Privacy policy — CoverTree Switchboard browser extension

Last updated: 30 September 2026

This covers the browser extension only. The Switchboard application it connects to is operated by

your own organisation, and how that handles your data is your organisation's policy.


The short version

The extension talks only to the CoverTree Switchboard server your organisation runs.

There is no analytics, no telemetry and no advertising, and nothing is sent to us. It is not a

product with users to monetise; it is a tool your employer installs so you can dial from your browser.

It never uses your microphone and never carries a call itself, in any browser. A call you start from

it is carried by your organisation's Switchboard: the CoverTree Phones desktop app, a Switchboard

page or phone window, or your own desk phone or mobile. (Before version 1.2.0 the Firefox version had

a browser phone of its own, which connected to Twilio, your organisation's carrier. It was removed,

and it is removed from your browser when the extension updates.)


What it stores on your computer

WhatWhyWhere
Your Switchboard server addressSo it knows where to send a call requestExtension storage, on your machine
A Switchboard address you type into its settings, if you doSo that Switchboard's own pages can connect it, as described belowExtension storage, on your machine
An access tokenSo it can act as you without asking you to sign in repeatedlyExtension storage, on your machine
Your dialling preferencesWhich of your numbers to call from, and whether to ring your phone or the browserExtension storage, on your machine
Which text conversations you have already been notified aboutSo the same message does not notify you twiceExtension storage, on your machine
Which window is the phone window, and a number waiting to be textedSo a click raises the one phone window rather than opening a second, and the popup opens on the right conversationExtension storage, on your machine

Nothing else. The Firefox browser phone of versions before 1.2.0 kept a random id for the browser and

whether you had allowed the microphone; version 1.2.0 deletes both when it is installed or updated,

and each time the browser starts. If you allowed that older version the microphone, Firefox keeps the

permission in its own settings until you remove it there; the extension no longer asks for it or uses

it. No browsing history, no page contents, no list of sites visited. The only addresses it

remembers are your Switchboard server's own: the one it is connected to, one you type into its

settings, and the one noted when you open a page of a Switchboard it already trusts, so the connect

screen does not have to ask for it.

Removing the extension removes all of it. Revoking the token in your dashboard stops that browser

working immediately, without touching anything else.


What it sends, and when

All of it goes to your organisation's Switchboard server.

A phone number, when you ask it to. Every number on your screen has a small call icon beside it,

and drawing the icons sends nothing. When you rest the pointer on an icon, that one number is sent to

your own Switchboard server so it can tell you whose number it is. Clicking call or text sends it

again, to place the call or open the conversation.

A text message, when you write one and press send.

A check that this browser is signed in, before a click opens the phone window. The extension asks

your Switchboard server whether this browser is signed in to it, with the same sign-in cookie the

Switchboard pages already use. If it is not, you are shown the sign-in page instead of a phone window

that could not dial.

Nothing else, ever. Specifically it does not send:

Your browser itself also checks your Switchboard server now and then for a newer version of the

extension, the way it checks any extension's update address. Like every request a browser makes,

the extension's carry the browser's own name and version, and your Switchboard server notes which

browser each connection is in, so it can show which of your browsers are connected.


What it can technically see, and what it actually looks at

The extension asks for access to all websites, because a phone number you want to dial can be on any

page — your CRM, your webmail, a supplier's portal, a public site.

What it does with that access is deliberately narrow:

a small call icon beside each one, and it watches the page for changes so that a number appearing

later gets its icon too. That text is never stored and never sent anywhere; only a number you point

at or click leaves the page, as described above.

page puts there when you press Connect this browser, and the marker a Switchboard page sets while a

call is ringing, so the extension can bring that window to the front. It reads nothing else on the

page and sends nothing about it. The extension accepts a connection code only from a page of your

own Switchboard (the one it was made for, the one it is already connected to, or one whose address

you typed into it) and only for that page's own server, so no other website can connect it to a

server of its own. The page the CoverTree Phones desktop app opens to connect it takes only a code

that app made, which works only from the network it was made on, and a connection made that way

never replaces one that is working for somebody else; one already working for you is kept as it is,

with no second connection made. To tell those apart it shows your Switchboard server the connection

it already has. When that connection belongs to somebody else, the server tells the person whose

desktop app made the code the name it is signed in as, so the app's settings can say why Firefox was

not connected. That is usually whoever is at this browser, but a colleague on the same network who

sent you such a link learns it too, and that you opened it. That page hands the extension nothing

until you press Connect on its question, which names the account the browser would join (the person

whose desktop app made the code), so a link somebody sends you cannot connect your browser as them

without your say.

are drawn over the page, not inserted into it.

Card details are never captured

Card numbers, security codes and expiry dates are excluded from the whole Switchboard product, not

just from this extension. Any rule configured to look for them is refused and does not run.


Children

This is a business tool, distributed by an employer to staff. It is not directed at children and

collects nothing from them.


Changes

Material changes to this policy will be published here before a version relying on them ships. The

extension's version number is visible on its own page in the browser's extension list.


Contact

Questions about this policy or about the extension: phones@covertree.com.