Flow Companion for Salesforce Add to Chrome

Docs

Privacy and security

The short version is on the homepage. This is the long one, written for the person who has to approve the extension.

What leaves your browser

Your Salesforce session

The extension uses the session you already have to read the flow from your own org through Salesforce's API. That session is sent only to your org's own My Domain hosts and never anywhere else. It is never stored.

Your API key

Kept in Chrome's extension storage on your computer. With Remember this key off, it lives in session storage and is gone when Chrome closes. Forget everything on this computer in Settings removes every key, every chat, and every setting. It is the only way to remove a saved key today; removing one key on its own, keeping the chats, is planned for a later version.

Permissions

Three: cookies, to read the Salesforce session; sidePanel, to be a side panel; storage, for the key and the chats. Host access is limited to your Salesforce My Domain hosts and the three providers. There is no access to other tabs or to browsing history.

What Chrome enforces

The extension ships a content security policy that Chrome applies whatever this page says: the panel may connect only to the Salesforce hosts and the three providers, and may load nothing from anywhere else, no remote scripts, images, fonts, or frames. Anything the model returns is rendered as sanitised text; it can never run as code in the panel.

How to check

Reporting a problem

Email support@getflowcompanion.com. Expect an acknowledgement within three business days.

The full privacy policy is the formal statement of all of this.

Previous: Limits · All docs