本文へ移動
Mattermost Deck
紹介ページ プライバシー 利用規約 GitHub
Privacy Policy

プライバシーポリシー

Mattermost Deckが拡張機能の単一目的を提供するために処理するデータ、 保存場所、通信先、ユーザーが管理できる範囲を説明します。

This policy explains the data Mattermost Deck processes for its single purpose, where that data is stored, where requests are sent, and the controls available to users.

適用対象 Chrome拡張と公開サイト
最終更新 2026-07-30
分析・広告 なし
概要 ローカル保存 処理するデータ 利用目的と通信先 共有とトラッキング 保持と管理 セキュリティ 公開サイト お問い合わせ

1. 概要

Mattermost Deckは、Mattermost Webの右側に監視向けのマルチペインワークスペースを追加するという 単一目的のために必要な範囲でのみユーザーデータを処理します。

拡張機能は、開発者が運営するサーバーへユーザーデータを送信しません。 第三者のanalytics、広告、プロファイリング機能も含みません。

2. ブラウザ内に保存するデータ

拡張機能は、設定とUI状態をブラウザ内に保存します。主な内容は以下です。

  • MattermostサーバーURLと任意のTeam Slug
  • テーマ、言語、ポーリング間隔、レイアウト、保存済みViews、プロファイルなどの表示・動作設定
  • 個人用お気に入りの投稿ID、登録日時、本文の一部、投稿者・チャンネル・添付ファイルのIDと投稿日時。サーバーとアカウントごとに最大100件を拡張機能のローカル保存領域に保存します。本文キャッシュは最終確認から7日を超えると次回読み込み時に破棄し、登録情報は解除するまで保持します。取得に成功した際に削除・閲覧不可と判明した投稿の本文も破棄します。解除すると該当のお気に入りとキャッシュを削除します。
  • PATを永続保存するかどうかの任意設定
  • トレース記録を有効にした場合の件数制限付き診断ログ。24時間を超えた項目は、次に拡張機能が動作、記録、または診断画面を開いたときに削除します。

Mattermost Personal Access Token(PAT)はセッションのみの保存が既定です。 ユーザーが永続保存を選択した場合、PATはクライアント側で暗号化してブラウザ内に保存されます。 同じクライアントが復号できるため、この暗号化は平文保存を避けるための補助であり、 完全なセキュリティ境界ではありません。

診断ログには、要求目的、パス、ステータス、所要時間、キュー待機時間、拡張機能のライフサイクルイベントが含まれます。 投稿本文や認証トークンは記録しません。

3. 拡張機能が処理するデータ

メンション、監視チャンネル、DM、検索結果、保存済み項目などを表示するため、 設定済みMattermostサーバーが提供する次のような情報をブラウザ内で処理します。

  • Mattermostのユーザー識別子、ユーザー名、表示名、アバター
  • チーム、チャンネル、DM、グループに関する情報
  • 投稿、添付画像、保存済み項目、未読・メンション状態
  • カスタムメンションキー、ユーザー/グループ所属、スレッド通知設定
  • 表示内容の再照合に必要な投稿の編集・削除・アクセス可否・保存期間による削除状態
  • ユーザーが入力した検索語と、表示機能に必要な検索結果

4. 利用目的と通信先

これらのデータは、Mattermost Deckの画面にユーザーが選択した情報を表示し、 更新・ナビゲーション・診断機能を提供するためだけに使います。

ネットワーク要求は、ユーザーが明示的に設定し、Chrome権限を許可したMattermostサーバーoriginへだけ送信します。 Mattermostサーバーとその管理者によるデータ処理には、そのサーバーのポリシーが適用されます。

5. データ共有とトラッキング

Mattermost Deckはユーザーデータを販売せず、広告プラットフォーム、データブローカー、 その他無関係な第三者と共有しません。機能提供に必要な範囲で、設定済みMattermostサーバーとのみ通信します。

Mattermost Deckによるユーザーデータの利用は、Limited Use要件を含む Chrome ウェブストア ユーザーデータポリシー に従います。

6. データ保持とユーザー管理

ローカル設定は、ユーザーが変更する、拡張機能ストレージを消去する、 または拡張機能をアンインストールするまでブラウザ内に残ります。

  • セッション保存のPATは、ブラウザセッション終了時に削除されます。
  • 永続保存したPATは、設定変更、拡張機能ストレージの消去、アンインストールで削除できます。
  • トレース記録をオフにすると保存ログを消去します。24時間を超えたログは、次に拡張機能が動作、記録、または診断画面を開いたときに削除します。Chromeが動作していない間は、その次の動作までストレージに残る場合があります。

7. セキュリティ

拡張機能は認証情報をブラウザ内に保ち、ネットワークアクセスを設定済みMattermostサーバーへ限定するよう設計しています。 ユーザーは、必要最小限の権限を持つトークンと、安全に構成されたMattermostサーバーを利用する責任があります。

Chrome alarm権限は、PWAインストールが正常に完了しなかった場合に一時的な補助スクリプトを確実に解除するためだけに使います。 analytics、追跡、ユーザーデータの定期送信には使用しません。

8. 公開サイトのホスティング

この公開サイトはCloudflare Pagesで配信しています。サイト自体にはanalytics、広告、 トラッキングCookieを組み込んでいません。Cloudflareは、配信とセキュリティのためにIPアドレスやHTTP要求情報などを インフラストラクチャログとして処理する場合があります。詳細は Cloudflare Privacy Policy を参照してください。

日本語/英語の選択は、このブラウザのlocalStorageへ保存します。この設定はサイト内の表示言語だけに使い、 ユーザーがブラウザのサイトデータを消去するまで保持されます。

9. お問い合わせ

プライバシーに関する質問は、 GitHub Issues からプロジェクト開発者へお問い合わせください。公開Issueへ秘密情報や個人情報を投稿しないでください。

1. Overview

Mattermost Deck processes user data only as needed for its single purpose: adding a monitoring-oriented multi-pane workspace to Mattermost Web.

The extension does not send user data to developer-operated servers and includes no third-party analytics, advertising, or profiling.

2. Data stored in the browser

The extension stores configuration and UI state in the browser, including:

  • Mattermost server URL and optional Team Slug
  • Theme, language, polling interval, layout, saved Views, profiles, and other display or behavior settings
  • Personal favorite post IDs, saved timestamps, bounded message text, author/channel/attachment IDs, and post timestamps. Up to 100 entries per server/account are kept in extension local storage. Cached bodies older than seven days since verification are discarded on the next load, while membership remains until removed. Bodies are also discarded when a successful fetch identifies a deleted or inaccessible post. Removing a favorite deletes its entry and cached body.
  • The optional preference for persistent PAT storage
  • Bounded diagnostic trace logs; entries older than 24 hours are pruned the next time the extension runs, writes a trace, or opens diagnostics

Session-only storage is the default for a Mattermost Personal Access Token (PAT). If the user chooses persistent storage, the PAT is stored locally with client-side encryption. Because the same client can decrypt it, this helps avoid plain-text storage but is not a complete security boundary.

Diagnostic logs contain request purpose, path, status, duration, queue wait time, and extension lifecycle events. They do not contain message bodies or authentication tokens.

3. Data processed by the extension

To display mentions, watched channels, DMs, search results, saved items, and related features, the extension processes information provided by the configured Mattermost server in the browser, such as:

  • Mattermost user identifiers, usernames, display names, and avatars
  • Team, channel, DM, and group information
  • Posts, image attachments, saved items, unread state, and mention state
  • Custom mention keys, user or group membership, and thread notification preferences
  • Post edit, deletion, access, and retention-deletion state needed to reconcile visible items
  • Search terms entered by the user and results required for visible features

4. Use and network destinations

This data is used only to display the information selected by the user and to provide update, navigation, and diagnostic features inside Mattermost Deck.

Network requests are sent only to the Mattermost server origin explicitly configured by the user and approved through Chrome permissions. Processing by that Mattermost server and its administrators is governed by the server's own policies.

5. Sharing and tracking

Mattermost Deck does not sell user data or share it with advertising platforms, data brokers, or unrelated third parties. It communicates only with the configured Mattermost server as needed to provide its features.

Mattermost Deck's use of user data complies with the Chrome Web Store User Data Policy , including its Limited Use requirements.

6. Retention and user control

Local settings remain in the browser until the user changes them, clears extension storage, or removes the extension.

  • Session-stored PAT data is removed when the browser session ends.
  • Persisted PAT data can be removed through settings, by clearing extension storage, or by uninstalling the extension.
  • Turning trace capture off clears stored logs. Entries older than 24 hours are pruned the next time the extension runs, writes a trace, or opens diagnostics. If Chrome remains inactive, expired entries may remain in extension storage until that next activity.

7. Security

The extension is designed to keep authentication information in the browser and to limit network access to the configured Mattermost server. Users are responsible for choosing appropriately scoped tokens and a securely configured server.

The Chrome alarm permission is used only to remove a temporary helper script if PWA installation does not complete normally. It is not used for analytics, tracking, or periodic transmission of user data.

8. Public website hosting

This public website is served through Cloudflare Pages. The site does not include analytics, advertising, or tracking cookies. Cloudflare may process IP addresses and HTTP request metadata in infrastructure logs for delivery and security. See the Cloudflare Privacy Policy for details.

The Japanese or English preference is stored in this browser's localStorage and is used only to choose the site's display language. It remains until the user clears browser site data.

9. Contact

For privacy questions, contact the developer through GitHub Issues. Do not post secrets or personal information in a public issue.

© 2026 Mattermost Deck. MIT License.

紹介ページ 利用規約 GitHub