Privacy,
in plain English.
What we keep when you use whistle.cv, why, and what we don't. This page covers the website. Updated 19 September 2026.
The short version
- Nobody sees who you are. The person you write to gets the words, never your name, email or number.
- We never store your IP. Only a salted, one-way hash of it, to stop spam and make blocks work.
- Codes are yours alone. We keep a hash of every one-time code, so even we can't read them back.
- Your email is used once. Join the waitlist and we write when the app is out. That's it.
Sending a message
When you send a message from someone's Whistle link, we store the message, which link it went to, and when. They see the words only, never who sent them.
To stop spam and let people block abusive senders, we keep a salted, one-way hash of your IP address. We don't store the IP itself, and the hash can't be turned back into it.
After sending you get a one-time code for the app. We only keep a hash of it, so we can't show it to you again.
What we keep
- Your message
- When you sent it
- Hashed IP
- Hashed code
Answering a Thought
Answering someone's Thought from the site works exactly like sending a message: the person who asked sees your answer, never who wrote it.
What we keep
- Your answer
- When you sent it
- Hashed IP
- Hashed code
The waitlist
If you join the waitlist we keep your email address, when you signed up and which page you signed up from. We use it once, to tell you the app is out. Ask us and we'll remove it.
What we keep
- Email address
- Sign-up date
- Hashed IP
The feedback board
Posts on the feedback board are public and don't show who wrote them. To count votes fairly we give your browser a random id and keep only a hash of it.
What we keep
- Your post
- Your votes
- Hashed browser id
- Hashed IP
Child safety
Whistle has zero tolerance for child sexual abuse and exploitation (CSAE). These are our published standards for the Whistle app (com.whistle.anon) and whistle.cv. Whistle is for people aged 16 and over, and anonymity never extends to harming children.
What's banned
Sharing, requesting or promoting child sexual abuse material (CSAM) of any kind, including drawn, edited or AI-generated images, links or descriptions; sexualising anyone under 18; grooming; sextortion; child trafficking or arranging to meet a minor for sexual purposes; and anything that excuses or encourages the sexual abuse of children.
How we prevent it
You must be 16 or older to sign up. There are no photo or video uploads: messages are text, and GIFs come only from a PG-13 rated library. Every message, post, reply and answer, including those sent from the website, is checked by a content filter before it's delivered. Anonymous accounts are tied to real, verified accounts, so bans follow the person, not the pseudonym.
How to report
In the app, press and hold a message (or tap ••• on a post or reply) and tap Report. Or email hello@whistle.cv with the handle or link involved. Please don't send us copies of abusive images. If a child is in immediate danger, contact local police or emergency services first. Child safety reports are reviewed ahead of everything else.
What we do
We remove the content, permanently ban the account and any related accounts, and keep the records needed to report it for only as long as the law requires. We report apparent CSAM and exploitation to the National Center for Missing & Exploited Children (NCMEC) through its CyberTipline and to the relevant authorities, including in Nigeria. We comply with the child protection laws that apply to us, including Nigeria's Cybercrimes Act 2015 and Child Rights Act 2003, and respond to valid requests from law enforcement.
Child safety contact
Our designated contact for child safety questions and reports, including from law enforcement, is hello@whistle.cv.
Contact
For questions, data removal or takedown requests, email us.
hello@whistle.cv