Skip to content

Legal

Security

Last updated: 4 October 2026

The safest data is data that is not kept. Vancely is built so that message content exists only while it is on its way, encrypted, and is erased once it is delivered. This page describes how we protect the service and the little we do keep.

At a glance

  • We never store message content: it is encrypted while in transit through our systems and erased on delivery.
  • Only our website is public. The application server and the WhatsApp connection service are not reachable from the internet.
  • API keys and passwords are stored hashed; webhook secrets are stored encrypted.
  • Every webhook we send is signed, and webhook targets are checked so they cannot point into private networks.

Message content

  • Text, captions, locations and files are kept only until they are delivered: encrypted (AES-256) in our database and job queues, and held briefly on our private internal network while being processed. They are then erased: outbound content when WhatsApp accepts the message, inbound content once your webhook receives it.
  • Inbound files stay on our WhatsApp connection service encrypted with AES-256-GCM, are never copied elsewhere, and are deleted a few minutes after their first complete download (24 hours at most).
  • Bot conversation state and open website chats live only in encrypted, short-lived memory storage, never in our logs. Webhook copies of chat messages are kept encrypted until your endpoint receives them, then their content is removed.
  • A scheduled job regularly sweeps and erases any leftover content, so nothing lingers if a delivery fails.
  • The only content ever kept is opt-in: saved flow responses and chat transcripts, stored encrypted and only when the business turned them on and the person agreed in the chat. See our privacy promise.

Infrastructure and network

  • The service runs on a private server hosted by Hostinger. Only the website is published to the internet, over HTTPS and behind Cloudflare; the application server and databases sit on an internal network.
  • The service that holds WhatsApp connections is never public and accepts only requests signed with a shared secret (HMAC-SHA256) by our application.
  • All connections to our website, dashboard and API use HTTPS.
  • Your browser talks only to our own domain, so sign-in cookies are first-party and protected against cross-site request forgery.

Accounts and API keys

  • Passwords are stored as one-way hashes.
  • API keys are generated with a cryptographically secure random generator, shown only once, and stored hashed. Each key carries only the scopes you give it, and you can revoke it at any time.
  • Sign-in, password reset and API requests are rate limited to slow down guessing and abuse.

Webhooks and outbound requests

  • Every webhook carries an HMAC-SHA256 signature with a timestamp, so your server can confirm it came from us and reject replays. Webhook secrets are stored encrypted.
  • Before we call any URL you configure (webhooks and bot flow web requests), we check it and refuse private, loopback and reserved addresses, so the service cannot be used to reach internal networks.
  • Webhook response bodies are never stored.

Access, retention and backups

  • Access to production systems is restricted to the people who run the service.
  • Metadata is deleted on a schedule: message records after 90 days, webhook delivery logs after 30 days and audit logs after 90 days.
  • The whole server is backed up regularly, so we can recover from hardware failure.
  • Built-in sending limits and opt-out handling protect your WhatsApp number and your recipients from misuse; see the Acceptable Use Policy.

Reporting a vulnerability

If you think you have found a security issue, email support@bytevancer.com with the details and steps to reproduce it. Please give us reasonable time to fix it before telling anyone else, and do not access other people's data or disrupt the service while testing. We will acknowledge your report and keep you updated.

See our Privacy Policy, Data Processing Addendum and Sub-processors.