Privacy Policy

SWAapp — Automated WhatsApp message scheduler

Last updated: August 4, 2026

SWAapp ("we", "our", "the app") lets you schedule recurring WhatsApp messages. This page explains what data we collect, why, and how it's used.

1. Information We Collect

  • Account information: your name and, if you sign in with Google, your email address. Sign-in is passwordless — we never ask for or store a password. If you sign in with a passkey (Face ID, fingerprint, or your device's screen lock), we store only a WebAuthn public key credential tied to your device, which cannot be used to sign in as you from anywhere else; your name is filled in automatically the first time you connect WhatsApp.
  • WhatsApp connection: your linked WhatsApp phone number and the session needed to send messages on your behalf, via a self-hosted Evolution API instance.
  • Contacts and groups: the names and identifiers of WhatsApp contacts and groups you choose as message recipients, synced from your connected WhatsApp account.
  • Schedules and messages: the message content, recurrence rules, and recipients you configure.
  • Delivery logs: timestamps and status (success/failure) of sent messages, for troubleshooting and history.
  • Google Calendar (optional): if you connect a Google Calendar, we request read-only access to list your calendars and cache event titles/times so you can schedule messages tied to events. This is only enabled if you explicitly connect a calendar.

2. How We Use Your Information

We use the data above solely to operate the app: authenticating you, sending your scheduled WhatsApp messages, showing your contacts/groups and calendar events for scheduling, and displaying delivery history. We do not sell your data or share it with advertisers.

3. Where Data Is Stored

Account, schedule, and log data is stored in AWS DynamoDB. WhatsApp session data is held by a self-hosted Evolution API instance we operate. Google Calendar access uses OAuth tokens stored securely and used only to fetch calendar/event data on your behalf.

4. How We Protect Your Data

  • Encryption in transit: all traffic between your device and our servers, and between our servers and the WhatsApp integration we operate, is encrypted with TLS (HTTPS) — nothing is ever sent in plaintext.
  • Encryption at rest: account, schedule, contact, log, and calendar data — including your cached calendar list, cached event details, and your Google Calendar access/refresh tokens — is stored in AWS DynamoDB with encryption at rest enabled. Separately, the application-level credentials we use to talk to Google's APIs (not your personal tokens) are stored in AWS Systems Manager Parameter Store, also encrypted, never in application code.
  • No passwords to leak: sign-in is passwordless by design — either Google OAuth or a WebAuthn passkey bound to your device — so there is no password database that could be exposed.
  • Access controls: every API request is authenticated with a signed token scoped to your account. Administrative features (aggregate usage analytics) are restricted to a single designated admin account and are rejected by the server for anyone else, regardless of what the client displays.
  • Backups: point-in-time recovery is enabled on our data stores, with the same encryption-at-rest protections applied to backups.

5. Third-Party Services

We integrate with WhatsApp (via Evolution API) and, optionally, Google for sign-in and calendar access. Each provider's own privacy policy governs the data they process on their side.

SWAapp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data obtained via the read-only Google Calendar scope is used solely to display your events and let you schedule messages tied to them — it is never used for advertising, never sold, and never shared with third parties, and no human at SWAapp reads it except as needed to provide support you request or to comply with the law.

6. Data Retention & Deletion

We retain your data for as long as your account is active. You can disconnect your WhatsApp or Google Calendar connection individually at any time from the app without deleting anything else.

You can also permanently delete your entire account and all associated data yourself, at any time, with no need to contact us — open Profile from the sidebar (click your name above "Sign Out") and choose Delete Account. This immediately and permanently deletes your account record, disconnects and removes your WhatsApp session, cancels and deletes all your schedules, deletes your saved audiences, and removes any Google Calendar connection. This action cannot be undone.

If you sign up fresh and then connect a WhatsApp number that's already linked to an existing SWAapp account of yours, we automatically merge the new, still-empty account into that existing one rather than keeping two separate accounts around — no data is lost in this process.

If you create an account but never connect a WhatsApp number to it, that account is automatically deleted after 24 hours — there's nothing to lose, since an account that has never connected WhatsApp can't yet hold any schedules, messages, or other data. This never applies to an account that has connected WhatsApp at any point, even if it's since disconnected.

7. Contact

Questions about this policy or your data? Contact ehab.abdelmalak@gmail.com.

← Back to SWAapp