What this page covers
This page describes the telemetry of the licensing system (activation + heartbeat) — what powers the instance count for the Evolution Foundation.Exact payload — activation
Sent once, onPOST /v1/activate:
Exact payload — heartbeat
Sent every 5 minutes, onPOST /v1/heartbeat:
telemetry_bundle fields
The telemetry_bundle is a free-form JSON object. The server auto-extracts:
Any extra field included in the bundle is stored in the
telemetry_bundles table for future inspection, but is not part of default processing.
What features can contain
Common values observed in production:
chatbot— integration with Chatwoot, Typebot, Dify, n8n, etc.broadcast— bulk sendwebhook— configured webhooksapi-rest— REST API usages3/minio— object-storage mediarabbitmq/sqs/websocket— event transportcloudapi— WhatsApp official Cloud APIcrm— Evo CRM integration
What is NOT in the payload
These fields are never sent, in any version:- Message content
- Conversation identifiers
- End-user WhatsApp numbers
- Media (images, audio, video)
- Webhook tokens or third-party API keys
- Instance environment variables
- Chatbot configurations
- Database credentials
- Application logs
- Stack traces or internal errors
How to audit locally
You can intercept the traffic to confirm what is being sent.With mitmproxy
POST /v1/heartbeat shows up in mitmproxy with the full body, ready for inspection.
With tcpdump + jq
Inspecting locally in code
Evolution API exposes a debug endpoint that returns the last heartbeat sent:The exact endpoint may vary by version. See the product changelog for details.
Frequency and cost
Estimated monthly traffic cost: < 3 MB per instance.
Data retention
Compliance
LGPD (Brazil)
- Email and phone are processed under legitimate interest for the operation of the open source project
- Operators can request data deletion via
[email protected] - No natural-person profiling
instance_idis a random UUID, not derived from PII
GDPR (Europe)
- Collection is proportionate and necessary for the registration to work
- Right to erasure preserved
- DPO via
[email protected]
Future changes
Any change to telemetry will be:- Announced in the product changelog
- Documented on this page
- Shipped as a release candidate before the stable release
Reporting inconsistencies
If you observe any field being sent outside what is documented on this page, report it as a security bug:- Email:
[email protected] - GitHub Security Advisory: evolution-api/security/advisories