Masking & privacy
How Relay keeps customers' phone numbers hidden from agents.
Overview
Privacy is built into Relay, not bolted on. Agents handle conversations without ever seeing the customer's WhatsApp phone number. This protects your customers and means you can let staff work the inbox without handing them a contact list.
What agents see
Every contact is shown to agents as a masked alias — Customer 0001, Customer 0002,
and so on. The real phone number lives only in the server and is never sent to an agent's
screen, nor put in a message id, a media filename, or a log line.
An agent sees a real name only when the conversation is linked to a customer record in your directory — and even then, the phone number stays hidden. The alias itself never changes; the name is shown from the linked record.
The one exception
One permission lifts the mask: Manage customers. An agent with it can open the customer directory, which shows real phone numbers (that's how they manage it). Everyone else — including agents who can link customers but not manage them — never sees a number.
Note: Because Manage customers exposes phone numbers, treat it as your most sensitive permission and grant it only to staff you trust with that data. See Agents & permissions.
Workspace isolation
Each workspace is sealed off. A contact belongs to the workspace whose number they messaged — so the same person writing to two different workspaces' numbers is two separate, independent contacts, with no shared history. Nothing a customer sends in one workspace is ever visible in another.
What this means in practice
- Agents can be given inbox access safely, without exposing your customer list.
- Reserve Manage customers for a small, trusted group.
- Names come from your directory; the underlying number stays masked throughout.
Next steps
- Agents & permissions — grant the right access per person.
- Customer directory — link chats to names.