Privacy Policy#
Last updated: 5 October 2026
kenari.dev ("kenari", "we") is an API for the WhatsApp Business Platform. Developers connect their WhatsApp Business numbers to kenari and send and receive messages through our API. This policy explains what we collect, why, how long we keep it, and who we share it with.
It covers the kenari.dev website, the dashboard at app.kenari.dev and the API at api.kenari.dev.
Who is responsible for what#
- Your account data. For data about you as a kenari customer, such as your login, team and billing records, we decide how it is used. In this policy, "you" means the customer.
- Your WhatsApp data. Messages and phone numbers of the people you message pass through kenari on your behalf. For that data you are responsible, and we act as your service provider (data processor). We only process it to run the service you asked for: delivering your messages to Meta, and delivering Meta's events to your webhooks.
If you are someone who messaged a business that uses kenari, contact that business first. They control how your messages are used. We will help them answer your request.
What we collect#
Account data#
- Your login. Your name, your email address and your sign-in method (email and password, or Google). Passwords are held by Firebase Authentication. We never see or store them.
- Your account. Account name, team members and their roles, your plan, trial and subscription status, and your retention setting.
- Billing records. Your plan's invoices and the payment provider's notices about them, once paid plans are live.
- Audit log. Who on your team changed what, for example created an API key or connected a number.
WhatsApp Business data#
- Meta identifiers. Your WhatsApp Business account id, business id, phone number ids, and the Meta user id that connected them.
- Your WhatsApp numbers. The display phone number, its verified name, quality rating, messaging tier and coexistence state.
- Credentials. Your Meta access token, and, if you bring your own Meta app, its app secret. Also your two-step verification PINs and your webhook signing secrets. All of these are encrypted at rest with AES-256-GCM, each bound to its own database row.
- API keys. We store only a keyed hash (HMAC-SHA256) of each API key, plus its prefix and last four characters so you can tell your keys apart. We cannot show you a key again after you create it.
- Templates. The names, languages, categories, review status and quality of your message templates. We do not store template bodies.
Message data#
- Messages you send. The message body goes straight to Meta and is not stored.
- Media you upload or download. It streams to and from Meta and is not stored.
- Events Meta sends to us. Examples are incoming messages, delivery statuses and template updates. These can contain message text, media ids, and the phone numbers and profile names of the people you message.
- We store each event so we can deliver it to your webhook endpoints and retry if they fail.
- We store the copy we deliver to you, and up to 1 KB of your endpoint's response.
- How long we keep them is set out under How long we keep it.
- Coexistence history sync. When you connect a number that is also used in the WhatsApp Business app, WhatsApp shares its contacts and recent chat history once. We pass it to your webhook. We clear our copy as soon as delivery finishes.
Request logs#
For every API call we log the time, the API key used, the method and route, the target id, the HTTP status, timings, the size of the request and response, and any error code. We do not log request or response bodies.
Cookies and local storage#
- The website (kenari.dev). It sets no cookies and uses no analytics.
- The dashboard. It sets one cookie,
kn_session, which keeps you signed in. It is HttpOnly and lasts up to 30 days. - Your browser's local storage. The dashboard stores your theme choice there. Firebase Authentication also keeps your sign-in state there.
- No tracking. We use no advertising or tracking cookies.
How we use it#
We use this data to:
- run the service: authenticate your requests, send them to Meta, deliver webhooks, and enforce rate limits and plan quotas;
- secure the service: detect abuse, investigate incidents and keep an audit trail;
- support you and tell you about your account, for example trial and billing notices;
- bill you for your plan.
We do not sell your data. We do not use message data for advertising, profiling, or training models.
Who we share it with#
- Meta. Messages, templates and the other Cloud API requests you send through kenari go to Meta, which runs WhatsApp. Meta's own terms and privacy policy apply to how Meta processes them.
- Google (Firebase Authentication). Your sign-in details, and the sign-in emails it sends (address confirmation and password reset).
- Hosting. Our servers and databases run on infrastructure we operate ourselves. DNS goes through Cloudflare, which does not proxy our traffic.
- Your webhook endpoints. We deliver events to the URLs you configure.
We disclose data to authorities only when the law requires it.
How long we keep it#
| Data | How long |
|---|---|
| Webhook deliveries (event bodies, including message content) | Your account's retention setting: 24 hours or 7 days (the default). |
| Meta events we could not deliver to any endpoint | 7 days. |
| Event bodies kept for delivery | Until delivery to every endpoint has finished, then cleared. Coexistence history bodies are cleared as soon as delivery finishes. |
| Request logs | Your account's retention setting: 24 hours or 7 days. |
| Unencrypted Meta tokens | Never stored. The decrypted token stays in memory for at most 5 minutes. |
| Account, credentials, numbers, keys, audit log | While your account exists. Removed 30 days after you delete the account. Credentials are wiped at once (see Your choices). |
| Billing records | Kept after account deletion as long as tax and accounting law requires. |
| Data deletion receipts | Kept so the status link Meta gives you keeps working. |
Your choices#
- Delete your account. Go to Settings → Danger zone in the dashboard.
- We disconnect your numbers, revoke your API keys, disable your webhooks, and wipe your Meta tokens and secrets at once.
- The account and its remaining data are permanently deleted 30 days later.
- Remove kenari from Facebook. In your Facebook settings, under Business Integrations, you can remove kenari's access, or ask for your data to be deleted.
- See Data deletion for what that does.
- Access, correction and export. Most of your data is visible and editable in the dashboard. For anything else, email support@kenari.dev.
Security#
- Encryption. Credentials are encrypted at rest, and API keys are stored only as keyed hashes.
- Access. Access to production systems is limited to the people who run the service.
- Breaches. If a breach affects your data, we will tell you without undue delay.
Children#
kenari is a business service for developers. It is not meant for anyone under 18.
Changes#
We will post changes to this policy on this page and update the date at the top. For material changes, we will also tell account owners by email.
Contact#
Questions about this policy or your data: support@kenari.dev.