Privacy Policy
This Privacy Policy explains how the SideRep Chrome extension ("SideRep," "we," or "the extension") handles information. SideRep is a sales-outreach assistant used alongside Salesforce. It has no developer-operated backend database; its persistent data is stored locally in the user's Chrome profile unless described below.
1. Information SideRep processes
Salesforce and website content
After an explicit user action, SideRep may read relevant information displayed on the active Salesforce page, including names, business and account names, contact details, websites, lender information, and other visible fields needed for outreach. SideRep does not collect general browsing history, clicks, keystrokes, or activity on unrelated websites.
Information entered by the user
Users may enter representative contact details, instructions, templates, account identity, current balance, percentage paid, lender details, eligibility context, email recipients, email content, SMS copy, and chat prompts. Current balance, percentage paid, lender, eligibility, research, source, SMS, and generated-only Renewal or Add-on draft fields are not retained in Renewal history.
Authentication information
SideRep stores separate user-provided OpenAI API keys for Assistant and Renewal features in
chrome.storage.local. Google authorization is handled through Chrome Identity
and Google OAuth. The connected Google email address is retrieved with user authorization
and stored locally for display. SideRep does not operate a server that stores these
credentials or account information.
2. How information is used and transmitted
-
OpenAI: When a user requests AI assistance, relevant prompts, approved
Salesforce context and user-entered information may be sent to OpenAI using the applicable
Assistant or Renewal API key. Renewal and Add-on research also sends business identity and
website information to OpenAI's Responses API, which performs live web searches on the
user's behalf. Current-cycle copied email history is included as context. Requests set
OpenAI's
storeoption tofalse. - Google: Only Gmail API delivery sends recipient addresses, subject, body, and required OAuth information from SideRep to Google. Gmail compose-link mode opens a prefilled Gmail page for the user, while manual composer mode keeps composition local until the user copies it elsewhere.
- Salesforce: Salesforce content is read locally from the visible page. SideRep does not use a Salesforce API or send extracted data to a SideRep-controlled server.
OpenAI and Google process information under their respective privacy policies and service terms. SideRep does not sell personal information, use it for advertising, or transfer it for unrelated purposes.
3. Local storage and retention
Depending on enabled features, SideRep may store locally:
- Extension preferences, representative profile, templates, model settings, and API configuration and the connected Google email address.
- When the user-controlled Remember Sent setting is enabled, a bounded history of Email-tool messages, including recipients, subject, body, delivery method, timestamp, and provider identifiers.
- Bulk-run status metadata and aggregate counts, without recipient lists or message bodies.
- Bounded Renewal and Add-on account identity, aliases, website, cycle type, and subject/body of emails successfully copied through Copy Email.
Renewal archives may be pruned when local bounds are reached. Users can clear applicable histories and delete saved Renewal accounts within SideRep. Removing the extension also removes its Chrome local storage, subject to Chrome's behavior.
4. Financial and lending information
SideRep may process user-supplied financial context solely to draft sales communications. It does not calculate creditworthiness, perform underwriting, establish financing terms, determine eligibility, or make lending decisions. Any eligibility value is manually supplied outreach context rather than a SideRep decision.
5. Security
SideRep limits network access to declared Salesforce, Force.com, Visualforce, Salesforce Setup, OpenAI, and Google API hosts. All executable extension code is included in the installed package; SideRep does not execute remotely hosted JavaScript or WebAssembly. No system can guarantee absolute security, and users are responsible for protecting their browser profile and API credentials.
6. Children's privacy
SideRep is a business productivity tool and is not directed to children under 13.
7. Changes to this policy
We may update this policy when SideRep's functionality or data practices change. The effective date and version shown above will be updated when material changes are published.