Privacy Policy
Last updated: September 25, 2026
Data processed locally
- Open tabs: titles, URLs, favicon URLs and window information are read to categorize, search, switch and close tabs. Results are processed inside your browser.
- Browsing history: queried locally based on the keyword you type in the palette to show relevant results. Your full history is never uploaded to a developer server.
- Favorites and preferences: saved URLs, titles, categories, favicon URLs, timestamps, and your language and appearance preferences are stored in the extension’s local browser storage. TabFlow does not offer cloud sync.
- Panel authorization state: short-lived credentials are kept only for the current browser session to validate panel requests and are deleted when the panel or tab closes.
This version has no developer-operated data reporting, analytics SDK or advertising SDK. If advertising, paid accounts or analytics features are added in the future, this policy will be updated to reflect the actual behavior.
What connects to the network
- Website icons. The palette shows favicons. Icons may load from remote addresses provided by websites; when a favicon is missing, a request is made to Google’s S2 favicon service for that domain. Remote icon services receive normal network information such as request URLs and IP addresses. The S2 request uses the domain name, not your search terms or full page paths.
- Google search. Only when you choose the Google search action in the palette does TabFlow open a Google search page with the keyword you entered.
- Opening web pages. Clicking a favorite or history result visits the corresponding website, which receives the request like any normal page visit.
TabFlow is not described as “zero network transfer”, “fully offline” or “100% private”, because the icon and search actions above use the network.
Isolation between the palette and web pages
Tabs, favorites, history results and search input are shown only inside an iframe from the extension origin. Content scripts on web pages only manage the outer frame and never receive these results; the background validates random credentials, sender origins, tab and document identities, and rejects unauthorized data requests. Local storage is restricted to the extension’s trusted context.
This is designed to stop ordinary web page scripts from reading palette data directly. It is not an absolute guarantee against browser vulnerabilities, malicious extensions or OS compromise. Host pages can still obscure or remove the outer frame, which affects display.
Upgrade note: older versions placed palette content in the shared DOM of web pages. Updating the extension does not automatically clear old content in already-open pages; please refresh those pages once, or restart the browser after saving your work.
Deleting data
Unfavoriting an item in the palette removes the corresponding local favorite. Uninstalling the extension removes its locally saved favorites and preferences; Chrome’s own browsing history is managed by browser settings.
隐私政策
最近更新:2026-09-25
在本地处理的数据
- 打开的标签页:读取标题、网址、图标地址和窗口信息,用于分类、搜索、切换和关闭标签页。结果在浏览器内处理。
- 浏览历史:根据面板中输入的关键词在本地查询 Chrome 历史记录,用于显示相关结果。不会把完整历史记录上传到开发者服务器。
- 收藏与偏好:收藏的网址、标题、分类、图标地址、创建时间,以及语言、主题偏好保存在浏览器的扩展本地存储中。本扩展不提供云同步。
- 面板授权状态:仅在当前浏览器会话内保存短期凭证,用于校验面板请求;关闭面板或标签时删除。
当前版本没有自有服务器上报、统计 SDK 或广告 SDK。未来若加入广告、收费账户或分析功能,将按实际行为更新本说明。
哪些操作会联网
- 网站图标。面板保留网站图标展示。图标可能从网页提供的远程地址加载;缺少图标时,会向 Google S2 图标服务请求对应域名的图标。远程图标服务会收到请求 URL、IP 地址等常规网络信息。S2 请求参数使用域名,不包含搜索词或网页完整路径。
- Google 搜索。只有选择面板中的 Google 搜索操作时,才会在新标签中打开包含所输入关键词的 Google 搜索页面。
- 打开网页。点击收藏或历史结果会访问对应网站,网站将按正常网页访问方式接收请求。
因此,本扩展不宣称“零外网传输”“完全离线”或“100% 隐私安全”:以上图标与搜索操作会使用网络。
面板与网页的隔离
标签、收藏、历史结果和搜索输入仅显示在扩展来源的 iframe 内。网页内的内容脚本只管理外框,不接收这些结果;后台校验随机凭证、发送来源、标签及文档身份,拒绝未授权的数据请求。本地存储限制为扩展可信上下文使用。
这用于阻止普通网页脚本直接读取面板里的数据,不是对浏览器漏洞、恶意扩展或操作系统入侵的绝对保证。宿主网页仍能遮挡或移除外框,影响显示。
旧版升级注意:旧版曾把面板内容放在网页共享 DOM 中。更新扩展不会自动清除所有已打开网页中的旧内容,请刷新这些网页一次,或保存工作后重启浏览器。
删除数据
在面板中取消收藏可移除对应的本地收藏项。卸载扩展可移除其本地保存的收藏和偏好;Chrome 自身的浏览历史由浏览器设置管理。
隱私權政策
最近更新:2026-09-25
在本地端處理的資料
- 已開啟的分頁:讀取標題、網址、圖示與視窗資訊,用於分類、搜尋、切換與關閉分頁。所有結果僅在瀏覽器本機端處理。
- 瀏覽紀錄:依據搜尋面板中輸入的關鍵字於本機端查詢瀏覽紀錄,用於顯示相關結果。絕不會將瀏覽紀錄上傳至開發者伺服器。
- 我的最愛與偏好設定:收藏的網址、標題、分類、圖示、建立時間,以及語言與主題偏好均儲存於瀏覽器的擴充功能本機端儲存空間。本擴充功能不提供雲端同步。
- 面板授權狀態:僅在當前瀏覽器工作階段內保存短期憑證,用於驗證面板請求;關閉面板或分頁時即刻銷毀。
目前版本沒有自建伺服器回報、統計 SDK 或廣告 SDK。未來若加入廣告、付費帳號或分析功能,將依實際運作行為更新此說明。
哪些操作會連線至網路
- 網站圖示:面板保留網站 Favicon 圖示顯示。圖示可能直接自網頁提供的遠端網址載入;若缺少圖示,會向 Google S2 圖示服務請求對應網域的圖示。遠端圖示服務會收到請求 URL、IP 位址等一般網路連線資訊。S2 請求參數僅使用網域名稱,不包含搜尋詞或網頁完整路徑。
- Google 搜尋:僅在點選面板中的 Google 搜尋選項時,才會在新分頁開啟包含所輸入關鍵字的 Google 搜尋頁面。
- 開啟網頁:點擊收藏或歷史紀錄結果時會前往對應網站,網站將依照正常瀏覽網頁方式接收請求。
因此,本擴充功能不宣稱「零外網傳輸」、「完全離線」或「100% 隱私無虞」:上述圖示載入與搜尋跳轉操作需要使用網路。
面板與網頁的安全隔離
分頁、書籤收藏、歷史紀錄與搜尋關鍵字僅在擴充功能來源的 iframe 內部顯示。宿主網頁的內容指令碼(Content Script)僅負責管理外框,無法取得搜尋結果;後台 Service Worker 會驗證隨機憑證、發送來源與文件識別碼,拒絕所有未經授權的資料請求。本機儲存空間僅限擴充功能的可信上下文存取。
此機制用於防止一般網頁指令碼直接窺探面板資料,但並非針對瀏覽器漏洞或作業系統遭受入侵的絕對保證。宿主網頁仍可能遮蔽或移除外框,影響介面正常顯示。
舊版升級提示:早期版本曾將面板直接渲染於網頁共用 DOM 中。更新擴充功能無法自動清除所有已開啟網頁中的舊內容,請手動重新整理這些網頁一次,或儲存工作後重啟瀏覽器。
刪除資料
在面板中取消收藏即可移除對應的本機收藏項目。解除安裝擴充功能會自動刪除其在本機端保存的所有收藏與偏好設定;瀏覽器本身的歷史紀錄則由 Chrome / Edge 系統設定統一管理。