The short version: we collect what the product needs to work, we do not sell it, there is no advertising tracking, and you can delete your account and take the data with it.
Last updated 11 September 2026.
Your account. An email address, and a password hash if you did not sign in with Google. Optionally a display name, username, bio and avatar — those are public, and the ones you choose.
What you make. Your Tabs, the findings your assistant pushes to them, your comments, who you follow, and what you have marked useful. Findings can contain anything your assistant sends, so treat a Tab as somewhere you have chosen to put that material.
How you use TabTab. Named product events — an account created, a Tab published, a finding viewed — attached to your account id. These are specific events we chose to record, not a recording of your session: there is no session replay, no heatmap, and page views are not captured automatically.
Technical necessities. Server logs, and your IP address at the moment of a request, used to rate-limit sign-ups and form submissions. We do not store IP addresses against your account or build a profile from them.
No advertising, no ad networks, no third-party advertising cookies, and no selling or renting personal data to anyone. No cross-site tracking. No session recording.
We do not read your private Tabs to train anything. Findings pass through AI providers to be summarised — that is the product — and those providers process them to return a result, not to train on them.
A session cookie so you stay signed in, and a stored preference for your chosen theme. That is all. There is no cookie banner because there is nothing to consent to beyond the cookie that makes signing in work.
We use the following providers to run TabTab. Each receives only what its job requires.
| Provider | Role | What it receives |
|---|---|---|
| Neon | Database hosting | Everything stored in the account: profile, Tabs, findings, comments. |
| Railway | Application hosting | Requests as they are served, and server logs. |
| Amazon S3 | File storage | Uploaded images and generated files. |
| Resend | Email delivery | Your email address and the contents of emails we send you. |
| PostHog | Product analytics | Named product events with your account id — never findings, comments, or page contents. |
| Sentry | Error monitoring | Error reports, which may incidentally include a request path or id. |
| Stripe | Payments | Your email and payment details, only if you subscribe to a paid Tab or take payouts. Card numbers never reach TabTab. |
| OpenAI and OpenRouter | AI processing | The text of findings being summarised, and prompts for images you generate. Not your profile or your comments. |
| Sign-in, if you use it | Confirms your identity to us; we receive your email and name. |
These providers operate in the United States and the European Union. Using TabTab means your data is processed in both.
Publishing a Tab makes it, its findings and its follower count public at a permanent address — readable by anyone, by search engines, and by AI agents, which TabTab deliberately serves. Your comments are public and attributed to your profile. Your username, display name, bio and avatar are public.
Private Tabs are private. So are your budgets and costs, agent runs, monitoring sources, notification settings, and every Tab you have not published. The publish dialog lists this before you confirm, and the terms set out the rest.
What it reads. Only when you choose “TabTab: Add to a Tab…” on a page: that page’s title, its address, and any text you had selected. Nothing else on the page, and nothing on pages you do not add. It never reads your browsing history or your open tabs.
Where it sends it. Only to TabTab — tabtab.com, and mcp.tabtab.com for signing in. What you add becomes a finding in the Tab you picked, marked as coming from your browser.
What it stores. In the browser’s own extension storage on that device: the connection to your TabTab account, the last copy of your Dock so the panel opens instantly, and product events waiting to be sent. Nothing is synced to your other browsers or devices.
Product events. Named events such as “panel opened” or “page added”, attached to your account id and forwarded to PostHog through TabTab. They never contain the address or text of a page.
Disconnecting. Disconnect in the extension, or revoke it in Settings, then Connections. Either stops it immediately; disconnecting also clears what it stored. The optional TabTab New Tab page asks the extension for the same Dock and stores nothing of its own.
Your account data stays until you delete it. Raw page snapshots taken while monitoring a site are deleted after 90 days. Replaced images — an avatar you changed, a Tab icon you swapped — are removed within a week. Emails we have sent stay in the delivery log at Resend on their schedule.
Deleting your account deletes your Tabs, findings, comments and uploads. Backups age out on their own schedule, and comments other people have already quoted in their own words stay theirs.
Access and export. Ask us and we will send you what we hold.
Correction. Your profile is editable in settings.
Deletion. Delete your account, or email us and we will do it.
Email. Notification cadence — immediate, daily, weekly or none — is a setting, and every email we send is one you can turn off there. Password resets and other account emails are not marketing and are always sent.
Depending on where you live you may also have the right to object to or restrict processing, or to complain to a data protection authority. Email contact@tabtab.com and we will help rather than ask you to fill in a form.
TabTab is not for people under 13, and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.
Passwords are hashed, never stored in a readable form. Traffic is encrypted in transit. Uploaded images are re-encoded on arrival, which strips embedded metadata including any location an original photograph carried.
No service is perfectly secure. If you find a vulnerability, email contact@tabtab.com and we will respond.
We will tell account holders before a change materially affects how we handle their data. Questions, requests and complaints all go to contact@tabtab.com, or through the contact form.