← Return to WhatsApp Contact Saver Home
⚠️ IMPORTANT TRADEMARK & AFFILIATION DISCLAIMER:
WhatsApp is a registered trademark of WhatsApp LLC and Meta Platforms, Inc., registered in the United States and other countries.
WhatsApp Contact Saver is an independent software tool created to assist users in managing their personal contact data. This software is NOT affiliated with, associated with, sponsored by, endorsed by, or in any way officially connected with WhatsApp LLC, Meta Platforms, Inc., or any of their subsidiaries or affiliates.
1. Single Purpose Specification
The sole and exclusive purpose of the WhatsApp Contact Saver extension is to provide a local productivity utility allowing users to format, organize, and export WhatsApp contacts and group member lists directly from their personal WhatsApp Web interface (web.whatsapp.com) into organized spreadsheet files (.xlsx, .csv) and phone contact files (.vcf / Google Contacts format).
The Extension does not perform any secondary functions, background browsing tracking, advertising injections, or unrelated data harvesting.
2. Data Collection & Processing Principles
We believe in radical data minimization. Our extension is engineered so that your sensitive contact information never leaves your personal device.
A. Data We DO NOT Collect, Transmit, or Store on Servers:
- No Contact Phone Numbers: Scanned WhatsApp phone numbers and formatted contact digits are processed 100% locally in your browser memory. They are NEVER uploaded or saved to our web server.
- No Chat Messages or Media: We never read, inspect, store, or transmit your private WhatsApp messages, conversations, voice notes, photos, documents, or status updates.
- No Contact List Transmission: The export files (Excel, CSV, vCard) are generated strictly on the client side using JavaScript and saved straight to your computer's local Downloads folder.
- No Web Browsing History: The extension does not record, track, or monitor any web page you visit outside of
web.whatsapp.com.
B. Data Collected Solely for Licensing & Account Management (Optional):
- Google Account Information (OAuth): If you choose to sign in to activate PRO features or track your quota, we receive your Google email address and public display name. This information is used strictly to identify your account and verify your subscription status.
- Export Usage Counter: A single numerical count of exports completed (e.g.
export_count: 2) is synchronized with our database to enforce Free vs. PRO tier limits.
- Payment & Order Verification: For users upgrading to PRO via PayPal or QRIS, we receive transaction confirmation records (such as Order ID, payment status, currency, and buyer email) through secure payment webhooks to activate lifetime PRO privileges. We never see or store credit card numbers or banking passwords.
3. Browser Permissions Usage & Justification
In adherence to the Chrome Web Store Minimal Permissions Policy, the Extension requests only the absolute minimum permissions necessary to deliver its core functionality:
| Permission |
Scope |
Technical Justification |
activeTab |
Active Browser Tab |
Allows the extension to interact with the currently active tab when the user clicks the extension popup, confirming that the user is actively on WhatsApp Web. |
scripting |
DOM Interaction |
Used strictly to execute client-side extraction scripts (content.js) on web.whatsapp.com to detect phone numbers visible on the screen upon explicit user action. |
storage |
Browser Local Storage |
Used exclusively to save user settings (auto-capture toggle, scan history deduplication list, and locally cached license tier) directly in chrome.storage.local on your device. |
identity |
Google OAuth 2.0 |
Allows users to optionally authenticate with their Google account via standard Chrome Identity APIs to unlock PRO features and synchronize subscription status. |
web.whatsapp.com/* |
Host Permission |
Required for the content script to read WhatsApp Web contact lists and auto-scroll group member drawers without reloading the page. |
wacontact.mikro.co.id/* |
Host Permission |
Required for the extension to communicate with our licensing server to check subscription tiers, redeem licenses, and receive quota status. |
4. Google API User Data Policy & Limited Use Disclosure
MANDATORY LIMITED USE DISCLOSURE:
WhatsApp Contact Saver's use and transfer to any other app of information received from Google APIs will adhere to the
Chrome Web Store User Data Policy, including the
Limited Use requirements.
Specifically, our practices strictly conform to the following standards:
- Prominent Feature Requirement: We only request access to Google user data (email and name) to provide user-facing features that are prominent in the extension's user interface (account authentication and PRO license access).
- No Transfer Except for Service Delivery: We do not transfer this data to third parties, except as strictly necessary to provide or improve these user-facing features, comply with applicable law, or as part of a formal corporate reorganization.
- No Advertising: We do not use or transfer user data for serving advertisements, including personalized, re-targeted, or interest-based advertising.
- No Credit Worthiness Assessments: We do not use or transfer user data to determine creditworthiness or for lending purposes.
- No Human Inspection: No human beings are permitted to read your personal account data unless you have given explicit consent for troubleshooting an individual technical support issue.
5. Prohibition of Data Sale & Data Brokerage
✓ ZERO DATA MONETIZATION GUARANTEE:
We DO NOT SELL, RENT, LEASE, OR TRADE any user personal data, contact information, email addresses, or telemetric data to third-party data brokers, advertising networks, or marketing agencies under any circumstances.
Our revenue model is based solely on transparent software licenses (PRO Tier purchases). We have no financial interest in monetizing or commercializing your personal data.
6. Data Storage & Retention
- Local Contact Data: Extracted contact records are stored strictly in your browser's private local storage (
chrome.storage.local). This data is completely destroyed whenever you clear browser storage or click "Reset" in the extension.
- Server-side Account Records: Account profile records (Google email, display name, account tier, and creation timestamp) are retained in our secure MySQL database for the duration of your active subscription or until you request account deletion.
7. User Rights & Data Deletion (GDPR & CCPA Compliance)
We respect your international data protection rights under the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA):
- Right of Access & Portability: You can view all captured contacts at any time inside the extension table and export them into open formats (.csv, .xlsx, .vcf).
- Right to Erasure (Right to be Forgotten): You can wipe all local extension data instantly by clicking the "Reset" button inside the extension.
- Right to Permanent Account Deletion: If you wish to delete your account record (email and license history) permanently from our administrative database, simply email our Data Privacy Officer at support@mikro.co.id with the subject "Delete My Account". Your records will be permanently purged within 48 business hours.
- Right to Non-Discrimination: We do not discriminate against users who exercise their privacy rights.
8. Security & Technical Safeguards
We implement robust technical and organizational security measures to protect your information:
- 256-bit SSL/TLS Encryption: All communications between the extension and our API endpoints (
https://wacontact.mikro.co.id/) are protected with modern HTTPS encryption.
- Strong Password Hashing: Administrative credentials are encrypted using industry-standard
bcrypt one-way hashing algorithms.
- No Embedded Third-Party Trackers: The extension does NOT include Google Analytics, Facebook Pixel, advertising SDKs, or foreign tracking scripts inside its content scripts or background runtime.
9. Third-Party Services
The extension interacts only with the following reputable third-party service providers:
- Google Identity Services (Google LLC): Used for secure single sign-on authentication. Governed by Google's Privacy Policy.
- PayPal Pte. Ltd.: Used for international payment processing. Governed by PayPal's User Agreement and Privacy Statement.
- Bank Indonesia QRIS Gateway: Used for Indonesian domestic QR payments. No financial card details are ever exposed to our software.
10. Children's Privacy (COPPA Compliance)
Our extension and services are not directed to individuals under the age of 13 (or under 16 in the European Union). We do not knowingly collect personal information from children. If you believe that a child has provided us with personal data, please contact us immediately so we can promptly delete the information.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect enhancements in extension functionality, security practices, or regulatory requirements. Any modifications will be posted directly on this page with an updated "Last Updated" timestamp. Substantial policy changes will be accompanied by an in-app notice.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our support team: