Privacy Policy

Last updated: May 18, 2026

1. Information We Collect

Whassabi collects the following categories of information to operate the Service:

  • Account data — your name, email address, password hash, and the business details you provide when creating an account.
  • WhatsApp Business Account (WABA) configuration — the WABA ID, phone number IDs, display names, and access tokens we receive from Meta when you connect your WhatsApp Business Account through Meta's Embedded Signup flow.
  • Customer contact data — the phone numbers, names, and tags you upload, along with consent provenance (opt-in source, timestamp, and verification record) used to enforce opt-in requirements.
  • Inbound and outbound WhatsApp message content — the text, media identifiers, and any attachments exchanged through your connected WABA, used to render conversations in the dashboard and to support customer service workflows.
  • Message metadata — sender, recipient, timestamps, delivery and read status, message IDs, the WhatsApp profile name shown by Meta, and the customer service window state used to enforce Meta's 24-hour conversation rules.
  • Opt-in and opt-out records — logs of when a contact opted in (with source) and when they opted out (with reason), retained for compliance audit purposes.

2. Token Storage & Security

System User access tokens obtained from Meta are encrypted at rest using AES-256 encryption before being stored in our database. We use these tokens solely to send WhatsApp messages and manage templates on behalf of your business. Tokens are never exposed to the client or to third parties.

3. How We Use Your Data

We use the information we collect to:

  • Operate and improve Whassabi.
  • Send WhatsApp messages you initiate through your connected WABA.
  • Enforce Meta's WhatsApp Business Messaging Policy on your behalf — including the 24-hour customer service window, opt-in consent requirements, and the automatic handling of opt-out (“STOP”) replies.
  • Process campaign requests and generate delivery analytics.
  • Provide customer support and respond to your inquiries.

We do not sell your data to third parties. We do not train our own AI models on your inbound or outbound message content.

3a. Optional AI Translation (Bring-Your-Own Key)

Whassabi offers an optional translation feature. Translation is not enabled by default. If you configure it under Settings → Translation, you choose a third-party AI provider (Google Gemini, Anthropic Claude, or OpenAI GPT) and supply your own API key for that provider. The key is encrypted at rest using AES-256-GCM before being stored.

When translation is enabled, the following message content is sent from our servers to your chosen AI provider, using your API key:

  • The text of outbound messages you type in a chat, in order to translate them into the contact's primary language before they are delivered through WhatsApp.
  • The text of inbound messages from contacts, in order to translate them into the operator's preferred language for display in the dashboard.

By enabling translation, you acknowledge that (a) the AI provider you choose is a separate processor governed by its own terms of service and privacy policy, (b) we do not control how that provider uses, logs, or retains the content you send to it, and (c) any usage costs, rate limits, or service availability are determined by the provider, not by Whassabi. You can disable translation at any time in Settings, after which no further message content is sent to any AI provider.

4. Data Retention

We retain your account data for as long as your account is active. Message logs are retained for 90 days. If you close your account, we will delete your personal data within 30 days, except where we are required by law to retain it longer.

5. Your Rights & Data Deletion

You have the right to access, correct, or delete your personal data at any time. To request deletion of your data, contact us at privacy@whassabi.com. We will process deletion requests within 30 days.

6. Meta Platform Data

Whassabi uses the Meta WhatsApp Business Cloud API. By connecting your WhatsApp Business Account, you authorize us to act on your behalf as permitted by Meta's Platform Terms. You can revoke this authorization at any time from your Meta Business Settings or by disconnecting your account in Whassabi Settings.

7. Contact Us

For privacy questions or data requests, please contact us at: privacy@whassabi.com