Privacy Policy

Effective date: 27 June 2026 · Last updated: 17 September 2026

Mastros ("we", "us", or "our") operates the mastros.online website and provides browser-based tools, including the WhatsApp Data Scraper Chrome extension, that allow users to export and organize data from WhatsApp conversations they already have access to.

This Privacy Policy explains how information is collected, used, and disclosed when you use the Mastros website, Chrome extension, and related services (collectively, the "Service").

Contact: admin@mastros.online

1. Information We Collect

1.1 WhatsApp Data Processed by the Extension

When you use the Mastros Chrome extension, the extension may process data visible to you within WhatsApp Web, including:

  • contact names and phone numbers
  • profile information (about and profile photo)
  • group membership, participant lists and participant roles
  • message content and timestamps
  • message previews shown in your chat list
  • media files (photos, videos, voice notes, documents and stickers)

This data is processed locally within your browser and exported directly to your device as CSV, JSON or JSONL files, or as a ZIP archive for media exports. It is never transmitted to Mastros servers or to any third party. For media exports the extension may request files from WhatsApp's own media servers, as described in section 2. No information about you is sent to those servers beyond what WhatsApp Web itself would send when displaying the same file. You can only export data from conversations you already have access to within WhatsApp.

The extension does not collect, request or store any WhatsApp credentials. It does not ask for your phone number, a login code or a device pairing, and it never sends messages, adds participants to groups, or performs any other write action in WhatsApp. It works read-only through the WhatsApp Web session you are already signed into.

1.2 Account and Billing Information

The extension has no login of its own and does not collect passwords or credentials.

The extension reads the email address of the Chrome profile you are signed into, using Chrome's identity.email permission. No other profile information is read, and no separate sign-in takes place. That address is sent to our backend service and used only to identify your own account: it is the key your plan and remaining monthly export allowance are attached to, so that a reinstall or a second computer does not cost you a subscription you have already paid for, and it gives us a way to reach you if an export fails. It is never used for marketing, never sold, never shared for advertising, never attached to analytics events, and never used to contact anyone on WhatsApp. If no address is available (for example in a Chrome profile that is not signed in), the extension runs in guest mode until a purchase links it to a billing record.

We hold an email address in two further cases, both of which you initiate:

  • you complete a paid subscription, in which case Stripe collects your email address on its own hosted checkout page and provides it to us so we can identify your subscription; or
  • you enter an email address yourself in order to restore a previous purchase, in which case it is sent to our backend service to locate that subscription.

An email address held for any of these reasons is used only for billing and subscription support. It is never used for marketing, never shared with third parties, and never attached to analytics events.

Payments are processed by Stripe, Inc. Mastros does not store credit card numbers or any other payment details. Stripe may process personal information in accordance with its own privacy policy.

1.3 Website Analytics

The Mastros website uses Cloudflare Web Analytics to understand how visitors interact with the site. This may include page views, browser type, approximate geographic region, device type, and referral source. Cloudflare Web Analytics is designed to be privacy-friendly and does not use client-side cookies for tracking.

1.4 Extension Diagnostic and Usage Data

When the Chrome extension is used, we collect limited product-analytics and diagnostic information through PostHog (EU region, eu.i.posthog.com), including:

  • extension version and interface language
  • feature usage events (for example: the sidebar was opened; an extraction was started or completed; an export was downloaded and in which format; a plan quota was reached; an upgrade was clicked)
  • export counts
  • diagnostic error reports, including cases where the extension failed to locate an element on the page
  • your plan tier

These events never contain WhatsApp content. No message text, contact names, phone numbers, group names or exported rows are included in any analytics event, and no email address is attached to them.

The extension also generates and stores three identifiers:

  • a random device identifier, generated on first use and stored in your browser, used as the anonymous key for analytics events;
  • a random install identifier, stored in Chrome's synchronised extension storage so that a paid plan can be restored if you reinstall the extension or set up a new device;
  • a browser fingerprint hash: a short one-way hash derived from four non-identifying browser characteristics (screen dimensions, language, time zone and platform). Only the hash leaves your device; the underlying values cannot be recovered from it. It is used solely to keep plan entitlements attached to the correct installation and to detect abuse of the free tier.

None of these identifiers is derived from your name, phone number, email address or WhatsApp account.

1.5 Uninstall Feedback

If you uninstall the extension, Chrome opens a feedback page on our website. The address of that page includes your plan tier, the number of days the extension was installed, the total number of rows you exported, your interface language and the extension version. It contains no email address, no identifier and no WhatsApp data. Completing the feedback form is entirely optional.

1.6 Contact and Support Information

If you contact us via email or the website contact form, we may collect your name, email address, and message content in order to respond to your inquiry. Contact form submissions are processed through SplitForms, a third-party form service.

2. Browser Extension Data Practices

Permissions. The extension requests three host permissions. https://web.whatsapp.com/* allows it to read the page content of WhatsApp Web in order to provide its export functionality. https://mmg.whatsapp.net/* and https://*.cdn.whatsapp.net/* are WhatsApp's own media servers: WhatsApp Web keeps only the metadata for some photos in a multi-photo album until one is displayed, so without these the corresponding files cannot be included in a media export. The extension requests those files from WhatsApp exactly as WhatsApp Web would, using the path and key already present in your local WhatsApp data, and decrypts them on your device; no cookies are sent and nothing is uploaded. It requests no access to any other website and cannot read any other site you visit. It also uses Chrome's storage permission (settings, quota counters, identifiers and the local data described below) and the identity and identity.email permissions (the billing account address described in section 1.2).

Local processing. Exported WhatsApp data (group members, messages, recent chats and media) is processed locally in your browser and downloaded directly to your device as CSV, JSON or JSONL files, or as a ZIP archive for media exports. This data is not transmitted to Mastros servers.

Local storage of extracted data. Some extracted data is stored on your own device, in your browser's extension storage, and never leaves it. This covers: a history of your past export sessions, including the rows they produced, so an export can be reviewed or saved again without re-running it; phone numbers matched to contact names, remembered so that a later export of the same people does not have to look them up again; and the names of the chats you selected for a multi-chat export, so the selection survives a browser restart. None of this is transmitted to Mastros or to anyone else. All of it is removed when you clear your browser data or uninstall the extension.

Backend services. Account management, billing, plan and quota validation, and product analytics involve communication with our backend service, hosted on Cloudflare Workers. The information sent is limited to the identifiers and billing email described in sections 1.2 and 1.4.

Limited use. Data obtained through the extension is used only to provide or improve user-facing functionality, security, support, billing, and abuse prevention. We do not sell data obtained through the extension to data brokers. We do not use data obtained through the extension for advertising purposes, and we do not transfer it to third parties except the service providers listed in section 4.

3. How We Use Information

We use collected information to:

  • provide and maintain the Service
  • process payments and manage subscriptions
  • enforce plan limits and prevent abuse of the free tier
  • respond to support inquiries
  • improve the product and website experience
  • detect and prevent abuse or misuse
  • comply with legal obligations

4. Data Sharing

We do not sell or rent personal data.

We may share information with service providers necessary to operate the Service, including:

  • payment processing: Stripe, Inc.
  • extension product analytics: PostHog (EU region)
  • website analytics: Cloudflare
  • form processing: SplitForms
  • infrastructure and hosting: Cloudflare

These providers receive only the information required to perform their services. No provider receives WhatsApp conversation data, because that data never leaves your device. We may also disclose information if required by law, legal process, or to protect the rights and safety of Mastros or others.

5. Data Storage and Retention

The extension stores configuration settings, export preferences, session state, usage counters and the identifiers described in section 1.4 locally in your browser using the browser storage APIs. It also stores the past-session history, remembered numbers and chat selection described in section 2, all locally. All of this is under your control and is removed when you clear your browser data or uninstall the extension.

Exported files are stored on your device unless you choose to store them elsewhere. Mastros does not retain WhatsApp conversation data on its servers.

Account, billing, analytics, and diagnostic data may be retained for as long as reasonably necessary for operational and legal purposes. We periodically review retention and delete data that is no longer needed.

6. International Transfers

Information collected through the Service may be processed in countries other than your own. Extension analytics are processed in the European Union. Payment processing (Stripe) and infrastructure (Cloudflare) may involve processing in the United States and other jurisdictions. By using the Service, you acknowledge that your information may be transferred to and processed in jurisdictions that may have different data protection laws than your jurisdiction. We take reasonable steps to ensure that information is treated securely.

7. User Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information, such as the right to access, correct, delete, or restrict processing of your data. To exercise these rights, please contact us at admin@mastros.online. We will respond to requests within a reasonable timeframe.

Because analytics records are keyed to random identifiers rather than to your name, please include the email address linked to your billing account, or contact us from that address, so we can locate your records.

8. User Responsibility

Users are responsible for ensuring they comply with:

  • WhatsApp's Terms of Service
  • applicable privacy and data protection laws
  • any other applicable regulations in their jurisdiction

Users must only export data they have legitimate access to and are solely responsible for the downstream use of exported data.

9. Security

We implement reasonable technical and organizational measures designed to protect the integrity and security of the Service. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Children

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us so we can take appropriate action.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

12. Contact

For privacy or support inquiries: admin@mastros.online