---
title: "WhatsMCP — Privacy Policy"
description: "What the WhatsMCP product collects and stores, and what this marketing site's cookies do."
url: "https://whatsmcp.com/privacy"
---

Privacy

# Privacy Policy

This page covers two things: what the WhatsMCP product collects and stores when you link a WhatsApp number to it, and what this marketing site's cookies do. They're separate — reading email doesn't set a tracking cookie, and browsing this site doesn't touch a linked WhatsApp account.

## What the product collects

To operate a linked WhatsApp account on your behalf and expose it through the API, we process: your account email; API keys (stored as salted hashes — we cannot read a key back out once it's created, only verify one presented to us); the phone number and linked-device session credentials of each WhatsApp account you connect; message content and metadata sent or received through that account; the account's local address book (contacts synced from the phone); call history; group and channel membership; media attachments you fetch through the API; and any webhook URL you configure to receive inbound messages.

## How it's used and stored

This data exists solely to operate your linked account and serve it back to you through the API — we do not use it for advertising, and we do not sell it. Every workspace is isolated: a request authenticated to one workspace cannot read another's data, and there is no field in which one workspace could name another. Webhook deliveries are signed with HMAC-SHA256 so your endpoint can verify they came from us.

## Who else sees it

We share data with the infrastructure that runs the service — our hosting/CDN provider (Cloudflare) and our transactional-email provider (Brevo, for account-related email) — and, if you're on a paid plan, our payment processor for billing. None of them may use your data for their own purposes. We do not share your data with WhatsApp/Meta beyond what operating as a linked device on the WhatsApp network inherently requires — see our [Terms of Service](https://whatsmcp.com/terms) for what that means.

## How long we keep it

Data tied to a linked account is retained for as long as that account stays paired, so the API can answer questions about your own message and call history. Unpairing a number (`wa_unpair_account`, or removing the linked device from your phone) or deleting your WhatsMCP account ends that. \[NEEDS INPUT: confirm the exact deletion timeline once data is unpaired/account-deleted — this draft doesn't invent a number.\]

## Your control

Your WhatsApp account stays yours: you can remove WhatsMCP as a linked device at any time from the phone (Settings → Linked devices) or by calling `wa_unpair_account`, and you can revoke an individual API key from the console at any time.

## This website's cookies

The rest of this page — everything below — covers only what this marketing site (not the product) does in your browser.

## What we use

This site loads Google Tag Manager (container `GTM-KCW8QCTH`), which is how we measure which pages get read. Until you accept, Tag Manager runs with analytics and advertising storage denied: it can count a page view without setting a cookie or an identifier in your browser.

## What your choice controls

Accepting grants exactly one Google Consent Mode signal, `analytics_storage`. The three advertising signals are denied at all times, whichever button you press — we do not ask for advertising consent, so we do not take it.

-   `analytics_storage` — cookies that let us tell a returning reader from a new one. This is the one your choice controls.
-   `ad_storage` — advertising cookies. Always denied.
-   `ad_user_data` — whether measurement data may be sent to Google for advertising. Always denied.
-   `ad_personalization` — whether that data may personalise advertising. Always denied.

`security_storage` is always on. It covers the storage needed to keep the site working and cannot be switched off.

## Where the choice is kept

Your decision is stored in your own browser under the `wm_consent` key, as the choice and the time you made it. That record itself never leaves your device, and we keep no server-side record of it. Clearing your site data erases it and you will be asked again.

## Changing your mind

You can change or withdraw your choice at any time. New collection stops immediately — the consent signal updates on the spot, without a reload. Cookies already set stay in your browser until you clear your site data; withdrawing consent stops further writes, it does not reach back and delete them.

Change cookie settings

## Contact

Questions about this page: [contact us](https://whatsmcp.com/contact).
