Word add-in privacy.
This policy covers Sliick Docs for Microsoft Word, the Sliick Docs add-in for Microsoft Word. It explains how the add-in handles your personal information and your document content. It is separate from the privacy policy for our Salesforce apps and the privacy policy for sliick.com. If you need more, contact us.
The short version
- Sliick does not receive your documents or your Salesforce data. The add-in talks directly to your own Salesforce org from your device. Your documents, your Salesforce records, and your login credentials do not pass through Sliick's servers.
- It does nothing at all until you connect it. The add-in starts in demo mode, running on sample data held in memory, with no network calls and no Salesforce connection.
- No analytics, no tracking, no profiling. The add-in contains no analytics, telemetry, advertising, or third-party tracking code of any kind.
- What is stored, is stored on your device. Your sign-in tokens and your settings are held in your own browser storage inside Word, not in an account we keep for you.
What this app is
Sliick Docs for Microsoft Word is an Office add-in for Microsoft Word, shown in Word as Sliick Docs. It opens as a task pane beside your document and lets you insert Salesforce merge fields into a Word document, validate the merge tags already in it, and save the finished document back to your Salesforce org as a Sliick Docs template.
The add-in is a static web application served from https://office.sliick.com and rendered by Word inside its own webview. There is no Sliick account to create, and no Sliick-operated service sitting between the add-in and your Salesforce org.
Demo mode: the default, and nothing leaves your device
When you first install the add-in it runs in demo mode. In demo mode it operates entirely on sample data held in memory so you can try the interface. It makes no network requests, connects to no Salesforce org, and reads no personal information. Nothing is transmitted anywhere, including to Sliick.
The add-in only leaves demo mode when you turn demo mode off and supply your own Salesforce org address.
Connected mode: what is sent, and where
Once you connect the add-in to your Salesforce org, it communicates with exactly two destinations, both of which are your own Salesforce org:
- Your org's OAuth token endpoint (
https://your-domain.my.salesforce.com/services/oauth2/token), to sign you in and to refresh your session. - Your org's API endpoints, to read the object and field metadata shown in the task pane, and to save a document into your org.
Signing in uses OAuth 2.0 with PKCE, performed entirely in your browser, directly against your own org. You enter your Salesforce credentials on Salesforce's own login page, not in the add-in. Sliick never sees your Salesforce username, password, or access tokens, and there is no Sliick-operated proxy that your tokens pass through.
By default, the add-in identifies itself to Salesforce using a Sliick-registered connected app identifier. That identifier is a public, non-secret client ID used to start the OAuth flow: it does not give Sliick any access to your org, and no data is routed to Sliick because of it. Your administrator can supply your organisation's own connected app consumer key instead, in the add-in's settings.
Your document's content
The add-in reads the text of the document you have open in Word in order to find and validate the merge tags in it, and to insert new merge fields where you place them. That reading happens locally, inside Word, on your device.
When you choose Save to Salesforce, the add-in uploads the document from your device directly to your own Salesforce org, where it is stored as a Salesforce file. Sliick does not receive, process, or store your document, and no copy of it is sent to Sliick or to any third party.
What is stored on your device
The add-in stores the following in your browser's storage inside Word, on your own device. None of it is transmitted to Sliick.
- Your access token, held in session storage, which is cleared when the task pane is closed.
- Your refresh token, held in local storage, so that reopening Word does not force you to sign in again.
- Your settings: your Salesforce org address, the connected app consumer key if your administrator supplied one, and whether demo mode is on. None of these are secrets.
- Convenience data: the names of merge fields you have recently used or pinned, so they appear at the top of the list next time.
Signing out clears both tokens. Removing the add-in from Word, or clearing the add-in's storage, removes the rest.
What Sliick does not collect
- We do not collect or store your Salesforce records, fields, or metadata.
- We do not collect or store your documents.
- We do not collect or store your Salesforce credentials, access tokens, or refresh tokens.
- We do not use analytics, telemetry, advertising, or third-party tracking in the add-in. There is no such code in it.
- We do not build a user profile, and we do not have user accounts for this add-in.
- We do not sell, rent, or share personal information with third parties for marketing or advertising.
- We do not use your documents or your org's data to train models.
Hosting and server logs
The add-in's files are served as a static site through Cloudflare. As with any website, Cloudflare's edge servers process standard web request information in order to deliver those files and to protect the service: IP address, user agent, the file requested, and a timestamp. This is the only information about your use of the add-in that reaches infrastructure Sliick operates, it is not linked to a Sliick account, and it contains none of your Salesforce data or document content.
Word also loads Microsoft's own Office JavaScript library from Microsoft's content delivery network, as it does for every Office add-in. That request is between your device and Microsoft, and is governed by Microsoft's privacy terms.
Security
Sign-in uses OAuth 2.0 with PKCE against your own Salesforce org, so no long-lived password is stored by the add-in and no credential is handled by Sliick. All communication with your org uses encrypted transport (HTTPS). Access to your org is limited to the permissions your Salesforce administrator grants the connected app and to what your own Salesforce user is permitted to see, so the add-in cannot reach data you could not reach yourself. If a security incident affects your data, our Cyber Security Incident Response Plan and Personal Information Breach Response Plan set out how we respond and notify you.
Australian Privacy Principles
We contractually commit to every customer, in every jurisdiction, to handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). See our Terms & Conditions for the binding commitment.
Data retention and removing the add-in
Because Sliick does not receive your documents or your Salesforce data through this add-in, there is nothing held by us to retain or delete on your behalf. Data stored on your device is under your control: sign out to clear your tokens, and remove the add-in from Word to remove it and its stored settings. Documents you have already saved into your Salesforce org remain in that org, under your organisation's own retention rules.
Children's privacy
This add-in is built for use by employees of a business working with their organisation's Salesforce org, and is not directed at children. We do not knowingly process data relating to anyone under the age of 18 through this add-in.
Changes to this policy
We may update this policy from time to time, particularly as the add-in gains new capabilities. We will post the revised policy on this page and update the "Last updated" date above. If a change materially affects how the add-in handles your information, we will say so in the add-in's release notes.
How this relates to our other privacy policies
- App privacy policy: covers the Sliick managed packages that run inside your Salesforce org, including the in-org Sliick Docs app.
- Website privacy policy: covers sliick.com itself, such as visiting the site, using the contact form, and cookies.
Contact us
If you have any questions about this policy or about how the add-in handles your information, please contact us, or email support@sliick.com.