Last updated: 30 September 2026
This covers the browser extension only. The Switchboard application it connects to is operated by
your own organisation, and how that handles your data is your organisation's policy.
The extension talks only to the CoverTree Switchboard server your organisation runs.
There is no analytics, no telemetry and no advertising, and nothing is sent to us. It is not a
product with users to monetise; it is a tool your employer installs so you can dial from your browser.
It never uses your microphone and never carries a call itself, in any browser. A call you start from
it is carried by your organisation's Switchboard: the CoverTree Phones desktop app, a Switchboard
page or phone window, or your own desk phone or mobile. (Before version 1.2.0 the Firefox version had
a browser phone of its own, which connected to Twilio, your organisation's carrier. It was removed,
and it is removed from your browser when the extension updates.)
| What | Why | Where |
|---|---|---|
| Your Switchboard server address | So it knows where to send a call request | Extension storage, on your machine |
| A Switchboard address you type into its settings, if you do | So that Switchboard's own pages can connect it, as described below | Extension storage, on your machine |
| An access token | So it can act as you without asking you to sign in repeatedly | Extension storage, on your machine |
| Your dialling preferences | Which of your numbers to call from, and whether to ring your phone or the browser | Extension storage, on your machine |
| Which text conversations you have already been notified about | So the same message does not notify you twice | Extension storage, on your machine |
| Which window is the phone window, and a number waiting to be texted | So a click raises the one phone window rather than opening a second, and the popup opens on the right conversation | Extension storage, on your machine |
Nothing else. The Firefox browser phone of versions before 1.2.0 kept a random id for the browser and
whether you had allowed the microphone; version 1.2.0 deletes both when it is installed or updated,
and each time the browser starts. If you allowed that older version the microphone, Firefox keeps the
permission in its own settings until you remove it there; the extension no longer asks for it or uses
it. No browsing history, no page contents, no list of sites visited. The only addresses it
remembers are your Switchboard server's own: the one it is connected to, one you type into its
settings, and the one noted when you open a page of a Switchboard it already trusts, so the connect
screen does not have to ask for it.
Removing the extension removes all of it. Revoking the token in your dashboard stops that browser
working immediately, without touching anything else.
All of it goes to your organisation's Switchboard server.
A phone number, when you ask it to. Every number on your screen has a small call icon beside it,
and drawing the icons sends nothing. When you rest the pointer on an icon, that one number is sent to
your own Switchboard server so it can tell you whose number it is. Clicking call or text sends it
again, to place the call or open the conversation.
A text message, when you write one and press send.
A check that this browser is signed in, before a click opens the phone window. The extension asks
your Switchboard server whether this browser is signed in to it, with the same sign-in cookie the
Switchboard pages already use. If it is not, you are shown the sign-in page instead of a phone window
that could not dial.
Nothing else, ever. Specifically it does not send:
Your browser itself also checks your Switchboard server now and then for a newer version of the
extension, the way it checks any extension's update address. Like every request a browser makes,
the extension's carry the browser's own name and version, and your Switchboard server notes which
browser each connection is in, so it can show which of your browsers are connected.
The extension asks for access to all websites, because a phone number you want to dial can be on any
page — your CRM, your webmail, a supplier's portal, a public site.
What it does with that access is deliberately narrow:
a small call icon beside each one, and it watches the page for changes so that a number appearing
later gets its icon too. That text is never stored and never sent anywhere; only a number you point
at or click leaves the page, as described above.
page puts there when you press Connect this browser, and the marker a Switchboard page sets while a
call is ringing, so the extension can bring that window to the front. It reads nothing else on the
page and sends nothing about it. The extension accepts a connection code only from a page of your
own Switchboard (the one it was made for, the one it is already connected to, or one whose address
you typed into it) and only for that page's own server, so no other website can connect it to a
server of its own. The page the CoverTree Phones desktop app opens to connect it takes only a code
that app made, which works only from the network it was made on, and a connection made that way
never replaces one that is working for somebody else; one already working for you is kept as it is,
with no second connection made. To tell those apart it shows your Switchboard server the connection
it already has. When that connection belongs to somebody else, the server tells the person whose
desktop app made the code the name it is signed in as, so the app's settings can say why Firefox was
not connected. That is usually whoever is at this browser, but a colleague on the same network who
sent you such a link learns it too, and that you opened it. That page hands the extension nothing
until you press Connect on its question, which names the account the browser would join (the person
whose desktop app made the code), so a link somebody sends you cannot connect your browser as them
without your say.
are drawn over the page, not inserted into it.
Card numbers, security codes and expiry dates are excluded from the whole Switchboard product, not
just from this extension. Any rule configured to look for them is refused and does not run.
This is a business tool, distributed by an employer to staff. It is not directed at children and
collects nothing from them.
Material changes to this policy will be published here before a version relying on them ships. The
extension's version number is visible on its own page in the browser's extension list.
Questions about this policy or about the extension: phones@covertree.com.