Workspace isolation
Row-level policies scope every protected record to a workspace membership.
When you choose Google sign-in, Google and Supabase Auth verify your identity using your email address and profile information. Apnelog does not request access to your Google contacts, inbox, or Google password.
Your display name is visible to collaborators in your shared workspaces. Creating an account does not grant access to another workspace; its membership and role rules still apply. Manage your name, appearance, and sign-out controls in My profile.
Row-level policies scope every protected record to a workspace membership.
Exports, imports, tokens and approvals are auditable and role-restricted.
Invitation preparation never sends a message from Apnelog.
Owners and managers can create bounded directory exports. Recovery packages require recent authentication.
Review export optionsDeletion requires identity confirmation and an explicit review of ownership consequences. Sign in and contact a workspace owner to begin the review.
Your phone opens its own contact picker only after you tap. Apnelog receives the names, phone numbers, and email addresses you approve, keeps the candidate in the current browser draft, and cannot see contacts you do not choose. During review, a normalized phone number or email address may be sent transiently to your configured workspace to check for an exact saved-person match. That lookup does not save the candidate. It does not read call or SMS history.
A .vcf or .vcard file is parsed in this browser and stays in the current draft. During review, a normalized phone number or email address may be sent transiently to your configured workspace to check for an exact saved-person match; the lookup does not save the candidate. Nothing is persisted until you review and save selected people. Supported, reviewable details are identified when possible; anything not imported remains in your original file.
A manager's spreadsheet dry run is different: the authenticated workspace stages the file and immutable row evidence on the server for mapping, review, commit, audit, and recovery. It is not described as local-only or automatically deleted.
You choose each source. Blank incoming fields do not replace saved details. Only rows you confirm are persisted. Google Contacts, profile-photo storage, location assistance, and background contact access are not enabled in this web release.
Audit history and import evidence are retained according to workspace policy. Archived people remain recoverable and traceable; they are not silently deleted. Contact a workspace owner for retention questions.