Legal
The terms you agree to when you use PulseApi, how we handle data, and what we ask of you in return.
Last updated 7 October 2026 · Operated by Mass & Void, Kolkata, West Bengal, India
These documents are a starting template, not legal advice. They were prepared to cover the obvious ground honestly. Before relying on them commercially, have a lawyer qualified in your jurisdiction review them — particularly the liability, indemnity and data-protection sections.
Terms of Service
1. What the service is
PulseApi connects a WhatsApp number you already control to an HTTP API, in the same way the official WhatsApp Web client does, so your own software can send and receive messages through that number. We provide the software, the servers it runs on, and support.
2. This is an unofficial integration — please read this part
PulseApi is not affiliated with, endorsed by, or sponsored by WhatsApp LLC or Meta Platforms, Inc. We are not a WhatsApp Business Solution Provider and this is not the official WhatsApp Business API.
Using an unofficial client is not something WhatsApp formally permits. WhatsApp may restrict, suspend or permanently ban any number that it judges to be behaving abnormally. That risk applies to any product in this category, including ours. The WhatsApp number you connect is yours, and the consequences of it being restricted are yours. We build in protections — a warm-up schedule, human-like pacing, daily caps, quiet hours and per-number proxies — and they materially reduce the risk, but no provider can eliminate it or offer a guarantee against it.
By connecting a number you confirm that you understand this, that you have the right to use that number for the messages you send, and that you accept the risk of restriction or loss of the number. If you need a guaranteed, sanctioned channel, use the official WhatsApp Business API through a Meta-approved provider instead.
3. Your account
- You must give accurate details and keep your login and API keys secret. Anything done with your credentials is treated as done by you.
- New accounts get a free trial of 3 days with every feature. After the trial, access to sending stops until a plan is purchased. There is no permanently free tier.
- Plans renew every 30 days until cancelled. Prices are shown before payment and may change with notice; a change never applies to a period you have already paid for.
- You may cancel at any time. Access continues to the end of the paid period. Because the service is delivered continuously, part-period refunds are not usually given — if something has genuinely gone wrong, contact us and we will deal with it fairly.
- You are responsible for any taxes on your side of the transaction.
4. Acceptable use
Your use must comply with the Acceptable Use Policy below, with WhatsApp's own terms, and with applicable law. We may suspend an account that breaches it, with or without notice depending on severity.
5. Availability
We aim for continuous availability and we monitor the platform, but we do not offer a contractual uptime guarantee on standard plans. Maintenance, upstream failures at WhatsApp, and changes WhatsApp makes to its protocol can all interrupt service. Queued messages are held and delivered when a number reconnects, for up to 12 hours.
6. Liability
To the extent permitted by law, our total liability to you for any claim relating to the service is limited to the fees you paid us in the three months before the claim arose. We are not liable for indirect or consequential loss, for lost profits or business, or for the restriction, suspension or loss of a WhatsApp number.
7. Suspension and termination
We may suspend or close an account for non-payment, for breach of the Acceptable Use Policy, or where continuing would expose us or other customers to legal or platform risk. You may close your account at any time from Settings, which deletes your data as described under Retention.
8. Changes and governing law
We may update these terms; material changes will be notified by email to the address on the account at least 14 days before they take effect. These terms are governed by the laws of Kolkata, West Bengal, India, and the courts of Kolkata, West Bengal, India have exclusive jurisdiction.
Privacy Policy
Our two roles
This distinction matters, because different obligations follow from it:
| Data | Our role | What that means |
|---|---|---|
| Your account details — name, email, phone, billing records, support tickets | Data Fiduciary (controller) | We decide how this is used, and we answer to you directly for it. |
| The messages you send and receive, and the phone numbers you send them to | Data Processor | We process this only on your instructions, to deliver the service. You are the Data Fiduciary for the people you message, and it is your responsibility to have a lawful basis for contacting them. |
What we collect
- Account information: name, email address, and the account and billing records created when you sign up and pay.
- WhatsApp session data: the credentials created when you link a number. These are encrypted at rest and are used solely to maintain your connection.
- Message data: the content, recipient number, timestamps and delivery status of messages sent or received through your numbers, plus any media you upload or receive.
- Contacts: only if you import a CSV or connect Google Contacts. Google contact access is read-only and nothing is ever written back.
- Technical data: IP address, browser and request logs, kept for security and debugging. Message content is not written to our application logs.
- Payments: handled by Razorpay. We receive a payment reference and status; we never see or store your card or UPI credentials.
What we do with it
We use it to run the service you asked for: delivering messages, showing you logs and statistics, protecting your numbers from restriction, taking payment, sending service and billing email, and providing support. We use aggregate, non-identifying totals (such as messages delivered platform-wide) on our public website. We do not sell personal data, and we do not use your message content to build profiles or train models.
Who else is involved
| Sub-processor | Purpose |
|---|---|
| Hostinger (VPS, India region) | Servers and storage |
| Razorpay | Payment processing |
| Brevo (Sendinblue) | Transactional email |
| Google (optional) | Contacts sync, only if you connect it |
We may also disclose data where the law requires it, or to establish or defend legal claims.
Retention and deletion
- Messages and media: retained while your account is active so you can search your own history. You can delete individual records at any time from the dashboard.
- Session credentials: deleted immediately when you remove a number or log it out.
- Account closure: deleting your account from Settings removes your numbers, messages, media, contacts, API keys, webhooks and support tickets from the live database immediately.
- Backups: encrypted backups are retained for 14 days, after which deleted data is gone from those too.
- Billing records: retained for as long as tax and accounting law requires, separately from the rest.
Security
Traffic is encrypted in transit with TLS. WhatsApp session credentials and API keys are encrypted at rest. Data is separated per account and every request is scoped to the account that made it. Access to production systems is restricted, and outbound requests to customer-supplied URLs are validated to prevent them reaching internal systems. No system is perfectly secure; if a breach affects your personal data we will notify you and the Data Protection Board of India as the Digital Personal Data Protection Act, 2023 requires.
Your rights
Under the DPDP Act you may ask us to give you a copy of your personal data, correct or complete it, erase it, or nominate someone to exercise these rights on your behalf. Most of this is available immediately in the dashboard; for anything else, write to our Grievance Officer below and we will respond within 30 days.
Grievance Officer
Questions, requests or complaints about personal data should go to:
Sourav Debnath, Mass & Void
Email: dme@massandvoid.in<br>Kolkata, West Bengal, India
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Children
The service is for businesses and is not directed at anyone under 18. We do not knowingly create accounts for children.
Acceptable Use Policy
This policy exists for a practical reason as much as an ethical one: accounts that send unwanted messages get their numbers banned by WhatsApp, and that harms you, us and the people receiving them.
Message people who expect to hear from you
- Send to your own customers, staff, students, patients or members — people with an existing relationship with you who would not be surprised to receive the message.
- Honour opt-outs promptly and permanently.
- Identify yourself clearly. Do not pretend to be another business or person.
Do not
- Send unsolicited bulk or promotional messages, or message purchased, scraped or rented contact lists.
- Send anything fraudulent, deceptive, or designed to obtain money or credentials under false pretences — including phishing, fake offers, investment or lottery scams.
- Send malware, or links to it.
- Send content that is illegal, harassing, threatening, defamatory, or that sexualises or endangers children.
- Impersonate a bank, government body, courier, or any organisation you are not.
- Attempt to bypass the sending limits, warm-up schedule or other protections built into the platform.
- Resell or sublicense the service without a written agreement with us.
- Probe, scan or attempt to breach the platform, or use it to reach systems you are not authorised to access.
What happens if you do
Depending on severity we may warn you, throttle or suspend sending, or close the account without refund. Serious cases — fraud, child safety, or anything unlawful — are actioned immediately and may be reported to the authorities.
Security and responsible disclosure
If you believe you have found a security vulnerability in PulseApi, please tell us before telling anyone else. Write to dme@massandvoid.in with enough detail to reproduce the issue.
- We will acknowledge your report within 3 working days and keep you updated on the fix.
- We will not pursue legal action against researchers who report in good faith, act in proportion, avoid accessing or altering other people's data, and give us reasonable time to fix the issue before publishing.
- Please do not run automated scans that degrade the service, or test using other customers' accounts.
- We do not currently run a paid bug bounty, but we will credit you if you would like us to.
Machine-readable contact details are published at /.well-known/security.txt.