Skip to content

WhatsApp ChatGPT Assistant That Answers Only Fitness Questions

Three Node.js APIs connect WhatsApp to ChatGPT for a fitness business, keep off-topic messages out, strip personal details and tie each chat to a license.

Software products and SaaSA fitness software business with licensed users ยท 4 min read

Gym member checking his phone while resting on a racked barbell, red machines behind
Client
A fitness software business with licensed users
Industry
Software products and SaaS
Platforms
WhatsApp
Download one-pager (PDF)
  1. The challenge

    The business wanted its licensed users to ask fitness questions on WhatsApp and get answers from ChatGPT. Off-topic messages had to stay out, every conversation had to belong to a valid user, and users' personal details could not be handed to the AI model.

  2. What we built

    We built three Node.js APIs with a MongoDB database. One connects to the WhatsApp Cloud API, one to the ChatGPT API, and a core backend links to the client's API manager. A filter passes only fitness-related messages on, and phone numbers and personal details are removed before any text reaches ChatGPT.

  3. The result

    Users message on WhatsApp in text, audio or image and receive text replies. Each chat session is stored against the user's license, new users are registered on first contact, and ChatGPT only ever sees de-identified, fitness-related text.

What the system does.

The parts of the system that made the difference for the client and the people who use it.

  • Fitness-only filter

    Only fitness-related content is forwarded to ChatGPT; anything else never reaches the model.

  • Personal details removed

    Our backend API strips phone numbers and personal details, or swaps them for placeholders, before any text goes to ChatGPT.

  • License-linked sessions

    Session IDs are created and stored against each user's license, so replies are matched to the right person inside the client's system.

  • Text, audio and image in

    The WhatsApp API receives all three message types and answers in text, in a standard message format.

  • Registration on first contact

    The core backend registers new users through the client's API manager and opens their first chat session.

  • Documented APIs

    Each API shipped with setup instructions, endpoint details and testing reports.

Built with

The tools behind it, layer by layer.

  1. Back end

    • Node.js
    • Express.js
  2. Database

    • MongoDB
  3. AI

    • OpenAI API
  4. Cloud and hosting

    • AWS
  5. CI/CD and DevOps

    • GitHub Actions
    • Git
  6. Integrations

    • WhatsApp Cloud API

The full story

The challenge

A fitness software business wanted its users to get answers where they already spend their day: on WhatsApp. It chose ChatGPT to write those answers and asked us to build a WhatsApp ChatGPT chatbot for fitness that it could trust.

Trust meant three rules. Only licensed, paying users should get answers. The assistant had to stay on fitness instead of turning into a general chatbot that answers anything. And a user's phone number and personal details had no business traveling to an AI model just because they sent a question about squats.

What we built: a WhatsApp ChatGPT chatbot for fitness

In 2024 we built three Node.js APIs on Express.js, with a MongoDB database behind them. Each one has a single job.

  • The WhatsApp API connects to the WhatsApp Cloud API. It receives messages as text, audio or images and sends replies as text in a standard format.

  • The ChatGPT API handles the AI side. It authenticates with ChatGPT, manages chat sessions and runs the safeguards: a filter that forwards only fitness-related content, and a redaction step that removes personal details first.

  • The core backend API joins the two. It links to the client's existing API manager, registers new users and opens a chat session on first contact. For returning users it fetches their details and routes messages between WhatsApp and ChatGPT.

Each session ID is created and stored against the user's license. Every API shipped with setup instructions, endpoint details and testing reports, so the client's team could run and extend it.

How it works day to day

A member finishes a workout and sends a quick question on WhatsApp. The core backend recognizes their number, confirms their license and finds their chat session.

The ChatGPT API checks the topic. A question about training goes ahead; a question about tomorrow's football scores stops there. Before the fitness question is sent on, the member's phone number and personal details are stripped out. ChatGPT answers the cleaned question, and the reply lands back in the member's WhatsApp chat as text.

For a brand-new user, the backend registers them through the client's API manager first, then opens their session.

What the AI never sees

The privacy rule is simple: ChatGPT receives redacted, de-identified text and nothing more.

  1. Personal details stay out. Phone numbers and personal details are removed or replaced with placeholders before any message text leaves the backend.

  2. Off-topic messages stay out. The fitness filter means anything unrelated never reaches the model at all.

  3. Identity stays in the client's system. Sessions are tied to licenses in the client's own database. ChatGPT works with a session, not a person, and the backend matches each reply to the right user.

No person reviews replies before they are sent, so the topic filter, the redaction step and the license check do that job together.

The result

Licensed users can ask fitness questions on WhatsApp by text, voice note or photo and get written answers in the same chat. New users are registered on first contact, and every conversation is stored against the right license.

The business gets an AI assistant that stays on topic and keeps personal details away from the model. We have no usage or outcome figures on file, so we don't quote any.

What the research says

  • WhatsApp is where people already are. Meta announced in 2020 that WhatsApp supports more than 2 billion users around the world (Meta newsroom).

  • Off-topic prompts are a known risk. The OWASP Top 10 for LLM applications ranks prompt injection first for 2025 and advises constraining the model to a defined role and filtering inputs and outputs (OWASP, LLM01:2025). The fitness-only filter does that before any message reaches ChatGPT.

  • Model providers still keep logs. OpenAI's documentation says API data has not trained its models since March 1, 2023 unless a customer opts in, but abuse monitoring logs may hold prompts and responses for up to 30 days (OpenAI data controls). Removing personal details before a message is sent keeps them out of those logs too.

Where AI fits next

The assistant does neither of these today. It could hand a conversation to a human coach when a message mentions injury, pain or a medical condition. Answers could also draw on the business's own programs, so advice matches what each user is paying for.

Planning something similar?

Before you put ChatGPT behind your WhatsApp number, decide:

  1. Which topics should the bot answer, and what happens to everything else?

  2. Which personal details must be removed before a message reaches the model?

  3. How will you know a user is entitled to answers, such as by license or subscription?

  4. When should a person step in instead of the bot?

Our AI chatbot development page explains how we connect messaging apps to a model, and AI automation covers the wider picture. Before you build, read how to plan a support chatbot customers will use and the difference between a chatbot and an AI agent.

For similar projects, browse our work for software companies.

Common questions

How does a WhatsApp ChatGPT chatbot for fitness work?

A user messages the business on WhatsApp. A backend checks the user's license and finds their chat session, a filter confirms the message is about fitness, personal details are removed, and the cleaned text goes to ChatGPT. The reply returns to the user on WhatsApp as text.

Does ChatGPT see users' phone numbers or personal details?

No. Our backend API, which sits between WhatsApp and ChatGPT, removes phone numbers and personal details or replaces them with placeholders before any text is sent. The link between a session and a real user stays in that backend, which matches each reply to the right person.

How do you stop a fitness chatbot answering off-topic questions?

A filtering step checks every message and forwards only fitness-related content to ChatGPT. Anything else never reaches the model, so the assistant stays on the subject users pay for.

Can users send voice notes or photos?

Yes. The WhatsApp API receives text, audio and image messages. Replies go back as text.

What technology does it use?

Node.js and Express.js for the three APIs, MongoDB for users and sessions, the WhatsApp Cloud API for messaging and the OpenAI ChatGPT API for answers.

More of our work.

Projects that used the same services or served the same industry.

See all our work

Free project estimate

Talk through a project like these.

Thirty minutes with a founder, not a salesperson. Bring the problem; leave knowing what we'd build first and what it would cost.

What you get back

  • An indicative budget range
  • A realistic timeline
  • What moves the cost up or down
  • A reply within 4 business hours
  • Answered by a founder
  • NDA on request, before you share details

Tell us what you need

A few lines is plenty. You get a number before any call.

Fields marked * are required.