Privacy Policy
Last updated: August 14, 2026
Sales Copilot ("the Extension") is a Chrome extension for Salesforce that syncs your meetings, emails and call transcripts, turns them into deal and account intelligence, and suggests CRM updates, follow-up emails and meeting briefs from a side panel on the Salesforce page. The Extension is a thin client: it renders the interface and talks to your Salesforce org, while the processing happens on our backend service. This Privacy Policy explains what data we collect, how we use it, and your rights.
1. Information We Collect
Salesforce Identity and Session
- The Extension reads your Salesforce user identifier (
sid_client) and your Salesforce domain, and exchanges the identifier for a short-lived access token that authenticates you to our backend. This identifier is stored on our servers as the key that all of your data is scoped to. - Your Salesforce session credentials never leave your browser. The session cookie and Aura token the Extension uses to call your own Salesforce org are held in local browser storage and are not transmitted to, or stored by, our servers. Our backend holds no Salesforce credentials and never connects to Salesforce directly — when it needs Salesforce data, it asks your browser to fetch it.
Salesforce Record Data
- The Extension reads Salesforce records — opportunities, accounts, contacts, contact roles, tasks and events, notes and attached files, and the field and picklist definitions of your org — and uploads them to our backend, where they are stored so the Extension's intelligence, search and suggestion features can be produced from them.
Google Account Data
- If you connect your Google account, our backend accesses your Gmail messages and Google Calendar events on a read-only basis, to match conversations and meetings to Salesforce opportunities. Message content, participants, subjects and event details are stored on our servers for that purpose.
- With your permission the backend can also create draft emails in your mailbox for follow-ups you ask it to write. It creates drafts only — it never sends email on your behalf.
- The connection is made by our backend, not by the Extension, and can be revoked at any time from the Extension's settings or from your Google Account.
Meeting Recordings and Transcripts
- If you connect Zoom, our backend fetches your cloud recordings' transcripts and stores their content, so they can be matched to the corresponding calendar meeting and opportunity and summarised.
AI Processing
- To produce summaries, risk assessments, briefs, suggested field values and chat answers, the relevant context — which can include the content of your emails, transcripts, notes and Salesforce fields — is sent to our AI providers (OpenAI and Anthropic) for processing.
- The results are stored on our servers alongside the records they describe. Conversations you have with the in-product assistant are stored so a thread can be reopened, and are deleted on the schedule in section 7.
- For account research the backend also queries public news sources by company name. No personal or CRM data is included in those queries.
Product Analytics and Diagnostics
- We collect usage analytics through PostHog to understand which features are used and where they fail. Events are keyed to a pseudonymous identifier derived from a one-way SHA-256 hash of your Salesforce user id, together with your Salesforce org id and extension version.
- These events carry counts, durations, identifiers and category labels only. They deliberately never include message text, chat content, Salesforce field values, or the names of records, accounts or people.
- We also collect error diagnostics (stack traces and technical context) to detect and fix crashes.
2. How We Use Your Information
- Authentication: to verify your identity and scope every request to your own data.
- Core features: to sync your CRM records, meetings, emails and transcripts, link activities to the right opportunity, and keep your workspace up to date.
- AI features: to generate summaries, deal and account intelligence, meeting briefs, suggested CRM updates, draft emails and answers to your questions.
- Product improvement: to measure feature usage and diagnose errors, using the limited event data described above.
We do not use your data to train AI models, and our AI providers are contractually bound not to train on data submitted through their APIs.
3. Data Storage & Security
- Data is stored in a PostgreSQL database. Every table is keyed to your Salesforce user id, and every query is scoped to the authenticated user — your data is never returned to another user.
- Access tokens for your Google and Zoom connections are encrypted at rest.
- Backend access uses short-lived signed tokens that expire after 60 minutes and are re-issued from your live Salesforce session.
- All communication between the Extension, our servers and third-party services uses HTTPS or secure WebSockets.
- Data is streamed back to the Extension over an authenticated, per-user connection and cached in your browser so the panel renders offline-tolerantly. Clearing browser data or uninstalling the Extension removes that local copy.
4. Third-Party Services
The Extension and its backend integrate with the following third-party services:
- Salesforce: to read and update your CRM data, using your own session, from your own browser.
- Google (Gmail & Calendar): to sync emails and meetings (read-only) and to create email drafts you request.
- Zoom: to fetch meeting recordings and transcripts.
- OpenAI and Anthropic: to process AI features. Data sent to these providers is subject to their respective privacy policies.
- PostHog: product analytics, limited to the event data described in section 1.
- Sentry: error and crash diagnostics.
5. Google API Services — Limited Use
Sales Copilot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide and improve the features described in this policy, is never sold, is never used for advertising, and is never used to train generalised AI or machine-learning models. Human access to Google user data occurs only with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.
6. Data Sharing
We do not sell, trade or rent your personal data, and we do not share it with advertisers. Data is shared only with the service providers listed in section 4, and only to the extent required to provide the Extension's features. We may disclose data where required by law.
7. Data Retention
- Synced Salesforce, email, calendar and transcript data, and the intelligence derived from it, are retained while your account is active.
- Assistant conversation threads are retained for 30 days, and only the 100 most recent threads are kept.
- Access tokens expire automatically; connection tokens are deleted when you disconnect the integration.
- When you request deletion of your account, the data scoped to your user id is deleted with it.
8. Your Rights
- Disconnect services: you can disconnect the Google or Zoom integration at any time from the Extension's settings, which stops further syncing and deletes the stored tokens.
- Delete data: you can request deletion of your account and its associated data by contacting us.
- Access data: you can request a copy of the data we store about you.
9. Chrome Extension Permissions
The Extension requests the following Chrome permissions:
- cookies: to read your existing Salesforce session cookie so the Extension can call your own org on your behalf.
- storage: to persist your session state, settings and panel navigation locally.
- alarms: to schedule periodic Salesforce syncs and token refreshes.
- scripting: to read your Salesforce user id from an open Salesforce tab.
- declarativeNetRequest: to adjust request headers so the Extension's own requests to Salesforce and our backend succeed. It does not block, redirect or inspect any other site's traffic.
Host permissions are limited to Salesforce domains (*.salesforce.com,
*.force.com, *.lightning.force.com) and our own backend
(*.nebulalabs.com). The Extension runs on no other site.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated "Last updated" date. Continued use of the Extension after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at chiragshetty98@gmail.com.