Skip to main content
PRIVACY NOTICE

Your account is online. Authorized contact activity stays local.

See how the StatStoat website, authentication service, optional transactional email, desktop runtime, and destinations handle account and WhatsApp presence data.

Version2026-07-22

What this notice covers

This notice covers statstoat.com, the account authentication service, the protected dashboard entry point, the current StatStoat desktop application, and the maintained Chrome extension compatibility surface.

Archived scripts, older extension builds, WhatsApp Web, user-configured webhooks, and notify.run are separate surfaces with their own behavior and policies.

The central privacy boundary: signing in does not upload your monitored contact list or presence timeline to your StatStoat account.

Information StatStoat handles

Account information

Email address, an optional display name, account creation and verification status, the accepted legal version, acceptance time and method for newly created accounts, opaque-session metadata, and—when you use Google sign-in—the provider's stable account identifier. Password accounts also store a salted password hash.

Security metadata

Request origin and network address may be processed to enforce origin checks and per-address authentication limits.

Device-local information

Selected contacts, identifiers, observed presence sessions, settings, diagnostics, and generated reports stay in local browser, Chrome extension, or Electron storage.

Optional destinations

Notification or webhook content leaves the device only when you explicitly configure and use that destination.

Passwords and raw session tokens are not stored in the authentication data file. Passwords use per-user salted scrypt hashes; only SHA-256 hashes of random session tokens are persisted.

Consent and email verification

The authentication screen presents the current Terms of use and this privacy notice before an authentication option becomes available. For a newly created account, StatStoat records the accepted legal version, acceptance time, and whether the account was created with password or Google authentication. This consent step does not grant access to local contact history or upload it to the account service.

When password-account email verification is enabled, StatStoat stores the SHA-256 hash of a random verification token, not the raw token. It also stores the account's verification state and the times needed to enforce expiry, single use, resend cooldowns, and pending-account retention. The raw token appears in the private link sent to the address and is submitted only when its holder explicitly confirms verification.

A resend replaces the previous verification token. A used, replaced, or expired token cannot verify an account. Google sign-in is accepted only when Google returns a verified email claim, so that flow does not send a separate StatStoat verification link.

Optional transactional mail

Email delivery is optional and operates only when an administrator has configured and enabled it. The configured mail service may process the recipient address, optional display name, message content, sending time, and technical delivery metadata needed to deliver or troubleshoot the verification message. StatStoat does not currently name a mail provider or claim that transactional mail is enabled.

Verification messages are transactional account-security messages. They do not contain advertising or tracking pixels. Delivery infrastructure may retain its own operational records under its applicable configuration and policy.

How information is used

  • To create and maintain your account.
  • To record verification state, issue or replace time-limited verification links, and send transactional verification mail when that feature is enabled.
  • To verify access to protected web routes.
  • To prevent excessive authentication attempts and reject requests from an unexpected configured origin.
  • To operate local monitoring, history, export, notification, and diagnostic features that you initiate.

The current website does not include advertising pixels or third-party analytics. StatStoat does not sell account or contact information.

Authentication cookies

A completed sign-in sets statstoat_session to authenticate requests. Starting Google sign-in also sets statstoat_google_state and statstoat_google_verifier for up to ten minutes so the callback can validate the request and its PKCE proof. The two temporary cookies are cleared when the callback is handled.

These cookies are HttpOnly and SameSite=Lax, and production uses the Secure attribute. JavaScript cannot read them. The session cookie is cleared when you sign out.

Local history, exports, and integrations

The desktop runtime and maintained Chrome extension can observe supported WhatsApp Web presence states through your local signed-in session. StatStoat stores the resulting timeline locally unless you take an explicit action that sends or exports it.

  • Exports are created only when you choose CSV, Excel, JSON, copy, print, or PDF output.
  • HTTPS webhooks send the payload described in the integration screen to the URL you provide.
  • notify.run and device notifications are optional and subject to the destination provider or operating system.
  • Deleting browser or application storage may remove local history and preferences permanently.

Before sharing an export: review it for phone numbers, contact names, timestamps, and patterns that may identify another person.

Retention, security, and your choices

Authentication sessions expire according to service configuration; the default is seven days. Expired sessions are pruned. When email verification is enabled, a verification link expires after the configured period—24 hours by default—and a never-verified account is pruned after the configured pending-account period—seven days by default. A verified account record remains while the account exists. Local monitoring data remains until you remove it, clear storage, or uninstall the relevant application data.

You can sign out to revoke the current session, clear local history through the application controls, disable optional notifications and webhooks, or stop using the service.

Settings > Account & session includes self-service account deletion. After confirmation, it removes the account record, revokes every server-side session for that account, and clears that account’s data from the current browser. Local data held by another browser or desktop installation must be cleared on that device.

Questions, requests, and changes

Account deletion is available directly in the dashboard. No public privacy-support channel is currently advertised; authorized repository collaborators can use the project’s private issue tracker for general, non-sensitive questions. Never share passwords, session cookies, phone numbers, contact history, identity documents, or other personal data in an issue.

If this notice changes materially, the revision date above will be updated. Continued use after an update means the revised notice applies from its stated date.