← Back to home

Privacy Policy

Last updated: 21 August 2026

This Privacy Policy explains what information WA Campaign ("the Service", "we") collects, how it is used, and the choices you have. WA Campaign is a self-hosted tool for sending WhatsApp messages from a number you control.

1. Information we collect

  • Account details — your name, email address, and mobile number, provided when you create an account.
  • WhatsApp session data — the authentication credentials produced when you link a WhatsApp number by scanning a QR code. These are stored so your session persists.
  • Campaign data — the recipient lists (CSV contents), message templates, and delivery results (sent / failed) you create.
  • Technical data — basic logs needed to operate the Service.

2. How we use your information

Your information is used solely to operate the Service you asked for:

  • Authenticating you and keeping your account secure.
  • Maintaining your linked WhatsApp session and sending the campaigns you create.
  • Showing you delivery progress and history.

We do not sell your data, and we do not use your contact lists or messages for advertising.

3. Where your data lives

Account data, WhatsApp session credentials, and campaign data are stored in a Supabase (PostgreSQL) database controlled by the operator of this instance. Access is protected by row-level security so each user can only access their own data.

4. Data sharing

Messages you send are delivered through WhatsApp's own infrastructure and are subject to WhatsApp's terms and privacy practices. We share your data with no other third parties except the infrastructure providers strictly required to run the Service.

5. Data retention & deletion

Your data is kept while your account is active. You can disconnect a WhatsApp number (which clears its stored credentials) or delete campaigns at any time. To delete your account and associated data, contact the administrator of this instance.

6. Data security & encryption

Protecting your data is core to how the Service is built:

  • Encrypted in transit. All traffic between your browser, the Service, and the database is protected with HTTPS/TLS.
  • Encrypted at rest. Your account details, WhatsApp session credentials, and campaign data are stored in a Supabase (PostgreSQL) database that is encrypted on disk.
  • Strict data isolation. Row-Level Security is enforced at the database level, so no other user of the Service can ever read your numbers, sessions, campaigns, or messages — you can only access your own data.
  • WhatsApp end-to-end encryption. The actual message content between you and each recipient is end-to-end encrypted by WhatsApp itself; the Service is not a party to that encryption.
  • Server-only secrets. Privileged keys are never exposed to the browser, and your WhatsApp session credentials are never shown to you or anyone else through the app.

To send messages on your behalf, the Service's server must be able to use your WhatsApp session and campaign data while a campaign runs. The operator/administrator of this instance therefore has the technical ability to access this data to run and support the Service, and is bound to use it only for that purpose. No method of storage or transmission is 100% secure, but we take strong, industry-standard measures to protect your information.

7. Your responsibilities

You are responsible for the contact data you upload and the messages you send. Only message people who have consented to hear from you. See our Terms & Conditions for details.

8. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "last updated" date above.

This is a general template provided for a self-hosted deployment and is not legal advice. The operator of this instance should adapt it to their jurisdiction and add real contact details before relying on it.
Home Terms & Conditions Log in