Privacy policy for Zapkit: WhatsApp Web toolkit
Zapkit: WhatsApp Web toolkit by Zapkit
Zapkit is a browser extension for WhatsApp Web with AI, privacy and productivity tools. This policy explains what data we use, why, and with whom.
Data we use
Account key: your account is created automatically when you install the extension, with no sign-up. Your identity is a random key stored on your machine; we keep only a hash of it, so we cannot read it back.
Phone number (from your WhatsApp) and extension version: sent to our backend as a label for your account, so we can recognize you in support and tell whether you are on an outdated version. It is not your account identity and grants no access on its own.
Email: optional, only if you subscribe to Pro (collected by Stripe at checkout).
Message content: only when you trigger an AI feature (transcribe, translate, rewrite, summarize), the text or audio of that message is sent to our backend for processing. Zapkit does not read your conversations in the background and processes nothing unless you trigger it.
IP address and browser: recorded when your extension talks to our backend, and kept as the last access on your account. We use them for support (recognizing your account, which has no name) and to limit abuse of the free AI quota. From the IP we also derive an approximate city and network provider, through the service listed below.
Contact notes: notes you write about a contact are stored on our server, tied to your account, so they come back when you use Zapkit on another computer. The contact is identified by a one-way hash of the phone number, never the number itself, so we cannot tell who a note is about. The text you write is stored as written, and we can read it; do not put anything there you would not want stored on a server. You can delete any note at any time, and deleting your account deletes them all.
Usage: we keep counters (which feature, when) to enforce plan quotas. We do not store the content of processed messages.
Anonymous product analytics: which feature was used, settings toggled and account actions, tied to a random identifier generated in your browser (not your phone number). Message content is never included.
How we process AI
When you trigger an AI feature, the content is sent to our backend, which forwards it to an AI provider (OpenAI) to generate the result and returns the response to you. The content is not retained after processing.
Third parties
OpenAI: processing of the AI features.
Stripe: Pro plan payments.
Google Analytics: anonymous usage analytics. Does not receive WhatsApp content.
ipwho.is: turns an IP address into an approximate city and network provider. Receives the IP address only, and nothing else about you.
We do not sell your data and do not share it for advertising.
Local storage in your browser
Some features need to remember things on your own machine. All of the items below stay in your browser's local extension storage. None of them is uploaded to us, and none of them is shared with third parties.
Account session key: to keep you signed in.
Your preferences: interface language, theme, icon style and which features are turned on.
Quick replies: the shortcuts and the text you wrote for them.
Reminders: the text you wrote, when it should fire and, if you linked one, the name of the conversation.
Session lock PIN: stored as a salted hash, never in plain text and never transmitted. We cannot read it or recover it for you.
Transcriptions you asked for: when you transcribe a voice message, the resulting text is kept locally so that you can search inside what was said and so the same audio is never transcribed twice. This is conversation content, and it stays on your machine. The feature has its own on/off switch in the extension, and turning it off stops new transcriptions from being kept.
Pinned conversations: the identifiers of the chats you pinned beyond WhatsApp's own limit.
Everything above is removed when you uninstall the extension. Message content only ever leaves your machine when you trigger an AI feature, as described above; contact notes, which you write yourself, are stored on our server so they survive a change of computer.