MSPortal

MSPORTAL CHROME EXTENSION PRIVACY POLICY

LAST UPDATED: JULY 15, 2026

1. OVERVIEW

This Privacy Policy describes how the MSPortal Chrome Extension (the “Extension”) collects, uses, and protects your information. The Extension is published by MSPortal (“Company”, “we”, or “us”) and provides browser-sidebar access to MSPortal ticket management, training tracking, and AI support.

This policy supplements the MSPortal Privacy Policy, which governs all data processed by the MSPortal platform. By installing and using the Extension, you agree to the terms of both this policy and the main MSPortal Privacy Policy.

2. INFORMATION WE COLLECT

The Extension collects and stores the following categories of information:

Personally Identifiable Information

When you sign in, the Extension stores the following from your MSPortal account:

  • Name
  • Email address
  • Profile avatar URL
  • Tenant (organization) name and identifier

Authentication Information

To maintain your authenticated session, the Extension stores:

  • Access token (JWT)
  • Refresh token
  • Token expiration timestamp

User Preferences

  • Theme preference (light, dark, or system)
  • Notification settings

3. INFORMATION WE DO NOT COLLECT

The Extension does not collect, access, or transmit:

  • Browsing history or the URLs of pages you visit
  • Page content, text, or images from websites you browse
  • Keystrokes, clicks, mouse movements, or other user activity
  • Location or geolocation data
  • Health, financial, or payment information
  • Personal communications (emails, messages, or chat history from other services)

4. SCREENSHOTS

The Extension includes the ability to capture a screenshot of your current browser tab. This feature is only activated when you explicitly click the screenshot button while creating a ticket or sending a message to the AI assistant.

Screenshots are:

  • Never captured automatically or in the background
  • Sent directly to the MSPortal API (app.msportal.ai) over HTTPS
  • Not stored locally in the Extension beyond the active session
  • Used only for the purpose you initiated (ticket attachment or AI context)
  • Subject to the same data handling policies as all MSPortal platform data

5. HOW DATA IS STORED

The Extension stores the data described above using chrome.storage.sync, Chrome's extension-scoped storage for settings and state. Depending on your Chrome Sync settings, Chrome may synchronize this data between browsers where you are signed in. This storage should not be understood as end-to-end or application-level encryption. It is:

  • Scoped to the Extension and inaccessible to ordinary websites or other extensions
  • Synchronized across your Chrome browsers when signed into the same Google account
  • Cleared by the Extension when you sign out; uninstall and synchronization behavior is also governed by Chrome

No data is written to your filesystem, cookies from other domains, or any location outside of Chrome's extension storage.

6. HOW DATA IS TRANSMITTED

The Extension communicates exclusively with MSPortal servers at *.msportal.ai. All communication occurs over HTTPS.

The Extension does not transmit data to any third-party services, analytics providers, advertising networks, or any domain other than msportal.ai.

API requests made by the Extension include:

  • Authentication requests (sign in, token refresh, sign out)
  • Ticket data retrieval and creation
  • Training enrollment and course data retrieval
  • AI assistant chat messages

7. PERMISSIONS

The Extension requests the following browser permissions, each for a specific purpose:

PermissionPurpose
storageStore authentication tokens, user preferences, and theme settings
activeTabCapture a screenshot of the current tab when you click the screenshot button
tabsQuery the active tab to enable screenshot capture
sidePanelDisplay the Extension as a browser sidebar
cookiesMaintain authenticated sessions with msportal.ai
host: *.msportal.aiCommunicate with the MSPortal API

No permissions are used to monitor, track, or collect data about your browsing activity.

8. REMOTE CODE

The Extension does not download or execute any remote code. All JavaScript is bundled locally at build time. No external scripts are loaded, evaluated, or injected at runtime.

9. THIRD-PARTY SERVICES

The Extension does not integrate with, transmit data to, or receive data from any third-party services. All data flows exclusively between the Extension and MSPortal servers. Data processed by the MSPortal platform (including data sent by the Extension) may be subject to third-party processing as described in the main MSPortal Privacy Policy.

10. DATA RETENTION & DELETION

Locally stored Extension data (tokens, user info, preferences) is retained until you:

  • Sign out of the Extension, which clears all authentication data and user information
  • Uninstall the Extension, which removes all stored data
  • Clear browser data for extensions in Chrome settings

Data transmitted to and stored on MSPortal servers is subject to the retention and deletion policies described in the main MSPortal Privacy Policy. You may request deletion of your data by contacting privacy@msportal.ai.

11. CHILDREN'S PRIVACY

The Extension is not intended for use by persons under the age of 18. We do not knowingly collect personal information from minors. If we become aware that personal information has been collected from a minor, we will delete it immediately.

12. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. Changes will be posted to this page with an updated “Last Updated” date. Continued use of the Extension after changes constitutes acceptance of the revised policy.

13. CONTACT US

If you have questions about this Privacy Policy or the Extension's data practices, please contact us at: privacy@msportal.ai

We will respond to all inquiries within 7 days.