Privacy Policy for Dina Agent for Salesforce
Last updated: August 18, 2026
Dina Agent for Salesforce is an independent Chrome extension in development for Salesforce administrators and developers. Version 0.5.0 combines an AI-assisted side panel with metadata, data, org review, permission, API, export, and monitoring workspaces.
Salesforce is a trademark of Salesforce, Inc. The extension is not affiliated with, endorsed by, or sponsored by Salesforce. The OpenAI name identifies the configured AI service; no affiliation with or endorsement by OpenAI is implied.
Data the Extension Handles
The extension may handle the following data to provide its user-facing features:
- Salesforce session cookies and session credentials for supported Salesforce domains, used inside the extension to connect to an org where the user is already signed in.
- Salesforce org, user, object, schema, metadata, record, report, permission, REST API, Tooling API, Metadata API, monitoring, and audit information requested by the user.
- Current Salesforce tab information, including the page title and URL, when available.
- Chat messages, assistant responses, selected Salesforce context, selected visible workspace context, extension tool results, and previous response IDs.
- Google identity information used to sign in to the Dina account, including the account email address.
- Local workspace settings, query sheets, saved files, metadata, pending edits, UI preferences, chat history, and bounded operation receipts.
- Aggregate Dina account usage counters, including Send, token, and estimated AI cost totals.
The extension is not designed to collect health information, GPS location, nearby device location, full browser history, mouse tracking, scroll tracking, keystroke logging, creditworthiness, or lending information.
How Salesforce Access Is Used
Salesforce REST, Tooling, and Metadata API tools run inside the extension using the Salesforce session already present in the browser. Salesforce session IDs, access tokens, cookies, and authorization headers are not included in AI chat requests.
The extension uses Salesforce data only to provide the requested workspace, investigation, review, export, and assistant features. Consequential workflows retain their existing user review and confirmation steps.
AI Requests and Google Cloud Processing
AI requests are sent only after the user presses Send. A request may contain the user's message, selected Salesforce context, selected visible workspace context, current tab context, and extension tool results. Salesforce authentication credentials are excluded.
The extension sends the Dina account sign-in token to the configured service so the account can be verified, usage limits can be applied, and the user-requested AI response can be returned.
The AI panel is advisory. It cannot independently deploy metadata, update or delete Salesforce records, execute Apex, or call Salesforce APIs from the AI panel.
Storage and Retention
Chrome extension storage and browser local storage may hold UI settings, chat history, previous response IDs, query sheets, workspace state, retrieved schema and metadata, pending edits, and bounded operation receipts on the user's device.
The Dina account service may store account identity and aggregate Send, token, and estimated cost counters. It is not designed to store Salesforce sessions, Salesforce records, prompts, or transcripts.
Users can clear supported saved data from the extension UI, uninstall the extension, or clear the extension's Chrome-managed storage.
Data Sharing and Transfers
Dina Agent for Salesforce does not sell user data and does not use user data for advertising, tracking, profiling, creditworthiness, or lending purposes.
- Salesforce data is requested from the selected Salesforce org for the signed-in Salesforce user.
- Google identity data is sent to Google services for sign-in and to the configured Google Cloud backend for Dina account verification.
- User-initiated AI input and selected bounded context are processed by the configured Google Cloud backend and OpenAI to return the requested response.
- Salesforce session IDs, access tokens, cookies, and authorization headers are not sent to OpenAI.
Remote Code
The extension does not load or execute remotely hosted extension code. Its executable JavaScript, HTML, CSS, and packaged third-party components are included with the extension. Salesforce and AI responses are treated as data, not executable code.
Human Access
The developer does not have access to data handled only inside the extension unless the user separately shares it for support. Data sent through the configured Google Cloud backend is processed to provide the requested account and AI functionality.
Billing Status
Version 0.5.0 is a development preview. Paid production billing is not publicly released and remains subject to separate live Stripe, Google Cloud, security, and release verification.
Chrome Web Store Limited Use Disclosure
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Contact
Support email: [OWNER INPUT REQUIRED: SUPPORT EMAIL]
Support phone: [OWNER INPUT REQUIRED: SUPPORT PHONE]
Seller and subscription disclosures are provided in the 特定商取引法に基づく表記.