Privacy Policy
Leadmaps, by Auradevs · Last updated: 18 June 2026
The short version. Leadmaps runs on your own computer. It collects
publicly-listed business information from Google Maps that you ask for.
Your Notion token is stored only on your machine, and Google Sheets needs
no sign-in at all — you simply share a sheet with us. We do not receive, store,
or sell your leads.
1. Who we are
Leadmaps is a desktop/CLI lead-generation tool published by Auradevs ("we",
"us"). This policy explains what data the software touches and how.
2. What the software does with data
- Where it runs: on your machine (or a server you host). It drives a
browser to read public Google Maps business listings for the niche and
city you specify.
- What it collects: only publicly-available business details (name,
phone, website, address, ratings, hours, etc.) for the searches you run. It
does not collect data about you.
- Where results go: to the destination you choose — a local file
(CSV/Excel/PDF) or your own Notion / Google Sheet. The results are
yours; they are not sent to us.
3. Connecting Notion and Google Sheets
The two destinations connect in completely different ways. Neither one asks
you to paste an API key, and neither sends your leads to us.
- Notion — you authorize in your browser. When you run
leadmaps connect notion you approve the app in Notion, granting
it permission to create and write to a "Leads" database in the page you
choose. The resulting access token is saved only on your computer at
~/.leadmaps/credentials.json with owner-only permissions.
- Notion token exchange: the one-time exchange of an authorization
code for a token is performed by our stateless auth broker so that no
application secret is shipped in the software. The broker passes the token
straight back to your machine and stores nothing — no tokens, no
leads, no logs of content.
- Google Sheets — there is no Google sign-in. Leadmaps does not ask
Google for permission on your behalf and never requests an OAuth scope on
your account. Instead,
leadmaps connect google shows you the
email address of the Leadmaps service account. You share your own
spreadsheet with that address and give it Editor — the same two clicks as
sharing with a colleague — then paste the link. You never type a Google
password anywhere, and Leadmaps never sees your Google account.
- What that service account can reach: exactly the spreadsheets you
have shared with it, and nothing else. It cannot list, open or search the
rest of your Drive, because it was never given access to it.
- Disconnect anytime:
leadmaps disconnect notion deletes
the Notion token from your machine. For Google Sheets, open the sheet, click
Share, and remove the Leadmaps service-account address — access ends
immediately and there is nothing stored on your machine to delete.
3a. Google user data — Limited Use
Leadmaps' use and transfer of information received from Google APIs adheres to
the Google API Services User Data Policy,
including the Limited Use requirements.
Specifically:
- We request no scopes on your Google account. Leadmaps has no
"Sign in with Google" flow and holds no OAuth token for you. It reaches
Google Sheets as its own service account, and only ever touches the
spreadsheets you chose to share with that account.
- What we access. The one spreadsheet you shared, to append your lead
rows to it. Nothing else in your Drive is reachable, because nothing else was
shared.
- How the credential works. The service account's private key is held
on our broker and is never shipped in the software. When you run an export,
your machine asks the broker for a short-lived access token; the rows
then travel directly from your computer to Google. The broker issues
the token and never receives a lead.
- We do not transfer it. Your spreadsheet contents are never sent to
us or to any third party.
- We do not use it for advertising, and we do not sell it.
- No human reads it. Nobody at Auradevs opens your spreadsheet. The
service account is used only to append the rows your own run produced.
- We do not use it to train models, generalised or otherwise.
- Retention. We retain nothing from your spreadsheet. You end our
access at any moment by removing the service account from the sheet's Share
dialog.
4. The MCP server (if you use AI assistants)
If you run Leadmaps as an MCP server for an AI assistant, scrapes run on the
machine hosting that server and any connection token is held in that server's
memory for your session only. Each user's data is isolated; tokens are never
shown in the chat.
5. What we do NOT do
- We do not receive, store, or sell your leads.
- We do not see your Notion/Google content or tokens.
- The software contains no advertising or third-party trackers.
6. Your responsibilities
You are responsible for using Leadmaps in compliance with applicable laws and
the terms of the services it interacts with (Google, Notion, Google Workspace),
and for how you use the leads you collect.
7. Changes & contact
We may update this policy; material changes will be reflected by the date
above. Questions? Contact us at the email listed on our product/support page.