Privacy Policy
Last updated: July 4, 2026
1. What Information Do We Collect?
We collect information you provide directly and information generated by operating the Service:
- Account data — your email address, chosen at signup. Password verification is handled by our authentication provider, Supabase; we never store your password ourselves.
- Two-factor authentication data — your TOTP secret and hashed backup codes, stored server-side to protect your account. These are never written to logs.
- Connected number data — the WhatsApp numbers you connect, their labels, connection timestamps, and the WhatsApp session state needed to keep them connected.
- Integration data — API key names and hashed key material, webhook destination URLs and event subscriptions, webhook signing keys, and MCP access tokens.
- Usage metrics — per-number counters such as API calls, webhook deliveries, broadcasts, and success rates, used to render your dashboard KPIs.
- Technical data — IP addresses and request metadata used for rate limiting and abuse prevention.
2. How Do We Process Your Information?
We process your information to create and secure your account, to operate your WhatsApp connections and integrations, to deliver webhooks you configure, to render usage analytics, to prevent fraud and abuse, and to comply with law. We do not sell your information or use it for advertising.
3. How Is WhatsApp Session Data Handled?
Connecting a number stores the encrypted session credentials WhatsApp issues when you scan the pairing QR code. These credentials exist so your number stays connected across restarts, and are used solely to operate the connection you created. Message content passing through the Service is delivered to your configured destinations (webhooks, API consumers, MCP clients) and is not retained beyond what delivery requires. The Service is not affiliated with WhatsApp LLC or Meta Platforms, Inc.
4. Where and With Whom Do We Share Your Information?
We share information only with the service providers required to operate the Service: Supabase (authentication) and our hosting infrastructure. We may disclose information where required by law, or in connection with a merger, acquisition, or sale of assets, in which case this policy continues to apply to the transferred data.
5. Do We Use Cookies and Tracking Technologies?
We use a single, essential session cookie to keep you signed in. It is HttpOnly and scoped to this Service. We do not use advertising or cross-site tracking cookies, and we do not respond to Do-Not-Track signals because we do not track you across sites in the first place.
6. How Long Do We Keep Your Information?
We retain your information only as long as your account exists or as needed to operate the Service. Disconnecting a number deletes its session credentials; deleting an API key or webhook removes it at the time of the mutation. Account data is deleted or anonymized when your account is deleted, unless a longer period is required for legal compliance.
7. How Do We Keep Your Information Safe?
We apply technical and organizational measures appropriate to the risk: mandatory two-factor authentication on every account, hashed API keys shown only once at creation, HMAC-signed webhook deliveries, rate limiting, CSRF protection, security headers, and services isolated on an internal network with no public exposure except the console itself. No transmission or storage system is 100% secure; we cannot guarantee absolute security.
8. Do We Collect Information From Minors?
The Service is not directed at anyone under 18, and we do not knowingly collect data from minors. If we learn that a user is under 18 we will deactivate the account and delete its data. If you believe we hold data on a minor, contact us at the address below.
9. What Are Your Privacy Rights?
Depending on your jurisdiction, you may have the right to access, correct, export, restrict the processing of, or erase your personal data. You can exercise these rights — including full account deletion — by emailing [email protected]. We will act on verified requests within 30 days.
10. Do We Make Updates to This Notice?
Yes — we may update this policy as the Service evolves. Material changes will be indicated by the "Last updated" date above, and where feasible we will notify you in the console. We encourage you to review this page periodically.
11. How Can You Contact Us?
Questions or requests about this policy can be sent to [email protected].