s store is kept out of iCloud and Android backups on purpose.
Windpost asks for the camera, microphone, photos, location while in use, notifications, local network on iPhone (Send to computer) and your phone’s fingerprint or face check, each when first needed. You can turn any of them off in your phone’s settings.
| Who | What for | What they get |
|---|---|---|
| Vultr | Rents us the relay and our two call forwarders in Toronto, with encrypted disks, and stores the nightly copy described below | The machines; everything on them is sealed or listed in section 4. Vultr is a US company. |
| Apple | App Store, TestFlight and iPhone notifications | A fixed sentence with no name and no content, such as “New message” (one more word, such as “New photograph”, only if you turned on “say what is waiting”), and a call wake-up if you turned on “Ring like a phone call”. Calls do not go into your iPhone’s Recents. |
| Google Play and Android notifications | An empty wake-up with one letter. Android phones keep their own connection to the relay, and Google is asked only when it is not open, or for calls, Help me, SOS and recovery warnings. Google’s service may give the app an installation identifier. | |
| Vercel | Hosts this website and the invitation link pages | Ordinary web requests, which it may log under its own policy; we add no analytics. The invitation preview key is in the part of a link browsers never send. |
| Namecheap | Our domain names and email forwarding | Emails you send to our addresses |
Apple and Google learn that our relay woke a device, and when. They do not learn who wrote, what was written, or which conversation it was. For a message sent without sound nothing goes through them, and for a chat you muted nothing does except calls, Help me, SOS and posts that name you. Call forwarders are our own: they carry encrypted call audio and video so neither phone learns the other’s internet address, and keep no log of who called whom.
We use no analytics, no advertising, no crash reporting service, no tracking and no data brokers.
A nightly copy of the relay’s database is encrypted on the relay with a key only we hold and kept for fourteen days in Vultr’s storage in New Jersey, United States; Vultr cannot open it. It holds the records in section 4, including sealed family posts and sealed backups still on the relay that night, but not one-to-one messages or files.
Block ends the connection on the relay and deletes the conversation on your phone. The other person is not told.
Report sends us one thing you saw, with a short reason. It is the only time we can read content, and only because you chose to show it. We keep it encrypted for 30 days. If it shows the sexual exploitation of a child, the law requires us to report it to Cybertip.ca and the US National Center for Missing & Exploited Children, with the report and the account ids.
We answer valid legal process, sent to legal@windpost.app, and nothing without it, except where the law allows disclosure to prevent imminent harm to someone’s life. What we could hand over is only what section 4 lists on that day. What we could not, because we do not have it: the content of any message, call, photo, document or location; names; phone numbers; email addresses; contact lists; internet address logs; call history; presence history. A court can order us to preserve what we hold; it cannot make us produce what we never had. How we handle foreign requests, and when we tell the account holder, is under review.
What other people keep. What you send is kept on the phones of the people you sent it to, as in any messenger, and they can export it, except view-once messages and anything you did not let them keep (phones running an older version of the app may not know to leave these out). Posts you made in a family stay on the other members’ phones after you leave or delete your account. An admin can hide a photo from an album but never delete what someone else sent.
Windpost is for people 18 and over. The app asks once, before it makes an account, and someone under 18 cannot continue. We do not allow child accounts; children may appear in photos adults share, but never hold an account. If we learn an account belongs to someone under 18, we close it: tell us at support@crowner.ca.
Wherever you live, you can ask us what we hold about your account, ask us to correct or delete it, withdraw consent, and complain to us. We answer within 30 days and do not charge you. We make no automated decisions about you.
Canada (PIPEDA; Quebec’s Law 25): you may complain to the Office of the Privacy Commissioner of Canada, or in Quebec to the Commission d’accès à l’information. European Union and United Kingdom (GDPR, UK GDPR): you may also restrict, object to and port your data, and complain to your data protection authority (in the UK, the ICO). We rely on contract to run the service you asked for, legitimate interests to keep it secure and free of abuse, consent for location you send, “say what is waiting” and online status, and legal obligation for child-safety reports and lawful orders. United States: we do not sell or share personal information or use it for targeted advertising, and will not treat you differently for asking about it.
Windpost is offered in Canada, the United States, Turkey, the European Union and the United Kingdom. Our servers are in Canada; the nightly copy is in the United States (section 8). Our representatives in the EU and the UK, transfer safeguards, and what Turkey’s KVKK requires are under review.
The relay has not yet had an independent security review. No system is perfect: if a breach affects you, we will tell you and the regulators as the law requires.
If we change what we collect or how long we keep it, we will update this page, give it a new version number and date, and tell you in the app before the change takes effect.