RocketReply Web — Privacy Policy

Last updated: 2026-09-03 · Applies to the RocketReply Web browser extension

This policy covers the RocketReply Web browser extension ("the extension"). The short version: we never see or store your messages. The details below explain exactly what data exists, where it lives, and how to delete it.

Overview

RocketReply Web adds privacy and productivity tools to WhatsApp Web, with optional AI draft replies you review and send. Almost everything the extension does happens on your own computer, in storage that belongs to your browser profile. Our servers play one narrow role: verifying your subscription. They never receive message content.

What We Never Collect

Message content — your chats, the text of messages you send or receive — is never sent to, stored on, or processed by our servers. This is an architectural fact, not just a policy commitment: the extension has no code path that transmits message content to any RocketReply-operated server. The one place message data leaves your browser is described under Webhooks below, and it goes only to destinations you chose yourself.

Data Stored Only On Your Device

The extension stores the following in your browser's local extension storage (chrome.storage.local), which lives on your computer and is not synced by us: your message templates and folders; your privacy and panel settings; your smart-reply rules; your scheduled-message queue; your broadcast campaigns; your tasks; your app-lock PIN as a salted SHA-256 hash (never the PIN itself); your deleted-message cache (see below); your OpenRouter API key (if you use AI drafts); your AI profiles and business-context text; and a cached copy of your subscription entitlement so the extension keeps working offline. None of this is uploaded. Uninstalling the extension deletes all of it (see Data Deletion).

What Our Servers Receive

Our licensing endpoint (license.rocketreply.ai) receives exactly two things: the email address associated with your subscription, and an anonymous install id with the extension version for the daily-active count described under Analytics. That is all. The license check returns a signed entitlement — which plan you are on and when it renews. No message content, no contact data, no message metadata is ever transmitted to this endpoint. The extension also fetches a DOM-selector configuration from this endpoint at most once a day — a small map of CSS selectors (which page elements to blur) so WhatsApp interface changes don't break the extension between releases; it contains no data about you, your messages, or your browsing.

AI Draft Replies (Bring Your Own Key)

AI draft replies are powered by OpenRouter, using your own API key, purchased by you, controlled by you. When you request a draft, the recent conversation context is sent directly from your browser to OpenRouter (openrouter.ai) under your key — it does not pass through, get logged by, or get stored on any RocketReply server. We cannot see your messages, your prompts, or your drafts. Your key is stored only in your browser's local extension storage and is never transmitted anywhere except to openrouter.ai. OpenRouter's handling of request data is governed by their privacy policy: https://openrouter.ai/privacy — read it before creating a key.

Webhooks

If you configure webhooks, the extension POSTs a signed JSON event (message_received) when messages arrive, only to the HTTPS URLs you personally typed in and saved — for example a Zapier hook or your own server. You choose which messages fire: all messages, incoming messages only, and whether group chats are included; each URL can be paused at any time. When you add a webhook, Chrome itself asks you for permission to contact that specific origin; nothing is granted until you accept, and removing the last webhook on an origin releases its grant. Each URL uses its own HMAC-SHA256 secret that you set, so the receiving server can verify the payload came from your extension and was not tampered with. Webhooks are off by default, the list ships empty, the extension never adds URLs on its own, and we never see your webhook destinations or their contents. Failed deliveries are retried with backoff and dropped after 24 hours; while a delivery is being retried, it is held — with its payload — in a retry queue in your browser's local extension storage for up to those 24 hours. Nothing queues on our servers at any point.

Deleted-Message Recovery

When the sender deletes a message, the extension can show you the original text in its own Recovered tab (sender, original message, time) inside the extension panel. This cache lives only in your browser's local extension storage — never on our servers — expires automatically after 7 days, can be disabled at any time, and a one-tap Clear in the Recovered tab purges the entire cache immediately.

Payments

Subscriptions are processed by Stripe. We never see or store your card details; Stripe handles all payment data under its own privacy policy. Our servers receive from Stripe only what is needed to verify your plan: your email, plan, status and renewal date.

Analytics

The extension sends exactly one kind of telemetry: an anonymous install/daily-active ping containing the install id and extension version. No message content, no message metadata, no contact data, no keystrokes, no usage tracking of individual features. No third-party analytics SDKs are bundled, with one nuance we disclose for completeness: the bundled WhatsApp integration library (@wppconnect/wa-js) ships a Google Analytics tracker class, which is disabled by configuration before it initializes (verified in the shipped bundle) — no analytics event is ever sent. This is the entire analytics footprint.

Data Retention And Deletion

Because your data lives in your browser's local extension storage, deleting it is one step: uninstall the extension. Chrome removes the extension's local storage with it — templates, settings, tasks, schedules, deleted-message cache, API key and cached entitlement all go. Server-side, we retain your email and subscription status for as long as your subscription is active or needed for billing records, and you may request erasure of licensing records at any time via the contact below. To revoke OpenRouter's access, delete your API key at openrouter.ai/keys — the extension stops being able to request drafts immediately.

Security

The extension communicates only over HTTPS. Your OpenRouter key is held in local extension storage, which is isolated per-extension and per-browser-profile, and is never included in any request except those to openrouter.ai. The extension requests no permissions beyond those disclosed in the Chrome Web Store listing.

Children

The extension is intended for adults managing business conversations and is not directed at children under 13 (or the equivalent minimum age in your jurisdiction).

Changes To This Policy

If this policy changes materially, the updated version will be posted at this URL with a new "Last updated" date, and extension updates will reference it.

Contact

Questions about this policy or data deletion requests: support@rocketreply.ai. Operator: Mahtani Pte Ltd, 60 Paya Lebar Road #06-28, Singapore 409051.