This website
Public pages are hosted through Sites infrastructure. Hosting receives ordinary request information such as IP address and request time. Your cookie preference is stored locally. Optional Google analytics is disabled unless you consent and a valid property is configured. Contact buttons open WhatsApp or your email application; this website does not submit a lead form or process a card payment. Private report pages do not run analytics.
Privacy policy
Effective 7 October 2026. MessageFlow Pro is operated by Yehia Ahmed to provide a productivity and sales communication workspace for WhatsApp Web. Privacy and deletion requests: WhatsApp support.
Account and licensing
Account registration and sign-in are handled by Supabase Auth. Email, account and license records are stored on the developer’s backend. Session tokens are stored locally in the browser. License checks use an installation identifier, coarse device/platform information and extension version. Stored installation identifiers are hashed but remain linked to accounts. Registration and license notifications may use Resend when configured. We do not request your WhatsApp password.
Messages, contacts and local records
Enabled features read relevant WhatsApp contact, chat and group identifiers, names, selected member details, message content and observable send/delivery/read status. Recipient lists, templates, drafts, campaign reports, leads, conversation context and local organization are stored in browser storage or memory. Exported reports are files on your device. Customer preferences and budgets may be processed when supplied in conversations. There is no general browsing-history, GPS or dedicated health-record collection feature.
AI processing and automatic replies
When you use AI, relevant message text, bounded conversation context, business instructions, lead preferences, language and project context are sent over HTTPS through authenticated Supabase services to Google Gemini. If you explicitly configure Advanced BYOK, the selected Google, OpenAI or Anthropic provider processes the applicable prompt instead. Managed credentials stay on the server. Marketing AI generates the selected number of drafts for your review; campaign media is not sent to Gemini by this marketing workflow. Optional web research sends relevant search queries to Gemini’s search service. Provider terms govern their processing and retention; we do not promise zero provider retention or training. AI providers and infrastructure may process information internationally. Draft Only prepares suggested replies for your review and manual send. When you enable Auto Reply, eligible replies are sent automatically within the selected personal-chat, campaign or group scope. One Reply Only and Continuous Conversation determine how often it responds. Review the scope and instructions before enabling automatic replies. Stop and human handoff controls remain available.
API credentials
Optional BYOK keys are transmitted to the authenticated backend and stored in Supabase Vault. Provider configuration shows metadata such as a masked key suffix, not the full stored key. Deleting a provider configuration removes its application configuration and Vault secret; it does not delete your account or copies retained by providers.
Attachments and Market Intelligence
Selected campaign files are processed locally and sent through WhatsApp to the recipients you choose, under WhatsApp/Meta’s policies. Local OCR, PDF and spreadsheet readers process supported Market Intelligence sources on your device. These files are not automatically uploaded to the developer’s AI service by the attachment or local extraction workflow.
Project images, news and network information
The project library fetches only the current page of records. Lazy project covers are loaded from their existing external HTTPS image hosts, which receive ordinary network information such as IP address and browser headers; image requests suppress the page referrer and do not include customer messages or API keys. Property news uses public headlines and a temporary server cache rather than a permanent browser news archive. Opening a headline visits its publisher. Backend, image hosts and providers can receive ordinary network metadata such as IP address and request time.
Operational analytics
The extension reports daily totals for active, focused panel time and successful Sender campaign recipients to authenticated Supabase services. Background or idle WhatsApp time is not counted as panel activity. AI services record successful reply and marketing generations and failed generation attempts; a generation is not proof that a reply was sent. These totals are linked to your account and hashed installation identifier. The publisher can view daily totals and user rankings for service administration. Analytics payloads exclude recipient numbers, message text and file names. Daily counters and deduplication receipts are pruned after 90 days; pending local counters cover up to 31 days. Hosted infrastructure may retain request and operational error logs under its own policies.
Payment and support
The developer sells the 500 EGP monthly subscription directly. Google and the Chrome Web Store do not process the payment. Activation uses a payment confirmation sent by you through WhatsApp. Send only the transaction information needed to verify payment and redact unrelated balances and account information. Never send bank passwords, PINs, OTPs or card security codes. The developer and WhatsApp/Meta receive the support and payment messages you choose to send.
Retention and deletion
Local records remain until applicable feature clearing, browser-data deletion or uninstall. Logout and Stop do not erase every local record. AI Reset can preserve a local restore backup. You manage exported files separately. Account, licensing and device records are retained for operating and securing the service; there is currently no application-wide scheduled expiry job for these records. Contact support to request access, correction or deletion of your account/service records. Requests are handled by the developer, subject to verification and any lawful retention requirement. Infrastructure/provider logs and backups follow the relevant services’ retention practices and may not disappear immediately after application deletion. Payment confirmations are used for activation, support and transaction reconciliation. No fixed deletion deadline or universal retention period is promised.
Security and limited use
Transfers use HTTPS; server features authenticate access and provider credentials use Vault. Local browser storage has no additional application encryption layer. No service can guarantee absolute security. MessageFlow Pro’s use and transfer of user data adheres to the Chrome Web Store User Data Policy, including Limited Use requirements. We do not sell user data, use it for personalized advertising or use it to determine creditworthiness or for lending. Data use and transfers are limited to disclosed features and permitted operational, security and legal purposes. Human access is limited to consented support/payment handling and permitted security/legal needs.
Policy updates
Material changes to these practices will be reflected on this page with an updated effective date. MessageFlow Pro is an independent product and is not affiliated with, endorsed by or sponsored by WhatsApp or Meta.
Optional online report summaries
If you sign in and choose to save a summary, the existing Supabase service stores your account identifier, campaign date, aggregate counts and duration. No customer names, recipient numbers, conversations or report HTML are accepted. Up to 100 reports are retained per account until you delete them or request account data deletion. Share links show aggregate counts to anyone holding the link; links created here expire after 24 hours and can be revoked sooner. Deleting a report removes its share links. Provider backups may follow separate retention. Sign-in tokens stay in page memory; reloading ends this page session.