Privacy Policy

Last updated September 27, 2026

This policy explains what wuapi stores and why.

Who is responsible

Zavu Labs Inc., a Delaware limited liability company, operates wuapi and is the data controller for your account data. Address: 1111B South Governors Avenue, Suite 99526, Dover, DE 19904, United States. Email: support@wuapi.dev.

What we store

  • Your account: email address and a hash of your password, or your Google or GitHub identity (name, verified email and avatar) if you sign in with one of them.
  • For each connected account: the phone number, the WhatsApp profile name, connection status, recent connection logs, and the session credentials needed to stay linked.
  • Messages sent and received through the API, including media, so the API and dashboard can return them and so webhooks can be delivered and retried.
  • Webhook endpoints and a log of deliveries. API keys are stored as hashes.
  • Proxy traffic volume per account, for billing.
  • Billing references from Stripe: your Stripe customer and subscription IDs, the subscription status, and the latest invoice's number, status, amount and links. No payment details.

Who processes it

Stripe (Stripe, Inc. and its affiliates) processes payments for Zavu Labs Inc.: it receives your billing data (name, email, billing address, tax ID and payment details) to take payments, calculate tax with Stripe Tax, and send invoices and receipts. Card data goes to Stripe and never touches wuapi. Our infrastructure providers host the database and the WhatsApp connections. Traffic between WhatsApp and each connected account passes through a residential proxy provider. We don't sell personal data.

Cookies and advertising

Zavu Labs Inc. is the controller for the data described in this section. Signing in uses a first-party cookie, and your theme is kept in your browser. Both are needed for the site to work.

We use one advertising tool, the Google Ads tag (gtag.js), to count how many sign-ups and upgrades to a paid plan came from our ads. Apart from product analytics (below), we run no other trackers. Google handles what the tag sends under its privacy policy. You choose two categories:

  • Advertising (ad_storage, ad_user_data, ad_personalization): Google Ads cookies and the ad click id (gclid). When you sign up or upgrade to a paid plan, Google receives a conversion with your organization ID and, only with this category on, a SHA-256 hash of your email address.
  • Analytics (analytics_storage): the campaign parameters (utm_*) and the site that sent you, kept in your browser's local storage (wuapi.attribution.v1) and saved with your account if you sign up, so we can see which channels bring customers.

We use Google Consent Mode v2. In the EEA, the UK and Switzerland, and wherever we can't tell your region, both categories stay off until you choose in the banner. Elsewhere they start on and you can turn them off the same way. While advertising is off, the Google tag sets no cookies and sends only cookieless pings with ad click ids removed, which Google uses for aggregate conversion modelling.

Without the analytics category, nothing about where you came from is stored in your browser. Each browser session still sends one anonymous visit count by source, with no identifier and with no click id unless advertising is on.

Your choice is stored in your browser (wuapi.consent.v1). Change it any time from Cookie settings in the footer, or here: .

Product analytics

To see how the site and the dashboard are used and to catch errors, we use PostHog (PostHog, Inc.). It is not loaded at all for visitors in the European Economic Area, the United Kingdom or Switzerland (32 countries), or whenever we can't tell your region: no PostHog script, cookie or local storage, and nothing is sent to PostHog. Your region is looked up from your IP address by our host when the page loads, and is not stored.

Everywhere else, PostHog records page views, clicks on our sign-up buttons, a few product events (such as connecting a number or creating an invitation) and errors, and keeps an identifier in a first-party cookie and local storage. When you sign in, it is linked to your account ID, email address and name. We use it only to improve wuapi, never for advertising, and we don't sell it.

Those requests go to https://us.i.posthog.com, PostHog's own host, with no wuapi.dev subdomain in between. Your wuapi cookies are not sent with them.

Your role

For the messages and contacts that pass through your numbers, you decide what is sent and to whom. You are responsible for having a lawful basis to message those people and for honouring their requests.

Deletion

Deleting a connected account unlinks it from the phone. To delete your wuapi account and its data, write to the address below.

Contact

Questions about privacy: privacy@wuapi.dev. Anything else: support@wuapi.dev. Postal address: Zavu Labs Inc., 1111B South Governors Avenue, Suite 99526, Dover, DE 19904, United States.