Privacy policy
Last updated October 5, 2026
Draft. This page hasn't had a legal review yet and may change before launch.
Whosentya is operated by Pragmatic Innovations, LLC, doing business as Whosentya. We collect as little as we can, delete it on a schedule, and never sell, share for marketing, or export anyone's data. There is no export feature, for admins or anyone else.
If you're joining a group
What we collect, and why:
- Your phone number: to send a one-time code and prove you control it, so the admin can match you to your WhatsApp join request. Stored encrypted. Admins see only the last four digits unless they choose to reveal it, and every reveal is logged.
- Your name, your answers, and (if you add it) your WhatsApp username: so the admin can recognize you. The username is stored encrypted.
- Payment: on gates that charge $1, you pay in Stripe's secure form, shown on our payment page. Stripe handles your card, emails your receipt, and asks for your billing address, which sales tax requires. On that page only, Stripe's script also collects device information to prevent fraud. Stripe's Link may offer to save your payment details and a phone number for faster checkout; that's optional and handled by Stripe under its own terms. We don't see or keep your card details, email address, billing address or Link details; we keep only Stripe's ids, the amount, the tax included in it, and its status.
- Technical data: your IP address is used briefly for rate limiting (stored hashed, for up to a day) and by Cloudflare's bot check. We don't use analytics or advertising trackers.
- Cookies: two functional cookies, only on that gate's pages: one for a verification in progress (up to an hour) and one that lets you see your status again (60 days).
- Your browser: while you fill in a gate's form, this tab keeps your entries (session storage) so you can start again without retyping. They never leave your device, and they're cleared when you finish, press Back, or close the tab.
- “Email me when I'm approved” (only if you choose it, on groups where an admin reviews each request): your email address and a copy of your private status link, both stored encrypted, only until the admin decides. If you're approved we send one email with your status link (never the group's invite link) and delete both; if you're not approved, or nobody decides within 30 days, we delete them without sending anything. We never use the address for anything else.
How long we keep it
- Unfinished verifications: deleted when they expire (within about 24 hours).
- Requests an admin hasn't decided on: deleted 60 days after you verified.
- Approved or rejected requests: deleted 30 days after the decision.
- Admin activity logs (ids and the last four digits, never full numbers): 180 days.
- Payment records (no phone number, name, or answers): 7 years, for accounting and disputes.
If you're an admin
We keep your name and email to sign you in (by email link or Google), and your own verified phone number, encrypted, to make fake gates harder. Co-admins see only its last four digits. We email you about your gates at most once an hour, and you can turn that off. We also record which version of our terms you accepted, and when.
If you subscribe to a plan
You pay on Stripe's checkout and manage your plan in Stripe's billing portal. Stripe collects your card, billing address (sales tax requires it) and email address, and sends your receipts and invoices. We never see or keep your card details. We give Stripe your sign-in email and our id for your account, so your plan stays linked to you.
We keep Stripe's ids for you and your subscription, your plan, its status and dates (trial, renewal, cancellation, a failed payment), and how many included verifications you've used this month: what we need to apply your plan's limits. We keep them while you have an account; Stripe keeps invoices for as long as tax and accounting rules require.
If you contact us
What you send through the contact and “Talk to us” forms (your name, email address and message, and on “Talk to us” your community's details) goes by email, through Resend, to our support inbox. It isn't stored in the app's database, and we keep it in the support inbox only as long as we need it to respond. We reply to the address you gave; we don't add it to any list. Your IP address is used briefly for rate limiting and the bot check, as above.
Who processes data for us
- Twilio: sends verification codes by text message (SMS).
- Stripe: processes $1 payments and admin subscriptions, calculates sales tax, and sends receipts and invoices.
- Cloudflare: the Turnstile bot check.
- Resend: sends emails (sign-in links, status links, approval emails you ask for, admin notices, and contact and “Talk to us” messages to our support inbox).
- Vercel: hosts the app.
- Neon: hosts the database.
- Upstash: rate limiting.
- Sentry: error reports, with personal data stripped before they're sent.
Admins who sign in with Google share their name and email with us through Google.
Your choices
To have your data deleted sooner, or to ask what we hold about you, contact us (choose “Privacy/data request”) and include the gate and the last four digits of your number. We'll verify the request and act on it.
We aren't affiliated with WhatsApp or Meta. What happens inside WhatsApp is covered by WhatsApp's own privacy policy.
See also our terms.