Privacy Policy โ Device Notes for ABM
Effective date: September 4, 2026 ยท Last updated: September 7, 2026
Device Notes for ABM ("the extension") is a browser extension published by 2Falls Inc. It connects Apple Business Manager device pages to an inventory database that you own โ your Airtable base, Google Sheet, Excel workbook in Microsoft 365, Notion database, or Supabase table. This policy explains what data the extension touches and where it goes. The short version: your data goes only to your own database, and we never see it.
What the extension does with data
When you open a device page on business.apple.com, the extension reads the device serial number from the page address and looks it up in the database you configured. When you edit and save, it writes your changes to that same database. That's the entire data flow.
All of this happens directly between your browser and your database provider. We operate no servers, and no device data, serial number, or inventory record ever passes through us.
What we don't do
The extension contains no analytics, no telemetry, no crash reporting, and no tracking of any kind. We do not collect, store, sell, or share any information about you, your devices, or your organization. There are no ads. We cannot see your data, your usage, or even whether you use the extension at all.
Where your data goes
Depending on the backend you choose in the extension's options, the extension communicates with exactly these services:
- Airtable mode โ your device records are read from and written to
api.airtable.com, using a personal access token you create. The token is stored in your browser's local extension storage on your computer and is sent only to Airtable. - Google Sheets mode โ your device records are read from and written to
sheets.googleapis.com, affecting only the one spreadsheet you specify. See the Google section below. - Excel (Microsoft 365) mode โ your device records are read from and written to
graph.microsoft.com(Microsoft's API), affecting only the one workbook whose share link you provide; sign-in tokens come fromlogin.microsoftonline.com. See the Microsoft section below. - Notion mode โ your device records are read from and written to
api.notion.com, using an integration token you create; the integration can only see the pages you explicitly connect it to in Notion. The token is stored in your browser's local extension storage and sent only to Notion. - Supabase mode โ your device records are read from and written to your own Supabase project's API (
https://<your-project>.supabase.co), using an API key from that project. The key is stored in your browser's local extension storage and sent only to your project's address. The extension contacts no Supabase server other than the project you configure. - License checks โ if you enter a license key, the key (and nothing else) is validated against
api.polar.sh, our payment provider, about once per day. Trial state is kept in local extension storage and never leaves your computer.
No other network connections are made.
Google user data
This section applies when you connect the Google Sheets backend. The extension requests only the drive.file scope (https://www.googleapis.com/auth/drive.file) โ Google's non-sensitive, per-file scope. It grants access to nothing until you pick your inventory sheet in Google's own file picker, and afterwards covers only the file you picked.
What Google user data the extension accesses
- The contents of one spreadsheet only โ the spreadsheet you pick in Google's file picker from the extension's options. The extension reads that spreadsheet's header row and data rows, and writes to its cells. Under the
drive.filescope, Google itself blocks the extension from accessing, listing, or enumerating any other file in your account โ the restriction is enforced by Google, not just promised by us. - Your Google OAuth access token, obtained when you sign in through Google's consent screen. The extension never sees your Google password.
- No other Google user data โ no profile information, no email contents, no Drive file listings โ is accessed.
How the extension uses Google user data
- Spreadsheet rows are read solely to display the matching device record (and the name labels) on Apple Business Manager pages in your browser.
- Cells are written solely when you save an edit or create a record in the sidebar.
- The access token is used solely to authorize these spreadsheet reads and writes with
sheets.googleapis.com. - Google user data is never used for advertising, profiling, model training, or any purpose beyond displaying and editing your device records at your direction; it is never sold, never transferred to us or to any third party, and never read by any human.
How the extension protects Google user data
- No servers. We operate no servers and store no Google user data anywhere. All traffic goes directly from your browser to Google.
- Encryption in transit. Every request to Google's APIs is made over HTTPS/TLS.
- Local, sandboxed token storage. The access token is stored only in your browser's local extension storage on your own computer โ an area isolated by the browser so that web pages (including business.apple.com) cannot read it โ and is sent only to Google's own endpoints. It expires on its own within about an hour.
- In-memory only. Spreadsheet contents exist only in your browser's memory while a page is open; the extension keeps no copy of them.
- Deletion. Removing the extension deletes the stored token and settings. You can revoke the extension's Google access at any time at myaccount.google.com/permissions, which immediately invalidates its tokens.
The extension's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft user data
If you connect Excel (Microsoft 365), the extension requests the Microsoft Graph Files.ReadWrite permission so it can read and write files on your behalf. It uses that access only for the single workbook whose share link you enter in the extension's options: reading its header row and rows to display device records, and writing cells when you save or create a record. What we store: a short-lived access token and a refresh token, kept in your browser's local extension storage and sent only to Microsoft's own endpoints. Your Microsoft password is never seen or stored. Nothing from your Microsoft account is transferred to us or any third party, used for advertising, or read by any human. You can revoke the extension's access at any time at account.live.com/consent/Manage (personal accounts) or myapps.microsoft.com (work accounts).
Data retention and deletion
Everything the extension stores โ your Airtable, Notion, or Supabase keys, Google or Microsoft sign-in tokens, spreadsheet/base/database IDs or share links, license key, and trial state โ lives in your browser's local extension storage on your own computer. Removing the extension from your browser deletes all of it. Your inventory data itself lives in your Airtable base, Google Sheet, Excel workbook, Notion database, or Supabase project, which you control entirely.
Changes to this policy
If this policy changes, the new version will be posted at this address with an updated effective date. Since the extension collects nothing, changes are expected to be rare and cosmetic.
Contact
Questions about this policy or the extension: support@codertricks.com (2Falls Inc).