Privacy policy — SFDC Zeta
SFDC Zeta is a Chrome extension that runs in your browser so you can query, load, and explore data in Salesforce orgs you connect.
Limited Use certification
SFDC Zeta certifies that user data is:
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item’s core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Core functionality is connecting to a Salesforce org you choose and using Query, Apex, Load, API, Events, Limits, Debug, Performance, Metadata, Schema, Config Workbook, Check, and Org tools against that org.
SFDC Zeta follows the Chrome Web Store Limited Use requirements: user data is used only to provide or improve those user-facing features. SFDC Zeta does not sell user data. SFDC Zeta does not use or transfer user data to determine creditworthiness, for lending, for ads, or for unrelated products.
What stays on this computer
SFDC Zeta does not operate a backend of its own. The following stay on this device:
- Salesforce refresh tokens (OAuth) in
chrome.storage.local, used to stay signed in after a browser restart - Live access tokens and Run as cookie snapshots in
chrome.storage.session(cleared when Chrome exits) - Org and user identity used in the UI (org Id, instance URL, user name)
- Settings, including optional AI keys you type, saved queries, API templates, load profiles, and the local activity log
- CSV / Excel / JSON rows you paste or upload, until you load them into the org or close the session
Uninstalling the extension deletes this local storage. Disconnect removes the stored refresh token for that org (revoked at Salesforce when possible).
What is sent off this computer
Network calls go to:
- The connected org’s instance URL over HTTPS (REST, Bulk, SOAP, Metadata, Streaming, and related Salesforce hosts listed in the manifest)
- AI chat (Settings → AI), when you use it. The default provider is the public open-source gateway at
api.llm7.io. Groq or OpenAI if you add a key. MCP / local models are localhost or 127.0.0.1 only. Salesforce Einstein uses the connected org’s Einstein APIs. Do not paste session ids, passwords, or production record dumps.
CSV / Excel data is parsed in the browser. It is uploaded only to the Salesforce org you choose to load into.
There is no analytics, advertising SDK, crash reporter, or other third-party tracker in SFDC Zeta. This website is static HTML. The feedback form opens a GitHub issue on the public SFDC Zeta tracker. GitHub issues are public. Do not include session ids, passwords, or production record dumps.
Permissions (why they exist)
| Permission | Use |
|---|---|
storage | Save settings, refresh tokens, queries, and the activity log on this device |
identity | OAuth PKCE sign-in to Salesforce |
cookies | Connect from a Salesforce tab you already logged into, and restore the session after Run as |
scripting | Run a fetch in the Salesforce tab when Connect is blocked by that page’s CSP (isolated world first; never send a Bearer token into page JavaScript on Experience Cloud / Sites) |
tabs / windows | Find Salesforce tabs to connect; open SFDC Zeta |
alarms | Refresh access tokens |
sidePanel | Dock SFDC Zeta beside Salesforce |
debugger | Performance tab only: attach Chrome’s Network protocol to the Salesforce tab you select while Analyze is running; detach on Stop or Cancel. Cookies and Authorization headers are redacted; response bodies are not stored |
| Host access | Salesforce domains, plus api.llm7.io, api.groq.com, api.openai.com, and localhost for a local model |
SFDC Zeta does not request access to arbitrary websites. Cookies and tabs are not used to record general browsing history.
Sharing
SFDC Zeta does not sell, rent, or share user data with data brokers, advertisers, or other products.
Org data you query or load is sent to Salesforce, as the service you already use. If you use default or third-party AI chat, the prompt text is sent to that provider so it can answer. Salesforce’s handling of org data is covered by your agreement with Salesforce.
If you use the Feedback page, the text you submit is sent to GitHub as a public issue on the SFDC Zeta issue tracker. That is separate from org data.
Creditworthiness and lending
SFDC Zeta is not a credit, underwriting, or lending product. It does not score users, orgs, or records for creditworthiness, and it does not transfer data for those purposes.
Children
SFDC Zeta is for Salesforce administrators and developers. It is not directed at children.
Changes
Material changes to this policy will be reflected on this page and in Help → Privacy inside the extension.
Contact
Privacy questions or requests: email sfdczeta@gmail.com, or use the Feedback page. Do not include session ids, passwords, or production record dumps.