Privacy
What Metrics helps you follow Whatnot live shows and manage your selling activity in a connected workspace. This policy explains the account, sales, show and message information we handle, how we use it, where it goes, and the controls and limits on keeping or deleting it.
Last updated September 14, 2026
Draft pending legal review.
This page is written in plain language to describe how What Metrics works right now. It has not been reviewed by a lawyer and it is not a final legal document. Wording will change when review is done.
The short version
- We store your workspace, your catalog and costs, the contents of the reports you upload, and buyer usernames with state and country when your own report includes them.
- Stream recording stores other people. On any show that gets recorded we keep the host's handle, the audience count each minute, every chat line with the handle that wrote it, and each lot with its price and the handle that won it. On someone else's show those are people who have not been asked and have not been told. It is the part of this page worth reading twice.
- When inbox syncing is enabled and website access is granted, the extension reads conversations available to your signed-in Whatnot account from an open Whatnot tab and sends conversation information and the latest available message to your What Metrics workspace. Replies you choose to send are delivered through your browser and recorded in the workspace.
- We filter address, email and phone columns from parsed report rows. Uploaded originals are kept unchanged, and message text is not filtered for contact details, so those files and messages can contain personal information.
- We never store your Whatnot password, session cookie or refresh token. Our worker watches shows from its own browser signed in to its own Whatnot account, never yours.
- Your rows live in Supabase in the United States, and row-level security scopes every row to one workspace.
- You can export supported workspace records or schedule workspace deletion from Settings. Inbox records are not included in that export and do not have an individual deletion control or automatic expiry. The controls and limits are explained below.
What we store
- Your account
- Your email address, the display name you choose, when you last signed in and when you last had the app open, and which workspaces you belong to and in what role.
- Your workspace
- Workspace name, currency, timezone, primary category, the members you invite and their roles, and your plan and billing status.
- Catalog and costs you enter
- Items, lots and purchase costs, supplies, templates, show plans, notes and tags — everything you type into What Metrics yourself.
- The contents of reports you upload
- Every row of the Show Report and Weekly Orders Report you download from your own Whatnot Seller Hub: order ids, item titles, sale prices, fees, refunds, shipping charges and payout totals. We also keep the file itself, byte for byte as you uploaded it, so an import can be re-run or corrected and so you can see where a number came from. That file is not filtered the way the rows are — see the first item under What we never store.
- Recordings of live shows
- When a show is recorded — by the extension on a page you have open, or by our worker on a seller you added to your research list — we store the show's title and category, the host's handle, the audience count each minute, every chat line the page displayed with the handle that wrote it, a per-handle tally of how much each person chatted, and each lot with its title, price, closing time and the handle that won it. On your own show those winners are your buyers. On anyone else's they are third parties, and neither they nor the host has agreed to any of this. The live room's video never leaves your computer: the extension hands it from your Whatnot tab to the What Metrics tab inside your browser, and nothing of it is stored.
- Buyer records built from those reports
- The buyer username, plus state and country when your own report includes them, and the order counts and totals we compute from your rows. Nothing else about a buyer, and nothing bought or enriched from anywhere else.
- Your Whatnot inbox and replies
- With inbox syncing enabled, we collect conversation identifiers, the other participant's username and identifier, the latest available message text, its direction and type, attachment counts, and the time the extension observed the conversation. The extension transmits the latest message body; the current inbox storage retains conversation previews and available conversation metadata. Confirmed replies sent through What Metrics are stored with their body, message identifier, time and the workspace member who sent them. We also store reply templates you create and their usage counts. This is not a complete copy of your Whatnot message history. Message text can contain personal or sensitive information that you or the other participant included.
- Operational records
- Import history, browser-extension pairings and heartbeats, permissions and their changes, diagnostic information, and an audit trail of destructive actions. Supported Whatnot page URLs, show titles, identifiers and observation times connect activity to the correct show. The extension handles show-opening clicks and keyboard activation to open its side panel. Hosting logs can contain IP addresses, request URLs and timestamps, and IP addresses are used to limit abusive requests. The audit trail keeps before-and-after copies of edited or deleted order rows that a buyer wipe does not reach.
How the extension handles data
The extension holds access to whatnot.com and to no other site. Chrome grants it when you install the extension, as part of the install dialog, and the extension cannot widen it afterwards. Earlier versions asked for access to all websites and requested it later, on your click; the current package asks for less and asks at install instead. The reader still checks the hostname, and it records no history of unrelated websites because it cannot read them. Show recording, earlier-sales loading and inbox syncing are all on from installation, and each has its own switch in the extension that turns it off.
An open, signed-in Whatnot tab lets the extension make requests to Whatnot using that browser session. Inbox syncing can run from any Whatnot page; you do not need to open each conversation or keep the inbox page visible. Each read retrieves the latest available message per conversation, not its earlier history. Messages between reads can be missed. If Whatnot does not supply a send time, we leave it unknown rather than treating the observation time as the send time. Attachment counts may be transmitted, but this inbox path does not upload attachment files to our workspace storage.
Captured information is sent to the What Metrics workspace paired with the extension. Workspace members can access its stored inbox records. Sending is restricted by workspace permissions: when a user initiates a reply, a packaged extension script submits that text and conversation identifier to Whatnot through an open signed-in tab. Whatnot and the recipient receive the reply. We record a sent reply after Whatnot confirms it; syncing does not automatically compose or send replies.
The extension uses Chrome local and session storage and IndexedDB for settings, pairing information, What Metrics authentication tokens, cached show data, diagnostics and records awaiting synchronization. What Metrics tokens authenticate the connection to your workspace; they are separate from your Whatnot login. Clipboard access is used only to copy diagnostics when you request it, and does not read your clipboard. Executable code is bundled with the extension; remote requests retrieve or send data, not executable code.
What we never store
- Address, email, phone and postcode columns as parsed report fields: columns with those headings are filtered before the rows are stored. Buyer-name and city columns may remain. This filter does not apply to uploaded original files, inbox messages, live chat or text you enter yourself, which can contain contact details.
- Private Whatnot conversations that are not accessible to the signed-in account you connect. Watching another seller's public show does not give us access to that seller's private inbox.
- Your Whatnot password, session cookie or any Whatnot token.
- Card numbers or bank details. There is no payment flow in the product today: billing is switched off, nothing charges you, and no payment processor receives anything. When billing is turned on, card details will go to that processor directly and this page will name it before it happens.
- Another seller's private costs, fees, payouts or reports merely because you watch their public show. Reports you upload and information shared in a conversation you connect are separate sources described above.
The first line is about the database, and it would be misleading to leave it there. The filter runs on the rows parsed out of your file, not on the file. The file itself is uploaded whole to a private storage bucket and kept until you delete the import, because an import you cannot re-run from the original is an import you cannot audit. So if the export you downloaded from Whatnot contained a shipping address, that address is in that stored file even though the corresponding parsed report column is filtered. Anyone who is a member of your workspace can download it, whatever their role. Deleting the import deletes the file with it, and deleting the workspace takes both.
We do not collect your Whatnot password or copy your Whatnot session or refresh token to our servers. The extension does not request Chrome’s cookies permission. It can nevertheless read earlier sales and inbox data, and send a reply you initiate, through requests made inside your signed-in Whatnot tab. The browser attaches its session credentials to Whatnot requests; page-accessible request-verification values may also be used within that tab. Those credentials are not included in the records synchronized to What Metrics. Not having cookies permission does not mean the extension cannot access your inbox.
What our servers do reach for is Whatnot’s own public browse feed, which is how the worker knows which shows are live. It never signs in as you: it runs a browser of its own, on a Whatnot account of ours, and your credentials are never involved in it. When it then watches a seller you put on your research list, what it records is the same set the extension records — the audience count, the lots that closed with their prices and the handle that won each one, and public chat with the handle that posted each line. Chat is sampled while it is watching rather than fetched as a complete history, because a show page only keeps the last stretch of chat on screen; the winners and the lot prices are not sampled, they are every lot it saw close.
Where it goes
Your data is stored in Supabase (Postgres) hosted in the United States. If you are outside the US, using What Metrics means your data is processed in the US.
Every tenant row carries a workspace_id, and Postgres row-level security policies scope every read and write to workspaces you are a member of. Queries in the app filter by workspace on top of that, so a bug in one layer is not enough to cross workspaces. Traffic is encrypted in transit and data is encrypted at rest. A small number of What Metrics staff can reach production for support and incident response; that access is logged.
We do not sell your data, and we do not share it with advertisers or data brokers.
We use extension data to provide show analytics, synchronize your workspace, display connected conversations, deliver replies you initiate, and maintain and secure these features. We do not use or transfer it for unrelated purposes, personalized advertising, determining creditworthiness or lending. What Metrics’ use of extension data follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
Data is shared with the service providers below to operate these features and with members of the workspace you connect. Replies you send also go to Whatnot and the intended conversation recipient. We may disclose information where required by law or necessary to address security incidents. Human access to extension data is limited to the purposes permitted by the Chrome Web Store policy, such as specific support access you authorize, security investigations and legal requirements.
Sub-processors
These are the companies that process data on our behalf. We update this list before adding a new one.
| Service | What it does | What it sees |
|---|---|---|
| Vercel | Hosting and request processing for the web app and extension API | Account, workspace, show and message data processed by application requests. Hosting request logs can include IP address, URL and timestamp; the primary workspace database is in Supabase. |
| Supabase | Database, sign-in and file storage | Account and workspace records, stream recordings, inbox conversations and sent replies, reply templates, and uploaded report files. US region. |
| Anthropic | Summaries of the chat on your own shows, a short read while your own show is live, and reply drafts in Messages when you ask for one | For a chat summary: chat lines from your own shows, the show's title, category and lot titles, with usernames replaced by u1, u2 or someone before they are sent. For a live read: the newest 80 lines of your own show's chat, whatever their age, with usernames replaced the same way, the show's title and category, the lots that just closed, the audience count and the sales figures so far. For a reply draft: the buyer's username, that conversation, what you typed, your shop's name, and a summary of that buyer's purchases from your shop and the lots they won in other shows recorded in your workspace. |
Three, and that is the entire list. While chat summaries are on in Settings, Anthropic receives the chat of your own shows, the show’s title, category and lot titles, with usernames replaced by u1, u2 or someone. When you ask it to draft a reply, it receives the buyer’s username, that conversation, what you typed, your shop’s name, and a summary of that buyer’s purchases from your shop and the lots they won in other shows recorded in your workspace — research or stalking targets included, not only your own. There is no error-reporting service, no product-analytics service and no email provider behind What Metrics today.
While you are live, the live room can send Anthropic the newest 80 lines of your own show’s chat, however long they took to arrive, with handles replaced by u1, u2 or someone, together with your sales pace, and gets back a two-sentence read. The chat summaries switch turns this off too.
How long we keep it
These are the windows the product runs to, and they are enforced by a job that runs every night. Say plainly what that job is: it is new. For most of this product’s life nothing expired on a timer at all, and the schedules that were supposed to enforce these windows were written into the schema and left switched off. If your workspace holds rows older than the windows below, they are being removed by the first passes of that sweep rather than having gone already.
- Workspace data — catalog, shows, orders, imports, buyer records — is kept while your workspace exists, because the point of the product is a running history you can compare against.
- The row-by-row copy an import makes of your report is kept for 90 days and then removed. The orders and line items it produced stay; it is the intermediate copy that goes.
- The report file itself is kept while its import exists, so the import can be re-run or audited. Delete the import and the file goes with it.
- The raw record of what a paired browser sent — kept so a figure in your ledger can be traced back to the observation that produced it — is removed 180 days after it has been processed.
- A pairing request that expired without being used is removed a day later.
- Inbox conversation records, stored message previews, confirmed replies and reply templates have no automatic age-based expiry in the current product. They remain until removed through a support request or the workspace is permanently deleted. The 90-day live-chat retention window does not apply to private inbox records.
- Local extension show recordings expire after a day without being seen. Other local buffers follow the extension's retention settings; settings and pairing information remain until cleared or the extension is removed. Removing the extension or disabling syncing does not delete records already synchronized to the server.
- Stream recordings are split. What the recording says about a business — the show, its audience curve, its lots, their prices — is kept while your workspace exists. What it says about a person is not: chat lines and the handles that wrote them, the per-handle chat tallies, and the handle recorded as winning a lot are removed 90 days after the show. The host's handle stays while that seller is on your research list and goes when you remove them.
- Buyer records can be wiped in one action without touching your orders or financial totals; the orders simply stop naming a buyer.
- Handles marked VIP in the live room stay until the mark is removed or the workspace is deleted. The live room's reads hold no usernames and go with the show's recording.
- The audit trail of destructive actions is kept for the life of the workspace and is not swept, because its whole purpose is to answer a question about something that was deleted. Be aware of what that means: it holds before-and-after copies of any order row that was edited or deleted, a buyer wipe does not reach those copies, and owners and admins can read and export them.
Exporting or deleting your data
The following controls are available in Settings → Privacy & data:
- Export a machine-readable copy of the supported workspace tables. The job produces a ZIP of CSV files in private storage and posts a notification when it is ready. This is not a complete export of everything we hold: inbox conversations, inbox messages and reply templates are not included, and the archive lists other exclusions. Download links expire, so download the file instead of saving the link. Ask support for access to records outside the standard export.
- Delete every buyer record in the workspace. This removes the buyer profiles and every note written about them; your orders keep their rows and stop naming a buyer.
- Delete the whole workspace (owner only). Deletion has a 30-day grace period during which an owner can restore it. The scheduled permanent deletion removes workspace rows and uploaded files, including inbox conversations, their stored messages and reply templates. A paired browser can continue submitting records during the grace period; disable extension capture or remove website access if you want collection to stop immediately.
- Stop future inbox reads by turning off Bring your Whatnot messages into What Metrics in the extension settings. You can also disable the extension or revoke its website access in Chrome. These controls stop future reads; they do not erase stored messages or recall replies already delivered to Whatnot.
- Pause recording, which stops every connected browser at once, or turn chat summaries on or off — both switches are in Settings, beside Connected browsers.
Some records do not have an individual deletion button. Inbox conversations and stored messages are among them: contact support to request their export, correction or deletion. Deleting a buyer profile does not delete that buyer’s inbox conversations. A recording of your own show is not attached to a research entry, so there is nothing to delete it from: it goes when its 90-day window reaches the handles in it, or when the workspace goes. And there is no way to erase one person — a single chatter, a single lot winner — from the recordings you hold. Both are gaps in the product, not positions we have taken.
If you are in a place with a statutory right of access, correction, portability or erasure, these controls are how you exercise it. If something you need is not covered by a button, ask us and we will do it by hand.
Cookies
We set a sign-in session cookie and a small cookie that remembers which workspace you last had open. That is all. No advertising cookies, no cross-site tracking pixels.
Changes and contact
If we change what we collect or add a sub-processor, we will update this page and, for anything material, tell you in the app. We say “in the app” rather than “in the app or by email” because there is no email provider behind What Metrics yet, so a notice in the product is the only channel that actually exists. Questions about your data: use the support link inside the app.