CONTACTS AND AUDIENCES
Build an audience you can defend
An audience is a list you can explain to the person who asks why they were messaged. That means a filter you can read back, an export that never leaves your browser, and a build that stops when it cannot see the opt-out list.
Everybody who has ever messaged one of your connected numbers is a contact, and so is every member of a group those numbers are in. The question this page answers is not how to store them — it is how to choose a defensible subset of them and prove later which subset it was.
What you can filter on
Eighteen filters, and the useful ones are about behaviour rather than fields.
When they last wrote
The filter most audiences are really about: somebody who messaged this month is a different proposition from somebody who messaged last year, and a free-text reply is only allowed to one of them.
Which number they reached
A contact belongs to the number they wrote to. An audience can be scoped to one number, which is also what keeps a campaign sending from the number the conversation already happened on.
Whether they came from an advert
A contact who arrived by tapping a Click-to-WhatsApp advert carries that fact, so an audience can be the people one campaign brought in.
Which groups they are in
Members of selected groups, or everybody who is not in them. Group members are contacts here, which is a deliberate reversal of how this product once worked.
Country, number type and marks
The country a number was allocated in, whether the range is a mobile or an internet line, and whether somebody has marked the contact suspicious or blocked them.
Where the contact came from
Added by a direct message, or added from a group. An audience of people who have actually written to you is a different list from an audience of group members, and the filter keeps them apart.
The export is built in your browser
The rows never pass through a third party, because they never leave the page.
Choosing export does not post your contact list to a file service and hand you a link. The rows are already on the page; the CSV is assembled in the browser and the download is a local file. There is nothing to expire, nothing to leak and nothing to delete afterwards.
Reading a spreadsheet works the same way round, and it carries one refusal worth knowing about: a phone number a spreadsheet saved in scientific notation is rejected rather than imported. By the time a number reads as 9.71E+11 its last digits are already gone, and an audience built from it would message whoever now owns the number it rounded to.
What makes a build refuse
Each of these is a build that produced nothing rather than a list that was quietly wrong.
The opt-out list could not be read
The build fails closed. A missing suppression list does not widen an audience here; it stops it. This is the one failure on the page that cannot be taken back once a send has happened.
The block list could not be read
Same answer, same reason. Somebody who was blocked must not reappear in a list because a query timed out.
An exclusion could not be resolved
If an audience is defined as these people, minus that list and the minus cannot be read, the build is refused. A missing exclusion must never widen a list.
It is larger than the ceiling
Past the member ceiling the build is refused outright and the previous members are kept, so a mistake in a filter does not destroy a list that was already correct.
An audience remembers how it was made
A saved audience holds either the members themselves or the filter that produced them. Only an explicit refresh re-runs a stored filter, and it runs as the person who pressed it — so an audience cannot quietly grow overnight, and it cannot quietly grow because somebody with wider access opened it.
Removing a person by hand is recorded as an exclusion rather than a deletion, which means a later refresh cannot put them back. That is the difference between a list you can defend and a list that happens to be right today.
The honest limit
WhatsApp does not always tell us a contact’s phone number. On an account it has migrated to identifier-only addressing, a one-to-one contact arrives as an opaque identifier and no amount of later traffic reveals a number — it is decided at WhatsApp, per account, and re-linking the number does not reverse it.
Such a contact is shown as hidden rather than as a number we guessed. They can be replied to in the inbox; they cannot be exported as a phone number, and an audience keyed on a number will not contain them. The transport that does return a customer’s number is the official one, which is a genuine reason to be on it.
Where it sits
Marketing campaigns
What an audience is for, and the claim that stops a retry sending twice.
Team inbox
Where a contact’s conversation lives, and who may open it.
How we protect your data
Where the contacts are stored and how long each thing is kept.