Last updated 9 August 2026
Security
Most account problems start with someone being persuaded to hand something over. This page covers how to avoid that, and how to reach us if something has already gone wrong.
Contents
What Witoh will never ask you for
This is the single most useful thing on this page. Nobody from Witoh will ever ask you for:
- a one-time code or OTP — not by message, not by email, not on a call, not for any reason;
- your password, if your account uses one;
- payment to keep, verify, restore or upgrade your account;
- remote access to your phone, or for you to install anything outside the App Store or Google Play.
If someone asks you for any of these while claiming to be from Witoh, they are not from Witoh. Stop, do not send anything, and tell us at security@witohapp.com.
Where official Witoh links go
Our website is witohapp.com. Official links and email from us use that domain. Anything on a lookalike domain — an extra word, a different ending, a hyphen — is not us, however convincing the page looks.
The Witoh apps are distributed only through the Apple App Store and Google Play. We do not send installable files, and we do not ask anyone to enable installation from unknown sources.
Keeping your account safe
- Keep the phone number or email on your account current — it is how you get back in.
- Use a device passcode or biometric lock, and keep your phone’s software updated.
- Never forward a verification code to anyone, including a friend who asks for it.
- Be sceptical of urgency. Messages that need you to act right now are the ones worth slowing down on.
- Sign out of Witoh on devices you no longer use.
If you think your account has been taken over
Move quickly, in this order:
- Try to sign in and, if you can, remove any other active sessions.
- Check that the phone number and email on the account are still yours.
- Write to support@witohapp.com from an address you control, describing what happened.
If your account was used to message people you know, tell them directly — the fastest way to stop a scam spreading through a group of friends is to say so out loud.
Reporting a security problem
If you have found a vulnerability in the Witoh app, our website or our infrastructure, please tell us at security@witohapp.com before telling anyone else. Include enough detail to reproduce it — what you did, what you saw, and where.
We ask that you do not access, modify or delete data belonging to anyone else, do not degrade the service for other people, and give us a reasonable opportunity to fix the issue. We will acknowledge your report and keep you informed while we work on it.
We do not currently run a paid bug bounty programme. We are grateful for reports regardless, and we will credit you if you would like us to.
What we do on our side
We encrypt traffic between the app and our servers, limit internal access to what people need to do their work, and keep our dependencies updated. Sign-ins are verified through a code sent to the contact details on the account.
Witoh is early, and we are not going to claim certifications, audits or compliance programmes we have not completed. What we can say is that security problems are treated as urgent, and that this page will be updated as our practices become more formal — not before.
How information is handled more generally is described in the Privacy Policy.
Security reports: security@witohapp.com. Everything else: support@witohapp.com.