Home · Guides · updated 3 September 2026
The WhatsApp export .zip, and what to do with it
Ask for media and WhatsApp hands you a .zip rather than a text file. It is not an obstacle to be cleared before the real work starts. The archive is the record, and most of the damage done to chat evidence is done in the first five minutes of opening one.
What is in the archive
- One transcript. Plain text, one line per message, prefixed with the date, time and sender. iPhone exports call it
_chat.txt; Android names it after the conversation. - The attachments, as ordinary files: images, video, voice notes as
.opus, documents in whatever format they were sent, contact cards, sometimes stickers. - Nothing else. No metadata sidecar, no manifest, no signature. The archive is a container, and the correspondence between the transcript and the files inside it is by filename alone.
That last point is what an exhibit has to fix. A transcript entry reading IMG-20240612-WA0007.jpg (file attached) is a pointer; the file it points at is somewhere in the same archive, and nothing but the exhibit ties the two together for a reader.
What the rendered document then has to carry — the range, the entry numbers, the hash, the verification commands — is set out in converting a WhatsApp chat to a PDF for court. What follows here is about the archive itself.
The one rule: do not repackage it
A hash is exact, and an archive is a file like any other. Unzip it and zip it again and the photographs are identical, the transcript is identical, and the hash is completely different — because compression settings, entry order and the timestamps recorded inside the archive have all changed. There is no way back to the original value.
- Hash the archive as WhatsApp produced it, before anything is extracted.
- Extract to a working folder if you need to read it, and treat that folder as a copy rather than as the record.
- Do not rename files inside the archive, and do not remove the ones that do not help you.
- Do not send the archive through a messaging app, which may recompress it in transit.
The commands for hashing on Windows, macOS and Linux are in verifying the hash, and the ordinary causes of an innocent mismatch are set out there too.
Reconciling the archive against the transcript
An archive and a transcript can disagree, and a disagreement is always better stated than discovered in cross-examination. Two counts are needed, and they are counted separately:
- Entries in the transcript that name a file. Every attachment the conversation says was sent.
- Files actually present in the archive. Every attachment that came out with it.
Where the first number exceeds the second, attachments are missing from the record — usually because they were no longer on the device, which is what “media omitted” means. Where the second exceeds the first, there are files in the archive the transcript does not account for, and that wants explaining before somebody else asks.
What becomes of each kind of file
- Images reproduce into the exhibit directly, one to a page, with filename, size and their own hash beneath.
- Documents render page by page.
- Voice notes, audio and video cannot be printed. They are tabulated — filename, duration where known, size, hash — and delivered as files. See voice notes, audio and transcripts.
- Contact cards and stickers are usually incidental, but they are files in the archive and an honest reconciliation accounts for them.
Each attachment also wants its own hash, not merely the hash of the archive around it. The archive hash fixes the whole export; it cannot identify one photograph, and a photograph put to a witness on its own has to be identifiable on its own. Photographs, voice notes and documents covers the mechanics.
When the archive is very large
WhatsApp caps the size of an export, and a long conversation with media is truncated from the older end rather than refused. Open the transcript and check where it begins. If it does not begin where the conversation did, say so on the exhibit rather than letting a reader assume the record is complete — a limitation stated is a limitation weighed, and a limitation found by the other side is something else entirely.
If all you got was a .txt
Then the export was taken without media, or the attachments were no longer on the device. If the conversation is still on the handset, take a fresh export with media; it will be a different file with a different hash, and it is that file which should be certified as the record. If the media is genuinely gone, what you hold is a record of a conversation in which attachments were sent, and their contents are not part of it.
Section63 reads the .zip without extracting it to disk, hashes the archive as it arrived, hashes each attachment inside it, and reconciles the two counts in both directions — then prints the result in the exhibit whether it is flattering or not.
This guide explains procedure and states the law as we understand it. It is not legal advice, and Aarohan Enterprises is not a law firm. Whether a court admits a particular record, and what weight it gives it, is for that court to decide. Have an advocate settle anything you intend to file.
Prepare one now
Section63 builds this document from your export.
Drop in the .txt or .zip WhatsApp gives you and read the whole exhibit — transcript, Part A, Part B, Schedules and the integrity checks — before you pay.
More guides