Privacy Policy

Last updated: September 25, 2026

Data processed locally

  • Open tabs: titles, URLs, favicon URLs and window information are read to categorize, search, switch and close tabs. Results are processed inside your browser.
  • Browsing history: queried locally based on the keyword you type in the palette to show relevant results. Your full history is never uploaded to a developer server.
  • Favorites and preferences: saved URLs, titles, categories, favicon URLs, timestamps, and your language and appearance preferences are stored in the extension’s local browser storage. TabFlow does not offer cloud sync.
  • Panel authorization state: short-lived credentials are kept only for the current browser session to validate panel requests and are deleted when the panel or tab closes.

This version has no developer-operated data reporting, analytics SDK or advertising SDK. If advertising, paid accounts or analytics features are added in the future, this policy will be updated to reflect the actual behavior.

What connects to the network

  • Website icons. The palette shows favicons. Icons may load from remote addresses provided by websites; when a favicon is missing, a request is made to Google’s S2 favicon service for that domain. Remote icon services receive normal network information such as request URLs and IP addresses. The S2 request uses the domain name, not your search terms or full page paths.
  • Google search. Only when you choose the Google search action in the palette does TabFlow open a Google search page with the keyword you entered.
  • Opening web pages. Clicking a favorite or history result visits the corresponding website, which receives the request like any normal page visit.

TabFlow is not described as “zero network transfer”, “fully offline” or “100% private”, because the icon and search actions above use the network.

Isolation between the palette and web pages

Tabs, favorites, history results and search input are shown only inside an iframe from the extension origin. Content scripts on web pages only manage the outer frame and never receive these results; the background validates random credentials, sender origins, tab and document identities, and rejects unauthorized data requests. Local storage is restricted to the extension’s trusted context.

This is designed to stop ordinary web page scripts from reading palette data directly. It is not an absolute guarantee against browser vulnerabilities, malicious extensions or OS compromise. Host pages can still obscure or remove the outer frame, which affects display.

Upgrade note: older versions placed palette content in the shared DOM of web pages. Updating the extension does not automatically clear old content in already-open pages; please refresh those pages once, or restart the browser after saving your work.

Deleting data

Unfavoriting an item in the palette removes the corresponding local favorite. Uninstalling the extension removes its locally saved favorites and preferences; Chrome’s own browsing history is managed by browser settings.