Your data belongs to you. Full stop.

No ads means we never had a reason to mine you, profile you, or sell you on. This is the plain-English version of that promise — what we collect, what we never touch, which half of wack a given line applies to, and how to take it all back.

Last updated August 4, 2026

Two apps, one account

Which half of wack are we talking about?

wack is two apps sharing one account, and they do not collect the same things. Where a line below applies to only one of them, it says which. If a line isn't scoped, it's true of both.

wack.dev
The social network. Feed, profiles, circles, communities, albums, pets, Nearby, and public posting to the AT Protocol.
Wack Message
message.wack.dev and the installable app of the same name. Direct messages, group threads, voice notes, GIFs, and 1:1 calls. No feed, no Nearby, no crash reporter.

What we collect, app by app

The minimum to make each thing actually run — and, where they differ, the difference.

Swipe the table sideways →

What Wack collects, by app
Datawack.devWack Message
Your handle, display name, avatar, and the bio you chose to writeYesYes — one account, one profile, both apps
The posts, photos, and albums you createYesNo — the messenger has no feed and no composer for any of it
The messages, attachments, voice notes, and GIFs you sendYesYes
Who's in your circleYes — it's the whole pointYes — it's who you're able to message
Account security signals: sign-ins, device sessions, and the IP address behind a sign-in or a rate-limited requestYesYes
Crash and error diagnosticsYes — scrubbed events, via SentryNo. The messaging app ships no crash reporter at all
Aggregate page-performance timingsYes — Vercel Speed Insights, no identifiers, never for adsNo
A city, region, and country you asked us to useOnly if you opt into Nearby. Auto-fill briefly sends your device coordinates to our reverse-geocoding provider; the coordinates themselves are not storedNo. Geolocation is switched off in the response headers, so the browser refuses the request before any code can make it
Coordinates riding along inside a photo, video, or voice note you sendNo — and not because we delete them later. Your browser strips them before the file is sentNo — same stripping, same place: before the file leaves your device
Microphone audioOnly for the length of a 1:1 call you place or answerOnly while you hold the record button on a voice note, and for the length of a 1:1 call
Camera videoOnly if you switch the camera on during a call. Off at the start of every callOnly if you switch the camera on during a call. Off at the start of every call
A push subscription for each device you turn notifications on forYes — a browser push endpointYes — a browser push endpoint, or an Apple push token in the installed app
Public AT Protocol replies, likes, reposts, actor details, counts, and moderation labels on records Wack publishedYesNo — the messenger publishes nothing to the AT network and reads nothing back from it

What we never collect

Both apps. No exceptions, no asterisks, nothing scoped away in a footnote.

  • ✕Your contacts or address book. Neither app asks for the contacts permission, because neither app has a line of code that would use it.
  • ✕Your phone number. We never ask for one — an account is a handle, an email, and a password.
  • ✕Continuous, background, or stored precise GPS location.
  • ✕Off-site browsing, ad pixels, fingerprinting, or cross-app tracking.
  • ✕A behavioural profile built to predict or nudge what you do next.
  • ✕Anything sold, rented, or “shared” with advertisers. There are no advertisers.
  • ✕The text of your messages inside a push notification, where anyone holding your phone could read it.

Microphone and camera

Yes, we use the microphone. Here is every place we do.

An earlier version of this page filed the microphone under things we never touch. That was wrong the day voice notes shipped, and wronger the day calls did. The accurate version is still a short one.

Wack Message opens the microphone in exactly two places: while you hold the record button on a voice note, and for the length of a 1:1 call. wack.dev opens it in one — a 1:1 call. Nothing opens it in the background, nothing holds it open afterwards, and no path reaches it without a deliberate press from you first.

The camera starts every call switched off. Turning it on is a separate, per-call tap; until you take it, the other person is looking at your avatar.

Calls are 1:1 and peer-to-peer. Audio and video travel browser to browser over WebRTC and are encrypted in transit. When a direct path can't be negotiated, the still-encrypted stream is relayed by Cloudflare's TURN service. We do not record calls, and no call audio or video passes through a Wack server. We keep the dull part — who called whom, when, how long it lasted, how it ended, and whether the connection was direct or relayed — so your call history and missed-call badges work.

A voice note is a different thing: it's a file you chose to record and send. It's stored and delivered like any other attachment, behind the same access rules as the thread it lives in.

Uploaded photos, video, and voice notes

A photo knows where it was taken. It stops knowing at your device.

Attachments are served from a CDN, and a CDN link is public by nature — anyone holding it can fetch the file. A photo or a clip straight off a phone carries far more than the picture: the coordinates it was shot at, the camera and its serial number, the date, sometimes a thumbnail of a different moment. None of it shows up anywhere in the app, and all of it used to survive the upload.

It doesn't now. Your browser rewrites the file before it is sent: EXIF, XMP, and IPTC out of JPEG, PNG, WebP, and GIF; the user-data and metadata atoms — QuickTime's GPS box among them — out of MP4, MOV, and M4A; tag and attachment elements out of WebM; the comment list out of an Ogg voice note; ID3 and APE blocks off MP3 and AAC. The picture and the sound are copied across byte for byte, so nothing is re-encoded and nothing looks or sounds worse for it.

The part that matters more than the list is what happens when the rewrite can't be trusted. A container we don't recognise, a fragmented MP4, a structure we can't walk exactly — those are refused, with an error, and the file is not uploaded at all. There is no quieter path where a file we couldn't read goes up as it came.

This is recent, and it is not retroactive. Anything uploaded before it shipped went up as it came off the camera and is still on the CDN in that state. Deleting your account deletes your uploaded files along with it.

Push notifications

A notification never contains your message

Push is off until you switch it on, once per device. Switching it on registers a single subscription for that device — a browser push endpoint, or an Apple push token inside the installed app. Switching it off deletes it.

The body of a notification is composed on our server from two things: the type of the notification and the sender's display name. The message itself is never read into it. The most a lock screen ever shows for a new message is a name followed by “sent you a message.” — the same sentence whether the message is one word or a thousand.

Public protocol activity · wack.dev only

What Wack reads back from the open network

For public posts Wack publishes through the AT Protocol, our server periodically asks the public Bluesky AppView for the post thread, likes, and reposts. This does not require access to your connected account or any additional OAuth permission.

We keep a separate server-only snapshot of public actor DIDs, handles, display names, avatars, reply text, interaction types, timestamps, engagement counts, and moderation labels. It is not written into Wack posts, likes, profiles, circles, or private messages. We hide labeled or unavailable results by default and purge the interaction snapshot when the source post is withdrawn or no longer public.

None of this happens in the messaging app. It publishes no records to the AT network and reads none back.

Who else, and for how long

The parts we can't promise on someone else's behalf

A new managed Wack signup creates a portable account on Wack's managed PDS behind the Wack interface. Publishing public posts to AT remains a separate activation. Members who connect an external AT identity use that provider's PDS, and public AT features may also contact identity, relay, and AppView services.

The public AT network is not one Wack service provider. Independent apps, PDS hosts, relays, crawlers, search engines, and other services may receive or copy records you publish publicly and apply their own terms and retention rules.

Wack data is kept while an account or feature needs it, subject to security, fraud, legal, and backup-retention needs. Leaving Nearby deletes the saved location row. Public AT activity snapshots are removed when their source Wack post is withdrawn or stops being public. Provider logs and encrypted backups follow settings that differ by service. Wack is documenting those periods for the public beta; ask hello@wack.dev for the current setting, or for an export or deletion request.

The no-tracking pledge

No ads, so nothing to track you for

No advertising pixels, fingerprinting, third-party ad cookies, or cross-site dossiers. wack.dev uses narrowly scoped crash reporting and aggregate performance telemetry to stay reliable; the messaging app uses neither, and neither is ever used for ads. We make money from software, not your attention.

Service providers

The companies that help Wack run

We use service providers to operate the product, never to monetise you. The right-hand column is the part worth reading: several of these exist only on wack.dev and have no presence in the messaging app whatsoever.

Swipe the table sideways →

Service providers, and which app each one is wired into
ProviderWhat it doesWhere
SupabaseAccounts, database, realtime, and the row-level rules that keep a thread private.Both
VercelWeb hosting for both sites.Both
CloudflareDNS, the human check at sign-up, and short-lived relay credentials for calls. On wack.dev it also does handle resolution and private AT blob and backup storage.Both
BunnyDelivery of images, video, and voice notes.Both
UpstashPersistent abuse and rate limits.Both
ResendSign-up, confirmation, and password-reset mail, wired as the sender behind our authentication provider.Both
GIPHYGIF search in the composer. Searches are proxied through our server, so GIPHY receives the search text but not your account or your device.Both
Apple and browser push servicesDelivering a notification to a device you turned push on for.Both
SentryScrubbed crash and error diagnostics. The messaging app does not include the Sentry SDK, so nothing from it is ever reported here.wack.dev only
Vercel Speed InsightsAggregate page-performance timings. No identifiers, never used for ads.wack.dev only
BigDataCloudTurning coordinates into a city, and only when you use Nearby's auto-fill.wack.dev only
SpotifyOptional account connection, track data, and the embedded player.wack.dev only
TicketmasterOptional event discovery.wack.dev only
OpenAIA short pet question, or a pet species plus a fixed, coarse page category.wack.dev only
DigitalOceanThe managed AT account host and the filtered public-record indexers.wack.dev — plus the one call the messenger's Delete account makes to remove your managed AT repository

Your data, on your terms

Export everything
Your public AT repository is available as a machine-readable export today. A complete private Wack archive is not self-service yet; request one from hello@wack.dev while we finish that control.
Delete everything
Delete account lives in Settings in the messenger and on wack.dev, and it removes the whole account — messages included — not just the app you pressed it in. Wack-managed accounts can also request a protocol deletion code and permanently delete their hosted AT repository and handle. External AT accounts stay under their provider's control. Public copies already distributed elsewhere may remain.
Correct anything
Edit your profile, fix a typo, change your handle. Your record is yours to keep accurate.
Take it and go
Leave whenever you like. Public AT repository export is available now; request the rest of your Wack archive while the complete self-service export is being built.

Security, by default

Locked at the database, not just the door

Row-level security
User-facing tables enforce row-level access policies. Privileged server routes use separate credentials and add their own authorization and input checks.
Encrypted in transit
Browser and service connections use HTTPS/TLS in production, and call media is encrypted browser-to-browser by WebRTC. This is transport encryption. Stored messages are not end-to-end encrypted — we could read them, and we say so rather than implying otherwise.
Least privilege
Infrastructure credentials are separated by purpose where the provider supports it, including dedicated PDS blob and encrypted backup storage credentials.