Security & data flow

What LeadSync reads, where data goes, and why

WhatsApp contact scanning and duplicate comparison happen in the browser. Contact data selected for saving goes to the user’s own Google Contacts—not to LeadSync’s licensing backend. Paid licensing, checkout, support, and consented website analytics are separate data flows.

Last reviewed:

Plain-language data flow

  1. 1. WhatsApp Web → browser: numbers visible in the open chat list or group-member list are scanned locally.
  2. 2. Browser ↔ Google: existing numbers are checked and selected new contacts are written through the People API.
  3. 3. Separate services: licensing receives account/binding data; Razorpay handles payment; analytics loads only after website consent.

Permissions and purpose

Permission or hostWhy LeadSync uses it
storageStores settings, sequence state, plan state, and a local duplicate cache.
identityStarts Chrome's Google OAuth flow for the Google account you choose.
scripting / activeTabRuns the scanner in the WhatsApp Web tab you actively use.
web.whatsapp.comReads visible phone-number-looking text in the chat list or an opened group-member list.
people.googleapis.comChecks existing numbers and creates contacts through the Google People API.

Google OAuth scope: https://www.googleapis.com/auth/contacts.

Stays in the browser

Visible phone numbers, Google Contacts used for duplicate checks, settings, sequence state, and a local duplicate cache are processed in the browser.

Sent to Google Contacts

New contact names and phone numbers selected for saving are sent to the user's Google Contacts through the Google People API.

Handled by LeadSync services

Paid licensing and account services process the licensed Google email, bound WhatsApp number, plan/account status, and payment identifiers. Razorpay processes checkout. Website analytics runs only after consent.

Group-member scanning

Version 1.3.0 scans numbers visibly rendered in an opened WhatsApp Web group-member list; hidden numbers and members displayed only as saved names cannot be recovered.

Not supported

Message reading, message sending, bulk outreach, and mobile-browser scanning are not supported.

Threats and known limitations

  • WhatsApp Web is not an official integration and can change without notice, temporarily breaking scanning.
  • A compromised browser profile, malicious extension, or device can expose browser-accessible data; review installed extensions and protect your Google account.
  • Google contact sync timing and device visibility depend on the user’s Google and phone settings.
  • Uninstalling removes LeadSync’s local extension storage but does not delete contacts already created in Google Contacts or commercial records subject to legal/operational retention.

Report a security issue

Email ayaanmotiwala786@gmail.com with reproduction steps, affected version, impact, and a safe proof of concept. Do not include real contacts, message content, credentials, or OAuth tokens. We aim to acknowledge reports within 2 business days.