SdCoreJS Link Insight

Privacy Policy

Last updated: August 16, 2026

SdCoreJS Link Insight is a Chrome extension for Google Chat. It provides on-demand summaries of supported work-item links and, for a Jira Cloud site explicitly connected by the user, carefully confirmed workflow-transition tools. This policy explains what data the extension handles, why it is needed, where it goes, and the controls available to users.

The extension does not include advertising, telemetry, analytics, data brokerage, or an extension account system. It does not sell user data or use it for lending, creditworthiness, or purposes unrelated to its disclosed functionality.

Data the extension handles

How data is used and shared

Confluence uses deterministic demonstration content in the current version. The extension does not authenticate to Confluence or retrieve live Confluence data.

Storage and retention

The Gemini API key, opaque Jira session, selected Jira sites, and consent setting are stored in chrome.storage.local. Access is restricted to trusted extension contexts so the Google Chat content script cannot read those values. Validated summaries are cached in chrome.storage.session for five minutes to reduce duplicate API requests. Raw work-item content is not placed in the summary cache.

Inactive companion-service installation records are removed after 30 days. Short-lived OAuth state, exchange codes, refresh leases, rate-limit windows, and idempotency records expire separately. Selecting Disconnect Jira requests immediate deletion of the associated installation and grant records.

User controls

Security and BYOK limitations

Personal or sensitive data is transmitted over HTTPS. Atlassian refresh tokens held by the companion service are encrypted at rest. The user-provided Gemini key is stored locally for this bring-your-own-key design; Chrome local storage is not a hardware-backed secret vault. A person with sufficient operating-system or Chrome-profile access, or a future compromised extension update, could access locally stored credentials. Users should monitor usage and revoke the key if the device or extension is compromised.

Gemini requests use store: false, but Google still processes submitted content under its applicable API terms, policies, quota, and pricing. Users should confirm that sending organizational Jira content to Gemini is permitted before enabling the consent setting. AI output can be inaccurate and important details should be checked in the source work item.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Policy hosting

GitHub Pages hosts this public policy document. The extension does not send extension data to this website. Requests to this page may be processed by GitHub under GitHub's own privacy terms as part of serving the page.

Contact

Questions or privacy requests can be submitted through the SdCoreJS Link Insight issue tracker. Do not include API keys, tokens, private Jira content, or other sensitive data in a public issue.