PRIVACY · OCTOBER 4, 2026

Your orgs.
Your context.

Headful Cloud is an independent beta service operated by Jalil Laaraichi. This notice explains the data this first release handles. Contact reachjalil@gmail.com for privacy questions or a deletion request.

What we store

Client credentials, Salesforce tokens, workflow drafts/results, and proposal payloads receive application-level encryption at rest. Account emails, org labels/identifiers, origins, and audit metadata are not encrypted by that application layer. We do not store Salesforce passwords.

What happens to Salesforce data

The service reads leads and permission-set data when you or an authorized agent request them. Lead results are bounded and returned to your browser or selected chat host; this release does not maintain a bulk lead database. User workflows retain supported identity fields such as names, email, username, profile, and locale settings as needed for creation, verification, and access setup. Permission reviews retain relevant before/after values and verified results so you can inspect their outcome.

Connecting an agent shares the returned CRM context with that host under its own privacy and retention policies. Choose only the orgs and access you intend to share, and avoid sending unnecessary personal or confidential fields into chat.

Infrastructure and disclosures

Cloudflare provides hosting, database, secrets, static assets, email delivery, and operational observability. Salesforce receives the OAuth and API requests needed for your connection. Your chat host receives the tool results and App context you request. We do not add an advertising tracker or sell your CRM data as part of this beta.

Cookies and access

We use essential cookies for browser sign-in and sessions. Agent access uses separate OAuth tokens; a browser cookie or public account URL does not authorize an agent. You can revoke an agent grant or disconnect an org in Setup. Disconnecting clears the service's stored token envelope, while Salesforce-side authorization must be revoked in Salesforce when needed.

Retention and deletion

Expired temporary authentication and rate-limit records are cleaned automatically. Account, waitlist, application, connection, workflow, audit, and permission-review records are retained in this beta until removed through an operator-reviewed request or later retention policy. There is no self-service account deletion screen or fixed universal deletion deadline in this release.

To request access, correction, or deletion, contact us from the account email. We will verify ownership and explain any relevant operational or legal retention limits. Disconnecting an org or deleting service data cannot undo a Salesforce change or remove a conversation already held by your chat host.

Beta updates

We will update this notice when the service's data handling changes. Public directory publication, additional providers, and broader access would need their own disclosures.