Privacy Policy — Mirage Webex Chat Injector
Last updated: 2026-07-15
The Mirage — Webex Chat Injector is an internal tool for CX
Advanced Solutions (cxsol.com) sales engineers. It injects a Webex Engage chat
widget into the current browser tab so an SE can demo the widget on a
customer’s real website during a screen-share and, optionally, record that
demo to the user’s own Mirage server (mirage.cxsol.com).
What we do not do
- We do not sell or share your data with any third party.
- We do not use your data for advertising, tracking, profiling, or creditworthiness/lending decisions.
- We do not run analytics or send data to the extension’s authors.
- We do not access web pages in the background — the extension acts only on the tab you are viewing, and only when you click a button in its popup.
Data stored locally (never leaves your browser)
Saved via chrome.storage.local for your convenience so you
don’t re-enter it:
- The last chat-widget snippet you used.
- Your Mirage project selection and the API-prefix setting for “drive with mock data.”
- Your personal Mirage access token, used only to authenticate to your own Mirage server.
This data stays on your device and is not synced.
Data sent to your own Mirage server
Only when you have linked the extension (by pasting your personal Mirage
token) and only to mirage.cxsol.com — your organization’s own
server — the extension may send:
- Your access token, as the authorization header, to identify you.
- Demo history: when you inject a widget, the host and path (query string removed) and page title of the tab, plus the time.
- A screenshot of the current tab — only if you click “Capture this site as Mirage backdrop” — stored as that project’s backdrop image.
The chat-widget snippet you inject is configured by you for your customer’s Webex Engage tenant. Retention of demo history is governed by your Mirage server’s policies, not by the extension.
Remote code
The extension contains no remote code of its own; all of its logic ships in the package. When you click Inject, it places the chat-widget embed you configured into the current page. That embed may load the vendor’s script from the vendor’s CDN — the same as if the widget were installed on the customer’s own site. This runs in the web page, not in the extension.
Permissions
- activeTab / scripting — inject or remove the widget, or screenshot the tab, only on your click.
- storage — remember the items above, locally.
- declarativeNetRequest — optional, per-tab, only when you enable “Bypass CSP” or “Drive with mock data”; applied in your browser only.
- Host access —
mirage.cxsol.com(your Mirage server). A broad host permission is requested at runtime only if you enable the optional per-tab features above, and is used solely to apply those rules in your browser.
Contact
Questions about this extension or your data: systems@cxsol.com (CX Advanced Solutions systems team).