Policy version 2026-07-23

User agreement

Your authorization

Use sf-deck only with Salesforce orgs, data, and functionality you are authorized to access. You are responsible for complying with the agreements and API limits that apply to your Salesforce account, choosing an appropriate user and permission set, protecting your computer and local state, and reviewing commands and targets before approving writes.

sf-deck reuses Salesforce CLI authorization. It does not grant additional Salesforce rights or bypass Salesforce permissions.

Local tool, not a hosted service

sf-deck runs on your computer and communicates directly with the selected Salesforce instance. The maintainer does not receive, host, or control your Salesforce customer data. See the privacy notice for the exact in-memory and on-disk behaviour.

You direct all reads, writes, exports, bundles, scripts, and agent actions. Local safety levels are an additional guardrail, not a substitute for Salesforce permissions, change control, backups, review, or your own security obligations.

Automation and agents

If you use the headless CLI, control socket, bundled agent skill, or another automated system, you are responsible for its identity, permissions, instructions, supervision, and output. Follow the Salesforce terms applicable to your use, including the Salesforce Agent Integration Protocols when applicable. Use least privilege and human review for consequential or destructive actions.

Open-source status and third parties

sf-deck is free and open source under Apache-2.0. It is not affiliated with, endorsed by, or sponsored by Salesforce, Inc. Salesforce CLI, Salesforce services, GitHub, Homebrew, operating systems, and other third-party tools have their own terms and privacy policies.

No warranty

The software is provided on the warranty and liability terms in the Apache License 2.0, on an “AS IS” basis and without warranties or conditions of any kind. You decide whether sf-deck is suitable for a particular org or workflow.

Ending use and changes

You can stop using sf-deck at any time, erase local data, and disconnect Salesforce CLI sessions using the steps in the privacy notice. Material changes receive a new policy version and require acknowledgement before sf-deck contacts a real org again. Check the current status with sf-deck legal status.

Questions can be sent to hello@jacobstokes.com.