Privacy & architecture FAQ · WhatsApp Coexistence

What changes when you connect Coexistence?

A focused privacy FAQ about connecting an existing WhatsApp Business App number directly to Frepi through Meta's Cloud API—without replacing the app or the number.

The central answer: Coexistence adds an authorized API path. Frepi currently uses that path for supported new message events and authorized Cloud API sends. It does not currently import the optional 180-day history, complete contact-list synchronization, or app-sent message echoes into the conversation view. The connection never gives Frepi unrestricted access to the phone, personal Facebook data, or WhatsApp group chats.

Brazilian legal entity

FREPI TECNOLOGIA LTDA

CNPJ 52.979.451/0001-16 · São Paulo/SP, Brazil · Workspace data hosted on Google Cloud in São Paulo (GCP Brazil) · Privacy contact: henry@frepi.ai

Technology Provider

Meta

App ID 1233214825458555

Scope of this document

The privacy delta—not every WhatsApp concern

This document compares using the WhatsApp Business App by itself with using the same number through the app and Frepi at the same time. It concentrates on the additional authorization, data flows and controls created by Coexistence.

Connection path covered: Meta-direct Coexistence through the Frepi Platform app. Some existing Frepi sources are labeled “Coexistence” but are connected through Respond.io instead. On that path, Respond.io is the Meta provider of record and Frepi receives configured contact and conversation data from Respond.io—not Meta's optional Coexistence history or complete contact synchronization.

What Frepi currently uses

  • An authorized connection between the business's WhatsApp assets and Frepi.
  • Meta's standard message webhooks for supported new incoming messages and status events.
  • Authorized Cloud API sends initiated from Frepi.
  • A workspace copy of supported events for inbox, analytics and enabled automation.

What Frepi does not currently import

  • Meta's optional one-time synchronization of up to 180 days of history.
  • Meta's complete contact-list synchronization.
  • App-sent message echoes in the displayed Frepi conversation.
  • WhatsApp group chats, which Meta does not make available through Coexistence.

The connection in five steps

  1. The business authorizes inside Meta's Embedded Signup.
  2. Meta returns scoped asset IDs and a short-lived exchange code.
  3. Frepi exchanges the code server-to-server and subscribes to approved webhooks.
  4. Meta sends signed events; Frepi verifies and routes them to the correct workspace.
  5. Enabled AI features may process selected content through an interactive request or a configured background job.

Tier 1

Connection authorization

Who grants access, which permissions are involved, and what credentials Frepi receives.

Does every Frepi line labeled “Coexistence” use this same connection path?

Short answer: No. The provider shown on the connection determines the privacy path.

  • Meta-direct Frepi: the business authorizes the Frepi Platform app and Meta sends approved events to Frepi. This is the path covered by the rest of this FAQ.
  • Via Respond.io: Respond.io remains the Meta provider of record. Frepi receives data through the Respond.io connection and credentials configured by the business. Meta's optional 180-day history and complete contact synchronization do not flow directly to Frepi on that path.

Customers should check the provider displayed for the number before relying on a privacy answer, because the processors, credentials and deletion boundaries differ.

What exactly is being connected?

Short answer: The business's existing WhatsApp Business App number is also onboarded to Meta's Cloud API for use by Frepi.

The number and the WhatsApp Business App remain usable. Coexistence creates a second, API-based operating path so messages can be mirrored between the app and an authorized business platform.

Who authorizes the connection?

Short answer: A representative of the business authorizes it through Meta's own Embedded Signup flow and confirms the connection in the WhatsApp Business App.

The person signs in with their Meta business credentials, chooses the relevant business assets and confirms the number. Frepi does not receive or store that person's Facebook password.

Which Meta permissions does Frepi request?

Short answer: WhatsApp business messaging and WhatsApp business management.

  • Messaging permits the authorized app to send and receive messages for the selected business number.
  • Management permits operations on the selected WhatsApp Business Account, such as reading phone-number settings and managing message templates.

These permissions concern selected WhatsApp business assets. They do not provide blanket access to a person's Facebook account or unrelated business portfolios.

What credential does Frepi keep after signup?

Short answer: Frepi exchanges Meta's temporary code for a customer-scoped business access token.

The exchange happens server-to-server. Frepi does not return token or app-secret values through connection APIs. Manually supplied tokens, refreshed add-number tokens and stored client app secrets use the current application-encryption helper. The initial Embedded Signup token and customer-supplied AI API keys do not yet have complete application-level encryption coverage, so Frepi does not make a blanket claim that every credential is application-encrypted at rest.

A token is powerful because it represents delegated access. Encryption, scope validation, daily validity checks and revocation are therefore more meaningful controls than hiding the existence of the token. Refresh of expiring Embedded Signup tokens remains an operational requirement.

What does Frepi's Meta verification prove?

Short answer: It shows that Meta marked Frepi's business and Technology Provider access verification complete and approved Advanced Access to the two WhatsApp permissions.

As of 1 September 2026, Frepi's Meta dashboard records business verification, Technology Provider access verification, and advanced access to whatsapp_business_messaging and whatsapp_business_management.

Anyone can independently confirm Frepi's public Meta app record: App ID 1233214825458555 returns the name Frepi Platform from Meta's Graph API without a token. Meta does not publish a Technology Provider license number or a public provider directory.

This is Meta's Technology Provider access verification. It is not a privacy certification, a penetration test or a blanket endorsement of this FAQ by Meta.

Tier 2

Data synchronization

Which information can leave the WhatsApp Business App environment and reach Frepi.

Which new data can flow after the connection?

Short answer: Frepi currently processes supported standard message events, identifiers, status and business-number metadata delivered by Meta.

The current processed path can include:

  • supported new incoming messages and Cloud API messages sent by Frepi;
  • delivery, read, failure, edit and deletion events when Meta provides them;
  • WhatsApp contact identifiers and profile names attached to those messages; and
  • message content and identifiers in the supported standard webhook format.

Meta can additionally deliver history, full contact synchronization and app-sent message echoes. Frepi retains incoming signed webhook payloads but does not currently import those three additional event types into the displayed conversation.

Does Frepi receive historical conversations?

Short answer: Not currently. Meta supports an optional history flow, but Frepi does not yet initiate or import it.

Meta supports a one-time synchronization covering messages sent or received during the 180 days before Cloud API onboarding. The request must be initiated within 24 hours after onboarding. If the business declines history sharing, Meta returns a “history not shared” result instead of the past conversations.

Historical media is more limited: Meta sends media asset identifiers separately only for media messages from the 14 days before onboarding.

What happens if the business declines historical sharing?

Short answer: Meta does not deliver the past conversations through its history flow.

Frepi does not currently request that flow in either case. If history import is enabled in a future release, declining the option will prevent that backlog from being shared while supported new message events can still operate after connection.

Are contacts synchronized?

Short answer: Frepi does not currently initiate Meta's complete contact-list synchronization.

Frepi receives contact identifiers and profile names attached to supported new message events. Meta's Coexistence API separately supports synchronization of all contacts that have a WhatsApp number, followed by contact-change events, but that broader flow is not currently imported by Frepi.

Can Frepi see messages employees send directly from the WhatsApp Business App?

Short answer: Meta can deliver those copies, but Frepi does not currently import them into the displayed conversation.

Meta sends supported app-sent copies through the smb_message_echoes webhook. Frepi's signed webhook buffer can receive the raw event, but the current conversation importer does not convert that event into a displayed message. Until that support ships, a Frepi conversation may omit messages employees sent from the app.

Which WhatsApp content is not synchronized?

Short answer: Group chats are not synchronized, and several privacy-sensitive app features are not supported in Coexistence.

  • WhatsApp group chats are not sent through the Coexistence API path.
  • Disappearing messages are turned off for individual chats after onboarding.
  • View-once messages and live-location messages are disabled for individual chats.
  • App broadcast lists cannot be newly created; existing lists become read-only.

These are Meta product behaviors, not Frepi settings. They should be reviewed with the business before connection because they change how employees use the app.

Does Frepi scrape the phone or WhatsApp application?

Short answer: No.

Frepi receives data through Meta's documented Embedded Signup, Cloud API and signed webhooks. It does not currently call Meta's optional history or complete contact-synchronization endpoints, remotely read the device, or automate the consumer interface.

Are Coexistence messages end-to-end encrypted all the way to Frepi?

Short answer: No—the accurate description is encrypted transport through Meta's Cloud API, not device-to-Frepi end-to-end encryption.

Meta documents that the message travels encrypted between the WhatsApp user and Cloud API. Cloud API decrypts it so it can forward the message to the business. Business-platform traffic then uses HTTPS/TLS, and Meta manages the Cloud API encryption keys on the business's behalf.

Frepi should not claim that only the sender and the employee's phone can read a Coexistence message. The connected business platform must receive usable message content in order to provide inbox and analytics services.

Tier 3

Frepi processing and storage

Where copies live, how they are protected, who can access them, and how optional AI changes the flow.

Two configurable controls at the workspace level

These controls address different risks, but neither is universal. The deployed data boundary depends on the workspace and data class; AI routing depends on the feature, inherited configuration and fallbacks.

Control 1 · Data boundary

Workspace-scoped data storage

Frepi hosts the product and stores the workspace copy on Google Cloud in São Paulo, Brazil (GCP Brazil). Dedicated tenant data planes are supported for canonical conversation and analytics tables. Some deployments or data classes remain in partnership or platform infrastructure and rely on workspace identity, row-level controls and application fences. The customer should confirm its deployed topology.

Control 2 · AI routing

Customer-supplied AI credentials where supported

An authorized administrator can configure supported provider credentials and a model for the workspace or partnership, or inherit Frepi's platform configuration. Feature-specific defaults, background processing and fallback behavior mean this is not a universal choice of processor for every AI operation.

Does each workspace have its own data boundary?

Short answer: Frepi supports dedicated workspace data planes, but not every record or deployment is physically isolated in a separate database.

When a dedicated tenant data plane is provisioned, canonical conversation and analytics tables are specific to that workspace. Frepi also supports partnership-level data sources and keeps platform records such as connection, credential and workspace configuration metadata in shared infrastructure. Those shared records depend on workspace identifiers, tenant fences, row-level controls and application authorization. Raw ingress and operational records may also live outside the dedicated tenant database.

Dedicated tables reduce the cross-customer blast radius when used, but they do not replace authentication, authorization, backups or operational controls. Ask Frepi to document the actual topology for the contracted workspace.

Can the customer choose which AI account processes its data?

Short answer: For supported surfaces, an authorized administrator can supply provider credentials; this is not yet a global processor-selection or AI-disable control.

The configuration resolves in this order:

  1. workspace-specific provider, model and API-key override;
  2. partnership-level configuration; then
  3. Frepi's platform default when no customer override is set.

Supported configuration can route some AI requests through the customer's own OpenAI, Anthropic or xAI account. If a selected provider lacks a usable key, the resolver can select another configured provider. Analysis Studio classification can use a separate platform provider and model. Removing an override moves the workspace back to inherited Frepi configuration. API keys are masked in responses, but masking is not encryption and complete application-level encryption of these keys remains open work.

Bring-your-own-key affects routing and billing on supported paths; it is not a tenant boundary or proof that every AI feature uses the same account. Frepi still orchestrates requests, and enabled background features may process content without a contemporaneous user prompt. Customers needing a single provider or no AI processing should require a feature-by-feature configuration and contract term.

Does Meta store Cloud API message data?

Short answer: Meta may retain encrypted Cloud API message data for up to 30 days to provide base functionality such as retransmission.

That Meta retention window is separate from the business copy stored in Frepi. The two systems have different purposes, policies and deletion controls.

What does Frepi store?

Short answer: Frepi stores the supported business copy and raw signed events on Google Cloud in São Paulo, Brazil (GCP Brazil).

The current Coexistence path can include:

  • supported new incoming content and messages sent through Frepi;
  • contact identifiers and profile names attached to those messages;
  • message status, timestamps, templates and campaign records;
  • raw signed webhook payloads, including media identifiers when Meta supplies them; and
  • derived analytics or AI classifications when those features are used.

Frepi does not currently download or display Coexistence media from those raw identifiers, and it does not currently import Meta's optional history, full contact-list or app-echo flows.

How long does Frepi retain Coexistence data?

Short answer: Conversation and campaign records are generally retained for the life of the workspace, subject to the controlling policy and contract.

Frepi's current Privacy Policy states response and deletion targets for validated requests. This FAQ does not represent that the workflow has been independently audited or fully automated across every tenant database, raw event, backup, log and subprocessor. Customers requiring a fixed deletion SLA should record its scope, exceptions and evidence in the applicable data-processing agreement.

How is the connection and its data protected?

Short answer: Frepi combines transport security, signed-event validation, workspace-scoped controls, role-based access and path-specific secret handling.

  • Meta API and webhook traffic uses HTTPS/TLS.
  • Frepi validates Meta's X-Hub-Signature-256 before processing webhook payloads.
  • Secret values are not returned by connection APIs; stored client app secrets and several token paths are application-encrypted, while initial Embedded Signup token encryption remains incomplete.
  • Customer data uses dedicated workspace tables where provisioned and tenant controls in shared infrastructure.
  • Application roles limit which workspace users can view or administer data.
  • Specified administrative actions performed through Frepi are logged; this document does not claim complete logging of every direct infrastructure access.

No technical control makes risk zero. Security reduces likelihood and impact; governance and incident response remain necessary.

Who can access a customer's conversations in Frepi?

Short answer: Authorized workspace users, authorized administrators, limited Frepi operations personnel, and necessary subprocessors.

A reseller or white-label partner can administer its own customer workspaces but not another partner's. The business controls which staff it invites. Infrastructure providers process data to host the service, and authorities may receive data where law requires it.

Is conversation content sent to an AI provider?

Short answer: It can be, when the workspace uses an AI feature that needs that content.

Features such as classification, Copilot or suggested audiences may send necessary prompts and conversation text to model providers outside the workspace. Interactive and configured background features must both be considered; supplying or removing one API key is not a global off switch.

Frepi does not use one customer's WhatsApp conversations to train a model that serves other customers. Model providers may apply their own security and abuse-monitoring terms, which should be assessed separately.

Does Frepi sell the data or use it for advertising?

Short answer: No.

Frepi's privacy policy states that it does not sell personal data, use one client's conversations to contact another client's customers, or build a cross-customer advertising graph from WhatsApp Platform Data. Meta states that Cloud API does not automatically use messages to inform the ads a person sees.

Does Coexistence guarantee that data stays in Brazil?

Short answer: Frepi stores the workspace copy on Google Cloud in São Paulo, Brazil (GCP Brazil). That is not a blanket Brazil-only guarantee for every system on the Coexistence path.

Frepi's production application and databases run in Google Cloud's Brazil region (São Paulo). Coexistence still involves Meta's Cloud API, and optional AI features can involve model providers outside that region. Businesses with residency requirements should request the current subprocessor and transfer details and record the required safeguards contractually.

Tier 4

Disconnection and customer control

How the business can stop the flow, delete Frepi copies, and meet its own privacy obligations.

Can the business disconnect without giving up its WhatsApp number?

Short answer: Yes.

Meta instructs the business to open WhatsApp Business App and go to Settings → Account → Business Platform → Disconnect Account. This offboards the Cloud API connection; it is not the same as deleting the WhatsApp account or surrendering the number.

What should stop after disconnection?

Short answer: Provider-side disconnection should stop authorized sends and future event delivery, but local cleanup differs by path today.

Meta can send a partner-removed event when the Coexistence connection is disconnected. Frepi excludes revoked connections from normal routing. The standard Connections path clears the stored token; a separate internal administrative path can currently mark the connection revoked without deleting it, and provider-originated disconnection is not yet a single verified credential-destruction workflow.

Disconnection stops the future connection. It does not by itself prove that every historical copy in every system has already been erased.

What data remains after disconnection?

Short answer: Existing business copies may remain under each system's retention policy until deletion or de-identification occurs.

Messages still in WhatsApp remain under WhatsApp's controls. Copies in a third-party inbox remain under that provider's controls. Frepi may delete or de-identify WhatsApp Platform Data after disconnection, and the customer can make an explicit deletion request for the Frepi copy.

How can the customer request deletion?

Short answer: Email henry@frepi.ai from the address associated with the Frepi account.

Use the subject Data deletion request and identify:

  • the workspace name or URL; and
  • whether the request covers one user, one contact's conversations, or the entire workspace.

The current Privacy Policy states response and completion targets. Customers should treat those policy terms as controlling and request a scoped contractual commitment where needed. Frepi is still consolidating end-to-end operational evidence across tenant data, raw events, backups, logs and subprocessors; this FAQ does not characterize that process as independently audited.

Who is the controller of the customer conversations?

Short answer: The business is generally the controller for customer conversations and Frepi generally acts as its processor for the contracted service.

The business decides why to message customers, which Frepi features to use, which employees receive access, and how long business records are needed. Frepi processes data to provide the contracted workspace. Applicable law and the parties' agreement ultimately determine these roles. Frepi may act as an independent controller for limited purposes it determines itself, such as its own account administration, billing, fraud prevention, security records and legal compliance.

What must the business tell its own customers?

Short answer: Its privacy notice should accurately describe business-platform processing, purposes, providers, retention, rights and marketing choices.

The business remains responsible for:

  • having a lawful basis for messaging and storing conversations;
  • providing required privacy notices;
  • honoring opt-outs and data-subject requests;
  • limiting staff access; and
  • assessing optional AI processing before enabling it.

Connecting a certified or verified provider does not transfer these controller obligations to Meta or Frepi.

Technology Provider

Meta

App ID 1233214825458555

Meta Technology Provider

Frepi is a Meta Technology Provider

Meta's business dashboard records Frepi's business verification and Technology Provider access verification as complete and grants Frepi Advanced Access to the WhatsApp business messaging and management permissions.

The independently checkable identifier is Meta App ID 1233214825458555. An unauthenticated Graph request for that id returns the name Frepi Platform. Meta does not issue a public Technology Provider certificate number.

Status recorded in Frepi's Meta Business dashboard on 1 September 2026. The lockup follows Meta's Partnering with Meta credit-line guidance. “Meta,” “WhatsApp,” and related marks belong to their respective owners. Meta did not author or audit this FAQ, and Technology Provider verification is not a standalone privacy or information-security certification.

Brazilian company information

FREPI TECNOLOGIA LTDA · CNPJ 52.979.451/0001-16

Rua California 233, Cidade Monções, São Paulo/SP, CEP 04.566-060 · Workspace data hosted on Google Cloud in São Paulo, Brazil (GCP Brazil) · henry@frepi.ai · Consult CNPJ at Receita Federal

Practical conclusion

The connection is controlled—not invisible

The honest customer answer

Coexistence does increase the number of authorized systems that can process a business conversation. Its value comes precisely from making supported conversations available to a business platform. Privacy depends on limiting that path to a documented purpose, protecting the credentials and copies, giving the business real controls, and explaining the flow accurately to customers.

  • Historical sharing is a separate, explicit choice.
  • The Frepi conversation is not currently a complete archive of app activity.
  • Enabled interactive or background AI creates an additional processing path.
  • Disconnection and deletion are separate operations with different residual copies.
  • Current remediation work must not be represented as an implemented control.

Primary documentation

Sources and controlling documents

  1. M1
    Meta · Onboard WhatsApp Business App users

    Coexistence operation, history consent, contacts, message echoes, feature limits and offboarding. Updated 26 June 2026 when reviewed.

  2. M2
    Meta · Embedded Signup

    Authentication, customer-scoped business tokens, permissions, asset selection and WABA subscriptions.

  3. M3
    Meta · Cloud API data privacy and security

    Encryption model, Meta's processor role, Cloud API processing and Meta message-retention limits.

  4. M4
    Meta · Managing webhooks

    Webhook subscriptions and business-account event delivery.

  5. F1
    Frepi · Privacy Policy

    Frepi data categories, purposes, AI providers, sharing, deletion, retention, security and controller/processor roles.

  6. F2
    Frepi · Data deletion instructions

    How to request deletion and the boundary between copies held by Frepi, WhatsApp and third-party inbox providers.

  7. F3
    Frepi · Terms of Service

    Service terms, customer responsibilities, AI processing, service availability, liability and contract hierarchy.

  8. F4
    Frepi · LGPD due-diligence package

    Draft DPA, security, subprocessors, transfers, retention, AI and incident materials are available for counsel review; drafts are not executed commitments until signed.