Privacy

Understand what Apnelog stores, who can access it, and how authorized workspace data can be exported or removed.
Your people are not our product.

Your account

When you choose Google sign-in, Google and Supabase Auth verify your identity using your email address and profile information. Apnelog does not request access to your Google contacts, inbox, or Google password.

Your display name is visible to collaborators in your shared workspaces. Creating an account does not grant access to another workspace; its membership and role rules still apply. Manage your name, appearance, and sign-out controls in My profile.

How data is protected

Workspace isolation

Row-level policies scope every protected record to a workspace membership.

Sensitive actions

Exports, imports, tokens and approvals are auditable and role-restricted.

No silent messaging

Invitation preparation never sends a message from Apnelog.

Your choices

Export workspace data

Owners and managers can create bounded directory exports. Recovery packages require recent authentication.

Review export options

Delete an account or workspace

Deletion requires identity confirmation and an explicit review of ownership consequences. Sign in and contact a workspace owner to begin the review.

How contact imports work

Choose from your phone

Your phone opens its own contact picker only after you tap. Apnelog receives the names, phone numbers, and email addresses you approve, keeps the candidate in the current browser draft, and cannot see contacts you do not choose. During review, a normalized phone number or email address may be sent transiently to your configured workspace to check for an exact saved-person match. That lookup does not save the candidate. It does not read call or SMS history.

Local vCard review

A .vcf or .vcard file is parsed in this browser and stays in the current draft. During review, a normalized phone number or email address may be sent transiently to your configured workspace to check for an exact saved-person match; the lookup does not save the candidate. Nothing is persisted until you review and save selected people. Supported, reviewable details are identified when possible; anything not imported remains in your original file.

CSV or XLSX review

A manager's spreadsheet dry run is different: the authenticated workspace stages the file and immutable row evidence on the server for mapping, review, commit, audit, and recovery. It is not described as local-only or automatically deleted.

No access is requested just for opening Add people.

You choose each source. Blank incoming fields do not replace saved details. Only rows you confirm are persisted. Google Contacts, profile-photo storage, location assistance, and background contact access are not enabled in this web release.

Retention

Audit history and import evidence are retained according to workspace policy. Archived people remain recoverable and traceable; they are not silently deleted. Contact a workspace owner for retention questions.