What we store and why
The short version: your board lives on your computer, and the only way a copy of it reaches a TabOasis server is if you press Upload yourself. The longer version is below, because “we take your privacy seriously” is not an inventory and this page is meant to be one.
On your device
Section titled “On your device”TabOasis uses the browser’s own extension storage. None of it is sent anywhere merely by being there.
| What | Holds |
|---|---|
| Your board | every bookmark, task, note and tab group — titles, URLs, note contents, tags, due dates |
| Your profiles | the same again, one set per profile, plus avatars |
| Focus data | sticky notes, session history, backgrounds, the music playlist |
| Settings | every preference, including Pomodoro lengths |
| Account | your sign-in tokens, and { id, email, name } once you sign in |
| Licence | plan, status, expiry, and when it was last checked |
| AI settings | your API key, obfuscated; provider and model |
| Install ID | a random identifier minted on this device the first time it is needed |
Two more, outside extension storage:
- A weather cache — latitude, longitude, city and country — kept in ordinary browser storage while the weather widget is on.
- A search index — one vector per item, if you built one for AI search. Vectors are not readable text, but they are derived from your titles, URLs, contents and tag names, so treat them as part of your library rather than as anonymous.
Uninstalling the extension removes all of it from that browser. There is no separate cleanup step. A copy you uploaded with Cloud sync is a different matter — see Getting the server copy back off below.
What reaches TabOasis servers
Section titled “What reaches TabOasis servers”Four things, and only these four.
1. Your account
Section titled “1. Your account”Email, password and an optional name at sign-up. Every sign-in also records the session it created: IP address, browser user-agent, and the country and city that IP resolves to. That is what makes Devices & sessions on the dashboard able to show you a list you can recognise and end.
2. Your licence
Section titled “2. Your licence”Plan, status, dates, and the Stripe identifiers that connect them to your payment. Card details never touch TabOasis — checkout happens on Stripe.
3. Your board — only if you sync
Section titled “3. Your board — only if you sync”Server Sync uploads the whole library: every profile, every card, note bodies, tags, folders, avatars, focus data and settings. It is by far the largest thing the extension ever sends.
It is manual, and Pro-only. There is no background upload, no upload on sign-in, and no upload on a timer. Until you press Upload, the server holds nothing.
Your API key is not in it. See Where the key lives.
4. Usage statistics, and bug reports
Section titled “4. Usage statistics, and bug reports”Covered in the next two sections, because they are the two that deserve detail.
Usage statistics
Section titled “Usage statistics”The toggle is under the gear → Data Management: Share anonymous usage statistics, described in the app as Helps improve TabOasis. Never includes your bookmarks, notes, or browsing.
It is on by default. Switching it off stops collection and discards anything already queued.
What is sent, when it is on, is a fixed list of event names with a fixed list of properties: which view you switched to, that a search happened, that a focus session finished and how many minutes it ran, which theme you picked, the name of an error class. Once a day it also sends a heartbeat with the extension version, your browser’s brand name, your operating system, your language and your theme.
Counts go in buckets — 0, 1-10, 11-50, 51-200, 200+ — so the exact
size of your library never leaves the device.
The important property is structural rather than a promise: the server has no field for a URL, a page or bookmark title, a note body, a search query or an AI prompt, and anything it does not recognise is discarded on arrival. The event that records a search records that a search happened, not what you searched for.
Events are tagged with the install ID above, which is per-install and never rotated. If you are signed in when a batch is sent, that batch is also linked to your account — so it is pseudonymous per event and, in aggregate, linkable to you. It is deleted after 90 days.
Bug reports
Section titled “Bug reports”Report a bug, in the same settings section. This is the one place you can hand over anything you like, so it is the one place to be careful.
Three fields go with it, and these are the genuinely personal data in the whole product:
| Field | What it is |
|---|---|
| Your description | free text, stored exactly as typed. Whatever you put in it — a URL, a name, a screenshot’s worth of detail — is what we get. |
| Your email | optional, and only used to reply. On the web dashboard’s form it is pre-filled with your account address, so it is sent unless you clear it. |
| Your browser | the full user-agent string, captured automatically along with the extension version, your language and which view you were in. |
Bug reports are also tagged with the install ID, which is how a report can be matched to the events around it — and, unlike those events, bug reports are not deleted on a schedule. Assume a report is kept.
None of this is collected unless you open the dialog and press Send report.
Third parties
Section titled “Third parties”Some things the extension does are requests to somebody else’s server. Listing them is the point of this page.
| Goes to | What it receives | When |
|---|---|---|
| Google, via Chrome Sync | the active profile in full — every card’s title and URL, note bodies, plus its columns, folders and tags, and your focus data | only if you press Sync to Chrome — see below |
| Google’s favicon service | the hostname of each bookmark being drawn, and of your open tabs | always, for everyone — see below |
| Open-Meteo | your coordinates, or a city name you typed | the weather widget |
| BigDataCloud | your coordinates | resolving “your location” for weather |
| OpenAI or Google Gemini | your prompts — titles, URLs, note text, search queries | only AI features, with your own key |
| jsDelivr, Unsplash, YouTube | requests for sound files, background images and the videos you added | Focus mode |
| Every site you have bookmarked | a request from your browser, to see whether the link still resolves | Bookmark Health Check, when you run it |
Getting the server copy back off
Section titled “Getting the server copy back off”The web dashboard has a Sync page. It lists what your account is actually storing — the entry, its version and when it was last written — and gives you a delete button for it. Deleting there removes the stored copy; the boards on your devices are untouched, and the next Upload simply creates a fresh one.
That is the whole of your library. Your account itself, your licence and your payment history are removed by a separate action, described next.
Deleting the account itself
Section titled “Deleting the account itself”The dashboard’s Overview page has a Delete account panel at the bottom. It asks for your password again — the action is irreversible and there is no undo, no tombstone and no export step, so a signed-in browser someone else walked up to is not enough on its own.
Confirming it deletes, immediately and permanently:
- your account — the email, the name and the password hash;
- every session, on every device, extension and dashboard alike;
- your licence and the devices registered against it;
- your synced library — the whole server copy, every profile;
- your payment history — the record of what you were charged;
- your sign-in history and your notifications.
Two things survive, with your name taken off them rather than being deleted: bug reports you sent (the text stays, so an open investigation does not vanish mid-thread) and anything you posted on the feature-request board — requests and comments stay readable, attributed to a removed account, because deleting them would take other people’s replies with them. Product telemetry loses its link to you the same way, and is purged on its own 90-day schedule.
Save what you need before you confirm. There is no export step in the flow, no e-mailed copy and no recovery window afterwards — so export your board to JSON or Markdown from the extension first, and keep your payment receipts: Stripe e-mails one for every charge, and the Billing page can only reach them while the account still exists. Once the account is gone, the record that you ever paid is gone from TabOasis with it.
Nothing on your own devices is touched. Uninstalling the extension is a separate step, and your local board survives account deletion untouched.
What the extension deliberately does not do
Section titled “What the extension deliberately does not do”- It does not read the pages you visit. The content script it injects exists only to draw the Spotlight overlay, and reads nothing from the page it sits on.
- It does not track your browsing history. No history permission is asked for, nothing records where you have been, and no tab URL is ever stored or uploaded unless you save that tab as a bookmark yourself. It can see your open tabs — that is what fills in Use this and Use all tabs in the popup. The one exception is the favicon service above: drawing a tab’s icon sends its hostname to Google. That is the hostname only, not the URL, the title or anything on the page — but it does leave the browser, so “nothing about your open tabs goes anywhere” would be too strong a claim to make.
- It does not sell or share data with advertisers. Nothing in the list above is an ad network.
- It does not upload your board in the background. Sync is a button.