← WhatsApp Chat Grid

WhatsApp Chat Grid Privacy Policy

Last updated: October 2, 2026

Scope

WhatsApp Chat Grid displays two, three or four conversations from one WhatsApp Web account in one browser window. This policy explains how the extension and the Chat Grid API handle data.

Data processed locally

The extension reads the conversations selected by the user so it can render the grid and activate the native WhatsApp composer. Message text, media, contact and group names, phone numbers, chat identifiers and drafts are processed in the browser and are not sent to the Chat Grid API. The extension does not automatically send WhatsApp messages.

Chrome local storage keeps the selected layout, scale settings, language, panel assignments, default chat identifiers, account installation identifier, a separate random analytics identifier, the last analytics-report time, account session, signed entitlement, the next allowed diagnostic-submission time and review-request schedule and choice. A browser-session flag limits the request to once per browser start. The extension cannot read whether a rating or review was submitted. Local data remains in the Chrome profile until it is replaced, cleared or the extension is removed.

Optional Google sign-in

Two-chat mode does not require a Chat Grid account. During early access, the user can voluntarily sign in with Google to unlock the three- and four-chat layouts. The sign-in request is limited to the openid and email scopes.

The API stores the Google account subject identifier, email address, verified-email flag, installation identifier and account, session and entitlement records. It does not receive the user's Google password or Google mail, contacts, files or calendar data.

Technical counters

At most once per 24 hours while it is running, the extension can send a separate random analytics identifier, extension version and locale. The API immediately stores only a SHA-256 hash of that identifier together with first-seen and last-seen timestamps. The analytics identifier is not the account installation identifier and the analytics record has no user ID, email address, Google identifier, chat identity or message content. It is used only for known-installation and active-installation counts and is deleted after 400 days without activity.

The extension can also send an allowlisted technical event name together with its version, locale and selected layout. The API stores these events only as daily aggregate counters without a user ID, installation ID, chat identity or message content. When the user explicitly presses Rate extension, the API counts the Store-link click; it does not confirm a submitted rating or review and cannot identify the user who clicked. Aggregate counters are retained for 400 days.

User-triggered diagnostic reports

A diagnostic report is sent only after the user presses Send report to developer. It contains a bounded set of technical fields: reason, extension and WhatsApp versions, locale, layout, panel positions, capability booleans, bounded timings and safe error codes. It contains no message text, chat or contact names or identifiers, phone numbers, DOM snapshots, cookies, drafts, attachments, OAuth tokens or refresh tokens.

Reports do not store a user ID or installation ID and are deleted after 30 days. One installation can submit one accepted report every 15 minutes. The API also applies limits per source address and a global safety ceiling to prevent abuse. A developer may review a submitted report only to investigate the technical issue for which the user explicitly sent it.

Purpose, sharing and sale

We use data only to provide, secure, maintain and measure the reliability of Chat Grid, comply with law, or respond to security abuse. We do not sell user data or use it for advertising, creditworthiness or unrelated purposes. Google is used only as the optional sign-in provider. Hosting infrastructure processes encrypted traffic and stored data only as necessary to operate the service.

Retention and deletion

OAuth states expire after 10 minutes, login tickets after 60 seconds, access tokens after 15 minutes and refresh sessions after 30 days. Expired session database records are retained until account deletion. Account, installation and entitlement records are retained while the account exists.

A verified deletion request permanently removes the account and related installations, sessions and entitlements from the active database. Daily rotating database backups may retain removed records for no more than seven backup cycles. See the account-deletion instructions.

Security

Network requests use HTTPS. Refresh credentials are stored as hashes, access rights are digitally signed, and the API accepts extension-origin requests only from the allowlisted production extension ID. Sound Box and Chat Grid use separate OAuth clients, token audiences, sessions, signing keys, storage keys and databases.

Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Contact

Questions and deletion requests can be sent to mellowgridlabs@gmail.com.

WhatsApp Chat Grid is independent and is not affiliated with WhatsApp LLC or Meta Platforms, Inc.