Privacy Policy

WhatStats for iOS

Last updated: June 26, 2026

WhatStats ("the App") is developed by Lorenzo Meccoli ("we", "the Controller"). This policy describes what data we collect, how we use it, and your rights under the GDPR (EU Regulation 2016/679).

1. Data we collect

1.1 WhatsApp chat data

When you import a WhatsApp export file, the App analyses the content locally on your device to calculate statistics (messages, emoji, times, media). This data never leaves your device during local statistics computation.

1.2 AI Analysis (requires your explicit consent)

AI features (Report, DNA, Moments, Wrapped, Ask Your Chat) require sending data to our servers. This feature is disabled by default and is only activated with your explicit consent via the dedicated toggle in the App.

When you enable AI analysis, the following is sent:

Not sent: the entire message history, phone numbers, photos, videos, voice notes, or other media.

Data is processed in real time and is not stored on our servers after processing is complete.

1.3 Device identifier

We use the device vendor identifier (identifierForVendor) exclusively for the referral system, to prevent abuse (duplicate registration/redemption). This identifier cannot be linked to your identity and changes if you reinstall the App.

1.4 Referral system data

If you use the referral program, we store on Firebase Firestore (EU):

1.5 Purchase data

In-app purchases (Premium subscription and credits) are managed by Apple through the App Store and by RevenueCat for subscription management. We do not store payment data. See RevenueCat's Privacy Policy.

1.6 Data we do NOT collect

2. Legal basis for processing

3. Data retention

4. Data transfers

Data for AI analysis passes through our EU servers (Firebase, Belgium) and is forwarded to Anthropic (USA) for processing. Anthropic adheres to EU-US standard contractual clauses for data protection.

5. Your rights

Under the GDPR you have the right to:

6. Security

Local data is encrypted at rest using iOS data protection APIs (completeUntilFirstUserAuthentication). All communications with servers are exclusively via HTTPS/TLS.

7. Children

The App is not intended for children under 13. We do not knowingly collect data from children.

8. Changes

We may update this policy. The last update date is shown at the top. We encourage you to review it periodically.

9. Contact

For any privacy questions:

Lorenzo Meccoli
Email: lorenzo.meccoli@gmail.com