This Privacy Policy explains what information the WA Chat Share
Android app (package com.share.whatsappchat — "the App")
handles, how it is used, who it is shared with, and the choices
you have. It applies to the App as distributed on Google Play. The App is developed and
published by Mohammed Malhas ("we", "our", "us"), who is the
data controller for the data described below. By using the App you agree to
the practices described here.
.zip file and open it in this App. The App turns it into a PDF
document or an interactive HTML page. All of that happens on your
phone. Your messages, media, participant names and file names are
never sent to us and never uploaded anywhere by the App. There are no
accounts and no sign-in. The App does use the internet — for anonymous
product analytics and to show ads — and those are described in full below.
1. What the App Does
WhatsApp lets you export a conversation ("Export chat"), which produces a
.zip archive containing a text file of the messages and, if you
chose to include them, the photos, videos and voice notes.
You open that archive in WA Chat Share — by sharing it to the App, tapping it in a file manager, or picking it from inside the App. The App reads it and builds one of two things:
- a PDF document you can print, keep or attach; or
- an interactive HTML page that opens in any browser and still plays the voice notes and shows the photos.
You choose what goes in — which people, which dates, whether to include photos or audio, whether to hide phone numbers, and so on. You can preview the conversation in the App, then save the finished file or share it wherever you like.
2. Data We Collect, and Why
The clearest way to say this is to split it into what stays on your device and what actually leaves it.
Stays on your device — we never receive it
- The chat export you open and everything in it: message text, timestamps, participant names and phone numbers, photos, videos, voice notes and file names.
- The PDF or HTML files the App produces, which are written to the App's own private storage on the phone.
- Small app settings, such as whether you have seen the intro screens and your light/dark theme choice.
We have no server that receives chats, and the App has no upload feature. Nothing in this list is transmitted to us or to anyone else by the App.
Leaves your device
- Anonymous product-usage analytics through Google Firebase Analytics — see section 4, which lists every event and every field.
- Advertising data collected by Google AdMob to serve and measure ads, including your Android Advertising ID — see section 5.
- Purchase records, if you buy something, handled by Google Play Billing — see section 6.
We do not collect your name, email address, phone number, contacts, precise location, photos, or the contents of any conversation. We do not sell personal information, and no chat content is ever used for advertising.
3. On-Device Processing of Your Chats
Reading the archive, decoding the media, laying out the pages and writing the PDF or HTML all happen locally on your phone. This is not a policy preference — the App has no upload path for chat data at all, and it can do the whole job with the network switched off.
- Finished exports are written to the App's private application storage, which other apps on the phone cannot read.
- Android Auto Backup and device-to-device transfer are disabled for this App. Your imported archives and finished exports are therefore not copied to your Google Drive and are not carried over automatically when you set up a new phone. If you want to keep an export, save or share it yourself.
- When you tap Share on a finished file, Android's share sheet hands that file to whichever app you pick — email, a messaging app, cloud storage. From that point the file is governed by that app's privacy policy, not ours. That step is always your choice and never automatic.
- The App can offer to open WhatsApp so you can start an export. This only launches WhatsApp; it gives the App no access to WhatsApp's data.
To be precise about one thing: the App does require internet access and is not an offline-only app, because analytics and ads use the network. Your chats simply are not part of what travels over it.
4. Analytics — Exactly What Is Sent
We use Google Firebase Analytics to understand how the App is used so we can improve it. The analytics in this App are deliberately built so that chat content cannot be sent: every event is assembled from a fixed list of internal tokens, true/false flags and rounded counts. There is no way for a chat name, a participant, a message or a file name to become part of an analytics event.
The events we send
| Event | What it records |
|---|---|
| Chat imported | Where the chat came from (zip file, text file, folder, or opened from another app), whether it was a group chat, and bucketed counts of messages and media items. |
| Import failed | Only where the chat came from. No error message and no file name — error text can name files, so it is never sent. |
| Export finished | The options you chose: format (PDF or HTML), page layout, HTML style, paper size, and true/false flags for photos, audio, system messages, hidden phone numbers, greyscale, cover page, 24-hour clock, and whether you filtered by people or by date. Plus bucketed message and page counts. It describes the settings, never the conversation. |
| Export failed | The format, and a category for the reason (nothing selected, read failed, write failed, unknown). |
| Preview opened | A bucketed message count. |
| WhatsApp opened | Whether the "Open WhatsApp" button succeeded. |
| Export shared / Export viewed | The format only (PDF or HTML). Never the file name, never the destination app. |
| Screen views | Which screen of the App you are on, using our own fixed route names
(/ and /onboarding). |
"Bucketed" counts
Exact counts are never sent. A precise figure like "7,118 messages" plus a timestamp starts to look like a fingerprint for one specific conversation, so counts are rounded up to an order of magnitude before they leave the device: 0, 10, 100, 500, 1,000, 5,000, 10,000, or 50,000+. A chat of 7,118 messages and a chat of 9,000 messages are reported identically. The only question we are asking is "are people exporting small chats or enormous ones?"
What Google collects automatically
Alongside the events above, the Firebase Analytics SDK collects a standard set of information by itself:
- a randomly generated app instance ID (an identifier for the App's installation on your device — not your name and not your Google account);
- device and OS information, such as device model, brand, screen size, operating system version, app version and language;
- approximate, country-level location, derived by Google from your IP address;
- session and engagement data, such as first launch, session starts, and how long the App is in the foreground.
This is Google's standard automatic collection and is described in Google's own documentation. Note that Firebase Analytics may also use your Advertising ID where it is available (see the next section).
When nothing is sent at all
If Firebase cannot start — for example on a device without Google Play services, offline, or behind a firewall — the App silently continues without it and no analytics event is sent or queued. Exporting works exactly the same either way.
5. Advertising and Your Advertising ID
The App shows ads supplied by Google AdMob, part of Google LLC. Ads are how the App stays free.
- Google serves the ads, and Google and its ad partners may collect and process device identifiers, IP address, approximate (non-precise) location, device and app information, and data about how you interact with an ad.
- The main identifier used is the Android Advertising ID (AAID) — a resettable ID provided by Google Play services. It is used to select ads, to apply frequency capping (so you are not shown the same ad over and over), to detect invalid traffic, and to measure ad performance.
- No chat content is ever used for ad targeting. Your messages, media, participants and file names are not available to the ad SDK and are never sent to any advertising network. The App does not read your export in order to choose an ad.
- Ad requests from this App are configured for a general audience and not for children — see section 11.
Your choices about ads
You control the Advertising ID at the Android level, not inside our App:
- Reset it — Android Settings → Privacy → Ads → Reset advertising ID. This gives you a new ID and breaks the link to previously collected ad data.
- Delete it — on Android 12 and later, Settings → Privacy → Ads → Delete advertising ID. Apps then receive a string of zeros instead of an ID.
- Opt out of personalised ads — Settings → Privacy → Ads → Opt out of Ads Personalisation. You will still see ads, but they will not be personalised to you.
Exact menu names vary a little between phone makers and Android versions; look for "Ads" or "Advertising ID" under Privacy or Google settings.
For details of how Google uses data from apps that use its advertising services, see Google's "How Google uses information from sites or apps that use our services", the AdMob & AdSense policies, and the Google Advertising policy. Google Play services are governed by the Google Terms of Service and the Google Privacy Policy.
6. In-App Purchases
The App offers optional in-app purchases (for example, removing ads or unlocking additional features). These are handled entirely by Google Play Billing.
- Google processes the payment, not us. Your card number, bank details and billing address go to Google and are never seen, handled or stored by us.
- What we receive is a purchase and entitlement record — essentially confirmation that a purchase for this app was made and is valid — which the App uses to unlock what you paid for. It is tied to your Google account by Google, not to any account with us.
- Restoring purchases: because entitlements are tied to your Google account, reinstalling the App or moving to a new Android phone lets you restore what you bought at no extra cost. The App queries Google Play for your existing purchases; there is nothing for you to send us.
- Refunds are handled through Google Play under Google's refund policy — see Google Play refunds. If Google directs you back to the developer, contact us at the address in section 15.
7. Device Permissions
| Permission | Why it's used |
|---|---|
| Internet / network state | Analytics, ads, and Google Play Billing. Chat conversion itself does not use the network. |
| Advertising ID | Declared by the Google advertising and analytics libraries so ads can be selected, frequency-capped and measured. See section 5 for how to reset, delete or opt out. |
| File access you grant per file | When you pick or share an export archive, Android grants the App access to that file only, for as long as it is needed. The App does not ask for broad access to your device storage. |
| Visibility of the WhatsApp package | So the "Open WhatsApp to Export" button can tell whether WhatsApp is installed and launch it. This declaration grants no access whatsoever to WhatsApp's data. |
The App does not request access to your contacts, camera, microphone, precise location, call logs, SMS, or your full device storage.
8. Sharing and Third-Party Processors
We do not sell your personal information and we do not share it with advertisers or data brokers of our own. The App relies on the following Google services, each acting under its own privacy policy:
| Provider | What it does | Policy |
|---|---|---|
| Google Firebase Analytics (Google LLC) |
Anonymous product-usage analytics, as listed in section 4 | Firebase privacy |
| Google AdMob (Google LLC) |
Serving, capping and measuring ads; uses the Advertising ID | How Google uses data |
| Google Play Billing (Google LLC) |
Processing in-app purchases and refunds | Google Privacy Policy |
| Google Play (Google LLC) |
App distribution and updates | Google Privacy Policy |
None of these providers receives chat content from the App, because the App never puts chat content into anything they can read.
We may also disclose information if required to do so by law, or to protect our rights, safety, or the integrity of the App — but note that we hold no chat data to disclose in the first place.
9. Retention and Deletion
- Your exports and imported chats: kept on your device until you delete them. Delete them inside the App from My Exports (long-press to select, then Delete), or uninstall the App to remove all of its local data at once. We cannot delete them for you, because we never have them.
- Files you shared out to another app, a chat, or cloud storage are outside the App's control. Delete them wherever you sent them.
- Analytics data: retained by Google under Firebase's retention settings — event-level data is retained for a limited period (currently set to Google's default of up to 14 months for the underlying user-level data) and then deleted or kept only in aggregate.
- Advertising data: retained by Google under its own policies. Resetting or deleting your Advertising ID breaks the link to past ad data.
- Purchase records: retained by Google Play as required for billing, tax and refund purposes.
10. Security
- Your chats and exports live in the App's private storage area, which the Android sandbox keeps other apps out of.
- Automatic cloud backup and device transfer are switched off for the App, so that storage is not silently copied off the phone.
- All network traffic to Google's analytics, advertising and billing services is encrypted in transit (HTTPS/TLS).
- Because we operate no server and hold no chat data, there is no database of your conversations for anyone to breach.
No method of electronic storage or transmission is completely secure. Please also protect the device itself with a screen lock, and think carefully about where you send an exported file.
11. Children's Privacy
The App is intended for a general adult audience. It is not directed to children under 13 (or the minimum age of digital consent where you live), and we do not knowingly collect personal information from children.
Ad serving is configured accordingly: ad requests from this App are not tagged as child-directed, and ad content is filtered to a maximum content rating suitable for a general audience. If you believe a child has provided us with personal information, contact us and we will act on it promptly.
12. International Transfers
The analytics, advertising and billing data described above is processed by Google LLC and its affiliates on servers that may be located in the United States and other countries, which may have different data-protection laws than your own. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, Google relies on legal transfer mechanisms such as the European Commission's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. Your chat content is not part of any such transfer, because it never leaves your phone.
13. Your Rights (GDPR, CCPA/CPRA and others)
Depending on where you live, you may have rights over your personal data. We honour these requests regardless of your location.
If you are in the EEA, the UK or Switzerland (GDPR)
You have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data protection authority. Our legal bases are: legitimate interests for basic product analytics and for keeping the App working and secure; consent where required for personalised advertising and for analytics identifiers; and performance of a contract for delivering purchases you make.
If you are in California (CCPA/CPRA)
You have the right to know what personal information is collected and for what purpose, to request deletion, to correct inaccurate information, to limit the use of sensitive personal information, and to opt out of the "sale" or "sharing" of personal information — and not to be discriminated against for exercising those rights. We do not sell personal information for money. Because advertising identifiers may be shared with Google for cross-context behavioural advertising, this may qualify as "sharing" under the CPRA; you can opt out at any time using the Android settings in section 5 or by emailing us.
How to exercise your rights
- Personalised ads: the fastest route is Android Settings → Privacy → Ads — opt out of ads personalisation, or reset or delete your Advertising ID. You may also object to personalised advertising by emailing us.
- Analytics: uninstalling the App stops all further analytics collection from your device.
- Everything else: email mohammedmalhas96@gmail.com with the subject "Privacy request" and tell us what you want. We will respond within the time your law allows (30 days under GDPR, 45 days under CCPA/CPRA). Because the App has no accounts, we may ask you for the approximate date of installation and your device model in order to locate any relevant analytics records — we do not otherwise have a way to identify you, and we will not ask for more information than necessary.
14. Changes to This Policy
We may update this Privacy Policy as the App changes or as the law requires. When we do, we update the "Last updated" date at the bottom of this page and publish the revised version at this address. If a change is significant — for example, a new category of data collection — we will give clearer notice, such as a message inside the App or in the Play Store release notes. Continuing to use the App after an update means you accept the revised policy. We suggest checking this page occasionally.
15. Contact Us
Questions, privacy requests, or anything else about this policy:
Mohammed Malhas
Developer of WA Chat Share
Email: mohammedmalhas96@gmail.com
Mohammed Malhas is the data controller for the analytics and advertising data described above.
Last updated: 24 August 2026