WillSignal Privacy Policy
Effective date: 2026-07-31
WillSignal is an inactivity-based private message delivery service. This Privacy Policy explains what personal information we handle, why we handle it, how long we keep it, when we share or transfer it, and how you can exercise privacy rights.
The personal information controller / operator is WillSignal, operated by an individual developer. The privacy officer or responsible department is the WillSignal operator.
1. Summary
WillSignal lets you prepare private messages for selected recipients. You keep your signal active by checking in. If your signal goes out, messages may be made available to your selected recipients according to your settings.
Some messages may be locked with end-to-end encryption. Locked message bodies are designed so that WillSignal cannot read them after lock. WillSignal may still process account data, recipient data, metadata, logs, consent records, and other information needed to operate, secure, and support the service.
2. Information we collect
The exact information we collect depends on how you use WillSignal.
Account information
- Examples: social-login identifier, username and tag, internal account ID, and email address if provided by your login provider.
- Purpose: account creation, login, authentication, account management, support, security.
- Retention: until account deletion plus the 30-day recovery window, then deleted, de-identified, or retained only as stated in "Retention and deletion".
Recipient and designation information
- Examples: recipient email addresses, recipient account status, recipient verification status, sender/recipient designations, reveal settings.
- Purpose: recipient setup, verification, message delivery, sender privacy settings, abuse prevention.
- Retention: see "Retention and deletion" below.
Friends and social connections
- Examples: friend requests and their status, your friends list, the private nickname you set for another user (which only you can see), and the users you have blocked, including when a block started and ended.
- Purpose: making it easier to choose recipients, showing who a message is from or to, applying blocks you have set, abuse prevention.
- Retention: see "Retention and deletion" below.
Message content and message metadata
- Examples: message body, title or label, delivery status, sender/recipient relationship, timestamps, encryption mode, key version, message identifiers.
- Purpose: message storage, encryption, signal-triggered delivery, support, security, abuse prevention.
- Retention: see "Retention and deletion" below.
Locked-message encryption data
- Examples: public keys, client-encrypted private keys, encrypted message keys, key versions, key fingerprints, and recovery-related encrypted material.
- Purpose: locked-message encryption, recovery flow, delivery, recipient access.
- Retention: see "Retention and deletion" below.
Signal and service settings
- Examples: countdown settings, check-in timestamps, activity timestamps, language preferences, notification preferences, skin or display preferences.
- Purpose: signal operation, reminders, service personalization, delivery logic.
- Retention: see "Retention and deletion" below.
Technical, security, and consent evidence
- Examples: IP address, user agent, device/browser information, timestamps, accepted document version and hash, consent/withdrawal records, access logs.
- Purpose: account security, audit trail, consent and acceptance evidence, abuse prevention, legal compliance.
- Retention: see "Retention and deletion" below; consent and acceptance evidence is kept as append-only proof and may outlive account deletion.
Support communications
- Examples: messages you send to support, related contact information, attachments if any, and technical details your device reports with a bug report (app and operating system version, device platform, the screen you were on, display size, language).
- Purpose: customer support, dispute handling, safety and security review.
- Retention: see "Retention and deletion" below.
Abuse reports
- Examples: the report you submit, what you are reporting and why, and — if you choose to include it — the content of the message you are reporting.
- Purpose: reviewing reports, enforcing the Terms of Service, protecting users and recipients, meeting legal obligations, and referring matters to law enforcement where required.
- Retention: see "Retention and deletion" below. We may retain a report and its evidence longer where the law requires it or where it is needed for an ongoing investigation or dispute.
Locked message bodies are end-to-end encrypted and WillSignal cannot read them. If you report a locked message and choose to include its content, you are voluntarily giving WillSignal content it could not otherwise read. WillSignal does not gain the ability to read your other locked messages by receiving a report — it receives only what the reporter chooses to send.
3. Required and optional information
Some information is required to provide WillSignal, including account information, recipient information, message and signal settings, technical logs, and consent records. If you do not provide required information, we may not be able to provide the service.
Some information is optional, such as display preferences and optional profile fields.
4. How we use information
We use personal information to:
- create, authenticate, and operate accounts;
- store encrypted messages;
- operate signal countdowns, check-ins, reminders, and inactivity-triggered delivery;
- verify or notify recipients;
- apply sender reveal settings;
- provide locked-message encryption and recovery flows;
- provide customer support;
- prevent abuse, spam, fraud, and unauthorized access;
- maintain consent and acceptance evidence;
- comply with legal obligations and enforce our terms;
- improve reliability, security, and product quality.
We do not use technical consent-evidence records for advertising, and WillSignal does not use advertising or web/product analytics tools.
5. Locked and non-locked messages
Locked message bodies are designed so that WillSignal cannot read them after lock. If you lose both your passphrase and recovery code, locked message bodies cannot be recovered.
This protection applies to locked message bodies, not necessarily to metadata or other service records. WillSignal may still process account data, recipient data, message metadata, delivery status, notification data, logs, and consent records.
Non-locked messages are encrypted at rest using keys controlled by the service so that they can remain recoverable and deliverable according to your settings. This means WillSignal may have the technical ability to process non-locked message bodies where needed to provide the service.
6. Recipients and sender privacy
When you designate a recipient, we process the recipient information you provide, such as email address and related designation settings.
If you choose not to reveal your name to a recipient, we will try to follow that setting in the product experience. However, sender reveal settings do not prevent processing or disclosure where reasonably necessary for security, abuse prevention, legal compliance, dispute handling, support, or service operation.
Recipients may receive service messages about account verification, recipient designation, message availability, delivery, or related service activity. These are service-related messages, not marketing messages.
7. Service notices and marketing
We may send service-related notices, including account, security, check-in, signal, recipient, delivery, and policy notices. These are necessary to provide the service.
WillSignal does not currently send marketing messages. If we introduce them, we will send them only where permitted by law and your preferences, and you may opt out as required by law. Opting out of marketing will not stop essential service, security, or delivery-related notices.
8. Sharing and disclosure
We do not sell personal information. We may share or disclose personal information as follows:
- Recipients you select — to make messages available according to your settings; involves message content and related sender/metadata, subject to encryption mode and reveal settings.
- Service providers / processors — to operate the service; involves the information needed for each provider's function. Our current providers are:
- Amazon Web Services (cloud compute, database, and storage infrastructure);
- Amazon Web Services (Amazon SES) for transactional email delivery;
- Amazon Web Services (Amazon Cognito) for authentication, together with the social-login provider you choose (currently Google, Kakao, or Apple);
- Amazon Web Services (Amazon CloudWatch) for operational and security logging.
- Legal, safety, and compliance recipients — to comply with law, legal process, enforce terms, prevent harm, or protect rights; involves information reasonably necessary for the purpose.
- Business transfer recipients — in a merger, acquisition, financing, restructuring, or asset transfer, if applicable; involves information reasonably necessary for the transaction, subject to applicable law.
We do not currently use advertising, analytics, or marketing processors. If that changes, we will update this Policy and obtain any consent required by law.
9. Overseas transfer
WillSignal stores and processes personal information using cloud infrastructure located in the United States, on Amazon Web Services in the us-east-1 (Northern Virginia) region.
Where required, we request separate consent for overseas transfer of personal information. The itemized details are provided in the separate "Consent to Overseas Transfer of Personal Information." WillSignal is the personal information controller. Amazon Web Services, Inc. provides the cloud infrastructure on which personal information is stored and processed, acting on WillSignal's behalf and under its instructions, and does not use that information for its own purposes.
10. Retention and deletion
We keep personal information only for as long as needed for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
When you request account deletion, your account enters a recoverable deletion period of 30 days. During that period, you may cancel deletion.
After the recoverable deletion period ends, we delete or de-identify account data and related content, except where retention is needed for legal, security, fraud-prevention, backup, dispute, tax, accounting, or operational purposes. Information removed from live systems may persist in encrypted backups until those backups expire on their normal cycle.
Unless a longer retention period is required or permitted by law, WillSignal applies the following retention periods:
- Account data: until account deletion, plus a 30-day recoverable deletion period.
- Message content and message metadata: until account deletion or message deletion, plus a 30-day recoverable deletion period.
- Recipient and designation data: until account deletion or removal of the relevant recipient/designation, plus a 30-day recoverable deletion period.
- Locked-message encrypted key material: until account deletion or deletion of the related locked message, plus a 30-day recoverable deletion period, unless earlier deletion makes recovery impossible.
- Signal and check-in records: until account deletion, plus a 30-day recoverable deletion period.
- Access logs and operational request logs: up to 30 days.
- Security and audit-event records: identifying details such as IP address, device/user-agent, and request identifiers are removed within 180 days; a limited audit reference (an internal account identifier, the event type, and a timestamp, without IP, device, or request details) may be retained longer where needed for security, abuse prevention, dispute handling, or legal compliance.
- Consent and acceptance evidence: 3 years after account deletion or withdrawal, unless longer retention is needed for dispute handling or legal compliance.
- Support records: until account deletion, plus a 30-day recoverable deletion period, unless longer retention is needed for dispute handling or legal compliance.
- Friends and social connections: until you remove the connection or delete your account, plus a 30-day recoverable deletion period. A block is kept after you unblock, for as long as your account exists, so that messages delivered while the block was active are not revealed again by unblocking.
- Abuse reports: a report is kept after the reporting or reported account is deleted, with the links to those accounts removed, for safety, abuse prevention, dispute handling, and legal compliance. Message content included in a report is deleted 30 days after the report is resolved, or when the reported account is permanently deleted, whichever comes first — unless it is subject to a legal or investigative hold.
- Invitations sent to an email address that has no WillSignal account: an invitation that is never accepted, and the email address in it, are deleted 90 days after the invitation is sent. If the invitation is accepted, the record is kept while that account exists and is deleted when the account is permanently deleted.
- Do-not-contact and email-suppression records (an email address and the reason it was suppressed): kept for as long as needed to honor the suppression, including after account deletion.
- Backups: deleted or overwritten on a rolling cycle of up to 7 days, unless backup retention is extended for security, disaster recovery, or legal reasons.
11. Destruction procedure and method
When personal information is no longer needed and is no longer required to be retained, we delete, de-identify, or otherwise destroy it using methods appropriate to the storage medium.
Methods include deleting database records, deleting or expiring stored objects, rotating or deleting encryption keys where applicable, and deleting or expiring logs and backups according to the applicable retention schedule.
12. Your privacy rights
Depending on applicable law, you may have rights to access, correct, delete, export, object to processing, restrict processing, or withdraw consent for your personal information.
You may exercise these rights in the app or by contacting admin.willsignal+privacy@gmail.com.
We may need to verify your identity before processing a request. Some requests may be limited where retention or processing is required or permitted by law, necessary for security, necessary for dispute handling, or technically limited by locked-message encryption.
Withdrawing consent may affect your ability to use WillSignal. For example, if you withdraw consent to processing or overseas transfer that is necessary to provide the service, we may not be able to continue providing the service.
13. Cookies, local storage, and SDKs
On the web, WillSignal uses browser local storage to keep you signed in and to store preferences. It does not use advertising cookies, advertising identifiers, or third-party tracking or analytics SDKs.
14. Security
We use technical and organizational measures designed to protect personal information, including encryption in transit, encryption at rest, access controls, and least-privilege practices. Locked message bodies are additionally protected by end-to-end encryption and are designed so that WillSignal cannot read them after lock.
Two limits on that design are worth stating plainly. Locking a message relies on WillSignal supplying the correct encryption key for each recipient, and WillSignal does not currently offer a way for you to verify a recipient's key independently. Locked messages also carry no cryptographic proof of who sent them. Messages you do not lock are encrypted using keys WillSignal manages, which means WillSignal has the technical ability to read them.
No service can guarantee perfect security. You are responsible for keeping your account credentials, passphrase, recovery code, and devices secure.
15. Minors
WillSignal is not intended for users below the minimum age for their region (19 in Korea, 18 elsewhere; see the Terms of Service). You may not create an account or use WillSignal if you do not meet the eligibility requirement.
If we learn that an ineligible user has created an account, we may suspend or delete the account. A parent, guardian, or user may contact us at admin.willsignal+privacy@gmail.com to report an underage account.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will provide notice by reasonable means, such as in-app notice, email, or posting an updated version.
Where required by law, we will request separate consent for changes that require consent.
17. Contact
For privacy questions or requests, contact:
- Operator: WillSignal, operated by an individual developer
- Privacy officer / responsible department: WillSignal operator
- Address: Not applicable (individual operator; contact by email)
- Privacy contact email: admin.willsignal+privacy@gmail.com
- Business registration / operator details: Not applicable / not registered