The challenge
A fitness software business wanted its users to get answers where they already spend their day: on WhatsApp. It chose ChatGPT to write those answers and asked us to build a WhatsApp ChatGPT chatbot for fitness that it could trust.
Trust meant three rules. Only licensed, paying users should get answers. The assistant had to stay on fitness instead of turning into a general chatbot that answers anything. And a user's phone number and personal details had no business traveling to an AI model just because they sent a question about squats.
What we built: a WhatsApp ChatGPT chatbot for fitness
In 2024 we built three Node.js APIs on Express.js, with a MongoDB database behind them. Each one has a single job.
The WhatsApp API connects to the WhatsApp Cloud API. It receives messages as text, audio or images and sends replies as text in a standard format.
The ChatGPT API handles the AI side. It authenticates with ChatGPT, manages chat sessions and runs the safeguards: a filter that forwards only fitness-related content, and a redaction step that removes personal details first.
The core backend API joins the two. It links to the client's existing API manager, registers new users and opens a chat session on first contact. For returning users it fetches their details and routes messages between WhatsApp and ChatGPT.
Each session ID is created and stored against the user's license. Every API shipped with setup instructions, endpoint details and testing reports, so the client's team could run and extend it.
How it works day to day
A member finishes a workout and sends a quick question on WhatsApp. The core backend recognizes their number, confirms their license and finds their chat session.
The ChatGPT API checks the topic. A question about training goes ahead; a question about tomorrow's football scores stops there. Before the fitness question is sent on, the member's phone number and personal details are stripped out. ChatGPT answers the cleaned question, and the reply lands back in the member's WhatsApp chat as text.
For a brand-new user, the backend registers them through the client's API manager first, then opens their session.
What the AI never sees
The privacy rule is simple: ChatGPT receives redacted, de-identified text and nothing more.
Personal details stay out. Phone numbers and personal details are removed or replaced with placeholders before any message text leaves the backend.
Off-topic messages stay out. The fitness filter means anything unrelated never reaches the model at all.
Identity stays in the client's system. Sessions are tied to licenses in the client's own database. ChatGPT works with a session, not a person, and the backend matches each reply to the right user.
No person reviews replies before they are sent, so the topic filter, the redaction step and the license check do that job together.
The result
Licensed users can ask fitness questions on WhatsApp by text, voice note or photo and get written answers in the same chat. New users are registered on first contact, and every conversation is stored against the right license.
The business gets an AI assistant that stays on topic and keeps personal details away from the model. We have no usage or outcome figures on file, so we don't quote any.
What the research says
WhatsApp is where people already are. Meta announced in 2020 that WhatsApp supports more than 2 billion users around the world (Meta newsroom).
Off-topic prompts are a known risk. The OWASP Top 10 for LLM applications ranks prompt injection first for 2025 and advises constraining the model to a defined role and filtering inputs and outputs (OWASP, LLM01:2025). The fitness-only filter does that before any message reaches ChatGPT.
Model providers still keep logs. OpenAI's documentation says API data has not trained its models since March 1, 2023 unless a customer opts in, but abuse monitoring logs may hold prompts and responses for up to 30 days (OpenAI data controls). Removing personal details before a message is sent keeps them out of those logs too.
Where AI fits next
The assistant does neither of these today. It could hand a conversation to a human coach when a message mentions injury, pain or a medical condition. Answers could also draw on the business's own programs, so advice matches what each user is paying for.
Planning something similar?
Before you put ChatGPT behind your WhatsApp number, decide:
Which topics should the bot answer, and what happens to everything else?
Which personal details must be removed before a message reaches the model?
How will you know a user is entitled to answers, such as by license or subscription?
When should a person step in instead of the bot?
Our AI chatbot development page explains how we connect messaging apps to a model, and AI automation covers the wider picture. Before you build, read how to plan a support chatbot customers will use and the difference between a chatbot and an AI agent.
For similar projects, browse our work for software companies.



