Skip to main content

What this page covers

This page describes the telemetry of the licensing system (activation + heartbeat) — what powers the instance count for the Evolution Foundation.

Exact payload — activation

Sent once, on POST /v1/activate:
Headers:
Fields auto-extracted by the server (not sent explicitly):

Exact payload — heartbeat

Sent every 5 minutes, on POST /v1/heartbeat:

telemetry_bundle fields

The telemetry_bundle is a free-form JSON object. The server auto-extracts: Any extra field included in the bundle is stored in the telemetry_bundles table for future inspection, but is not part of default processing.

What features can contain

Common values observed in production:
  • chatbot — integration with Chatwoot, Typebot, Dify, n8n, etc.
  • broadcast — bulk send
  • webhook — configured webhooks
  • api-rest — REST API usage
  • s3 / minio — object-storage media
  • rabbitmq / sqs / websocket — event transport
  • cloudapi — WhatsApp official Cloud API
  • crm — Evo CRM integration
The exact list depends on the product version.

What is NOT in the payload

These fields are never sent, in any version:
  • Message content
  • Conversation identifiers
  • End-user WhatsApp numbers
  • Media (images, audio, video)
  • Webhook tokens or third-party API keys
  • Instance environment variables
  • Chatbot configurations
  • Database credentials
  • Application logs
  • Stack traces or internal errors
The presence of any of these in a payload would be a critical violation of the telemetry policy and treated as a critical bug.

How to audit locally

You can intercept the traffic to confirm what is being sent.

With mitmproxy

Each POST /v1/heartbeat shows up in mitmproxy with the full body, ready for inspection.

With tcpdump + jq

(TLS encrypts the content — to inspect JSON, use mitmproxy with a local CA installed.)

Inspecting locally in code

Evolution API exposes a debug endpoint that returns the last heartbeat sent:
Response:
The exact endpoint may vary by version. See the product changelog for details.

Frequency and cost

Estimated monthly traffic cost: < 3 MB per instance.

Data retention


Compliance

LGPD (Brazil)

  • Email and phone are processed under legitimate interest for the operation of the open source project
  • Operators can request data deletion via [email protected]
  • No natural-person profiling
  • instance_id is a random UUID, not derived from PII

GDPR (Europe)

  • Collection is proportionate and necessary for the registration to work
  • Right to erasure preserved
  • DPO via [email protected]

Future changes

Any change to telemetry will be:
  1. Announced in the product changelog
  2. Documented on this page
  3. Shipped as a release candidate before the stable release
If a new collected field is added, it will appear explicitly in the “Exact payload” section above.

Reporting inconsistencies

If you observe any field being sent outside what is documented on this page, report it as a security bug: Undocumented telemetry issues are treated as high priority.