Security & data flow
What LeadSync reads, where data goes, and why
WhatsApp contact scanning and duplicate comparison happen in the browser. Contact data selected for saving goes to the user’s own Google Contacts—not to LeadSync’s licensing backend. Paid licensing, checkout, support, and consented website analytics are separate data flows.
Last reviewed:
Plain-language data flow
- 1. WhatsApp Web → browser: numbers visible in the open chat list or group-member list are scanned locally.
- 2. Browser ↔ Google: existing numbers are checked and selected new contacts are written through the People API.
- 3. Separate services: licensing receives account/binding data; Razorpay handles payment; analytics loads only after website consent.
Permissions and purpose
| Permission or host | Why LeadSync uses it |
|---|---|
| storage | Stores settings, sequence state, plan state, and a local duplicate cache. |
| identity | Starts Chrome's Google OAuth flow for the Google account you choose. |
| scripting / activeTab | Runs the scanner in the WhatsApp Web tab you actively use. |
| web.whatsapp.com | Reads visible phone-number-looking text in the chat list or an opened group-member list. |
| people.googleapis.com | Checks existing numbers and creates contacts through the Google People API. |
Google OAuth scope: https://www.googleapis.com/auth/contacts.
Stays in the browser
Visible phone numbers, Google Contacts used for duplicate checks, settings, sequence state, and a local duplicate cache are processed in the browser.
Sent to Google Contacts
New contact names and phone numbers selected for saving are sent to the user's Google Contacts through the Google People API.
Handled by LeadSync services
Paid licensing and account services process the licensed Google email, bound WhatsApp number, plan/account status, and payment identifiers. Razorpay processes checkout. Website analytics runs only after consent.
Group-member scanning
Version 1.3.0 scans numbers visibly rendered in an opened WhatsApp Web group-member list; hidden numbers and members displayed only as saved names cannot be recovered.
Not supported
Message reading, message sending, bulk outreach, and mobile-browser scanning are not supported.
Threats and known limitations
- WhatsApp Web is not an official integration and can change without notice, temporarily breaking scanning.
- A compromised browser profile, malicious extension, or device can expose browser-accessible data; review installed extensions and protect your Google account.
- Google contact sync timing and device visibility depend on the user’s Google and phone settings.
- Uninstalling removes LeadSync’s local extension storage but does not delete contacts already created in Google Contacts or commercial records subject to legal/operational retention.
Report a security issue
Email ayaanmotiwala786@gmail.com with reproduction steps, affected version, impact, and a safe proof of concept. Do not include real contacts, message content, credentials, or OAuth tokens. We aim to acknowledge reports within 2 business days.