Security
How your conversations are kept apart.
The protections that matter most are the boring ones: your data is separated from everyone else's at the database level, and the keys that could read it never leave the server.
Row-level separation
Every table carrying user content enforces ownership in the database itself, not only in application code. A request without your identity returns nothing at all — not a filtered list, nothing.
Credentials never reach your device
The AI keys live on the server. For live voice the app receives a short-lived, single-use token instead, and the Android release build refuses to start if a key was ever baked into it.
In the browser
- A strict content security policy: the page may only talk to the hosts it actually needs.
- HTTPS enforced, with the site on the browser preload list.
- The site cannot be framed by another site.
- Camera, payment and USB access are switched off entirely; microphone and location only when you allow them.
Documents
Uploads go to private storage rather than a public bucket. There is no shareable link to your file unless you create one.
What we do not claim
Warisha is not end-to-end encrypted. Your conversations are processed by an AI model to answer them, and staff operating the service could access data where the law or an investigation requires it. Anyone claiming a consumer AI assistant is end-to-end encrypted is describing something else.
Warisha AI · Languages · Urdu AI chatbot · Voice · Behaviours · Use cases · Memory · Documents · Android app · Pricing and limits · How it compares · About · Privacy