OrgKit Privacy Policy
Last updated: 30 July 2026 · Applies to the OrgKit Chrome extension
Summary
OrgKit is a Salesforce developer toolkit that runs in your browser. It uses your already open Salesforce tab session to call Salesforce APIs for actions you start. OrgKit does not operate a backend that collects your org data, and it does not sell personal information.
Data OrgKit accesses
-
Salesforce session cookie (
sid) — read only on Salesforce-related domains so the extension can call Salesforce REST/Tooling APIs as you. The cookie is used in-browser as an Authorization bearer token and is never logged or written to extension sync storage. - Salesforce org data you request — for example SOQL results, object describes, Apex class bodies, flow metadata, and Org Compare inventories (objects, profiles, permission sets, flows, Apex, and related metadata) between open org sessions — shown in the extension UI and optionally exported by you (CSV/Excel/JSON). This data is not uploaded to OrgKit servers (there are none).
-
Settings & library items — favorites, API version, UI toggles, saved SOQL
names/queries, Session Workbench continue history and scratch pad (per org key),
last Org Compare A/B org-key pair (never
sid), optional AI settings. Stored in Chrome extension storage on your device/profile. Saved SOQL never includes your session id. - Optional AI provider — only if you enable AI and provide your own API key. Then the text you paste into NL→SOQL / Formula / Error / Apex Review may be sent to the OpenAI-compatible endpoint you configure. Salesforce session cookies are stripped from prompts and are not sent to the AI provider.
Permissions (why they exist)
- cookies — read Salesforce
sidon Salesforce domains only (same session model as tools like Salesforce Inspector Reloaded). - storage — settings, favorites, saved queries, workbench history/scratch pad, optional AI key (local). Never stores
sid. - Host access to Salesforce domains — call Salesforce APIs and show the on-page OrgKit launcher on Salesforce pages only.
- Optional OpenAI hosts — only after you enable AI and grant access.
What we do not do
- No analytics SDKs, ad networks, or third-party trackers in the extension.
- No sale of personal or org data.
- No transmission of
sidto non-Salesforce destinations. - No remote code execution; the extension only runs its packaged scripts.
Destructive actions
Features that update or delete Salesforce records (for example All data Save/Delete, inactive flow version deletion) run only after an explicit action in the UI and, for deletes, a confirmation dialog. OrgKit cannot delete Active flow versions via the cleaner.
Data retention
Data remains in your browser profile until you clear extension storage, remove the extension, or delete saved items. Uninstalling OrgKit removes its extension storage.
Children
OrgKit is intended for professional Salesforce developers and administrators, not for children.
Changes
We may update this policy when the extension’s data practices change. The “Last updated” date will change accordingly.
Contact
For privacy questions about OrgKit, contact the publisher listed on the Chrome Web Store listing (or the repository maintainer if you installed from source).