Privacy policy — SFDC Zeta

SFDC Zeta is a Chrome extension that runs in your browser so you can query, load, and explore data in Salesforce orgs you connect.

Limited Use certification

SFDC Zeta certifies that user data is:

Core functionality is connecting to a Salesforce org you choose and using Query, Apex, Load, API, Events, Limits, Debug, Performance, Metadata, Schema, Config Workbook, Check, and Org tools against that org.

SFDC Zeta follows the Chrome Web Store Limited Use requirements: user data is used only to provide or improve those user-facing features. SFDC Zeta does not sell user data. SFDC Zeta does not use or transfer user data to determine creditworthiness, for lending, for ads, or for unrelated products.

What stays on this computer

SFDC Zeta does not operate a backend of its own. The following stay on this device:

Uninstalling the extension deletes this local storage. Disconnect removes the stored refresh token for that org (revoked at Salesforce when possible).

What is sent off this computer

Network calls go to:

CSV / Excel data is parsed in the browser. It is uploaded only to the Salesforce org you choose to load into.

There is no analytics, advertising SDK, crash reporter, or other third-party tracker in SFDC Zeta. This website is static HTML. The feedback form opens a GitHub issue on the public SFDC Zeta tracker. GitHub issues are public. Do not include session ids, passwords, or production record dumps.

Permissions (why they exist)

PermissionUse
storageSave settings, refresh tokens, queries, and the activity log on this device
identityOAuth PKCE sign-in to Salesforce
cookiesConnect from a Salesforce tab you already logged into, and restore the session after Run as
scriptingRun a fetch in the Salesforce tab when Connect is blocked by that page’s CSP (isolated world first; never send a Bearer token into page JavaScript on Experience Cloud / Sites)
tabs / windowsFind Salesforce tabs to connect; open SFDC Zeta
alarmsRefresh access tokens
sidePanelDock SFDC Zeta beside Salesforce
debuggerPerformance tab only: attach Chrome’s Network protocol to the Salesforce tab you select while Analyze is running; detach on Stop or Cancel. Cookies and Authorization headers are redacted; response bodies are not stored
Host accessSalesforce domains, plus api.llm7.io, api.groq.com, api.openai.com, and localhost for a local model

SFDC Zeta does not request access to arbitrary websites. Cookies and tabs are not used to record general browsing history.

Sharing

SFDC Zeta does not sell, rent, or share user data with data brokers, advertisers, or other products.

Org data you query or load is sent to Salesforce, as the service you already use. If you use default or third-party AI chat, the prompt text is sent to that provider so it can answer. Salesforce’s handling of org data is covered by your agreement with Salesforce.

If you use the Feedback page, the text you submit is sent to GitHub as a public issue on the SFDC Zeta issue tracker. That is separate from org data.

Creditworthiness and lending

SFDC Zeta is not a credit, underwriting, or lending product. It does not score users, orgs, or records for creditworthiness, and it does not transfer data for those purposes.

Children

SFDC Zeta is for Salesforce administrators and developers. It is not directed at children.

Changes

Material changes to this policy will be reflected on this page and in Help → Privacy inside the extension.

Contact

Privacy questions or requests: email sfdczeta@gmail.com, or use the Feedback page. Do not include session ids, passwords, or production record dumps.