Skip to main content

Hushtalks

Donate

Version HT.PP.003.00 Effective 12 September 2026

HUSHTALKS Privacy Policy

Privacy by default. HushTalks is designed to minimize the collection of information that directly identifies users. Standard HushTalks profiles are pseudonymous and do not require users to disclose their real-world identity. Users who voluntarily request a Verified Profile may provide identifying information for the limited purpose of verifying and publicly displaying an approved identity.

This Privacy Policy explains how HushTalks AG (“HushTalks”, “we”, “us”, or “our”) collects, uses, stores, discloses and protects information when you use the HushTalks application, website and related services (collectively, the “Service”).

HushTalks App is subject to Swiss data protection law (Federal Act on Data Protection, FADP) and any applicable foreign data protection law, in particular that of the European Union (EU) with the General Data Protection Regulation (GDPR).

Table of Contents:
  1. Scope and Controller
  2. How We Process Personal Data
  3. Definitions
  4. Registration
  5. Standard User Profiles
  6. Verified Profiles and Verification Requests
  7. Login
  8. Voice Messages and External Sharing
  9. Notifications and Technical Data
  10. Data Security
  11. Third-Party Content and Embedded Media
  12. Service Providers and International Data Transfers
  13. Data Retention
  14. Age Restrictions
  15. Child Sexual Abuse and Exploitation (CSAE)
  16. Rights of Data Subjects
  17. Contact Us
1. Scope and Controller

HushTalks AG is responsible for the processing of personal data described in this Privacy Policy, unless another controller is specifically identified.

This Privacy Policy applies to information processed through the HushTalks app, our website, support and verification communications, and other interactions directly related to the Service.

2. How We Process Personal Data

We process personal data only for specified purposes and in accordance with applicable data protection law. We seek to limit collection to information that is necessary for the operation, security and requested features of the Service.

Where the GDPR applies, processing may be based, as appropriate, on one or more of the following legal bases:

• 6 para. 1 lit. b GDPR for the necessary processing of personal data for the fulfilment of a contract with the data subject as well as for the implementation of precontractual measures.

• 6 para. 1 lit. f GDPR for the necessary processing of personal data to protect the legitimate interests of us or of third parties unless the fundamental freedoms and freedom rights and interests of the data subject prevail. Legitimate interests are, in particular, our interest in being able to provide the offer by FGP permanently, in a user-friendly, secure and reliable manner, as well as to be able to advertise for it as required, information security as well as protection against misuse and unauthorized use, the enforcement of our own legal claims and compliance with Swiss law.

• 6 para. 1 lit. c GDPR for the necessary processing of personal data to comply with a legal obligation to which FGP are subject under any applicable law of Member States in the European Economic Area (EEA).

• 6 para. 1 lit. e GDPR for the necessary processing of personal data for the performance of a task which is in the public interest.

• 6 para. 1 lit. a GDPR for the processing of personal data with the consent of the data subject.

• 6 para. 1 lit. d GDPR for the necessary processing of personal data to protect vital interests of the data subject or another natural person.

Where we rely on consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

3. Definitions

Personal data is any information relating to an identified or identifiable person. A data subject is a person about whom personal data is processed. Processing includes any handling of personal data, regardless of the means and procedures used, in particular the storage, disclosure, acquisition, deletion, storage, modification, destruction and use of personal data.

Hashing is a technique in both cryptographic and non-cryptographic applications to protect sensitive data, ensure data integrity, and accelerate data processing. Hashed data increases security by converting sensitive temporal data such as personal data into an unreadable format, thus preventing unauthorized access or manipulation. In clear terms hashing is a
technique to convert sensitive data into an unreadable format, enhancing security.

HTTPS (Hypertext Transfer Protocol Secure) is an extension of the HTTP protocol used for secure transmission of data on the internet. It ensures the protection of communications between a client (such as a web browser) and a server by providing three important security
features:

  • Encryption:

Encryption prevents third parties from reading or intercepting the transmitted information.

  • Data integrity:

With HTTPS, the transmitted data cannot be altered or tampered with during the transfer. If any manipulation occurs, it is detected, and the connection is terminated.

  • Authentication:

HTTPS ensures that communication is taking place with the correct website, not an imposter. This is achieved through certificates issued by trusted certificate authorities (CAs). The browser checks these certificates to verify that the website is legitimate.

An avatar is a visual or symbolic representation of a person in the digital world.

4. Registration

Data collection / Data transmission

To use the HushTalks app, you need to register. The following data is required for this:

  • device_id
    • A unique identifier for the user’s device (email id for android and cloud id for ios)
    • Hashing: The device_id is hashed using a Web3 library before being sent to the back end.
  • language_id
    • The user’s selected primary language
  • second_language_id
  • The user’s selected secondary language
  • topics
    • A list of topics selected by the user to personalize content
  • push_id
    • The user’s Firebase ID, used to send push notifications

The data collected in this way is transmitted securely to the back end over HTTPS. Before transmission, the device_id is hashed using a Web3 library.

Data Handling

The above data is used to generate a secure username and an avatar that is assigned to the user.

All received data (hashed device_id, language_id, second_language_id, topics, push_id) is stored in the database.

5. Standard User Profiles

Standard HushTalks profiles are designed to be pseudonymous. Users may customize profile information such as a username, avatar, topics, languages, password and recovery information without providing a real-world identity.

Depending on the features used, the backend may store:

  • username;
  • avatar;
  • selected topics and languages;
  • password hash;
  • recovery phrase hash; and
  • technical account identifiers required to operate the Service.

Data transmission

All collected and processed profile data is securely transmitted to the back end over HTTPS.

The hashed password ensures that sensitive information remains protected during transmission.

Data handling

Upon receiving the profile data from the front-end, the back end performs several operations to securely store and manage the user’s profile information.

The back end stores the following user-selected and generated data in the database:

  • Username
  • Avatar
  • Topics
  • Languages
  • Password Hash
  • Recovery Phrases Hash

All data stored in the database does not allow HushTalks to identify a specific person.

For standard pseudonymous profiles, this profile data is not intended to identify the user by their real-world identity. Users who voluntarily request a Verified Profile are subject to the additional processing described in Section 6 below.

6. Verified Profiles and Verification Requests

Optional features

HushTalks may offer an optional verification feature to creators, public figures, organisations, non-governmental organisations, companies, brands and other eligible users. Verification is voluntary. A user who does not request verification may continue to use HushTalks through the standard pseudonymous profile system, subject to these Terms and applicable account rules.

Information processed for verification

When you request verification, we may process information necessary to review and administer the request, including:

  • your HushTalks username, user identifier and verification request identifier;
  • the verification category selected or assigned to the request, such as Creator/Public Figure, Organisation/NGO or Company/Brand;
  • your real name, public name or organisation/brand name;
  • the profile photo, logo or other approved image you ask us to display;
  • the email address from which you contact us and the content of verification-related correspondence;
  • links to official social media profiles, websites, business domains or other public references used to confirm identity or authority;
  • verification status, timestamps and administrative records associated with the request; and
  • other information reasonably necessary to resolve a verification question, security issue, impersonation report or ownership/authority dispute.

Please do not send identity documents or other sensitive information unless HushTalks specifically requests them and explains why they are necessary.

Verification by email and external channels

The app may create a verification request and open a pre-filled email in your device’s email application. If you send that email, it is transmitted through your chosen email provider. Your email address will therefore be visible to HushTalks and may be processed as part of the verification record.

To confirm identity or authority, HushTalks may contact an applicant through an official or publicly available channel, such as an official social media account, business email address, organisation website or company domain.

Purposes of verification processing

We process verification information to:

  • review and decide verification requests;
  • confirm that a profile is operated by the person, organisation, company or brand it represents, or by an authorised representative;
  • prevent impersonation, fraud and misuse of verification badges;
  • activate, maintain, suspend or revoke Verified Profiles;
  • protect users and the integrity and security of the Service; and
  • handle disputes, reports, account compromise and other verification-related incidents.

Public information after approval

If a verification request is approved, the approved verified name or public name, approved profile photo or logo, verification badge and, where applicable, verification category may be displayed publicly on HushTalks wherever the Verified Profile is represented, including profiles, HushClubs, Talkrooms and host or speaker views.

Verification correspondence, email addresses, request identifiers, internal review notes and supporting verification references are not made public solely because a profile is verified.

A Verified Profile does not require other users in the same HushClub or Talkroom to disclose their real-world identity.

7. Login

The login feature enables existing users to authenticate themselves in the application by providing a username and password.

Data Collection

The following data is collected from the user during login:

  • Username
  • Password: The password is hashed using a Web3 library before being sent to the back end
  • Push_id
8. Voice Massages and External Sharing

Users can record voice messages using their own voice or a voice filter. Voice messages are a core part of communication within the HushTalks platform.

a) In-App Sharing

By default, voice messages are shared and accessed within the HushTalks community only. Users have the option to choose how long their voice messages are stored, with several duration options available in the app.

If users choose not to use a voice filter, their original voice will be audible to other users. This choice indicates their explicit consent to this condition.

Your voice messages may also be suspended or reviewed as part of our internal reporting and moderation process. Learn more about this procedure in: Process Procedure of a Report.

b) External Sharing and Web Playback

HushTalks allows users to share certain content externally, including but not limited to:

• PINGs

• Archived Talkroom audio recordings

When a user explicitly chooses to share this content (e.g., other platforms), a secure, temporary link is generated. The recipient of the link may preview and play the audio in a lightweight web player without installing the HushTalks app.

To protect user privacy and data:

These shared links are protected with technical safeguards such as token-based access, expiration mechanisms, and non-indexed URLs.

Only the audio content is accessible — no personal or identifying user data is exposed.

The sharing function is entirely opt-in: content is never made public by default. Users maintain full control over what they choose to share.

9. Notifications and Technical Data

HushTalks may process push notification identifiers and notification preferences in order to deliver notifications selected or enabled by the user. Users can manage available notification preferences within the Service or through their device settings.

The Service may also process limited technical information reasonably necessary to maintain security, diagnose errors, prevent misuse and operate the Service.

10. Data Security

HushTalks implements appropriate technical and organisational measures designed to protect information against unauthorised access, loss, misuse, alteration or disclosure. These measures may include encryption in transit, access controls, authentication measures, hashing and operational security procedures.

No method of transmission or storage is completely secure. If you suspect that your account or data has been compromised, please contact us at support@hushtalks.com.

11. Third-Party Content and Embedded Media

We do not download, store, modify, or redistribute any third-party content. All such content remains the intellectual property of its respective platform and is shown strictly in accordance with the terms and conditions of those platforms:

We do not claim ownership of or responsibility for the accuracy, availability, or legality of third-party content. Users are solely responsible for ensuring that any shared content does not violate the rights of third parties or applicable laws.

If you believe content shown through HushTalks infringes upon your rights or violates any law, please contact us immediately at support@hushtalks.com.

12. Service Providers and International Data Transfers

HushTalks may use service providers to support hosting, infrastructure, communications, push notifications, security, technical support and other functions necessary to operate the Service. Such providers may process information only to the extent necessary to provide their services to HushTalks and are subject to contractual or legal safeguards as applicable.

Depending on the provider and the location from which you use the Service, information may be processed in countries outside Switzerland. Where required by applicable law, HushTalks uses appropriate safeguards for international data transfers.

13. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including operating the Service, maintaining security, enforcing our rights, resolving disputes and complying with legal obligations.

Verification information is retained for as long as reasonably necessary to review and administer the verification, maintain the integrity of the Verified Profile, prevent impersonation or repeated misuse, address account compromise or disputes, and comply with legal obligations. When verification information is no longer required for these purposes, it will be deleted or anonymised in accordance with our retention practices.

Retention periods may differ depending on the type of information, the feature used, user-selected retention settings, security requirements and legal obligations.

14. Age Restrictions

HushTalks is intended only for users who are at least 16 years old. By accessing or using the Service, you confirm that you are at least 16 years old. We do not knowingly permit children under 16 to create or use HushTalks accounts.

If we become aware that an account is being used by a person under 16, we may restrict or terminate the account and take appropriate steps regarding associated data, subject to applicable law.

15. Child Sexual Abuse and Exploitation (CSAE)

a) Introduction :  At HushTalks, we are committed to creating a safe and respectful environment for all our users. Protecting children from sexual abuse and exploitation is of paramount importance to us. This policy outlines our standards and measures to prevent, detect, and address CSAE within our platform

b) Prohibition of CSAE Any form of sexual abuse, exploitation, or inappropriate behavior towards children is strictly prohibited. This includes, but is not limited to:

• Sharing, distributing, or storing child sexual abuse material (CSAM).

• Attempting to coerce or entice children into sexual activities.

• Engaging in any communication aimed at the sexual exploitation of children.

c) Reporting Mechanisms

We encourage our users to promptly report any suspicious activities or content. Reports can be made through the following channels:

• In-App Reporting Feature: Users can report incidents directly within the app via the report button.

• Email: Reports can be sent to support@hushtalks.com

• Anonymous Reporting: For anonymous submissions, users can utilize our in-app feedback form.

All reports will be treated confidentially and reviewed promptly.

d) Actions Upon Violation

Upon confirmation of a violation of this policy, we will take the following actions:

• Immediate suspension or termination of the offending account.

• Removal of any illegal content.

• Reporting the incident to relevant law enforcement authorities following a court decision.

e) Preventive Measures

To prevent CSAE, we implement the following measures:

• Content Moderation: Utilizing automated tools and human moderators to monitor content. 

• Education: Providing resources and information to parents and children about safe online practices. https://www.technologycoalition.org/developer-good-practicescombating-online-child-sexual-exploitation-and-abuse

f) Collaboration with Authorities

We work closely with national and international law enforcement agencies and child protection organizations to effectively combat CSAE.

16. Rights of Data Subjects
Data subjects whose personal data HushTalks processes have the rights under Swiss data protection law. These include the right to information as well as the right to correction, deletion or blocking of the personal data processed.
Data subjects whose personal data HushTalks processes may – if and to the extent that the General Data Protection Regulation (GDPR) is applicable – request confirmation free of charge as to whether HushTalks is processing their personal data and, if so, request information on the processing of their personal data, have the processing of their personal data restricted, exercise their right to data portability and have their personal data corrected, deleted (“right to be forgotten”), blocked or completed.
Data subjects whose personal data HushTalks processes may – if and insofar as the GDPR applies – revoke their consent at any time with future effect and object to the processing of their personal data at any time.
Data subjects whose personal data HushTalks processes have a right of appeal to a competent supervisory authority. The supervisory authority for data protection in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).
17. Contact us

If you have any questions or suggestions about this Privacy Policy, please feel free to contact us.

HushTalks AG

Gotthardstrasse 30

6300 Zug

Switzerland

Email: support@hushtalks.com

We may update this Privacy Policy from time to time to reflect changes to the Service, our data practices, legal requirements or security measures. Where required, we will provide appropriate notice of material changes.

Version HT.PP.003.00 · Effective 12 September 2026