Security
How it works & your data
TextMyWorker is a small program that runs on your Mac and connects your Claude Code to WhatsApp. This page explains exactly what runs where, what data goes to whom, and what you control.
The short version
- It runs on your Mac, on your own Claude plan. We don't run a server in the middle, and we don't receive your messages or files.
- It only handles messages from the numbers you allow: by default, just yours.
- Permission requests are approved only when you tap Allow. No answer means nothing is approved.
- Your tokens and keys are stored in a file on your Mac that only your user can read.
Architecture
- On your Mac: a background service (launchd) receives your WhatsApp messages and runs them in Claude Code inside one folder you choose, your workspace. Hooks in Claude Code send you permission requests and summaries from your other sessions.
- The tunnel: Meta delivers messages to a web address. A tunnel from ngrok or Cloudflare forwards that address to your Mac, so nothing on your Mac is opened to the internet directly. The tunnel passes traffic through; TextMyWorker doesn't store anything outside your Mac.
- Claude: the worker is the Claude Code CLI you already use, signed in to your own Claude plan.
- Every incoming message is verified. Meta signs each delivery with your app's secret, and the service checks that signature before doing anything. It refuses to start without the secret.
What goes where
- Anthropic: your prompts, and the parts of your files that Claude reads while working on a task, the same as any Claude Code use. Your files themselves stay on your disk.
- Meta (WhatsApp): the messages between you and your worker, including voice notes, photos and documents you send, pass through Meta's WhatsApp Business Cloud API.
- ElevenLabs: voice notes are sent to ElevenLabs for transcription, then handled like text. No ElevenLabs key, no transcription.
- The tunnel provider (ngrok or Cloudflare): carries the webhook traffic from Meta to your Mac.
- Your Mac: photos and documents you send are saved in your workspace (an
attachmentsfolder). The activity log and the service's state and logs stay on your Mac too. - TextMyWorker (us): nothing. We don't receive your messages, files, prompts or keys.
Permissions
- Only your number. Messages from any number that isn't on the allowlist are ignored. By default the allowlist is just your number, and only your number can answer permission requests and questions.
- Default is no. When a Claude Code session on your Mac asks for permission and you've been away from the keyboard for a few minutes, you get Allow and Deny buttons on WhatsApp. If you don't answer within 5 minutes, nothing is approved and the request goes back to the normal dialog on your Mac.
- Only a tap counts. A permission is approved only when you tap Allow (or reply to that exact message). Typing “yes” into the chat doesn't approve anything, and neither does an emoji reaction.
- Back at your desk? As soon as you touch the keyboard or mouse, the request moves back to the normal dialog.
- The worker's own session (the one you text) runs Claude Code in its auto permission mode, inside your workspace folder. That's why the allowlist matters: keep it to your own number.
- Before anything leaves: the worker is instructed to draft emails, client messages, deletions and posts first, and ask you before doing them.
Secrets
Your Meta token and app secret, and your ElevenLabs and ngrok keys, are stored in one env file on your Mac with owner-only permissions (chmod 600). They're used only by the service on your Mac. The WhatsApp business number belongs to a Meta app in your own Meta Business account, so you can revoke its token at any time.
If you lose your phone
Your worker answers your WhatsApp number, so someone holding your unlocked phone could text it. To cut it off:
- Stop the service on your Mac (
./service.sh stop). Nothing is handled until you start it again. - Remove the number from the allowlist in your settings file, and restart the service.
- Recover your WhatsApp on a new phone. That signs the lost phone out of your account.
- If you think your Mac or your keys were exposed, revoke the token in Meta Business settings and create a new one.
We walk through these steps with you during setup.
Limits worth knowing
- Your Mac has to be on. While it's plugged in, the service keeps it awake and reconnects after sleep.
- WhatsApp only allows free-form messages within 24 hours of your last message. Outside that window, a short approved template goes out first and the full message follows when you reply.
- macOS only today. Windows and a Telegram backup channel are planned.
Questions
Ask the builder directly: eyal@textmyworker.com. See also Privacy and Terms.