Privacy policy — SFDC Zeta
SFDC Zeta is a Chrome extension that runs in your browser so you can query, load, and explore data in Salesforce orgs you connect.
Limited Use certification
SFDC Zeta certifies that user data is:
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item’s core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Core functionality is connecting to a Salesforce org you choose and using Query, Apex, Load, API, Events, Limits, Debug, Metadata, Schema, and Org tools against that org.
SFDC Zeta follows the Chrome Web Store Limited Use requirements: user data is used only to provide or improve those user-facing features. SFDC Zeta does not sell user data. SFDC Zeta does not use or transfer user data to determine creditworthiness, for lending, for ads, or for unrelated products.
What stays on this computer
SFDC Zeta does not operate a backend of its own. The following stay in Chrome extension storage (chrome.storage.local) or in memory on this device:
- Salesforce OAuth tokens and, when you connect from a logged-in tab, session cookies needed for that org
- Org and user identity used in the UI (org Id, instance URL, user name)
- Settings, saved queries, API templates, load profiles, and the local activity log
- CSV / Excel rows you paste or upload, until you load them into the org or close the session
Uninstalling the extension deletes this local storage. Disconnect removes the stored refresh token for that org (revoked at Salesforce when possible).
What is sent off this computer
Network calls go only to Salesforce over HTTPS:
- The connected org’s instance URL (REST, Bulk, SOAP, Metadata, Streaming, and related Salesforce hosts listed in the manifest)
- Optional Einstein assist (off until you enable it in Settings): your prompt is sent to that org’s Salesforce Einstein / Prompt Builder APIs so SFDC Zeta can draft SOQL or an API call. SFDC Zeta does not send prompts to OpenAI, Google, or any other model host directly.
CSV / Excel data is parsed in the browser. It is uploaded only to the Salesforce org you choose to load into.
There is no analytics, advertising SDK, crash reporter, or other third-party tracker in SFDC Zeta.
Permissions (why they exist)
| Permission | Use |
|---|---|
storage | Save settings, tokens, queries, and the activity log on this device |
identity | OAuth PKCE sign-in to Salesforce |
cookies | Connect from a Salesforce tab you already logged into, and restore the session after Run as |
scripting | Run a fetch in the Salesforce tab when Connect is blocked by that page’s CSP (nested My Domain). Not used on other sites |
tabs / windows | Find Salesforce tabs to connect; open SFDC Zeta |
alarms | Refresh access tokens |
sidePanel | Dock SFDC Zeta beside Salesforce |
| Host access | Salesforce domains only (*.salesforce.com, *.force.com, and related Salesforce hosts) |
SFDC Zeta does not request access to arbitrary websites. Cookies and tabs are not used to record general browsing history.
Sharing
SFDC Zeta does not sell, rent, or share user data with data brokers, advertisers, or other products.
The only recipient of org data is Salesforce, as the service you already use, so SFDC Zeta can perform the action you started (query, DML, describe, and so on). Salesforce’s handling of that data is covered by your agreement with Salesforce.
Creditworthiness and lending
SFDC Zeta is not a credit, underwriting, or lending product. It does not score users, orgs, or records for creditworthiness, and it does not transfer data for those purposes.
Children
SFDC Zeta is for Salesforce administrators and developers. It is not directed at children.
Changes
Material changes to this policy will be reflected on this page and in Help → Privacy inside the extension.
Contact
Privacy questions or requests: use the publisher contact email on the Chrome Web Store listing for SFDC Zeta.