Encrypted at Rest
AES-256-GCM encryption with PBKDF2 key derivation (310,000 iterations)
No Publisher Backend
The extension does not upload your Salesforce data to servers operated by the publisher.
No Ads or Tracking
No advertising, behavioral analytics, telemetry, sale of data, or cross-site tracking.
User Control
Delete saved accounts and histories in the UI, or uninstall to remove extension storage.
Salesforce Session
To call the Salesforce REST / Tooling APIs on your behalf, the extension reads your existing Salesforce session cookie (sid) from the org you are already logged into. This is done locally, in your browser, using the browser's cookie APIs.
Use
Authentication for API calls that power the extension's features — record inspection, data export/import, metadata browsing, debug logs, flow scanning, etc.
Transmission
The session token is transmitted over HTTPS only to the applicable Salesforce org to authenticate requests needed for extension features. It is not sent to the publisher, advertisers, analytics providers, or unrelated third parties.
Storage
The session token is kept in memory while features run. A timestamped copy may be placed in Chrome's in-memory session storage for up to ten minutes so standalone tool tabs can use it. It is never written to persistent extension storage and is cleared when the browser session ends.
Saved Org Accounts
The popup lets you save the login details (name, username, password, login URL, color) of Salesforce orgs for one-click login.
Storage
All data is stored locally in your browser via chrome.storage.local.
Encryption
Passwords are encrypted at rest with AES-256-GCM using a key derived (PBKDF2, 310,000 iterations) from a master passphrase that you create. The master passphrase itself is never stored; the derived key lives only in memory for the current browser session and is wiped when the browser restarts. If you forget the master passphrase, encrypted passwords cannot be recovered and must be re-entered.
Transmission
During one-click login, the decrypted credential is provided to the selected Salesforce login page so the browser can submit it to Salesforce over HTTPS. A temporary value may be held in extension local storage for no more than 40 seconds and is then deleted by a watchdog. Credentials are not transmitted to the publisher.
Salesforce Org Data
When you use a feature, the extension may read, create, update, delete, export, or deploy records, metadata, Apex code, debug logs, flow definitions, permission information, event payloads, and related Salesforce content through Salesforce APIs. The requested operation is performed between your browser and the selected Salesforce org over HTTPS. This content is not uploaded to the publisher.
Some user-facing features save local working data such as favorites, recent items, query history, clone templates, editor preferences, feature settings, cached object descriptions, and locally generated exports. These values remain in Chrome extension storage or in files you explicitly download. They are not used for advertising or profiling.
Browsing Activity
The extension is scoped to supported Salesforce domains (*.salesforce.com, *.force.com, *.salesforce-setup.com, *.visualforce.com, and related Salesforce hosts). To provide page-aware tools, it may inspect the current Salesforce URL, page content, selected record or object context, and Salesforce network responses. That information is used only for the feature the user invokes or enables. The extension does not monitor browsing on unrelated sites and does not transmit browsing activity to the publisher.
Chrome Permissions
Salesforce Comet requests only permissions used by its current user-facing features:
Salesforce host access
Runs tools and sends API requests only on supported Salesforce domains opened or selected by the user.
cookies
Reads the Salesforce sid session cookie for the selected org and supports user-initiated org login or switching. It does not read cookies for unrelated sites.
storage
Stores encrypted vault entries, settings, favorites, recent activity, templates, bounded caches, and temporary session handoff data.
scripting
Loads the extension's packaged interface and page-aware Salesforce tools into authorized Salesforce pages. It does not download or execute remote code.
alarms
Runs a one-time watchdog that deletes temporary quick-login credentials after no more than 40 seconds.
contextMenus
Adds Salesforce-only right-click shortcuts for tools. The extension does not collect or transmit clicked page, link, selection, or field contents through this permission.
What the Extension Does NOT Do
No advertising, analytics, or tracking.
No sale, transfer, or sharing of user data with third parties.
No data is sent to our servers — the extension has no backend.
No use of data for personalization, creditworthiness, or any purpose beyond the extension's single purpose as a Salesforce development tool.
No remote executable code. All logic ships inside the extension package.
External Links
Uninstalling opens an optional feedback page hosted by Google Forms. The extension also contains user-initiated links to the Chrome Web Store, GitHub support, and Buy Me a Coffee. Opening an external page may disclose ordinary request information such as IP address, browser details, and referrer to that site's operator under its own privacy policy. No form response or donation information is available to the extension unless you separately choose to provide it through that external service. The extension contains no remote executable code.
User Controls & Deletion
Vault
You can delete individual accounts or whole groups from the popup. To delete everything, remove the extension — uninstalling removes all data stored in browser storage.
Permissions
You can revoke the extension's permissions at any time from chrome://extensions.
Retention & Security
Session handoff data is kept in memory-backed chrome.storage.session for up to ten minutes and is cleared when the browser session ends. Temporary quick-login credentials are deleted after no more than 40 seconds. Persistent settings, encrypted vault entries, histories, templates, and caches remain until the user removes them, clears extension data, or uninstalls the extension. Downloaded exports remain wherever the user saves them.
Salesforce API traffic and login submissions use HTTPS. Vault passwords use AES-256-GCM encryption with PBKDF2 key derivation. The extension ships its executable code in the signed extension package and does not load remote executable code. No security measure can guarantee absolute protection; users should protect their device, Chrome profile, Salesforce account, and master passphrase.
Limited Use Disclosure
The use of information received from Salesforce APIs and Chrome extension permissions adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Allowed use: User data is used only to provide or improve Salesforce Comet's disclosed Salesforce development and administration features.
Allowed transfer: Data is transmitted only when necessary to perform the user's requested operation with the selected Salesforce org, or when required for security or legal compliance.
No advertising: User data is not used or transferred for personalized advertising, retargeting, interest-based advertising, or advertising measurement.
No human access: The publisher does not access user data. An exception would apply only with the user's affirmative agreement for support, for security investigation, to comply with law, or when aggregated and anonymized for internal improvement; Salesforce Comet currently provides no publisher backend for such access.
User data is never sold and is not used for creditworthiness, lending, or unrelated profiling.
Contact
For privacy questions, security reports, or support requests, use the public Salesforce Comet support page or the publisher contact information on the Chrome Web Store listing. Do not include Salesforce session tokens, passwords, customer records, or other sensitive information in a public issue.
Material policy changes will be posted on this page with a revised effective date. Continued use after an update is subject to the updated policy.