Privacy Policy
Last updated: 19 August 2026
This policy covers the SF Metadata Comparator Chrome extension and the hosted web application it opens. It explains what data is collected, why it is used, how it is stored, and who it is shared with.
1. The Chrome extension
The extension is a companion launcher. It does not collect Salesforce usernames, passwords, security tokens, or org metadata. It does not inject ads, and it does not sell data.
- It opens the hosted web app in a Chrome tab or window when you click the icon, use the keyboard shortcut, or use the context menu.
- On Salesforce pages, it may read the current tab URL after you click the extension so it can show that you are already in an org.
- Developer (unpacked) builds may store a local app URL in
chrome.storageand ping/api/health. Store builds do not let you change the backend URL.
2. The web application
When you sign in to the hosted app, we process:
- Account data: email, name, password hash, organization membership, and role.
- Session data: an HTTP-only session cookie (
sf_session) so you stay logged in. - Salesforce connection data: OAuth tokens and related org identifiers, stored encrypted at rest. We do not ask the Chrome extension to collect Salesforce passwords.
- Product data you create: saved orgs, packages, change sets, deployment logs, chat sessions, and direct messages.
- Operational logs: timestamps and status of comparisons or deployments you run.
Metadata is read from Salesforce only after you connect an org and only for actions you start (list, compare, deploy, chat against that org).
3. How we use this data
- Authenticate you and enforce permissions in your organization.
- Connect to Salesforce APIs on your behalf to compare and deploy metadata.
- Send one-time passcodes and optional email reports you enable.
- Provide in-app AI chat if you configure an AI key. Prompts you send may be forwarded to that provider.
- Operate, secure, and debug the service.
We do not sell personal data or use it for advertising.
4. Sharing
Data is shared only as needed to run the product:
- Salesforce: API calls you initiate (login, metadata, deploy, tests).
- Database host (Supabase): account, session, org, and product records.
- Email provider: OTP and optional reports.
- AI provider: only if you use chat and have configured a key.
We may disclose information if required by law or to prevent abuse of the service.
5. Storage and retention
- Session cookies expire after 7 days, or when you log out.
- Account and product data remain until you or an org admin delete them, or until the service is shut down.
- Salesforce access can be revoked in the app (disconnect org) and in Salesforce (revoke the Connected App).
6. Security
Passwords are hashed. Salesforce credentials and tokens are encrypted at rest. Production traffic uses HTTPS. The Chrome extension never receives your Salesforce password.
7. Your choices
- You can close the extension or uninstall it at any time in
chrome://extensions. - You can log out, disconnect Salesforce orgs, and delete packages, logs, and chats in the web app.
- Org admins can deactivate members. You can request account deletion by contacting the operator of the hosted app you use.
8. Children
This product is for workplace use. It is not directed at children under 13.
9. Contact
For privacy questions, use the contact email on the Chrome Web Store listing or the administrator of the hosted SF Metadata Comparator instance you signed into.