Last updated: 2026-09-07 · Effective as of 2026-09-07
Pragmaz ("we", "us", or "our") developed the Pragmaz browser extension (the "Extension") as a productivity tool for professionals who use WhatsApp Web. This Privacy Policy describes how the Extension collects, uses, stores, shares, and protects user data, in compliance with the Chrome Web Store User Data Policy, the LGPD (Brazil), GDPR (EU), and CCPA (California).
For information about data collected by the Pragmaz website and dashboard (pragmaz.ai), please refer to our website Privacy Policy.
The Pragmaz Extension has a single, narrowly-scoped purpose: to provide professional productivity features (CRM Kanban, message templates, scheduled messaging, transcription, AI assistant, chatbot flow, broadcast lists) inside the WhatsApp Web interface (web.whatsapp.com) for business users with an active Pragmaz subscription.
The Extension's content scripts run on one website only: web.whatsapp.com. It does not inject code into, read, or collect data from any other website you visit. Its remaining host access is limited to WhatsApp's own media domain (*.whatsapp.net) and to our own API (pragmaz.ai) — both explained in Section 3.
The Extension may collect the following categories of user data, only when necessary to deliver its features:
| Category (Chrome Web Store) | What we collect | Purpose |
|---|---|---|
| Personally identifiable information | Email address and name, provided by you when you subscribe on the Pragmaz website | Account identification, license validation, support communication |
| Authentication information | License/activation code (unique key) and session token, stored locally and sent to our API to verify your subscription | Validate active subscription; gate features behind the paywall |
| Financial and payment information | Limited billing metadata (subscription status, plan). Card data is collected on the Pragmaz website by Stripe — never by the Extension, and it never touches Pragmaz servers | Subscription billing |
| Personal communications | WhatsApp messages, contact names, group metadata, media files (audio, image, video, document), labels, message status, timestamps. Processed locally in your browser by default. Specific items are sent to Pragmaz servers ONLY when explicitly required by a feature you trigger (see Sections 4 and 8) | To render Kanban CRM cards, allow scheduling, send template broadcasts, automate replies (chatbot), transcribe audios, and analyze content with AI — strictly for the features you enable |
| Website content | WhatsApp Web page state needed to inject the Pragmaz interface (chat list, open conversation, toolbar). Read from web.whatsapp.com only |
Render Pragmaz features inside the WhatsApp Web page |
| User activity | Aggregated, anonymous feature-usage events (which feature was opened, error reports). No keystrokes, no message content | Diagnose bugs, prioritize roadmap. Never used for advertising |
The Extension does NOT collect: browsing history, browsing activity on any site other than web.whatsapp.com, passwords, payment card numbers, biometric data, health data, or geolocation.
The list below is the complete and exact set of permissions declared in the Extension's manifest.json. Each one is justified by a corresponding feature, and each is limited to the narrowest scope the feature allows.
| Permission | Why we need it | Scope limit |
|---|---|---|
storage |
Save your preferences, Kanban board layout, message templates, scheduled-message queue and offline cache locally inside the browser (chrome.storage.local). |
Local to your browser. Not transmitted. |
unlimitedStorage |
Lift the default storage quota so large local data (media cache, long conversation history used by the Kanban and the exporter) fits without being evicted. | Local to your browser. Not transmitted. |
contextMenus |
Add "share to WhatsApp" entries to the browser right-click menu, so you can send a selected image, link or text to a conversation. | Menu entries only. Reads the item you explicitly right-click. |
browsingData |
Provide the "clear WhatsApp Web cache / reset session" repair tool, which fixes the frequent case of WhatsApp Web getting stuck on a stale service worker or corrupted local database. | Hard-limited in code to origins: ["https://web.whatsapp.com"]. The Extension cannot and does not clear data for any other site, and never touches your browsing history, downloads or saved passwords. Runs only when you click the tool. |
declarativeNetRequest |
Apply a fixed set of 18 static rules that adjust response headers on WhatsApp Web (COOP, COEP, Content-Security-Policy, Permissions-Policy) so the Pragmaz interface can be injected into the page, plus 4 rules that block known-broken requests. | Declared statically in rules.json, all matching *://*.whatsapp.com/* only. Rules are declarative: the Extension does not read, log or transmit the content of any request. |
| Host | Why |
|---|---|
*://*.whatsapp.com/* | Run the Extension's content scripts inside WhatsApp Web and apply the header rules above. This is the only site the Extension injects code into. |
*://*.whatsapp.net/* | WhatsApp's own media and CDN domain. Needed to load the media of a message you open inside a Pragmaz feature (e.g. transcribing an audio, exporting a conversation). |
*://pragmaz.ai/* | Our own API: license validation, and the cloud features you explicitly trigger (transcription, AI assistant, chatbot, scheduling). |
proxy, webRequest, webRequestAuthProvider, tabs, cookies, history, bookmarks, downloads, management, debugger, nativeMessaging, or <all_urls> host access. It therefore cannot route, intercept, redirect or inspect your network traffic, cannot supply credentials to websites, cannot read your open tabs or cookies, and cannot see your activity outside WhatsApp Web.
We use the data we collect solely to provide and improve the Extension's features:
We do not use your data for advertising, ad targeting, profiling, or any purpose unrelated to delivering the features you subscribed to.
Local storage (in your browser, never transmitted): Kanban configuration, message templates you authored, scheduled messages queue, user-interface preferences. Stored in chrome.storage.local and standard browser caches. Wiped automatically when you uninstall the Extension.
Cloud storage (Pragmaz servers, hosted on Google Cloud Platform — regions in Brazil and the United States):
All data in transit is encrypted with TLS 1.3. All data at rest is encrypted with AES-256.
We share user data with the following named third-party service providers, exclusively to operate the Extension. Each is bound by a Data Processing Agreement and is contractually prohibited from using the data for any other purpose. This list is complete — no other third party receives user data.
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe, Inc. (USA) | Payment processing, billing | Email, name, billing address, card data (handled directly by Stripe — never touches Pragmaz servers) |
| Google LLC (Google Cloud Platform, USA + Brazil) | Backend hosting (virtual machines, managed databases) | All cloud-stored Extension data (encrypted at rest) |
| Amazon Web Services, Inc. (AWS, USA) | Transactional email (SES), backup storage | Email, name, transactional message bodies (license alerts, password reset) |
| OpenAI, L.L.C. (USA) | AI features (audio transcription via Whisper, GPT models for AI assistant) | Only the specific audio file or prompt you explicitly submit to an AI feature. Per OpenAI policy, content sent via the API is not used to train models. |
| Anthropic, PBC (USA) | AI features (alternative AI provider for assistant / chatbot replies) | Only the specific prompt you explicitly submit to an AI feature. Per Anthropic policy, API content is not used to train models. |
| Competent authorities | When required by law, court order, or valid request | Only data legally required and after evaluating the legitimacy of the request |
Pragmaz does not sell, rent, lease, or transfer user data to third parties for purposes outside the limited operational uses described in Section 6. The only "transfers" are to the subprocessors listed above, strictly to deliver the contracted service.
We do not use user data for:
Local-first by default. The Extension runs inside your browser on top of WhatsApp Web. It reads WhatsApp conversation data (messages, contacts, groups, media) locally in your browser to render Kanban CRM, message templates, and other features. Private WhatsApp messages and contact lists are not transmitted to Pragmaz servers, stored on Pragmaz infrastructure, or shared with third parties by default.
Exceptions — only on explicit user action: when you click a feature that requires cloud processing (for example: transcribe an audio with AI, ask the AI assistant about a conversation, run a chatbot flow, schedule a broadcast), the specific content you targeted is sent to the relevant cloud service (Pragmaz or the AI subprocessor named in Section 6) for the purpose of that feature only. Nothing is sent in the background or without your explicit action.
The Extension does not intercept, proxy, or reroute WhatsApp's network traffic. It reads the data that WhatsApp Web has already loaded into the page you are logged into, in your own browser.
Some Extension data is processed by our subprocessors in the United States. Transfers from Brazil and the European Economic Area are protected by Standard Contractual Clauses and the safeguards required by Article 33 of the LGPD and Article 46 of the GDPR. Brazilian Resolution ANPD 04/2024 is followed for international transfers.
You may exercise the following rights at any time:
To exercise any of these rights, email privacidade@pragmaz.ai. We will respond within 15 business days (LGPD requirement). Self-service deletion is available via the Pragmaz dashboard at pragmaz.ai/business/data-deletion.
We use industry-standard safeguards to protect your data:
No method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security but we strive to use commercially acceptable means of protecting your data.
The Extension does not set its own cookies, and it does not read or transmit the cookies of any website. It has no cookies permission.
The Extension stores data locally in your browser (chrome.storage.local and standard web storage) as described in Sections 3 and 5. In addition, the "clear WhatsApp Web cache / reset session" repair tool described in Section 3 deletes local site data for web.whatsapp.com — which may include that site's cookies, cache, IndexedDB and service worker — when, and only when, you click it. That data is deleted, never read or transmitted. No other site is affected.
The Extension is intended for use by business professionals and is not directed at children under 13 (or 16 in the EEA / 18 in Brazil for LGPD purposes). We do not knowingly collect personal information from children. If we discover that a minor has provided us with personal information, we will delete it promptly.
Specifically, Pragmaz's use and transfer of information received from Google APIs to any other app:
Pragmaz is an independent browser extension. We are not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc., WhatsApp LLC, or any of their subsidiaries. WhatsApp is a trademark of WhatsApp LLC. Meta is a trademark of Meta Platforms, Inc.
We may update this Privacy Policy from time to time. Material changes will be communicated by email to active subscribers at least 30 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.
For any questions, complaints, or requests related to this Privacy Policy or your data: