Skip to content

What we store and why

Your board lives on your computer, and the only way a copy of it reaches a TabOasis server is if you press Upload yourself. The full inventory is below.

TabOasis uses the browser’s own extension storage. None of it is sent anywhere merely by being there.

What Holds
Your board every bookmark, task, note and tab group: titles, URLs, note contents, tags, due dates
Your profiles the same again, one set per profile, plus avatars
Focus data sticky notes, session history, backgrounds, the music playlist
Settings every preference, including Pomodoro lengths
Account your sign-in tokens, and your account id, email and name once you sign in
License plan, status, expiry, and when it was last checked
AI settings your API key, obfuscated; provider and model
Install ID a random identifier minted on this device while usage statistics are on; deleted when you turn them off, and minted afresh if you turn them back on

Two more, outside extension storage:

  • A weather cache (latitude, longitude, city and country), kept in ordinary browser storage while the weather widget is on. The coordinates are rounded to two decimal places (about 1 km) before they are stored or sent anywhere, and turning Show weather off stops every weather request.
  • A search index, if you built one for AI search. It is not readable text, but it is built from your titles, URLs, contents and tag names, so treat it as part of your library rather than as anonymous.

Uninstalling the extension removes all of it from that browser. There is no separate cleanup step. A copy you uploaded with Cloud sync is a different matter: see Getting the server copy back off below.

Four things, and only these four.

Email, password and an optional name at sign-up. Every sign-in also records the session it created: IP address, browser user-agent, and the country and city that IP resolves to. That is what makes Devices & sessions on the dashboard able to show you a list you can recognize and end.

If you use Continue with Google, Google sends TabOasis your Google account’s identifier (Google calls it sub), your email address, whether Google has verified that address, and your name. What is kept:

Kept Where How long
Google’s identifier for your account, and when it was connected the account until you delete the account
the verified email address and your Google profile name the account, only if Google sign-in created it; connecting Google to an existing account changes neither until you delete the account (you can change the name)
the identifier, email and name again, next to a one-time sign-in code stored only as a hash a record for that one sign-in the code works once, within 60 seconds (5 minutes while it waits for the password of an existing account); the daily cleanup deletes the record after that, and deleting the account deletes it at once

An address Google has not verified is refused, and the verified flag itself is checked, not stored. Google also sends a profile-photo link, which is not stored. Nothing else about your Google account is: TabOasis asks Google only to confirm who you are (the openid email profile scopes), keeps no Google access token, and never calls a Google service on your behalf. A sign-in also writes a short-lived record of random values that tie Google’s answer to the request that asked for it; it carries nothing about you, stops working after 10 minutes, and is deleted by the daily cleanup after that. The session and sign-in history are recorded exactly as for a password sign-in.

An account created with Google has no password. There is no button to disconnect Google from an account: deleting the account deletes the connection. Removing TabOasis from the apps connected to your Google account removes nothing here; Google just asks for your consent again the next time you use it.

Plan, status, dates, and the Polar identifiers that connect them to your payment. Card details never touch TabOasis: checkout happens on Polar, which sells TabOasis for us, and the card itself goes to Stripe, the payment processor Polar uses.

Server Sync uploads the whole library: every profile, every card, note bodies, tags, folders, avatars, focus data and settings. It is the largest thing the extension sends to a TabOasis server.

It is manual, and Pro-only. There is no background upload, no upload on sign-in, and no upload on a timer. Until you press Upload, the server holds nothing.

Your API key is not in it. See Where the key lives.

See Usage statistics and Bug reports.

The toggle is under the gear → Data Management: Share usage statistics, described in the app as Helps improve TabOasis. Never includes your bookmarks, notes, or browsing. While you are signed in, events are linked to your account.

It is on by default. Switching it off stops collection and discards anything already queued.

What is sent, when it is on, is a fixed list of event names with a fixed list of properties: which view you switched to, that a search happened, that a focus session finished and how many minutes it ran, which theme you picked, the name of an error class. Once a day it also sends a heartbeat with the extension version, your browser’s brand name, your operating system, your language and your theme.

Counts go in buckets (0, 1-10, 11-50, 51-200, 200+), so the exact size of your library never leaves the device.

The server has no field for a URL, a page or bookmark title, a note body, a search query or an AI prompt. The event that records a search records that a search happened, not what you searched for.

Events are tagged with the install ID above, which is per-install and lives as long as the switch is on. Turning it off deletes the id, turning it back on mints a fresh one, and nothing links the two. If you are signed in when a batch is sent, that batch is also linked to your account, so those events can be linked back to you. They are deleted after 90 days.

Three things outlive them, and they are kept indefinitely, because a product that can only see the last 90 days cannot tell whether anyone stays. Every accepted batch feeds all three whether or not you have an account: signing up is not what starts them, installing is. They are not all the same shape, so here is each one separately, and two of them can carry a link to an account.

A record of the install. Its ID, the day it was first seen, when it was last seen; which account first signed in on this browser, and the date that happened; and, copied from its most recent daily signal, the five environment fields that signal carries: extension version, browser name, operating system, language and color theme.

That account link is the most personal thing on the row. It is written the first time a batch arrives authenticated and is never moved to a later account, so on a shared browser it names whoever signed in first. It is kept for as long as the record is, which is forever. If you never sign in it stays empty.

Those five environment fields are a copy, not a count. Before this record existed they lived only inside the events and disappeared with them at 90 days; now the latest values stay for as long as the record does.

A daily activity line per install. Which days that install sent anything, how many events on each, and, for a day the install was signed in, which account it was signed in as. No event names and no property values; what a line holds is a date, the install ID, a count and that account. The account is a direct link to a named person in a table nothing purges, which is why deleting the account deletes those lines outright rather than blanking them.

Daily counters per event name. For each day and each event name: how many times it happened, how many distinct installs sent it, and one property per event name (which color theme, which extension version, the class name of a JavaScript error, the code of a failed sync, which view, which import or export format, which capture source, which AI action). One property, not one value: for each day and event name the twenty most common values of that property get a row each, everything rarer is folded into a single (other) row, and a total row sits beside them. They are short values the extension picks itself and caps in length (never anything you typed), and there is still no field for a URL, a title, a note, a search query or an AI prompt. These rows carry no install ID and no account; they are totals across everybody, so they cannot be traced to a person at all.

Report a bug, in the same settings section. This is the one place you can hand over anything you like, so it is the one place to be careful.

Three fields go with it, and these are the genuinely personal data in the whole product:

Field What it is
Your description free text, stored exactly as typed. Whatever you put in it (a URL, a name, a screenshot’s worth of detail) is what we get.
Your email optional, and only used to reply. The web dashboard’s form fills in your account address, and sends it unless you type a different one.
Your browser its user-agent string, truncated, captured automatically along with the extension version, your language and which view you were in.

Bug reports also carry the install ID while Share usage statistics is on, which is how a report can be matched to the events around it. Switch that off and reports go without one, the same way the events stop. A report is deleted 180 days after you send it. That is longer than the 90 days those events get, because a report nobody has fixed yet is still a job to do. Deleting your account does not wait for that: the four fields above are erased at once from every report you sent while signed in. A report sent while signed out is not attached to an account, so deletion cannot find it; it keeps what you put in it until its 180 days are up.

None of this is collected unless you open the dialog and press Send report.

Some things the extension does are requests to somebody else’s server:

Goes to What it receives When
Google, via Chrome Sync the active profile in full: every card’s title and URL, note bodies, plus its columns, folders and tags, and your focus data only if you press Sync to Chrome (see below)
Google’s favicon service the hostname of each saved bookmark being drawn, and of a URL you type into the item form always, for everyone (see below)
Open-Meteo your coordinates, or a city name you typed the weather widget
BigDataCloud your coordinates resolving “your location” for weather
OpenAI or Google Gemini your prompts: titles, URLs, note text, search queries only AI features, with your own key
jsDelivr, Unsplash, YouTube requests for sound files, background images and the videos you added Focus mode
Every site you have bookmarked a request from your browser, to see whether the link still resolves Bookmark Health Check, when you run it
Google, as a sign-in provider your Google sign-in itself, and the fact that it is TabOasis you are signing in to. Google then sends TabOasis what is listed under Your account only if you use Continue with Google

The web dashboard has a Sync page. It lists what your account is actually storing (the entry, its version and when it was last written) and gives you a delete button for it. Deleting there removes the stored copy; the boards on your devices are untouched, and the next Upload simply creates a fresh one.

The dashboard’s Account page has a Delete account panel at the bottom. It asks for your password again. An account created with Google has none, so it sends you through Google sign-in once more instead, and the deletion finishes when you come back. There is no undo and no export step.

Confirming it deletes, immediately and permanently:

  • your account: the email, the name, the password hash and the connection to your Google account, with any Google sign-in still in progress;
  • every session, on every device, extension and dashboard alike;
  • your license and the devices registered against it;
  • your synced library: the whole server copy, every profile;
  • your payment history: the record of what you were charged;
  • your sign-in history and your notifications;
  • your votes and reactions on the feature-request board.

What you posted on the feature-request board survives with your name taken off it. Requests and comments stay readable, attributed to a removed account, because other people replied to and voted on them. Bug reports keep only a dated stub: the description, the email, the browser details and the install ID are erased as part of the deletion, and the stub goes on its own 180-day schedule. Usage events lose their link to you and are deleted on their own 90-day schedule.

Of the three permanent records described above, the deletion erases the account link and the date it was made from the install record, along with all five environment fields on it, and deletes every daily activity line for the days that install was signed in. What stays is the install record itself (an ID and some dates, describing a browser rather than a person), the activity lines for days it was signed out, which carry nothing that could be matched to you, and the daily per-event counters, which are totals across everyone and have never held an install ID or an account.

Two limits on that, both small and both real. The install record it reaches is the one where yours was the first account to sign in; because that link is written once and never moved, a browser somebody else signed in on before you carries their link, so your deletion finds no record there to clear and the environment snapshot on it (a description of that browser, rewritten by its next daily signal) stays. And a deleted activity line is only permanently gone outside the last three days: inside that window the nightly rollup rebuilds the line from usage events that survive the deletion unlinked, so the day comes back as a bare count. It comes back without an account on it, so nothing above is untrue of it; the link is what is gone for good, not the count.

Save what you need before you confirm. There is no export step in the flow, no emailed copy and no recovery window afterwards. So export your board to JSON or Markdown from the extension first. Your payment receipts are safer: Polar emails a confirmation for every order and keeps every receipt in its own billing portal, which you can sign in to with your email address whether or not the TabOasis account still exists. What goes is TabOasis’s own record that you ever paid.

Nothing on your own devices is touched. Your local board survives account deletion, and uninstalling the extension is a separate step.

  • It does not scan the pages you visit. It reads one thing: whenever you right-click a link, TabOasis reads that link’s own text and address, so it can fill in the title if you then choose Save to TabOasis. That read happens on the right-click itself, not on choosing the menu item, but neither the link nor anything about the page reaches a TabOasis server unless you save. (The capture form draws the site’s icon, which asks Google for that hostname the way every card does.) Nothing else on the page is read, and the Spotlight overlay reads nothing from the page around it.
  • It does not track your browsing history. No history permission is asked for, nothing records where you have been, and no tab URL is ever stored or uploaded unless you save that tab as a bookmark yourself. It can see your open tabs; that is what fills in Use this and Use all tabs in the popup. Their icons come from Chrome’s own cache, so listing them sends nothing anywhere. The favicon service above is asked only about bookmarks you have saved and a URL you type into the form.
  • It does not sell or share data with advertisers. Nothing in the list above is an ad network.
  • It does not upload your board in the background. Sync is a button.