ONLY
The one rule that covers most of it: a safe exporter only reads. It never sends a message, never adds anyone, never automates. Reading your own contacts is invisible to WhatsApp's anti-spam systems; automation is what gets accounts banned.
The five things a risky exporter does
Most WhatsApp contact exporters look identical on their store page. The differences are in what the code actually does once it's installed. These are the five patterns worth avoiding — described generically, because they show up across many tools:
Some exporters upload the contacts they read — and a few even report your own WhatsApp number and a device ID back to their servers on every action. Once data leaves your machine, you can't unsend it.
Does everything on your device. The file is built locally and lands in your Downloads folder. Nothing is uploaded — it keeps working even with your network switched off.
A contact exporter only needs WhatsApp Web. If it requests access to all sites (or a long list of domains), it can read pages that have nothing to do with WhatsApp.
Requests one permission: WhatsApp Web. You can read the permission prompt at install and check it on the store listing before you ever click Add.
Some tools modify the WhatsApp Web page to show their own promos, upsells or banners. Anything that rewrites the page can also read everything on it.
Never changes WhatsApp. It reads the data already loaded in your session and leaves the interface exactly as WhatsApp built it.
A number of tools detect your location by IP and quietly raise or lower the price. You can pay more than someone in another country for the identical product.
Publishes one price for everyone, everywhere. No location sniffing, no surprises at checkout.
"Leave 5 stars to unlock." Beyond being against store policy, it tells you the ratings you're trusting were coerced, not earned.
Gives you the free features with no strings, and only ever asks for a review — it never gates anything behind one.
Your 6-point safety checklist
You can apply this to any WhatsApp exporter — Tooly included — in under a minute:
- Read-only. Does it only read, or can it also send/add/broadcast? Sending is the ban risk — avoid it.
- One permission. Does it ask for WhatsApp Web only, or access to all sites? Fewer is safer.
- On-device. Does it still work with your network off? If yes, your contacts aren't being uploaded.
- No page injection. Does WhatsApp look untouched while it runs? It shouldn't add banners or popups.
- Honest pricing. Is the price the same regardless of where you are? Watch for IP-based pricing.
- Earned reviews. Are features free without a forced rating? No "5 stars to unlock."
How Tooly answers all six
Tooly was built to pass its own checklist. Every line here is something you can verify — on the store listing, in the permission prompt, or by pulling the plug on your Wi-Fi mid-export:
Is exporting against WhatsApp's rules?
No. Your contacts belong to you, and reading them out of your own signed-in session is not automation. What crosses WhatsApp's line — and what actually gets accounts restricted — is doing things to the account: bulk-messaging strangers, auto-adding people to groups, or broadcasting. A read-only exporter never does any of that. Use the numbers you export responsibly and with consent: export is for organising the contacts you already have a relationship with, not for cold outreach.
Export your contacts the safe way
Read-only, on your device, one permission — and it shows you exactly what it read.
Add Tooly to Chrome — free