Databricks Command Center (DCC) โ also known as LakeForce โ is a Chrome browser extension developed by SCube AI. It is a professional productivity and administration toolkit that operates entirely within your browser against your own Databricks workspace(s) on AWS, Azure, or GCP.
This Privacy Policy explains exactly what data the Extension accesses, how it is used, where it is stored, and what it never does. If you have questions, see Section 11 for contact details.
The Extension reads the following categories of data solely to power its features. All data is accessed via your workspace's authenticated REST APIs using a session token or Personal Access Token that you provide and that is stored only on your device.
| Data category | Examples | Sent to SCube? | Stored where? |
|---|---|---|---|
| Workspace session token / PAT | CSRF token from active Databricks tab; or PAT you enter manually | Never | chrome.storage.local (your device) |
| Cluster & warehouse metadata | Names, sizes, states, runtime versions, auto-termination settings | Never | Displayed in-page only |
| Unity Catalog objects | Catalog, schema, table, column names; row counts; table metadata | Never | Displayed in-page only |
| SQL query text & results | Queries you write or run; result rows returned from Databricks SQL | Never | Query history in chrome.storage.local |
| Job & pipeline run data | Job names, run states, error messages, task-level status | Never | Displayed in-page only |
| Billing & cost data | DBU usage, cost estimates from system.billing.usage (requires your SQL warehouse) | Never | Displayed in-page only |
| Users & groups | Usernames, email addresses, group memberships, service principal names | Never | Displayed in-page only |
| MLflow models & experiments | Model names, versions, run metrics, deployment stage | Never | Displayed in-page only |
| AI provider API keys | Keys for OpenAI, Anthropic, Gemini, Mistral, Groq, or Databricks endpoints | Never | chrome.storage.local (your device) |
| User preferences & settings | Theme, keyboard shortcuts, warehouse selection, budget thresholds | Never | chrome.storage.local (your device) |
All data accessed by the Extension is used exclusively to render features within your browser. There are three possible destinations for any data โ your Databricks workspace, your chosen AI provider (BYOK), or local browser storage โ and nothing else.
chrome.storage.local on your device.chrome.storage.sync โ all storage is local onlyThe Extension requests the following Chrome permissions. Each is required for a specific feature โ no permission is requested speculatively.
| Permission | Why it's needed |
|---|---|
| storage | Saves workspace connections, session tokens, PATs, AI API keys, saved SQL queries, query history, budget alert thresholds, keyboard shortcut mappings, and UI preferences. All stored locally on your device only โ never synced. |
| alarms | Powers the Idle Radar auto-kill feature โ schedules background checks to detect and optionally terminate clusters or warehouses that have exceeded your configured idle threshold (15 min โ 1 hr). Also used for budget alert polling. |
| notifications | Displays a desktop notification when a budget alert threshold is crossed, when an auto-kill fires, or when a job run completes. Notifications contain only locally-derived status โ no external data is fetched to generate them. |
| scripting | Injects content scripts into Databricks pages to add the floating Sยณ launch button, cost overlay chips, table hover previews, the command palette (Alt+K), and keyboard shortcuts. Without this permission, none of the in-page overlays work. |
| contextMenus | Reserved for a future right-click context menu shortcut feature inside Databricks pages. Currently declared but not yet active. |
| identity | Supports the OAuth U2M (user-to-machine) fallback authentication flow for workspace-scoped auth. Used only if you choose OAuth as your auth method in Settings. |
| tabs | Reads the URL of your active tab to detect which Databricks workspace you are on and to retrieve the CSRF token for zero-setup session authentication. No tab content, history, or other tab data is read. |
Host permissions are requested for *.cloud.databricks.com, *.azuredatabricks.net, and *.gcp.databricks.com (including their account console subdomains). These are required to make REST API calls to your workspace from the Extension's background service worker.
All AI-powered features in the Extension are optional and disabled by default. To use them, you must provide an API key for one of the supported providers in Settings. Your key is stored only in chrome.storage.local on your device.
Supported AI providers and what is sent when you use AI features:
| Provider | Data sent (by your browser, directly) | Governed by |
|---|---|---|
| OpenAI | Your SQL query, schema context you select, or code you submit for review/optimization | OpenAI Privacy Policy |
| Anthropic Claude | Your SQL query, schema context you select, or code you submit for review/optimization | Anthropic Privacy Policy |
| Google Gemini | Your SQL query, schema context you select, or code you submit for review/optimization | Google Privacy Policy |
| Mistral AI | Your SQL query, schema context you select, or code you submit for review/optimization | Mistral AI Privacy Policy |
| Groq | Your SQL query, schema context you select, or code you submit for review/optimization | Groq Privacy Policy |
| Databricks Model Serving | Your SQL query or code โ sent to your own Databricks workspace serving endpoint, not to any external party | Your Databricks agreement |
Context chips (schema, billing tables, query history, Delta patterns) that you optionally attach to an AI request are assembled in your browser from data already fetched from your workspace. Including them in an AI request means that context is transmitted to your chosen provider subject to their terms.
All data stored by the Extension lives exclusively in chrome.storage.local on your device. Nothing is written to chrome.storage.sync, cookies, localStorage, IndexedDB, or any external server.
Uninstalling the Extension from Chrome removes all locally stored data automatically via Chrome's standard extension lifecycle. You can also clear all stored data at any time via Settings โ Clear All Data.
chrome.storage.local, sandboxed to the Extension's originscript-src 'self'; object-src 'self' โ no inline scripts or external script loadingIf you discover a security vulnerability in this Extension, please disclose it responsibly by emailing scubedevelopmentteam@gmail.com.
The Extension communicates with the following third-party services solely on your explicit instruction and using your own credentials. SCube does not operate, control, or have visibility into these services.
The Extension does not use any analytics SDKs, advertising networks, crash reporting services, or telemetry libraries. There are no third-party tracking scripts embedded in the Extension.
Databricks Command Center is a professional data engineering and analytics tool designed exclusively for use by adults in enterprise environments. It is not directed at or intended for use by children under the age of 13. We do not knowingly collect any information from children.
If this Privacy Policy is updated, the revised version will be published at this URL with an updated "Last Updated" date at the top of the page. Continued use of the Extension after any changes constitutes acceptance of the updated policy. For material changes, we will update the version number in the Extension's manifest.
Questions about Databricks Command Center's privacy practices? We typically respond within 2 business days.
โ๏ธ scubedevelopmentteam@gmail.com