This privacy policy applies to SFMC Scout, a Chrome extension published by Aldorino Rrushi. The extension adds a side panel inside Salesforce Marketing Cloud (SFMC) that helps users search, browse, and inspect their own SFMC assets (Data Extensions, Automations, Journeys, Emails, Content Builder assets, Activities) plus create / import / export Data Extensions and save reusable code snippets. It only runs on SFMC domains (*.exacttarget.com, *.marketingcloudapps.com) and only when the user is already signed into SFMC.
The extension reads data from the user's own active SFMC session: Data Extensions and their fields, automations and their step breakdowns, journeys, content assets, activities, and folder metadata. All API calls go to the user's own SFMC instance using the user's existing browser cookies. No data leaves the user's browser.
For the few operations that involve creating or modifying records (DE create, DE import, contact lookup), SFMC requires a short-lived x-csrf-token header. The extension passively reads this header from outbound traffic the user's own SFMC tab is already sending, and stores it in chrome.storage.local for the duration of the session. The token is a session-scoped CSRF token issued by SFMC, not a credential. It cannot be used outside the user's logged-in browser. Tokens are never transmitted to any third party.
None. All API requests go directly from the browser to the user's SFMC instance. The extension does not contact any server controlled by the developer. There is no analytics, no telemetry, no remote logging.
chrome.storage.local is used to persist:
All values are local to the browser profile. Storage is cleared when the user uninstalls the extension or clears Chrome storage manually.
The Snippets tab lets users save code they write themselves and deploy it into open SFMC editors (CloudPages HTML editor, Script Activity editor) with one click. The extension reaches the Ace editor on the user's own active SFMC tab through standard DOM access from the injected panel. No code from any external source is injected. Only code the user themselves saved in the panel can be deployed.
None. The extension does not load remote code, does not include analytics, and does not call any developer-controlled endpoint. No CDNs are used at runtime.
The extension is a developer tool intended for Salesforce Marketing Cloud users. It is not directed at children.
This policy may be updated when extension functionality changes. The "Last updated" date will reflect material changes. The latest version is always available at this URL.
Aldorino Rrushi