Extension privacy policy
Updated September 9, 2026
This policy covers the GetMyKPI Sales Companion Chrome extension and the screen-sharing service it opens at share.getmykpi.com. Separate third-party services and the main GetMyKPI application may have additional policies.
Information used by the extension
On the supported VanillaSoft pages, the extension reads the current lead's contact ID, name, phone numbers, email, date of birth, address, city, state and postal code when present. It observes supported-page context and call-initiation events to connect your sales workflow. It does not request access to your general browser history or unrelated websites.
If you connect Onlysales, the extension stores the API token you supply, account identifiers, account names, selected workflow and Auto-send settings in Chrome extension-local storage. Tokens are restricted to trusted extension contexts and are not synchronized using Chrome Sync. Local duplicate-send receipts include account, contact, phone and workflow identifiers and send status.
When information is sent
Connecting Onlysales sends your token to Onlysales to validate the account and retrieve workflows. Clicking Send transfers the reviewed lead fields to Onlysales to create a contact and enroll it in your chosen workflow. If you explicitly enable Auto-send, the extension performs these actions for subsequent stable leads in the active supported VanillaSoft tab until you stop it. Workflows may send communications; select an appropriate test or customer workflow before enabling them.
For the optional locally installed macOS Call Companion, supported call-initiation/contact events are sent to its loopback listener on your own computer at 127.0.0.1:47631. The browser extension itself does not record call audio or create call transcripts. The separate companion controls its own on-device capture and local transcript files.
Screen sharing and sign-in
Screen sharing opens a separate GetMyKPI website. Your email and password are forwarded over HTTPS through the sharing server to the existing GetMyKPI Supabase authentication service. The sharing service does not retain your password. The returned access token stays in the sharing page's memory until sign-out, expiry or closure.
Chrome asks you to choose the tab, window or screen to share. The selected pixels are transmitted through encrypted WebRTC to the viewer who joins your private link, directly when possible or through Cloudflare's TURN relay when required. The selected content may contain personal or sensitive information; choose your source carefully. Pause holds the last frame visible to the viewer; Stop ends sharing. GetMyKPI does not save shared media to its server. An optional screen recording is created in your browser and downloaded locally; unsaved recordings are discarded when the window closes. Screen sharing does not include audio, webcam or remote control.
The sharing service records session ID, agent account ID, optional contact reference, start/end time, duration, whether a viewer joined and how the session ended. Account IDs associate history with the signed-in agent. Infrastructure providers necessarily process connection information such as IP addresses, request details and relay usage to operate and secure the service. Private links grant viewer access; do not publish them or share them with unintended recipients.
Providers and purposes
Onlysales processes information you send to your account. Supabase provides authentication, Railway hosts the sharing service, and Cloudflare provides network traversal/relay service. Information is used to provide the requested integrations, authentication, sharing, history, reliability and abuse prevention. The extension does not contain advertising or analytics trackers, sell personal data, or use collected information for creditworthiness or lending. Provider processing is also governed by their applicable policies and agreements.
Storage, retention and deletion
Local extension settings and duplicate-send receipts remain until cleared or the extension is uninstalled. Removing an Onlysales account in the popup deletes its stored token, but does not delete contacts or workflow enrollment already sent to Onlysales; manage those in Onlysales. Stop Auto-send before removing the account. Locally downloaded recordings and desktop companion records remain under your control and can be deleted from your computer.
Active sharing sessions are held in server memory for at most one hour and end earlier when stopped, closed or interrupted. Completed session metadata is retained on the sharing service's persistent storage; there is currently no automatic deletion schedule. Contact GetMyKPI to request deletion of retained session history. Operational provider logs may have separate retention periods controlled by the provider. Account information maintained by the main GetMyKPI application is managed separately.
Your choices
Onlysales and the desktop companion are optional. You can stop Auto-send, remove connected accounts, stop screen sharing, sign out or uninstall the extension. Changing the advanced sharing-service address causes the separate sharing window to use that service; use only a service you trust. This policy describes the default GetMyKPI service.
Contact
Privacy and support contact: getmykpi@gmail.com. Contact us about access, correction, deletion or questions about this policy. We may request information needed to verify account ownership before acting.
Changes
We will update this page when the extension's data practices change. The date above identifies this version.