Privacy Policy — Duda Admin Toolkit

Last updated: 30 September 2026

This policy describes how the Duda Admin Toolkit browser extension handles data. It covers the extension only. Duda's general privacy policy, covering the Duda platform and website, is at https://www.duda.co/legal/privacy.

Who it applies to

The extension is distributed privately to Duda staff and is not offered to the public. Its users are Duda employees already signed in to Duda's internal staff administration console. It has no function for Duda customers or for visitors to sites built on Duda.

Where it runs

The extension activates on one set of addresses only: https://*.duda.co/*admin/vaadin*, Duda's internal staff administration console. It does not run on any other website. It has no background process, and does nothing at all while no console page is open.

What it accesses

Section headings. It reads the headings already displayed on the console page you are viewing, to build a sidebar that scrolls to them. These never leave the page.

A switch-to-user link — authentication information. The console has a Switch to User action that generates a single sign-on URL, which signs the holder in as the selected account. Normally the console opens that URL in a new tab immediately. If you switch on the extension's capture option, the extension holds that one navigation back and shows you the URL instead, so you can copy it — for example to test as a client in a separate browser profile. This URL is a live credential for as long as it remains valid.

Capture is off by default. While it is off, the extension does not read the link at all.

What happens to it

The link is held in the page's memory for as long as that page stays open, and is discarded when you reload or navigate away. If you press Copy, the extension writes it to your system clipboard. That is the only time it leaves the page, and only because you asked it to.

What it does not do

The extension does not:

  • transmit anything. It makes no network request of any kind, and contains no code able to make one.
  • store anything. It writes nothing to extension storage, browser local or session storage, IndexedDB, or cookies.
  • read any other site, tab, browsing history, or bookmark.
  • include analytics, telemetry, tracking, or advertising.
  • send data to Duda, or to any third party.
  • sell or transfer data to anyone, for any purpose.

Permissions

The extension requests no Chrome permissions and no host permissions. Its two scripts are authorised solely by the match pattern above.

Duda's own records

Separately from the extension, the administration console records switch-to-user actions in its own audit trail, exactly as it does when the feature is used without the extension. The extension neither adds to those records nor suppresses them. They fall under Duda's internal logging practices, not under this policy.

Handling a captured link

A captured switch-to-user link is a working credential until it expires. Treat it as you would a password: do not paste it into a ticket, a chat message, or a shared document, and reload the page once you are finished with it.

Changes

If the extension's data handling changes, this page is updated and the date above changes with it.

Contact

Questions about this policy: privacy@duda.co