Back to Developer Portal
Wani for Developers
API & Developer Portal

Privacy Policy

Last updated: August 9, 2026

1

Introduction

Welcome to Wani for Developers (the Developer Portal). This policy is specific to the Developer Portal and differs from the privacy policy of the main Wani campaign platform, because the nature of the data processed here is different: here you're using an API to send OTP and WhatsApp messages programmatically from your own application, not through a campaign dashboard.

By using the Developer Portal or its API, you agree to this policy.

2

Roles: you're the controller, we're the processor

This distinction matters, so let's be precise:

You (the developer / project owner) are the **Data Controller** for the phone numbers of your own end customers that you send OTP or WhatsApp messages to via the API
We (Wani) act as a **Data Processor** for those numbers — we only relay the message through the WhatsApp Business API on your behalf, and don't use it for any other purpose
You are responsible for obtaining your end customers' consent, and for having your own privacy policy that informs them of this

This policy covers your data as a developer/project owner, and how we handle the end-customer data that passes through the API.

3

Data We Collect

Your data as a developer/project owner:

Name, email, and password (hashed with bcrypt)
Data for the projects you create (name, members, roles: Owner or Developer)
Your API keys (shown only once at creation; we keep only a hashed copy that we ourselves cannot reverse)
WhatsApp connection data per project: Access Token (encrypted with AES-256-GCM), Phone Number ID, WABA ID, display phone number
The OTP templates you configure
API usage logs: request counts, send status (success/failure), timestamps

Data that passes through the API (belonging to your end customers):

The recipient phone number, and the content of the message/template used, at the moment of sending only
We keep a brief log of these requests (for billing, error tracking, and usage limits), not to analyze the identity of those customers
4

How We Use the Data

Operating the API and sending messages on behalf of your project via the WhatsApp Business API
Validating API keys and applying rate limits
Displaying usage statistics in your project dashboard
Receiving template status updates from Meta via the portal's webhook
Contacting you about your account or project (security alerts, service updates)

We do not use your end customers' data (the phone numbers you send to via the API) for any marketing or analytical purpose of our own.

5

Data Sharing

**Meta / WhatsApp:** to send messages via the WhatsApp Business API on behalf of your project
**Neon / Vercel:** hosting for our database and application
We do not sell or share your project's data or your end customers' data with any advertising or marketing party
6

Security

Passwords are hashed with bcrypt, and API keys are stored only as a hashed value
Each project's Access Token is encrypted with AES-256-GCM and is never returned in any API response after being saved
Every webhook request from Meta is signature-verified (HMAC-SHA256) before being accepted
Rate limiting is applied to prevent abuse or brute-force attacks
7

Your Obligations to Your End Customers

Since you're the data controller for your end customers, you are responsible for:

Obtaining their explicit consent before sending them any OTP or WhatsApp message via the API
Providing your own product/app privacy policy that discloses your use of this service to them
Fully complying with Meta and WhatsApp Business policies on content and sending limits
Not using the API to send spam or non-compliant content

We are not responsible for any violation on your part in this regard.

8

Data Retention

We retain your account and project data for as long as the account is active. Upon deleting a project or your account:

Meta connection data (the Access Token) and API keys are deleted immediately
Detailed usage logs are deleted within 30 days
We may retain aggregated, non-identifying logs for internal statistical purposes
9

Your Rights

As an account or project owner, you have the right to access, correct, and delete your data, and to request a copy of it in a readable format. To exercise any of these rights, contact us at the email below.

10

Changes to This Policy

We may update this policy from time to time. We will notify you of any material changes by email or an in-portal notice at least 7 days before they take effect.

11

Contact Us

For questions about the Developer Portal or the API:

Email: developers@wani.app

Have a question about this policy?

Contact us
Terms of UseDeveloper Portal Home