Legal
Privacy Policy
Last updated: October 8, 2026
This Privacy Policy explains how COSTTRAIL INC (“we”, “us”) handles information when you use SF2BI, including the website at sf2bi.com and the SF2BI web application (together, the “Service”).
1. The short version
- We connect to your Salesforce org through an External Client App you create yourself, and only ever run read-only SOQL queries. Section 4 lists every scope and object.
- We never create, change or delete anything in your org, and we do not query your customer records (Accounts, Contacts, Leads, Opportunities, Orders) or files.
- Your data is visible only to your workspace. Teammates you invite share your workspace's connections and token balance; each person's copilot history stays private.
- We do not sell personal information and we do not use your data or questions to train AI models.
2. Who is responsible
For personal information about you as an account holder, COSTTRAIL INC is the data controller. For data in the Salesforce orgs you connect, you decide what we can access and we process it on your behalf to provide the Service. Questions, access requests or complaints: support@costtrail.io. Mailing address: COSTTRAIL INC, 1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA.
3. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account information | name, email, company (optional), password (stored only as a salted hash by Amazon Cognito) | You, during sign-up |
| Authentication and session | session tokens, IP address, user-agent, sign-in timestamps | Automatically on use |
| Salesforce connection details | your External Client App’s Consumer Key and Secret, the OAuth refresh token, your org’s login and instance URLs, connection labels, and any negotiated licence rates you enter — kept in AWS Secrets Manager | You, when connecting an org |
| Salesforce data we read | org configuration: users and their licences, profiles, permission sets, login and session history, setup audit trail, OAuth grants, connected apps, and your Salesforce invoice and contract headers — read live through the read-only queries listed in section 4 | Your Salesforce org |
| Invoices you upload | the PDF, the lines extracted from it and the reconciliation against your licences | You |
| Copilot conversations | your questions and the answers, kept only in your own browser as your private chat history — not on our servers | You |
| Workspace data | settings, team members and pending invitations | You and your teammates |
| Billing information | token purchases and balances; card details are handled by our payment partner, never by us | You; Lemon Squeezy |
| Usage records | which AI calls used tokens and how many, timings and error logs | Automatically on use |
| Support communications | messages you send through the contact form or by email | You |
4. Exactly what access we take in your Salesforce org
The lists below are taken from the code: the OAuth request SF2BI makes and the catalog of SOQL queries it runs. The copilot can only choose from that catalog.
How SF2BI connects
You create an External Client App in your own org and authorise it as a user you choose. There is no managed package to install. The handshake is OAuth 2.0 authorization code with PKCE; you can revoke it at any time in Setup → Connected Apps OAuth Usage, or disconnect in SF2BI’s Settings.
OAuth scopes requested
api— Run SOQL queries through the REST API. Salesforce’s api scope does not separate reading from writing, which is why we recommend connecting a user with a read-only profile: then Salesforce itself guarantees SF2BI can only read.refresh_token, offline_access— Keep the connection working without you logging in each time. The refresh token is exchanged for a short-lived access token when a report runs.
What it reads
- Users and licences: User, UserLicense, PermissionSetLicense and its assignments, PackageLicense, UserPackageLicense, Profile
- Permissions: PermissionSet, PermissionSetAssignment, PermissionSetGroup and its components, ObjectPermissions, FieldPermissions
- Logins and sessions: LoginHistory, UserLogin, AuthSession, multi-factor registrations (TwoFactorMethodsInfo)
- Configuration and audit: SetupAuditTrail, Organization, OauthToken, ConnectedApplication, NamedCredential, ExternalDataSource, AuthProvider, SamlSsoConfig, EmailDomainKey (DKIM), and the list of Event Monitoring log files (type, date, size — not their contents)
- Billing: SalesforceInvoice (number, dates, totals, balance) and SalesforceContract (terms, renewal)
- Case and AgentWork are referenced only inside two licence reports, to find which users own a case or handled work in the period. No case or work-item fields are read.
What it never does
- No Account, Contact, Lead, Opportunity or Order records, and no files — not their contents and not their names.
- Nothing is created, changed or deleted: every call is a SOQL SELECT. No Apex, no Metadata API, no package.
- The AI copilot never writes SOQL. It picks one report from the reviewed catalog; your question and the catalog’s descriptions are what the model sees — not your org’s records.
Where your keys and data live
- Your External Client App’s Consumer Key and Secret, the refresh token, your org’s login and instance URLs, and any negotiated licence rates you enter are kept in AWS Secrets Manager (encrypted at rest), one secret per connection under your workspace. Only the SF2BI service can read them.
- Access tokens are never stored: they live in the service’s memory for up to 50 minutes.
- Report results are not stored. To spare your API allocation, an identical report repeated within a minute may be answered from the service’s memory.
- Invoices you upload are kept in a private, encrypted S3 bucket under your workspace, with the extracted lines and reconciliation stored alongside so you can reopen them. You can delete any invoice from the Invoice reconciliation page. The invoice text is read by an AI model on Amazon Bedrock to extract its lines.
- Disconnecting in Settings either clears the refresh token (one-click reconnect) or wipes the connection’s secret entirely — your choice, effective immediately.
- Salesforce tokens, report rows and the text of your questions are never written to our logs.
Each connection belongs to one workspace: its secret is stored under that workspace and only the SF2BI service can read it, and an OAuth handshake started in one workspace can only be completed by a signed-in member of that same workspace. You can revoke access at any time in Salesforce (Setup → Connected Apps OAuth Usage, or by deleting your External Client App) or by disconnecting in SF2BI's Settings.
5. How we use information
- Provide, maintain and secure the Service, your account and your team's workspace.
- Read your org's configuration and invoices to show reports and answer your copilot questions.
- Meter AI token usage, process purchases, and send transactional emails (verification codes, password resets, team invitations).
- Detect and prevent fraud, abuse and security incidents.
- Improve reliability and performance using aggregated, de-identified metrics.
6. Legal bases
- Contract: to deliver the Service you signed up for.
- Legitimate interests: security, fraud prevention and service improvement, balanced against your rights.
- Legal obligation: tax, accounting and responding to lawful requests.
- Consent: optional communications, which you can withdraw at any time.
7. AI processing
The copilot and invoice reading use an AI model hosted on Amazon Bedrock. For the copilot, only your question and the descriptions of our report catalog are sent — not your org's records; the model picks a report, which then runs against your org. For invoice reading, the text of the invoice you uploaded is sent so its lines can be extracted. Amazon Bedrock processes requests on an inference-only basis and does not use your content to train models. We do not train models on your data.
8. Who we share information with
- Amazon Web Services (US) — hosting, databases, sign-in (Amazon Cognito), email (Amazon SES) and AI processing (Amazon Bedrock).
- Lemon Squeezy (US) — our payment partner and merchant of record for token purchases.
- Your teammates — members of your workspace see its Salesforce connections, reports, uploaded invoices and the team list.
- Professional advisors — legal, accounting and audit firms, under confidentiality.
- Authorities — when required by law or to protect rights, safety or property.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
9. International transfers
The Service is hosted in the United States (AWS US East). If you use it from outside the US, your information is transferred to and processed in the US, with appropriate safeguards where required.
10. Retention and deletion
Salesforce connection details are kept until you disconnect the org or close your account. Report results are not stored; an identical report repeated within a minute may be answered from the service's memory. Uploaded invoices are kept until you delete them or close your account. Copilot history lives only in your browser and is removed when you delete a conversation or clear your browser storage. Account information is kept for the life of your account and a reasonable period afterwards for legal, tax and audit purposes; token usage and billing records are retained for up to 7 years.
11. Security
We use TLS 1.2+ in transit, encryption at rest, per-workspace access checks on every request, least-privilege access, and monitoring. Salesforce tokens, report rows and the text of your questions are never written to our logs. No method of transmission or storage is perfectly secure; we will notify affected customers of a confirmed incident without undue delay.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, port your data, and withdraw consent. California residents have additional rights under the CCPA/CPRA. To exercise any right, email support@costtrail.io. We respond within the timeframes required by law.
13. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information.
14. Cookies and browser storage
We use strictly necessary cookies and browser storage to keep you signed in, to keep your copilot chat history on your device, and to remember preferences such as light or dark mode and the org you last selected. We do not use advertising cookies.
15. Changes
We may update this Policy. Material changes will be posted here with a new “Last updated” date and, where appropriate, communicated by email or in-product notice. See also our Terms of Service.
16. Contact
COSTTRAIL INC, 1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA. Privacy: support@costtrail.io.