Trust

Trust and security

walpio sends your business's WhatsApp messages with your Meta credentials, so you should know how they are protected. This page says what the service does today — and, as plainly, what it does not do yet.

How data is protected

Backups and monitoring

The operator console’s Needs attention board with one item: two texts refused in the last 24 hours for a demo client, the reasons, and what to do.The operator console’s Needs attention board with one item: two texts refused in the last 24 hours for a demo client, the reasons, and what to do.
The operators' board of what needs attention, from a demo workspace (made-up data, masked numbers).

The API also publishes a public health check: api.walpio.com/health.

Where data lives, and for how long

walpio runs on Cloudflare's global network. Its database and backups are Cloudflare's, and are not pinned to one country, so data may be processed and stored outside yours. Meta delivers the messages under your own Meta account and its own terms. If you want message content at rest in the UAE, Meta can keep it there when you switch on its local storage before your number is registered — our connection guide shows how. That setting covers what Meta stores, not walpio's own records.

We keep message details and a preview of up to 160 characters, not an archive of conversations. The full text of a message is held only while a send is being retried and, for a customer's message, in the log of the status reports we post to you. How long each kind of data is kept:

DataKept for
Message records (details and the 160-character preview)About 13 months
Status reports posted to your server, delivered or not30 days
The activity logAbout 13 months
Counters of sign-in attempts and form submissions by IP addressA few hours
Nightly backups35 days
Your workspace's team, contacts, templates and settingsWhile the workspace is active; deleted on request when you leave

You can ask for an export of your workspace's data, or its erasure, at [email protected]. Erasure revokes the workspace's API keys and signs everyone out at once, then deletes its records; the activity log expires on its own schedule, and backups roll off within 35 days. The Privacy Policy has the full detail.

Sub-processors

The companies that process data for walpio, and what each does:

ProviderWhat it does for walpioWhere
CloudflareHosts this website, the dashboard and the API; runs the database and stores the nightly backups; forwards e-mail and form notifications to the walpio team; counts visits to this website (Cloudflare Web Analytics).Cloudflare's global network; no country pinned
Meta PlatformsDelivers WhatsApp messages through the WhatsApp Business Cloud API, under your own Meta account and Meta's own terms.Meta's data centres; message content in the UAE if you switch on Meta's local storage

Apart from Cloudflare's e-mail forwarding, walpio uses no e-mail sending service today. If one is added — for sign-in or invitation e-mails — it will be listed here before it handles any data. The same list is in section 4 of the Privacy Policy; the date at the top of each page shows when it last changed, and clients are told by e-mail of a change that materially affects how we handle their data.

Reporting a security problem

If you think you have found a security problem in walpio.com, the dashboard or the API, write to [email protected] with “Security” in the subject, and tell us what you found and how to reproduce it. We reply to every report, usually within one business day. Please do not access or change other people's data, do not disrupt the service, and give us time to fix the problem before you tell anyone else. The same contact is published in the standard /.well-known/security.txt file.

Not yet, and coming