Legal · GDPR-ready
Privacy Policy
Effective October 3, 2026
GRAVENX is a browser-first Salesforce workbench for architects. It is designed so that your Salesforce credentials and org data stay with you: session secrets live in your browser tab, your work is stored in your browser's local databases, and this site sets no tracking cookies and runs no analytics or advertising. This page explains what is stored, why (including the GDPR lawful basis), and what rights you have.
1. Who is responsible
For data-protection purposes, you (or your organisation) are the controller of the Salesforce org data you choose to load into the tool. The tool itself performs no independent processing of your org data — it renders what you request, in your browser, against the org you connect.
The publisher of this utility is Kuldeep Singh. Privacy questions: kuldeep@coffeediscussions.com.
2. What is stored, where, and why
- Salesforce session (instance URL, access token, API version) — kept in
sessionStorage(tab-scoped; cleared when the tab closes) and in page memory so you can work across tabs of this tool. Lawful basis: your consent when you click Connect, and performance of the service you requested (GDPR Art. 6(1)(a), (b)). - Your designs (collections, payloads, snapshots, history, autosaves) — kept in your browser's IndexedDB, per organisation. They never leave your device except when you explicitly export or share them.
- Banner acknowledgement — a single
localStorageflag records that you dismissed the privacy banner, so we don't show it again. Strictly necessary, no consent required. - No accounts, no tracking, no ad cookies. There is nothing to log into on our side and nothing measuring you across sites.
3. How Salesforce calls travel
When you connect, your browser sends the session to this app's server-side API routes, which proxy the request to your Salesforce org (e.g. *.salesforce.com, *.force.com) and return the response. This covers reads, the record edits you make in Data Walkers, and — only in Author mode on the schema canvas — the metadata changes you explicitly confirm (new custom fields, objects, and relationships). Tokens are used only to fulfil your request and are not written to server disks or logs beyond transient error handling. Rate limiting (200 requests/minute per IP) protects the proxy from abuse.
4. Retention and deletion
Close the tab and the session secret is gone from sessionStorage; use Disconnect and it is cleared immediately. IndexedDB designs persist on your device until you delete them (per-item delete, collection delete, or browser site-data clearing). The banner flag persists until you clear site data.
5. Your rights (GDPR / UK GDPR and equivalents)
Because processing happens in your own browser, most rights are exercised directly: access and portability via Export, rectification by editing, erasure by deleting items or clearing site data, restriction by disconnecting. For anything you cannot do yourself — or for requests under applicable laws (GDPR, UK GDPR, CCPA/CPRA, and similar regimes) — contact kuldeep@coffeediscussions.com. You also have the right to lodge a complaint with your supervisory authority.
7. Security
Transport is HTTPS-only with strict security headers (Content-Security-Policy, no framing, no-sniff, strict referrer). See the Security overview for the full model — and note the shared-responsibility part: use least-privilege tokens, rotate them, and never paste a production session into a shared machine.
8. Children and changes
This is a professional tooling site, not directed at children. If this policy changes materially, the effective date above will be updated and the change noted in the tool.