Privacy Policy
Last updated: 09 April 2026 · Effective date: 24 March 2026
Summary: LeadFlow Auto Saver processes contact data
on your device. We do not sell your data and we do not upload your contacts or message content. To operate subscriptions and limits, we store plan and usage metadata on our backend. The free and locked-feature experience may display ads via Google AdMob.
Official policy URL:
https://leadflow-rglabs.netlify.app/privacy-policy
1. Who We Are
LeadFlow Auto Saver ("LeadFlow", "we", "us", or "our") is an Android application developed and operated by Rajeev Godambe. The app is published under the package name com.leadflow.autosaver on the Google Play Store.
If you have any questions about this Privacy Policy, please contact us at rajeevgodambe@proton.me.
2. Information We Collect
2.1 Information Processed On-Device (Not Uploaded)
The following data is processed locally on your device and is never transmitted to our servers:
- Notification content: Phone numbers and sender names extracted from notification previews of WhatsApp, WhatsApp Business, and Telegram.
- Contact data: Phone numbers saved to your device's Contacts app via Android's ContactsContract API.
- Lead records: Lead entries, follow-up schedules, notes, and status changes you create within the app, stored in your device's local app storage.
- App settings: Your configuration (prefix, naming format, selected apps, theme, etc.) stored in Android SharedPreferences on your device.
2.2 Subscription and Usage Metadata Stored on Our Server
To support subscriptions, feature limits, and account continuity, we store the following data on our backend (hosted on secure cloud infrastructure):
- Subscription details: Current plan (Free, Pro, Growth), status, start/expiry timestamps, and billing source.
- Usage counters: Aggregated usage metrics such as monthly and total auto-saves, leads, lead updates, and exports.
- Plan limits: Feature-limit values applied to your account (for example max leads, max exports, and automation availability).
- Technical identifiers: Internal app/user identifiers needed to sync subscription state and enforce limits.
This server-side metadata does not include your full contact list, message bodies, or uploaded chat history.
2.3 Information Collected by Third-Party SDKs
The app integrates Firebase and ad services which may collect the following anonymised data:
- Firebase Analytics: App usage events (e.g., app_open, contact_saved, settings_changed). No personally identifiable information (PII) is attached to these events. Events include metadata such as timestamps and feature names.
- Firebase Crashlytics: Crash reports and non-fatal error logs to help us diagnose and fix bugs. These reports include device model, OS version, app version, and anonymised stack traces.
- Firebase Performance Monitoring: Anonymised performance metrics such as app start time and screen load times.
- Firebase Remote Config: Feature-flag configuration fetched from Firebase. This is read-only from the app's perspective.
- Firebase Cloud Messaging (FCM): An FCM registration token is generated to enable push notifications. This token is stored locally and is not linked to any personal account unless you sign in.
- Google Mobile Ads (AdMob): Ad request and delivery data such as device/app identifiers, coarse diagnostics, and ad interaction events may be processed by Google to serve and measure ads. We request non-personalized ads where applicable in-app.
2.4 Account Information (Optional)
If you choose to sign in with Google, we receive your Google Account email address and display name via Firebase Authentication. This information is used solely to personalise the welcome message within the app and is not used for marketing or shared with third parties.
3. How We Use Your Information
We use the information described above for the following purposes:
- Core functionality: To extract phone numbers from notifications and save them to your contacts.
- App improvement: To understand which features are used most, diagnose crashes, and prioritise development (via Firebase Analytics and Crashlytics).
- Feature flags: To enable or disable features remotely without requiring an app update (via Firebase Remote Config).
- Push notifications: To deliver app-related notifications to your device (via FCM), if enabled.
- Personalisation: To display your name in the welcome message if you sign in with Google.
- Subscription operations: To validate your active plan, enforce feature limits, and keep usage counters in sync across sessions.
- Ads support for free features: To display banner/native ads in free or locked-feature views and support app monetization.
We do not:
- Sell or rent your personal data to any third party.
- Use your data for advertising targeting.
- Upload your contact list, chat history, or raw notification content to our server.
- Share your data with third parties other than the Firebase services described in Section 5.
4. Data Storage & Security
Contact data and message-derived lead content are stored locally on your Android device using Android's native storage mechanisms (ContactsContract, SharedPreferences, and app-private storage).
We also operate backend services that store subscription and usage metadata required for billing, plan management, and feature-limit enforcement. Firebase services (Analytics, Crashlytics, etc.) store anonymised telemetry on Google's infrastructure under Google's Privacy Policy.
We implement the following security measures:
- We request only the minimum Android permissions necessary for the app to function (see Section 6).
- Notification content is processed in memory and discarded after saving; it is not logged or stored in plaintext.
- We follow Google's Play Store policies and Firebase's security best practices.
Despite our efforts, no method of electronic storage is 100% secure. We encourage you to keep your device OS and the app updated.
5. Third-Party Services
LeadFlow integrates the following third-party services. Each service has its own privacy policy, which we encourage you to review:
We are not responsible for the privacy practices of these third-party services. The information you provide to them is governed by their respective privacy policies.
6. Permissions Explained
LeadFlow requests the following Android permissions and uses them solely as described:
- READ_CONTACTS: To check for duplicate phone numbers before saving a new contact.
- WRITE_CONTACTS: To save new contacts to your device's address book.
- POST_NOTIFICATIONS: To show you a notification when a contact is successfully saved (Android 13+).
- BIND_NOTIFICATION_LISTENER_SERVICE: To receive notification content from WhatsApp, WhatsApp Business, and Telegram so that phone numbers can be extracted automatically. This permission must be explicitly granted by you in Android Settings.
- com.android.vending.BILLING: To enable Google Play subscription purchases, upgrades, downgrades, and renewals.
Important: The Notification Listener only reads the notification text (the brief preview shown in your status bar). It does not access your full conversation history, photos, videos, or any other message content.
7. Children's Privacy
LeadFlow Auto Saver is not directed at children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child under 13 has provided us with personal information, please contact us at rajeevgodambe@proton.me and we will take steps to delete such information.
8. Your Rights
Depending on your location, you may have the following rights with respect to your personal data:
- Access: You may request a copy of personal data we hold about you.
- Correction: You may request correction of inaccurate personal data.
- Deletion: You may request deletion of your personal data. Since contact and lead data is stored only on your device, you can delete it at any time by clearing the app data in Android Settings or uninstalling the app.
- Portability: You may export your contact data as a .vcf file at any time from within the app (Pro and Growth plan).
- Withdrawal of consent: You may withdraw notification listener permission at any time via Android Settings → Apps → LeadFlow → Permissions. This will disable auto-save functionality.
To exercise any right, or if you have a privacy concern, please contact us at rajeevgodambe@proton.me. We will respond within 30 days.
9. Data Retention
On-device data (contacts, leads, settings) is retained for as long as the app is installed on your device. You can delete all app data at any time via Android Settings → Apps → LeadFlow → Clear Data, or by uninstalling the app.
Firebase Analytics and Crashlytics retain anonymised event data for up to 14 months by default, as per Google's data retention policies.
Subscription and usage metadata stored on our backend is retained while your account or subscription is active, and for a limited period afterward for legal, accounting, fraud-prevention, and dispute-resolution purposes.
10. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you via in-app notification.
We encourage you to review this Privacy Policy periodically. Continued use of the app after changes are posted constitutes your acceptance of the revised policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: