How the connection works, and what we do to keep your number safe.
Plain language first, because it matters more than a badge.
This is a linked-device connection, not the official API
Your workspace links to each WhatsApp number through WhatsApp’s Linked devices feature — the same mechanism as WhatsApp Web. That is what lets you keep your existing numbers, use groups, and see history. It is not Meta’s official Business API, and we are not affiliated with, endorsed by, or supported by WhatsApp or Meta.
WhatsApp’s terms do not permit this kind of connection, and WhatsApp can restrict or ban a number it detects being misused. We do not hide that; you accept it in writing when you sign up and again each time you link a number. What we can do — and do — is build the product so a number behaves like a person replying to clients, which is the pattern WhatsApp has no reason to act on.
Read the exact statement you’ll accept
Your WhatsApp number is linked to this service the same way WhatsApp Web links a browser — through WhatsApp's "Linked devices" feature. This is not an official WhatsApp or Meta integration, and WhatsApp's terms do not permit it. WhatsApp can restrict or permanently ban a number it detects being used this way. We built this service for replying to clients who message you, and it enforces limits to keep your number behaving like a person: a small daily cap on messages to people who have never written to you, a pace limit, a warm-up period for newly linked numbers, and no bulk or broadcast sending of any kind. Use it that way and the risk is low. Use it to message people who did not ask to hear from you and your number will be banned. That is not something we can prevent, reverse, or compensate you for, and by continuing you accept that risk.
Enforced in the product, not left to a best-practices page.
Bans are triggered by behaviour — cold outreach, speed, sameness, reports — not by a message count. So the limits are on behaviour.
Messages to someone who has never written to this number are capped at 20 a day by default. You can lower it. Nobody can raise it.
There is no broadcast, no CSV send, no "message all". The send path takes one recipient. It is not a setting; the feature does not exist.
At most one outbound message every few seconds per number, and a daily ceiling. Sends queue visibly rather than fire in a burst.
A typing indicator and a short delay proportional to the message length before each send. On by default, cannot be turned off.
A newly linked number is held to a quarter of the caps for its first 14 days.
Identical text to many contacts in an hour, or the same link to many new contacts, triggers a soft block and a warning.
Each customer’s numbers run in their own session container with their own outbound address. No two customers share a session or an IP.
A disconnect or a restriction alerts your team within a minute and pauses outbound automatically.
Where it is and who can see it.
Your conversations and session keys live on servers we run, encrypted at rest and in transit. Session keys are never logged.
Only members of your workspace, subject to the access you set. We look at customer data only to fix a problem you ask us to fix.
Per-customer backups of session and data, restorable on a clean machine. We drill it.
Full export on request. Deletion, including session keys, within 30 days of leaving.
Keyword rules withhold matching messages from Slack in both directions; a per-message lock keeps a reply out on demand.
Access to your workspace uses individual accounts with server-side sessions that can be revoked at any time. Passwords are hashed with scrypt. All traffic is TLS. Every action in the workspace is written to an activity log your admins can read.