Your data belongs to you. Full stop.
No ads means we never had a reason to mine you, profile you, or sell you on. This is the plain-English version of that promise — what we collect, what we never touch, which half of wack a given line applies to, and how to take it all back.
Last updated August 4, 2026
Two apps, one account
Which half of wack are we talking about?
wack is two apps sharing one account, and they do not collect the same things. Where a line below applies to only one of them, it says which. If a line isn't scoped, it's true of both.
- wack.dev
- The social network. Feed, profiles, circles, communities, albums, pets, Nearby, and public posting to the AT Protocol.
- Wack Message
- message.wack.dev and the installable app of the same name. Direct messages, group threads, voice notes, GIFs, and 1:1 calls. No feed, no Nearby, no crash reporter.
What we collect, app by app
The minimum to make each thing actually run — and, where they differ, the difference.
Swipe the table sideways →
| Data | wack.dev | Wack Message |
|---|---|---|
| Your handle, display name, avatar, and the bio you chose to write | Yes | Yes — one account, one profile, both apps |
| The posts, photos, and albums you create | Yes | No — the messenger has no feed and no composer for any of it |
| The messages, attachments, voice notes, and GIFs you send | Yes | Yes |
| Who's in your circle | Yes — it's the whole point | Yes — it's who you're able to message |
| Account security signals: sign-ins, device sessions, and the IP address behind a sign-in or a rate-limited request | Yes | Yes |
| Crash and error diagnostics | Yes — scrubbed events, via Sentry | No. The messaging app ships no crash reporter at all |
| Aggregate page-performance timings | Yes — Vercel Speed Insights, no identifiers, never for ads | No |
| A city, region, and country you asked us to use | Only if you opt into Nearby. Auto-fill briefly sends your device coordinates to our reverse-geocoding provider; the coordinates themselves are not stored | No. Geolocation is switched off in the response headers, so the browser refuses the request before any code can make it |
| Coordinates riding along inside a photo, video, or voice note you send | No — and not because we delete them later. Your browser strips them before the file is sent | No — same stripping, same place: before the file leaves your device |
| Microphone audio | Only for the length of a 1:1 call you place or answer | Only while you hold the record button on a voice note, and for the length of a 1:1 call |
| Camera video | Only if you switch the camera on during a call. Off at the start of every call | Only if you switch the camera on during a call. Off at the start of every call |
| A push subscription for each device you turn notifications on for | Yes — a browser push endpoint | Yes — a browser push endpoint, or an Apple push token in the installed app |
| Public AT Protocol replies, likes, reposts, actor details, counts, and moderation labels on records Wack published | Yes | No — the messenger publishes nothing to the AT network and reads nothing back from it |
What we never collect
Both apps. No exceptions, no asterisks, nothing scoped away in a footnote.
- ✕Your contacts or address book. Neither app asks for the contacts permission, because neither app has a line of code that would use it.
- ✕Your phone number. We never ask for one — an account is a handle, an email, and a password.
- ✕Continuous, background, or stored precise GPS location.
- ✕Off-site browsing, ad pixels, fingerprinting, or cross-app tracking.
- ✕A behavioural profile built to predict or nudge what you do next.
- ✕Anything sold, rented, or “shared” with advertisers. There are no advertisers.
- ✕The text of your messages inside a push notification, where anyone holding your phone could read it.
Microphone and camera
Yes, we use the microphone. Here is every place we do.
An earlier version of this page filed the microphone under things we never touch. That was wrong the day voice notes shipped, and wronger the day calls did. The accurate version is still a short one.
Wack Message opens the microphone in exactly two places: while you hold the record button on a voice note, and for the length of a 1:1 call. wack.dev opens it in one — a 1:1 call. Nothing opens it in the background, nothing holds it open afterwards, and no path reaches it without a deliberate press from you first.
The camera starts every call switched off. Turning it on is a separate, per-call tap; until you take it, the other person is looking at your avatar.
Calls are 1:1 and peer-to-peer. Audio and video travel browser to browser over WebRTC and are encrypted in transit. When a direct path can't be negotiated, the still-encrypted stream is relayed by Cloudflare's TURN service. We do not record calls, and no call audio or video passes through a Wack server. We keep the dull part — who called whom, when, how long it lasted, how it ended, and whether the connection was direct or relayed — so your call history and missed-call badges work.
A voice note is a different thing: it's a file you chose to record and send. It's stored and delivered like any other attachment, behind the same access rules as the thread it lives in.
Uploaded photos, video, and voice notes
A photo knows where it was taken. It stops knowing at your device.
Attachments are served from a CDN, and a CDN link is public by nature — anyone holding it can fetch the file. A photo or a clip straight off a phone carries far more than the picture: the coordinates it was shot at, the camera and its serial number, the date, sometimes a thumbnail of a different moment. None of it shows up anywhere in the app, and all of it used to survive the upload.
It doesn't now. Your browser rewrites the file before it is sent: EXIF, XMP, and IPTC out of JPEG, PNG, WebP, and GIF; the user-data and metadata atoms — QuickTime's GPS box among them — out of MP4, MOV, and M4A; tag and attachment elements out of WebM; the comment list out of an Ogg voice note; ID3 and APE blocks off MP3 and AAC. The picture and the sound are copied across byte for byte, so nothing is re-encoded and nothing looks or sounds worse for it.
The part that matters more than the list is what happens when the rewrite can't be trusted. A container we don't recognise, a fragmented MP4, a structure we can't walk exactly — those are refused, with an error, and the file is not uploaded at all. There is no quieter path where a file we couldn't read goes up as it came.
This is recent, and it is not retroactive. Anything uploaded before it shipped went up as it came off the camera and is still on the CDN in that state. Deleting your account deletes your uploaded files along with it.
Push notifications
A notification never contains your message
Push is off until you switch it on, once per device. Switching it on registers a single subscription for that device — a browser push endpoint, or an Apple push token inside the installed app. Switching it off deletes it.
The body of a notification is composed on our server from two things: the type of the notification and the sender's display name. The message itself is never read into it. The most a lock screen ever shows for a new message is a name followed by “sent you a message.” — the same sentence whether the message is one word or a thousand.
Public protocol activity · wack.dev only
What Wack reads back from the open network
For public posts Wack publishes through the AT Protocol, our server periodically asks the public Bluesky AppView for the post thread, likes, and reposts. This does not require access to your connected account or any additional OAuth permission.
We keep a separate server-only snapshot of public actor DIDs, handles, display names, avatars, reply text, interaction types, timestamps, engagement counts, and moderation labels. It is not written into Wack posts, likes, profiles, circles, or private messages. We hide labeled or unavailable results by default and purge the interaction snapshot when the source post is withdrawn or no longer public.
None of this happens in the messaging app. It publishes no records to the AT network and reads none back.
Who else, and for how long
The parts we can't promise on someone else's behalf
A new managed Wack signup creates a portable account on Wack's managed PDS behind the Wack interface. Publishing public posts to AT remains a separate activation. Members who connect an external AT identity use that provider's PDS, and public AT features may also contact identity, relay, and AppView services.
The public AT network is not one Wack service provider. Independent apps, PDS hosts, relays, crawlers, search engines, and other services may receive or copy records you publish publicly and apply their own terms and retention rules.
Wack data is kept while an account or feature needs it, subject to security, fraud, legal, and backup-retention needs. Leaving Nearby deletes the saved location row. Public AT activity snapshots are removed when their source Wack post is withdrawn or stops being public. Provider logs and encrypted backups follow settings that differ by service. Wack is documenting those periods for the public beta; ask hello@wack.dev for the current setting, or for an export or deletion request.
The no-tracking pledge
No ads, so nothing to track you for
No advertising pixels, fingerprinting, third-party ad cookies, or cross-site dossiers. wack.dev uses narrowly scoped crash reporting and aggregate performance telemetry to stay reliable; the messaging app uses neither, and neither is ever used for ads. We make money from software, not your attention.
Service providers
The companies that help Wack run
We use service providers to operate the product, never to monetise you. The right-hand column is the part worth reading: several of these exist only on wack.dev and have no presence in the messaging app whatsoever.
Swipe the table sideways →
| Provider | What it does | Where |
|---|---|---|
| Supabase | Accounts, database, realtime, and the row-level rules that keep a thread private. | Both |
| Vercel | Web hosting for both sites. | Both |
| Cloudflare | DNS, the human check at sign-up, and short-lived relay credentials for calls. On wack.dev it also does handle resolution and private AT blob and backup storage. | Both |
| Bunny | Delivery of images, video, and voice notes. | Both |
| Upstash | Persistent abuse and rate limits. | Both |
| Resend | Sign-up, confirmation, and password-reset mail, wired as the sender behind our authentication provider. | Both |
| GIPHY | GIF search in the composer. Searches are proxied through our server, so GIPHY receives the search text but not your account or your device. | Both |
| Apple and browser push services | Delivering a notification to a device you turned push on for. | Both |
| Sentry | Scrubbed crash and error diagnostics. The messaging app does not include the Sentry SDK, so nothing from it is ever reported here. | wack.dev only |
| Vercel Speed Insights | Aggregate page-performance timings. No identifiers, never used for ads. | wack.dev only |
| BigDataCloud | Turning coordinates into a city, and only when you use Nearby's auto-fill. | wack.dev only |
| Spotify | Optional account connection, track data, and the embedded player. | wack.dev only |
| Ticketmaster | Optional event discovery. | wack.dev only |
| OpenAI | A short pet question, or a pet species plus a fixed, coarse page category. | wack.dev only |
| DigitalOcean | The managed AT account host and the filtered public-record indexers. | wack.dev — plus the one call the messenger's Delete account makes to remove your managed AT repository |
Your data, on your terms
- Export everything
- Your public AT repository is available as a machine-readable export today. A complete private Wack archive is not self-service yet; request one from hello@wack.dev while we finish that control.
- Delete everything
- Delete account lives in Settings in the messenger and on wack.dev, and it removes the whole account — messages included — not just the app you pressed it in. Wack-managed accounts can also request a protocol deletion code and permanently delete their hosted AT repository and handle. External AT accounts stay under their provider's control. Public copies already distributed elsewhere may remain.
- Correct anything
- Edit your profile, fix a typo, change your handle. Your record is yours to keep accurate.
- Take it and go
- Leave whenever you like. Public AT repository export is available now; request the rest of your Wack archive while the complete self-service export is being built.
Security, by default
Locked at the database, not just the door
- Row-level security
- User-facing tables enforce row-level access policies. Privileged server routes use separate credentials and add their own authorization and input checks.
- Encrypted in transit
- Browser and service connections use HTTPS/TLS in production, and call media is encrypted browser-to-browser by WebRTC. This is transport encryption. Stored messages are not end-to-end encrypted — we could read them, and we say so rather than implying otherwise.
- Least privilege
- Infrastructure credentials are separated by purpose where the provider supports it, including dedicated PDS blob and encrypted backup storage credentials.