Privacy policy
Last updated: 25 September 2026
This is the privacy policy for the TabOasis browser extension and the TabOasis
backend at app.taboasis.minhdevtree.tech.
If you want the engineering detail rather than the legal statement, read What we store and why. It is the same facts with the code behind them.
The short version
Section titled “The short version”Your board (bookmarks, tasks, notes, folders, tags, focus data, settings) lives in your own browser. TabOasis works with no account, and no copy of your board reaches a TabOasis server unless you sign in and upload it yourself.
An account is optional. It is what unlocks cloud sync, a Pro license and the feature-request board. The With an account section below applies from the point you create one, with three exceptions marked there: the install record, the daily activity line and the daily per-event counters are written for every install, whether or not it ever signs in.
We do not sell your data, share it with advertisers, or use it to build a profile of you. There is no third-party analytics product, no advertising SDK and no tracking pixel anywhere in the extension.
Three things are worth knowing before the detail:
- Usage statistics are on by default, with or without an account, and while you are signed in the events are linked to your account. The events are deleted after 90 days, but three summaries built from them (one of which is a record of this install) are kept indefinitely, again with or without an account. One switch turns all of it off: gear → Data Management → Share usage statistics.
- Some things leave your browser even with no account. One of them, site icons, has no off switch. The next section is the complete list.
- Deleting your account does not delete everything. Anything you posted on the feature-request board stays, with your name taken off it. Bug reports keep a dated stub, but everything you typed into them is erased. There is a section below that says exactly what goes and what stays.
Without an account
Section titled “Without an account”Your board is stored by your browser, on your machine, and read back from there. The extension works fully offline, and nothing you save is uploaded to us.
“Nothing is collected”, though, would not be true. Here is everything that leaves your browser before you ever sign in.
Usage statistics: on unless you turn them off
Section titled “Usage statistics: on unless you turn them off”The extension sends a small, fixed set of named events to our server: that a
view was switched, that a search happened, that a focus session finished and how
many minutes it ran, which theme you picked, that a sync succeeded or failed,
the class name of an error. Once a day it also sends a heartbeat carrying the
extension version, your browser’s brand name, your operating system, your
interface language and your color theme, plus how many bookmarks, notes, tasks
and profiles you have as a bucket range (0, 1-10, 11-50, 51-200,
200+) rather than an exact figure. That is the brand and the platform, not
the full browser identification string a bug report sends.
Every batch carries an install ID: a random identifier created on this device while the switch is on, and not derived from anything about you. It is what links one day’s events to another’s. Turning Share usage statistics off deletes it; turning it back on mints a fresh one, so events from before and after are not linked to each other. If you happen to be signed in when a batch is sent, that batch is also linked to your account. The first time that ever happens, the permanent install record described below keeps which account it was and the date it happened, written once and never changed afterwards.
It never sends URLs, page titles, bookmark titles, note contents, search terms, AI prompts, or anything from a page you visit. That is structural rather than a promise: the server has no field for any of them, and it discards any event or property it does not recognize. The event that records a search records that a search happened, not what you searched for. Raw events are deleted after 90 days.
The 90 days is the raw events, and not everything they leave behind. Every accepted batch, signed in or not, also feeds three summaries that are kept indefinitely: a record of this install; one line per day saying that this install sent something and how many events; and daily totals per event name, added up across everybody. So the lasting record starts when you install, not when you sign up. They are the rows for a record of the install, a daily activity line and daily per-event counters in What we store below. Those rows apply whether or not you ever create an account, and What we store and why sets out each one field by field.
With no account, none of the three ever carries one: the install record’s account link stays empty, the daily lines carry no account, and the per-event totals carry neither an account nor an install ID. What the install record does keep for good is the install ID itself, the day it was first seen, when it was last seen, and a copy of your latest heartbeat’s extension version, browser, operating system, language and color theme. Turning the switch off stops all of it: nothing is written for a batch that is never sent.
This is on by default. To turn it off: gear → Data Management → Share usage statistics. Switching it off stops collection and throws away anything already queued on your device.
Site icons: always, with no off switch
Section titled “Site icons: always, with no off switch”The little site icons on your cards come from Google’s public favicon service
(google.com/s2/favicons). Drawing one tells Google the hostname of that
bookmark, not the full URL, not the title, and with no identifier attached.
This happens for every user, with no account and no Pro, and no setting turns it off. It is limited to bookmarks you have saved, or are about to: the toolbar popup and the item dialog’s Select a tab list draw an open tab’s icon from Chrome’s own cache, which sends nothing anywhere. The one other lookup is the URL field in the item form: once what you have typed looks like a hostname and you pause for a moment, its icon is fetched, so a hostname you type and then never save still reaches Google. Blocking that host in your browser loses you the icons and nothing else.
Weather: on by default, and it asks only when you ask it to
Section titled “Weather: on by default, and it asks only when you ask it to”The weather indicator is on when you install the extension, but it does not reach for your position by itself. It rests on a Set Location button, and Chrome’s own location permission prompt appears only once you press that. So a fresh install puts no permission dialog in front of you, and nothing is sent until you have chosen to be asked. Nothing is sent if you then dismiss or deny it either. The Widgets dashboard’s weather card works the same way, and offers Search city next to it, which needs no permission at all.
If you allow it, your latitude and longitude (rounded to two decimal
places first, which is about a kilometer) are sent to two services:
open-meteo.com for the forecast and bigdatacloud.net to turn the coordinates
into a city name. While the widget is on it checks every ten minutes and fetches
again once its half-hour cache has gone stale, so this repeats quietly in the
background. If instead you search for a city by name, the text you type goes
to Open-Meteo’s geocoding service, and that city’s coordinates, not yours, are
what get used from then on.
To stop all of it: gear → Preferences → Show weather. Off, no weather request is made at all; the Widgets dashboard’s card goes with it.
Bug reports: only when you send one
Section titled “Bug reports: only when you send one”Nothing is sent unless you open Report a bug and press send. What goes with it is listed under Bug reports below. Turning Share usage statistics off does not stop a report you choose to send (that is your decision to make, not the switch’s), but it does keep the install ID off it. If you are signed in the report is still tied to your account, whatever the switch says; that is how a reply reaches you.
AI features: only with your own key
Section titled “AI features: only with your own key”One AI action is available without Pro. If you have entered your own OpenAI or Google Gemini key, using it sends your prompt (which can include bookmark titles, URLs, note text or a search query) directly from your browser to that provider. See AI keys.
What cannot happen without an account
Section titled “What cannot happen without an account”Focus mode’s ambient sounds (from jsDelivr), its background photos (from Unsplash) and its music (from YouTube), the Bookmark Health Check’s requests to every site you have bookmarked, Server Sync and Chrome Sync are all Pro features, and a Pro license requires an account. None of them can fire for a signed-out user.
With an account
Section titled “With an account”What we store
Section titled “What we store”| Data | Why | How long |
|---|---|---|
| Email address | Identifies the account; used for password reset. If Google sign-in created the account, it is the address Google verified | Until you delete the account |
| Name | Optional, shown in the dashboard and next to anything you post on the feature-request board. If Google sign-in created the account, it starts as the name on your Google profile | Until you delete the account |
| Password | Sign-in. Stored only as a bcrypt hash (cost 12), never in readable form, and unrecoverable by us. An account created with Google sign-in has none | Until you delete the account |
| Google account link, if you use Google sign-in: Google’s identifier for your Google account, and when it was connected | Recognizing your Google account when you sign in with it again. The identifier is the key, not the email address, because a Google account can change its address | Until you delete the account |
| A Google sign-in in progress: a one-time code (stored only as a hash) with your Google identifier, email address and name | Finishing that one sign-in | The code works once, within 60 seconds (5 minutes while it waits for the password of an existing account). The daily cleanup deletes the record after that; deleting the account deletes it at once |
| Session records: IP address, browser user-agent, and the country and city derived from that IP | Powers the “your devices” list, so you can see and revoke a session you do not recognize. Enforces the limit of three signed-in extensions | Replaced each time the session renews, so never more than 30 days old (see below) |
| Sign-in history: the IP, country, city and time of each sign-in | Lets you and us spot an account being accessed from somewhere it should not be | 90 days |
| Your board, if you use cloud sync | The sync itself | Until you delete it or the account |
| License record: plan, status, dates, and the Polar customer and subscription identifiers | Restoring Pro on a new device; reaching the billing portal | Until you delete the account |
| Payment records: the Polar order identifier, amount, currency and status | The record that a given charge succeeded | Until you delete the account |
| Usage events | See above | 90 days. The ones sent while you were signed in are deleted with the account; ones sent while signed out are not attached to it and stay |
| A record of the install itself: the install ID, the day it was first seen, when it was last seen, which account first signed in on it and when (written once and never moved to a later one), and, copied from its most recent daily signal, the extension version, browser name, operating system, language and color theme | Telling whether people keep using TabOasis after installing it, whether an install ever became an account, and what they are running it on. Raw events deleted at 90 days cannot answer any of those | Kept indefinitely. Those five environment fields are a copy of the latest values, not a count, and they are held for as long as the install record is. Deleting the account erases the account link, the date of that link, and all five environment fields, from the install records where yours was the first account to sign in. Because that link never moves, a browser where somebody else signed in before you carries their link, not yours, and your deletion does not reach it; what stays there is their link and a snapshot of the browser, which its next daily signal overwrites |
| A daily activity line per install: which days it sent anything, how many events on each, and, for a day the install was signed in, which account it was signed in as | The same question: whether an install comes back, and whether the people who stay are the ones who signed up | Kept indefinitely, with one exception: the days you were signed in are deleted along with the account. For the most recent three days the nightly job can rebuild the line itself from events that outlive the deletion unlinked, so such a day may reappear as a bare count with no account on it; the account is what does not come back. Days the install was active while signed out carry nothing that could be matched to you, and stay |
| Daily per-event counters, totaled across everyone: for each day and event name, how many times it happened, how many distinct installs sent it, and one property per event name (which color theme, which extension version, the class name of a JavaScript error, the code of a failed sync, which view, which import or export format, which capture source, which AI action) | Seeing which features are used and what breaks | Kept indefinitely. These rows carry no install ID and no account; they are totals, not per-person records. One property, not one value: for each day and event name the twenty most common values of that property get a row each, everything rarer is folded into a single (other) row, and a total row sits beside them. They are short values the extension picks itself and caps in length. There is still no field here for a URL, a page or bookmark title, a note, a search query or an AI prompt |
| Bug reports you submit | Fixing the bug | 180 days. Deleting your account does not wait for that: it erases the description, the email, the browser details and the install ID from the report immediately |
| Feature-request posts, comments, votes and reactions | Running the board | Posts and comments outlive the account, unlinked; votes and reactions are deleted with it |
| Notifications we raise for you (billing events, replies on your posts) | The dashboard’s notification list | Until you delete the account |
| Password-reset requests: a one-time hash of the emailed link, and the IP it was requested from | Making the link work once, and no more; spotting abuse | Removed by the daily cleanup once the link has expired (one hour) |
| A daily count of how many requests each endpoint received from each country | Knowing whether the service is being used, and from where | 365 days. It is a counter; there is no row for you in it |
About session records. A session’s record is deleted when you sign that session out, when you delete the account, when a fourth extension sign-in pushes out the least recently used one, or 30 days after it was last used.
Renewing a session, which happens automatically while you keep using it, resets that 30-day clock and replaces the stored IP, browser and location with the ones the renewal came from. So what the list shows is where the session is being used now, not where it started, and no address here is more than 30 days old. That is the point of the list: a session showing a city you do not recognize is one you should revoke.
What the sync blob contains, and what we do with it
Section titled “What the sync blob contains, and what we do with it”If you turn on cloud sync, a copy of your board is uploaded: every profile with its bookmarks, tasks, notes, folders, tags and profile avatars (including the URLs and titles you saved and the text of your notes), plus your focus data (sticky notes, session history, the YouTube tracks you added, the background you chose) and your settings: view mode, color theme, font and Pomodoro. Settings that describe the device rather than the board stay on it: language, Spotlight search on web pages, and the notification toggles.
Your AI key is not in it. See AI keys.
The server treats it as an opaque blob. It checks the size and that it is a JSON object, stores it, and hands it back. It does not parse it, index it, search it, or read what is inside, and nothing on the server acts on its contents.
Sync is manual and Pro-only. You press the button. There is no background upload, no upload on sign-in and no upload on a timer.
You can delete the stored copy without deleting your account, from the dashboard’s Sync page. That works with no license at all, so canceling never traps your data on our server.
Chrome Sync is a separate thing, and it goes to Google
Section titled “Chrome Sync is a separate thing, and it goes to Google”Next to Server Sync there is a second button, Sync to Chrome. It is easy to read as a local convenience and it is not one.
Pressing it writes the whole active profile (every card’s title and URL, note contents, columns, folders and tags), plus your focus data, your Pomodoro settings, and the name and item count of each of your other profiles, into Chrome’s own sync storage, which Chrome replicates through your Google account to your other browsers. It never reaches a TabOasis server, and it is by some margin the largest thing the extension can send anywhere.
It is Pro-only and entirely manual: nothing is written until you press the button. What Google then does with it is governed by Google’s policy, not this one, and removing it means clearing it from your Google account rather than from us.
Signing in with Google
Section titled “Signing in with Google”Continue with Google is optional; an email and password work just as well. If you use it, Google confirms who you are and sends us your Google account’s identifier, your email address, whether Google has verified that address, your name and a link to your profile photo. We refuse an address Google has not verified. We keep the identifier and the date you connected it, and, only when Google sign-in creates the account, the address and the name, as listed in What we store. We check the verified flag without keeping it, and we do not keep the photo link.
We ask Google only to confirm who you are (the openid email profile scopes).
We never see your Google password, we keep no Google access token, and we never
call a Google service on your behalf. Google, for its part, learns that you
signed in to TabOasis; that is governed by Google’s privacy policy.
There is no button to disconnect Google from an account; deleting the account removes the connection. Removing TabOasis from the apps connected to your Google account deletes nothing here.
Bug reports
Section titled “Bug reports”The bug-report form is the one place you can hand over anything you like, so it is the one place to be careful. What is stored:
- Your description, free text, exactly as you typed it. Whatever you put in it is what we get.
- Your email, if you supply one, used only to reply. On the dashboard’s form, leaving the field blank sends your account address instead.
- Your browser’s user-agent string (truncated), your interface language, the extension version and which view you were in, attached automatically.
- The install ID described above, which is how a report can be matched to the usage events around it, and only while Share usage statistics is on. With that switch off, the report is sent without one.
Two things to be clear about. Sending a report is always your own decision, so the usage-statistics switch does not gate it; what that switch decides here is the install ID. And a report is kept for 180 days, then deleted by the nightly cleanup whether or not anyone has acted on it. That is longer than the 90 days usage events get, because a report nobody has fixed yet is still a job to do.
Deleting your account does not wait for the 180 days, for the reports you sent while signed in. It erases from those: the description you typed, the email address on it, the browser details, and the install ID. What is left is the date, which app it came from, and whether it was marked resolved.
A report you sent while signed out is not covered. The extension lets you report a bug without an account, and such a report is not attached to one. So account deletion has no way to find it, and it keeps whatever you put in it until its 180 days are up. If you want one gone sooner, ask.
The feature-request board
Section titled “The feature-request board”Posting a request, commenting, voting or reacting stores that action against your account. Public posts and their comments are visible to anyone signed in, with your name (not your email) shown as the author. A post marked private is visible only to you and to an administrator.
Posts and comments outlive your account: deleting it detaches your name and leaves the text in place, because removing a thread would take other people’s replies with it. Your votes and reactions are deleted. You can delete your own post yourself while it is still under review, or at any time if it is private.
Card details
Section titled “Card details”We never receive them. TabOasis is sold through Polar, which acts as the merchant of record: Polar, not TabOasis, is the seller in the transaction. Its checkout takes the payment, it sends the receipt, it works out and charges any sales tax or VAT that applies where you live, and it handles any dispute over a charge. Polar passes the card itself to Stripe, the payment processor it uses. The extension and this backend never see a card number.
When you start a checkout we send Polar two things: your account’s internal ID, so the payment can be matched to your account when it comes back, and your account email address, to fill in the form. Polar’s notifications back to us describe the order and the subscription, and of those we keep only this: the identifier Polar gives each order, along with its amount, currency and status, and, on your license record, the plan, its dates and status, and the Polar customer and subscription identifiers that connect your account to your billing.
Everything else needed to take the payment and work out the tax (your name, billing address, card and the country you are paying from) is collected by Polar and Stripe directly, and their privacy policies cover it, not this one.
AI keys
Section titled “AI keys”If you use the AI features you supply your own OpenAI or Google Gemini key. It is stored in your browser and used to call that provider directly from your machine. It is never sent to our server, and it is not in the sync blob, so there is nothing here to leak.
What is sent to that provider is your prompt, which depending on the action can include bookmark titles and URLs, the text of a note, or a search query. If you build a search index, the text of your library is sent to be turned into vectors. All of that is covered by that provider’s policy, not this one.
Who else sees any of this
Section titled “Who else sees any of this”Nobody, in the sense that matters: we do not sell, rent, trade or share your data with anyone for their own purposes.
These services are involved in running the product, and each sees only its own slice:
- Polar: sells TabOasis for us as the merchant of record. Receives your account email and an internal account ID when you start a checkout, and collects what it needs to charge you and account for tax. As the seller it keeps its own records of the sale, under its own privacy policy.
- Stripe: the payment processor behind Polar’s checkout. Sees your card details, which we never do. It is also how Polar pays the developer.
- Google, as a sign-in provider: only if you use Continue with Google. Confirms who you are, sends us the details listed under Signing in with Google, and learns that you signed in to TabOasis.
- Google’s favicon service: sees the hostname of each saved bookmark being drawn, and of a URL you type into the item form. Everyone, always.
- Google, via Chrome Sync: receives your whole active profile if you press Sync to Chrome, through your own Google account.
- Open-Meteo: receives your coordinates, or a city name you type, for the weather widget.
- BigDataCloud: receives your coordinates, to turn them into a city name.
- jsDelivr, Unsplash and YouTube: receive requests for ambient sound files, background photos and the videos you added, in Focus mode.
- OpenAI or Google Gemini: receive your prompts, using your own key.
- Every site you have bookmarked: receives a request from your browser asking whether the link still resolves, while a Bookmark Health Check you started is running.
- The mail service configured for this install: carries password-reset emails, which contain a one-time link and nothing else about you.
The backend is self-hosted on hardware operated by the developer. It is not on a third-party analytics platform and there is no data-sharing arrangement with anyone.
Your choices
Section titled “Your choices”-
Use it without an account. Then none of the account section applies, but read Without an account, because it is not the same as nothing leaving your browser.
-
Turn off usage statistics. Gear → Data Management → Share usage statistics. Immediate, and it discards anything queued.
-
Turn off the weather widget. Gear → Preferences → Show weather. That stops every weather request. Simply never pressing Set Location works too: it does not ask on its own.
-
Export everything. JSON or Markdown, any time, from gear → Data Management. No account needed.
-
Delete the synced copy without deleting the account. The dashboard’s Sync page lists what is stored and deletes it. No license required.
-
Revoke a session. The dashboard’s Devices page lists every signed-in session and signs one out. That immediately destroys the credential it uses to renew itself, so it can never sign in again. But the short-lived token it is already holding keeps working until it expires, which is up to 15 minutes. Treat a revoked session as gone within a quarter of an hour, not instantly. If the device may be in someone else’s hands, change your password too.
-
Delete the account. The dashboard’s Account page, at the bottom. It requires your password (or, for an account created with Google, which has none, a fresh Google sign-in), it is immediate, and it cannot be undone. (There is no delete button inside the extension.)
It removes: the account itself (including its link to your Google account), every session on every device, your license and the devices registered against it, the whole synced board, your payment records, your sign-in history, your notifications, and your votes and reactions on the feature-request board. Unlike a revoked session, this takes effect at once: every request re-checks that the account still exists.
It removes from the permanent activity records above: every daily activity line for the days your install was signed in, and, on each install record where yours was the first account to sign in, the account link, the date it was made, and the environment fields: version, browser, operating system, language and theme. That first link is written once and never moves to a later account, so a browser where somebody else signed in before you carries their link rather than yours and the deletion does not reach that record; what remains on it is their link and a snapshot of the browser, which its next daily signal overwrites. And for the most recent three days the nightly job can rebuild a deleted activity line from usage events that outlive the deletion unlinked, so such a day may come back as a bare count, never with the account on it, which is the part that does not come back.
It leaves behind: feature-request posts and comments you wrote, still readable but with your name taken off; usage events, which are unlinked and then purged on their own 90-day schedule; the install record itself, holding an install ID and dates once the clearing above has run, because it describes a browser rather than a person and removing it would make a still-running install look brand new; the daily activity lines for days that install was signed out, which carry nothing to match to you (the same limit signed-out usage events have); the daily per-event counters, which are totals across everyone and have never carried an install ID or an account; and a stub of each bug report (the date, which app it came from, and whether it was resolved). The description, the email address, the browser details and the install ID are erased from those reports as part of the deletion, and the stub goes on its own 180-day schedule.
Board posts are the deliberate exception, because other people replied to and voted on them, and blanking a post would take their thread with it. If you want a post gone, delete it yourself before you delete the account, or ask.
Two warnings. Export your board first: there is no export step in the flow and no recovery window afterwards. And cancel a live subscription under Billing before you delete: deleting the account does not cancel anything at Polar, and the dashboard’s way into the billing portal goes with the account. Polar’s own emails still link to that portal, which signs you in by email, so a subscription can still be canceled afterwards and your receipts stay there. Our own record that you ever paid is gone with the account.
Children
Section titled “Children”TabOasis is not directed at children under 13 and we do not knowingly collect data from them.
Changes
Section titled “Changes”If this policy changes materially, the date at the top changes and the change is noted in the release notes. Continuing to use the extension after that is acceptance of the revised policy.
Contact
Section titled “Contact”Questions, or a request about your data (including having a bug report or a board post removed): open an issue on the project’s issue tracker, or use the in-app bug report, which reaches the same place.