PRIVATE PILOT · SEPTEMBER 20, 2026

Necessary processing.
Limited retention.

We do not claim that nothing is stored. The API processes messages and temporarily retains technical information, alongside account and connection data. This notice describes the current pilot; it does not replace the complete legal policy required before public subscriptions.

What we process and for how long

InformationPurpose and retention
Text, captions, source URLs and attachment descriptorsSending, receiving and recovering messages. Removed from active databases about 24 hours after receipt by the API.
Events and their message copiesWebhooks and event polling, for about 24 hours. Your application must save what it needs before expiry.
Image, audio, video and document bytesDownloaded as needed to transmit them. Memory and temporary RAM files are used; no permanent attachment library is created.
IDs, phone numbers, message types, timestamps, status and idempotencyUp to 30 days in active databases for operation, limits and diagnostics. Numbers may also remain in legacy authorization or blocking records.
Account, email, derived password/API credentials, authorizations, blocks, audit and subscription recordsAs necessary for account operation, security and pilot traceability. Account deletion is requested through the administrator; self-service deletion is not yet available.
WhatsApp session credentials and webhook secretStored to maintain the connection and sign events. These are sensitive credentials, separate from message text. They are not deleted when a trial expires. Unlinking in the portal removes local WhatsApp credentials; the account and webhook secret remain.
Google sign-inIf used, we store your stable Google identifier and verified email to identify your account. We do not request Gmail, Contacts or Drive access. Authentication uses a temporary cookie lasting up to 10 minutes; the portal session lasts up to 24 hours. The language preference cookie lasts up to one year.

Cleanup runs about every minute while the service is running and on restart. Outages may delay physical deletion; immediate forensic erasure is not guaranteed. This policy applies to the public WhatsApp portal, not the operator’s private SMS gateway.

Who receives information

WhatsApp processes traffic on its platform. Your webhook receives incoming messages, replies and status updates for your account. The server hosting a media URL receives the download request. Your application decides what to retain in its own database.

We do not sell message content or use it for advertising. We do not import full chat histories. Application logs do not record messages, API keys or QR codes. The server processes readable content to provide the requested service; we do not claim the operator is technically unable to access it. The pilot does not yet provide its own database encryption at rest.

Deleting data here does not delete copies on phones, WhatsApp, your applications or external services. Restricted manual operational backups exist and may retain content already removed from active databases. Automatic portal backups are not configured. Encryption, access, expiry and restore procedures must be defined and verified before launch.

Responsibilities and limits

Link only numbers you control or are authorized to use. Your application chooses recipients and content and manages permissions, opt-outs and rights to attachments. OswiLink provides the technical channel and delivers replies to your integration. Spam, impersonation, unlawful content and attempts to evade WhatsApp restrictions are not permitted. Do not use the pilot for especially sensitive information.

Attachments are served as downloads, not automatically executed or displayed. Antivirus scanning is not provided; receivers should treat files as untrusted. View-once content is not downloaded or unwrapped.

The connection uses Baileys and is not the official WhatsApp API. Provider changes, disconnections and restrictions may occur. Delivery, reading and continuity are not guaranteed. This notice does not remove the operator’s legal obligations or users’ applicable rights.

Service status and contact

Live sending is disabled by default and requires targeted operator activation. The pilot does not charge subscriptions or request cards. Contact the administrator who invited you for support, privacy questions, revocation or deletion requests.

Before subscriptions are offered, the operator’s identity and contact details, complete legal policy, cancellation/refund rules, payment processing and applicable agreements must be published. Professional review for the countries served remains pending.

Payments and subscriptions

When monthly subscriptions become available, Stripe will process payments and card details. OswiLink will retain customer, subscription and billing event identifiers and the access period to manage the service. Billing records are kept separately from temporary message content. The free trial does not trigger automatic charges. A subscription selected by the customer renews monthly until canceled; pricing and terms are displayed before payment.