Instant Salesforce permission analysis: inspect users, profiles, permission sets, objects, fields, Apex classes, flows, triggers and layouts — all with full provenance.
Last updated: July 2026
SFAnalyzer does not collect, transmit, or share any user data with any third party.
All data processed by the extension remains entirely on the user’s local machine:
chrome.storage.local) on the user’s device only. Access tokens are stored in session storage (chrome.storage.session) and are cleared when the browser closes.identity: Required for the OAuth 2.0 authorization flow via chrome.identity.launchWebAuthFlow.storage: Required to persist refresh tokens, org connections, and user settings locally.https://*.salesforce.com/* and https://*.force.com/*: Required to make API calls to Salesforce orgs.http://localhost/*: Required ONLY to observe the OAuth redirect URL (http://localhost:1717/OauthRedirect) during the authorization flow. Nothing is served on this port — the extension only reads the redirect URL from its own auth tab to capture the authorization code.This extension does not use any third-party analytics, advertising, or tracking services. The only external communication is with the user’s own Salesforce orgs via the Salesforce REST and Tooling APIs.
For questions about this privacy policy, please open an issue on the extension’s GitHub repository.
Any changes to this privacy policy will be reflected in an updated version published alongside the extension update.