Data policy
Whatnot Metrics is deliberately narrow about where its data comes from. This page says what we read, what we refuse to read, and what we will never build — and why those limits exist. It also says the uncomfortable part out loud: recording a live show records the people on it, and they never agreed to anything.
Last updated September 2, 2026
Draft pending legal review.
This page is written in plain language to describe how Whatnot Metrics works right now. It has not been reviewed by a lawyer and it is not a final legal document. Wording will change when review is done.
What we read, what we never read, where it goes
| What we read | What we never read | Where it goes |
|---|---|---|
| Reports you uploadThe rows of the Show Report and Weekly Orders Report you download from your own Whatnot Seller Hub: order ids, item titles, sale prices, fees, refunds, shipping and payout totals. | whatnot.com itself. An import reads the file you uploaded and nothing else: it never signs in as you, and we never see your Whatnot password or session. Columns headed like an address, an email address, a phone number or a postcode are dropped before any row is stored. | Your workspace only, behind row-level security. The file itself is kept, unchanged, so an import can be re-run or audited — which means the dropped columns are still in that stored file even though no database column holds them. Delete the import and the file goes with it. |
| What you type inItem costs, lots, supplies, templates, show plans, notes and sales you log by hand during a show. | Anything you did not type. We do not guess costs from outside sources or buy data about your business. | Your workspace only. Every money value carries a provenance tag so you can see it came from you. |
| Optional browser extensionThe item, price and time of a sale you confirm yourself, plus its own version number and a heartbeat so you can tell it is alive. Once you grant it the Chrome host permission it reads pages too, and the biggest thing it reads then is the row below. | Any page at all until you grant that permission, which Chrome lets you revoke at any moment. The inside of a conversation, anywhere. Anyone else’s messages. Buyer addresses, emails or phone numbers. | Your workspace only, as reviewable events. Unpair a device in Settings and it stops sending immediately; Pause recording on Settings › Extension stops every paired device at once. |
| Stream recordingEverything a live show page displays. From a show you have open in your own browser, and from a seller you put on your research list for our worker to watch: the show's title and category, the host's handle, how many people are in the room each minute, every chat line with the handle that wrote it and a running tally per handle, and each lot as it closes with its price and the handle that won it. With the sold-list history read switched on, also the lots that closed before the show was opened — title, price, quantity, settlement time and winning handle — asked for from Whatnot's own web API. | Who is watching — we keep how many, never a list. Who placed a bid — we keep how many bids a lot drew, never the bidders. Any page that is not a public show page, and any site that is not Whatnot. The extension reads a tab you opened and stops when you close it; the worker watches only handles you added to the list yourself. | Your workspace only, under Research, and never pooled with another customer's. Delete a tracked seller and every stream, lot, chat line and chatter under them goes too. A recording of your own show has no tracked-seller entry and therefore no delete button — the handles in it age out after 90 days, and the rest goes when the workspace does. |
| Your own inbox (off by default)With this switched on, and only while you have your own Whatnot inbox page open in your own browser: the list that page has already drawn for you — each correspondent’s handle and picture, the short date on their row, and the one-line preview of the last message. Every conversation on that page is one you are already part of. | The inside of a conversation. Nothing opens a thread and nothing reads a message body; the preview line is what the list itself prints. Nobody else’s inbox, ever, and not yours either unless you are looking at it — there is no way for us to reach it while your browser is closed, and that is a limit of what we hold rather than a policy we could change. | Your workspace only, under Inbox. It is exactly as current as the last time you opened that page, and every figure on it says so. |
| Buyer recordsBuyer usernames, plus state and country when your own report includes them, and counts and totals we compute from your rows. | Street addresses, email addresses, phone numbers, payment details, or anything enriched from elsewhere. | Your workspace only. One action deletes every buyer record without touching your financial totals. |
The four ways data reaches Whatnot Metrics
There are exactly four, and each one starts with an action you take. This section listed three for a long while, with stream recording folded into the extension — which was wrong in the direction that mattered, because recording is the one channel that collects people who are not you.
- 1. Official exports you upload
- You download your Show Report or Weekly Orders Report from your own Whatnot Seller Hub and upload the CSV or XLSX here. This is the main source of truth for money: sale prices, fees, refunds, shipping and payouts all come from a report you exported yourself. Copy on screen says imported from your Whatnot report, because that is what happened — nothing here is synced.
- 2. Manual entry
- What a report cannot know: what an item cost you, which lot it came from, supplies, your plan for a show, and sales you log by hand while you are live. You type it, so you own it, and each money value is stamped with where it came from.
- 3. The optional browser extension
- A convenience for live shows, and off unless you pair it. On its own it is a button — you confirm a sale, and it sends that item, price and time to your workspace. It can also read pages, and that needs a Chrome host permission you grant at runtime and can revoke at any moment from chrome://extensions. Be clear about what happens when you grant it: stream recording is on from that point, and so is the sold-list history read, because both ship on and neither waits for a second switch. What they then do is the channel below. The Seller Hub orders surface and the inbox surface are the other way round and stay off until you find them and turn them on. All four are switches in the extension's Options, whichever way they start. It never opens a tab, and never clicks, bids, posts or types anything for you. It does send requests to whatnot.com in one case: with the sold-list history read switched on, it asks Whatnot's own web API for a show's settled lots and status, from the tab you already have open. Those are read queries and change nothing there. Unpairing it in Settings stops it at once.
- 4. Stream recording
- Recording a live show is its own channel because it is the only one that collects people who are not you, and folding it into the extension hid that. Two things record: the extension, on a show page you have open, and our worker, which watches the sellers on your research list from its own browser signed in to its own Whatnot account, whether or not you are at your desk. Both record the same set — the show and its category, the host's handle, the audience count each minute, every chat line with the handle that wrote it, and each lot with its price and the handle that won it. On your own show those winners are your buyers, and that is how buyer records get built without an import. On another seller's show they are strangers: they were not asked, they were not told, and no switch of theirs governs it. That is a real cost of this feature and we would rather write it here than have you work it out from a table. What we hold it to is in the two sections below, and how long we keep the names is on the Privacy page.
What we will never build
- Chat or DM automation
- No auto-greeting, no auto-replies, no bulk messages to buyers, no templates that send. Whatnot Metrics writes nothing anywhere on Whatnot, and there is no button in it that would. Reading is a separate question and the answer is not “nothing”: we record public chat, with the handle on every line, from a show you opened and from a seller you put on your research list, and with the inbox switch on we record the conversation list your own inbox page draws for you. What we will never build is the half that acts — sending on your behalf, in a show's chat or in anybody's inbox. The other limit here is narrower than it sounds and is worth stating exactly: your inbox is only ever read while you have that page open in front of you, because we hold no credential of yours and could not reach it otherwise. A public show is different — our worker watches the sellers you listed from its own browser, so recording a show does not need you at your desk.
- Bidding or buying
- Whatnot Metrics will never place, raise or cancel a bid, and will never buy anything on anyone's behalf.
- Giveaway automation
- No entering giveaways, no picking winners on Whatnot, no automated follow or share actions.
- Pooling buyers across customers, or selling what we record
- Be clear about what this does and does not promise, because an earlier version of this page overclaimed and we would rather correct it in public than quietly. Stream recording DOES record the handle of whoever won each lot, and public chat with the handle that posted it — that is what the buyer views are built from, and it is other people's names, kept. What we will never build is the thing that makes that dangerous: your recordings and another customer's are never pooled into a shared buyer graph, no handle we record is ever sold, shared or used to advertise, and nothing recorded about a buyer leaves the workspace that recorded it. We also do not record who is watching a show, only how many, and we record how many bids a lot drew, never who placed them. And the names we do keep no longer keep themselves: chat lines, the per-handle chat tallies and a lot's winning handle are removed 90 days after the show. That window is new — for most of this product's life those rows had no expiry at all — so it is a promise about what happens from here, not a description of something that has been running quietly all along.
- Harvesting the catalogue
- No crawler walking whatnot.com to collect listings, prices or sold data wholesale, and no headless browser doing it quietly. What our worker reads is Whatnot's own public browse feed — the same list of live shows the site puts in front of anyone — and then the public page of a show while it is running, at the pace a viewer watches it. It reads no page that requires your account and takes no action on the site. It is signed in, and to its own Whatnot account rather than nobody's: a show's lot panel does not render for a signed-out viewer, so without that account it could record the audience and the chat and never a sale, a price or a winner. Your credentials are not involved in it and never could be. That is the sentence that matters, and it is not the same claim as "nobody is signed in", which is what this said before and was not true. The extension reads only a tab you opened and left open, and stops the moment you close it.
- Signing in as you, or holding your Whatnot session
- We never store your Whatnot password or your payment details, and we never store or relay your Whatnot session or refresh token to our servers — not to make one request on your behalf, not for a minute, not at all. This is a limit you can check yourself rather than a promise you have to take on trust: open chrome://extensions, click Details, and read the permissions. The extension does not ask for Chrome's "cookies" permission, and without it no code we ship can reach your Whatnot login cookies at all — those are httpOnly, which puts them beyond the page-level access a content script has. Some tools in this category do request that permission and relay the whole cookie jar, refresh token included, to their own servers; it is how they read your inbox or your sold list while your browser is closed. We cannot do that, and the limit it puts on us is worth stating exactly rather than roundly, because an earlier version of this page rounded it and we would rather correct that in public than quietly. That version said we never read your Whatnot direct messages. Since the Inbox feature there is a switch, off until you find it and turn it on, that records the conversation list your own inbox page has already drawn — handles, dates and the one preview line each row shows — while you have that page open in front of you. It opens no conversation and reads no message body. What has not changed is the part that was ever load-bearing: we hold no credential, so we cannot read your inbox when you are not looking at it, we cannot read it from our servers, and we cannot read anybody else’s at all. The tools that can do those things are the ones that took the cookie.
Why these limits exist
Whatnot’s Terms of Service prohibit automated use of the platform, scraping or otherwise harvesting data from it, and sending unsolicited messages to its users. A tool that automates chat, bids for you, or crawls public pages is not a grey area — it puts the seller’s own account at risk of suspension, and the seller is the one who loses the shows and the payouts, not the tool vendor.
The distribution risk is just as real. The Chrome Web Store has removed extensions that automated chat. The line we hold is between reading and acting: nothing here takes an action on Whatnot — no click, no keystroke, no post, no bid, no message, and no request that changes anything. That is checked at build time, not merely promised: the extension will not package if its page reader contains a GraphQL mutation or names any origin but Whatnot’s.
Reading is not free of cost, and we will not pretend otherwise. Not everything the extension reads is already on your screen. With the sold-list history read switched on, it asks Whatnot’s own web API for a show’s settled lots, a page at a time, and for the show’s status — the same operations the show page uses for itself, sent from the tab you already have open, using the Whatnot session already in that browser. That is a real, if small, load on Whatnot: a show of a thousand sales is ten pages. So we bound it. The read starts once per show per page load, retries at most five times if you turned out to be signed out, re-reads the tail at most twelve times while the show is still running and not once after it ends, stops at a hard cap of 400 pages, and makes no request at all unless you switch it on. Every surface is off until you turn it on, this read has its own switch on top of that, and the permission behind them all is optional and revocable.
There is a product reason too. Numbers you can defend have to come from a source you can point at. Every figure in Whatnot Metrics traces back to a report you exported or a value you typed, which is what makes it usable for tax, for pricing and for arguing with your own past decisions.
The honest cost of that: Whatnot Metrics is only as current as your last import. A show’s true fees settle when the report lands, so figures during a live show are your own estimates until then.
Related
- Privacy — what we store, where it lives, who processes it, and how to export or delete it.
- Terms — beta software, as-is, and an independent tool.
- Settings → Privacy & data — the switches themselves, once you are signed in.