WhatsWizard
Como funcionaPrivacidadePreçosComeçar grátis

Privacy Policy

Last updated: 11 August 2026

This is an English translation provided for convenience. The Portuguese version is the governing text.

The short version: the phone numbers the extension finds never reach a server of ours. They go from your browser straight into your Google account, or into a CSV file on your computer. What we store is your account: a Google identifier, an email address, billing status, and how many free contacts you have left.

1. Who we are

This policy explains how PurpleApps Studio (Av. Romeu Strazzi, 325 — Vila Sinibaldi, São José do Rio Preto/SP, CEP 15084-010, Brazil) handles personal data in the WhatsWizard Chrome extension and on this website. Data protection contact: support@purpleapps.studio.

2. Two roles, and why the distinction matters

  • Your account data. We are the controller. Sections 3 and 5 onward.
  • Third-party phone numbers you capture. Those people are not our users and never agreed to anything with us. You decide to capture them, what to use them for and how long to keep them. You are the controller of that data and we are at most a processor.

We make that second role true in engineering rather than only in text: as section 4 explains, those numbers pass through no system of ours, which means we cannot use, sell, leak or hand them over. The trade-off is that the obligations attached to them are yours. The Terms of Service cover this.

3. What we process

3.1. On our server

DataSourcePurpose
Google account identifier (“sub”)Google sign-inIdentifies your account. It is our user number.
Email addressGoogle sign-inSupport, billing notices, account recovery.
Subscription status and payment-provider customer IDStripeKnowing whether your plan is active. We never store card details.
Free contact balanceExtension usageEnforcing the 30-contact lifetime allowance.
Device sessions (a random identifier per installation)The extensionLimiting concurrent devices per account.
Technical logs: IP address, timestamp, route, errorsServerSecurity, diagnostics, abuse prevention. Kept 30 days.

That is the entire list. It contains no phone number, contact name, message, group name or any other content from your WhatsApp.

3.2. In your browser only

Held in Chrome’s local storage on your computer and sent nowhere: the numbers in the current capture session, the batch name you chose, your language preference, the version of the first-run notice you accepted, and that installation’s identifier. Deleting your account from the Account screen, or uninstalling the extension, removes all of it.

3.3. On this website

This site is static and uses no cookies, no analytics and no tracking pixels. Our hosting provider (Microsoft Azure Static Web Apps) keeps its own access logs, including IP addresses.

4. Where phone numbers actually go

  1. The extension reads the WhatsApp Web page already open in your browser and identifies numbers not yet in your contacts.
  2. Those numbers stay in your browser’s memory during the capture.
  3. When you save, your browser calls the Google Contacts API directly, with your authorisation, or writes a CSV file on your computer.

No server of ours appears anywhere in that path. There is no endpoint in our API that accepts a phone number. This is not a setting that could be changed by mistake, it is code that does not exist.

The extension also never sends messages, never replies to conversations, never joins groups and never automates outreach of any kind. It only reads.

5. Use of Google APIs

ScopeWhat it grantsWhy we need it
openid, emailYour Google account identifier, email address and name.It is how you sign in. There is no password-based account. Your Google account is the account.
https://www.googleapis.com/auth/contactsReading and creating contacts in your Google account.Reading is for de-duplication: we compare captured numbers against the ones already in your address book and skip repeats. Creating is the product itself. We never delete or modify a contact that already existed.

WhatsWizard’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice, data obtained from Google APIs:

  • is used only for the features described in this policy;
  • is never sold, rented or transferred to anyone;
  • is never used for advertising, profiling or training AI models;
  • is not read by humans on our team, except with your permission for support, where necessary for security, or where required by law;
  • is not transferred to servers of ours. The Google API call originates in your browser.

The extension does not store your Google access token: it exists in memory for the duration of one write and is discarded afterwards. We store no refresh token, which means we cannot access your account while you are not using the product, and also that we cannot revoke the grant on your behalf. To withdraw it, use your Google Account permissions page.

6. Legal bases

Under Brazil’s LGPD (Law 13.709/2018): performance of a contract for the account and the product itself; compliance with a legal obligation for billing and tax records; and legitimate interest for technical logs, abuse prevention and the deletion tombstone described in section 8.1.

7. Who we share with

We do not sell personal data and we run no advertising. Our providers are Google (sign-in and contact writing: the exchange is between your browser and Google, not through us), Microsoft Azure (hosting) and Stripe (card payments). We may also disclose data in response to a lawful order. In which case what we have to hand over is the list in section 3.1, never your contacts’ phone numbers, because we do not have them.

8. Location and retention

Section 3.1 data is stored on Microsoft Azure in the East US 2 region (United States). For Brazilian users this is an international transfer, permitted by LGPD article 33 and covered by Microsoft’s standard contractual clauses. Google and Stripe likewise run their own infrastructure under their respective safeguards. None of your contacts’ phone numbers ever leave your browser — what sits on those servers is the short list in section 3.1. Retention: account data for as long as the account exists; technical logs 30 days; tax documents for the period required by law; browser-side data until you delete your account or uninstall.

8.1. What survives account deletion, and why

Deleting your account removes your email address, subscription status, device sessions and everything the extension held on that computer. We keep one thing: a deletion tombstone holding your Google account identifier and your remaining free balance.

The reason is direct: the free tier is 30 contacts per account, for life. Without the tombstone, deleting and signing up again would renew the allowance indefinitely and the free tier would cease to exist. The tombstone identifies you for no other purpose and is never used to contact you.

Contacts already saved into your Google account are unaffected. They are yours, in your account, not in ours.

9. Security

Everything travels over HTTPS. Server access is restricted, credentials live in cloud configuration and never in source, and the database has no field capable of holding a phone number. The strongest security measure in this product is not a setting: it is that the most sensitive data never reaches us.

10. Your rights

You may request confirmation of processing, access, correction, deletion, portability, information about sharing, and withdrawal of consent. Most of this is in the extension’s Account screen. For the rest, write to support@purpleapps.studio; we answer within 15 days. Brazilian users may also complain to the ANPD.

If you are someone whose number was captured by one of our users and you want them to stop using it: contact them. We do not have your number, do not know who captured it, and have no way to find it, the direct consequence of storing none of it.

11. Children

The product is intended for professional use and not for anyone under 18. We do not knowingly collect data from children.

12. Changes

If what we do with data changes, we update the date at the top and the extension asks you to read the first-run notice again before continuing. Wording changes that do not alter meaning do not trigger that prompt.

13. Contact

support@purpleapps.studio, PurpleApps Studio, Av. Romeu Strazzi, 325 — Vila Sinibaldi, São José do Rio Preto/SP, CEP 15084-010.

See also the Terms of Service →

WhatsWizard
SuportePrivacidadeTermosPrivacy (EN)Terms (EN)support@purpleapps.studio

WhatsWizard é um produto independente. Não é afiliado, associado, autorizado nem patrocinado pela WhatsApp LLC, pela Meta Platforms, Inc. ou pelo Google LLC. WhatsApp é marca registrada da WhatsApp LLC; Google e Google Contacts são marcas registradas do Google LLC. A extensão apenas lê a tela do WhatsApp Web aberta no seu navegador. Ela nunca envia mensagens.

© 2026 WhatsWizard — um produto da PurpleApps Studio