Who we are
Mhisper (“we”, “us”, “our”) is a note-taking application operated from Australia. You can contact us at:
- Email: connect@mhisper.com
- Operator: Mhisper
How we handle the most personal data on the internet — your thinking.
Effective 16 May 2026 · Last updated 16 May 2026
Your thoughts belong to you.
Always exportable as a portable memory file. Always deletable in a single action. No proprietary lock-in.
We never sell or share your data.
No advertising network, no data broker, no behavioural pixel. Mhisper makes money from people choosing to pay — not from selling attention.
We don't train AI on what you write.
Your content is not used to train any model — ours or anyone else's. If a future feature involves an AI provider, it will be opt-in and named.
Free tier stays on your device.
Your bubbles, zones, and threads live in your browser's local storage by default. You decide if and when to sync.
Memory files are sealed with a passkey only you know.
The passkey never leaves your device. We cannot read a memory file. Neither can anyone else, including in response to legal requests.
Minimum data, retained briefly.
Accounts require an email only. Logs are kept long enough to keep the service alive and protect it — then rotated.
Mhisper (“we”, “us”, “our”) is a note-taking application operated from Australia. You can contact us at:
This policy explains what personal information we collect when you use the Mhisper website and apps (the “Service”), how we use it, who we share it with, where it is stored, how long we keep it, and the rights you have over it.
By using the Service you agree to this policy. If you do not agree, please do not use the Service.
We try to collect as little as possible. Specifically:
Everything you put into the app:
You own this content. We store it so you can access it across devices.
For paid subscriptions purchased on the website, payment is processed by Stripe. We never see or store your full card number, CVV, or bank details. We do receive and store:
Stripe's privacy policy: stripe.com/privacy
We use the information above only to:
We do not use your content to train AI models. If we ever build features that involve sending your content to a third-party AI provider, we will update this policy, make it opt-in, and state the provider.
We share personal information only with the limited set of providers who help us run the Service:
Each provider is bound by a data-processing agreement. We do not sell or rent personal information to anyone.
We may disclose information when required by law (a valid subpoena or court order from a jurisdiction we are bound by) or to protect the rights, property, or safety of Mhisper, our users, or the public.
Your data is stored with our database provider; some sub-processors (payment, hosting, sign-in, error reporting) may process data in other countries including the United States and the European Union.
For users in the EU and UK, where we transfer personal data outside the EEA we rely on Standard Contractual Clauses (SCCs) with each sub-processor.
When you delete your account (Settings → Account → Delete account), your content and account record are deleted from live systems immediately. Backups age out within 30 days. Payment records are retained per the tax retention rule above.
You have rights over your personal information. Depending on where you live, these include:
Email connect@mhisper.com to exercise any right that isn't available in-app. We will respond within 30 days.
We protect your information by encrypting data in transit and at rest, storing only hashed and salted passwords where local authentication is used, limiting employee access to production data on a strict need-to-know basis, and reviewing dependencies for known vulnerabilities. For more detail on the principles behind this, see our security page.
No system is perfect. If we discover a breach affecting your personal information, we will notify you and the OAIC where required by the Notifiable Data Breaches scheme.
We use a small number of cookies and similar storage mechanisms:
We do not use third-party advertising or tracking cookies. You can clear local storage and cookies in your browser settings; doing so will sign you out and clear the offline cache.
Mhisper is not intended for children under 13 (or under 16 in the EU and UK). We do not knowingly collect personal information from anyone in that age range. If you believe a child has provided us personal information, email connect@mhisper.com and we will delete it.
We may update this policy as the Service evolves. Material changes will be announced in-app and by email to your account email at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the current version.
Questions, requests, or complaints: