Tabulary Privacy policy  /  v1.2.0 ← Home

Privacy Policy

Tabulary 1.2.0 · Last updated 2026-10-02

Tabulary is a browser extension for saving and organizing open tabs, for Chrome, Edge, Brave and Firefox. This page sets out what it handles, where that data goes, and what you can do about it.

The short version

  • Everything you save stays on your device by default. No account, no server of ours, no tracking in the extension.
  • If you sign in with Google, your library and a small profile file are backed up to a hidden folder inside your own Google Drive — never to a database we operate.
  • A photo you put behind Home never leaves the device it was chosen on.
  • The extension has no analytics and no advertising, and nothing is sold or shared with anyone. This website counts page views (see “This website” below).

What Tabulary stores, and where

“Your library” below means everything the extension keeps for you: boards, collections, saved tabs, tags, sessions, review markers, Live Collection rules, Home shortcuts, and your settings, including how Home looks.

DataWhere it livesWho can see it
Your libraryYour browser’s own storage (IndexedDB)Only you, on this device
Your library, if you sign in with GoogleAdditionally: a hidden, app-private folder in your own Google Drive (Drive’s appDataFolder)Only you — invisible in your normal Drive view, unreachable by any other app
Home background photoIndexedDB on the device where you chose it. Never backed up, synced or exported; your other devices show the theme instead.Only you, on this device
Display name, profile photo, theme and appearance choicesLocal storage, plus the same private Drive folder if signed in with GoogleOnly you
Getting-started guide progresslocalStorage on this device only — never syncedOnly you, on this device
Other per-device view state (which view you last had open, the popup’s last section and board, a copy of Home’s look so it appears without a flash)Local storage only — deliberately never syncedOnly you, on this device
Whether the toolbar button opens the popup or the side panelchrome.storage.local on this deviceOnly you, on this device
Account identity (email address, or your Google account)Firebase Authentication, operated by Google — used only to know who you areYou and Google’s authentication infrastructure. We never see or store your password.
A short-lived Google Drive access tokenchrome.storage.local on this device, replaced when it expiresOnly you

If you used the Desk in Tabulary 1.1, its widgets are still in your browser’s storage, untouched, but they are no longer backed up or synced; copies already in your Drive backup folder are left as they were. Its shortcuts were copied into Home.

Sign-in and Google Drive access

Signing in is optional — the extension is fully usable without ever doing it. There are two ways:

You can revoke that access at any time from Google Account → Security → Third-party apps, or delete the stored data directly from Google Drive → Settings → Manage apps → Tabulary → “Delete hidden app data.”

The token service

Keeping Drive backup working without asking you to reconnect requires a Google refresh token, and a refresh token must never ship inside an extension. Tabulary’s is held by a small separate service (a Cloudflare Worker), encrypted, one record per signed-in account. It hands the extension a short-lived access token when a backup is due.

That service never receives your boards, collections, tabs, sessions, rules, or any browsing data. It only knows that an account exists and holds the credential needed to refresh that account’s own Drive access. Signing out tells it to disconnect.

What goes over the network

Without an account, Tabulary sends nothing to us, to Google, or to the token service. Its fonts are built into the extension. The only requests it makes on its own are for site icons:

Everything else happens because you asked for it: opening a saved tab or a Home shortcut loads that site, and pressing Enter in the search box sends your query to the search engine you picked. The saved-tab suggestions that appear as you type are worked out on the device.

With an account, Tabulary additionally talks to:

What Tabulary does not do

  • It does not run a server that stores your tab data.
  • The extension does not use analytics, advertising networks, or tracking pixels.
  • It does not sell, rent, or share your data with third parties.
  • It does not watch your browsing. It reads a tab’s title and URL when you ask it to save that tab, lists the tabs in your current window when you open the Open tabs section, and loads site icons as described above.

Browser permissions Tabulary requests

PermissionWhy
tabsTo read the title and URL of your open tabs when you choose to save them, to list this window’s tabs in the popup and side panel so you can pick some to save, and to compare a session against what’s already open before restoring it.
storage, unlimitedStorageTo keep your library on the device without a size cap.
faviconChrome, Edge, BraveTo read the browser’s own icon cache, so saved links show their site’s icon without a network request.
sidePanelChrome, Edge, BraveTo show Tabulary in the browser’s side panel when you choose it. Firefox’s sidebar needs no permission.
identityTo run the Google sign-in flow, if you use it.
bookmarksoptionalAsked for only when you click Import browser bookmarks. Tabulary reads your bookmarks for that import and shows you a preview; nothing is written back to your bookmarks. The browser keeps the permission once granted, until you remove it in its extension settings, but Tabulary reads bookmarks only when you start an import.
topSitesoptionalAsked for only when you click Add your most visited sites on Home. Tabulary reads the browser’s list of most visited sites once and adds up to eight that aren’t already shortcuts, keeping each one’s address and a short name. Nothing else from the list is kept, and it is read only when you click that button.

Tabulary also replaces the new tab page and registers tt as an address-bar keyword. Neither sends anything anywhere: the new tab page is the extension’s own library and Home, and an address-bar search is answered from local storage.

The feedback form

Settings → Support links to an optional feedback form hosted on Google Forms. Using it is entirely up to you, it never opens by itself, and it collects only what you type into it. Nothing from your library is attached.

Deleting your data

From Settings → Data you can export everything as a JSON file, clear this device’s data, clear the signed-in account’s data, or delete the account outright. Every destructive action offers to export first, and account deletion tombstones your cloud data before the identity is removed. An export does not include Home background photos.

Children’s privacy

Tabulary is not directed at children, and we do not knowingly collect data from anyone under 13.

Changes to this policy

This website

This page and the rest of the Tabulary website (tabulary.vercel.app) count page views with Vercel Web Analytics. It sets no cookies and builds no profile of you: it records that a page was viewed, roughly where in the world from, and the kind of device and browser, with no way to follow you from one site to another. It is used only to see which pages people read. It does not run inside the extension, and the extension sends nothing to it. The site loads no advertising and no other tracking.

If this policy changes, the “Last updated” date above changes with it.

Contact

Questions about any of this: hishamsunjeq123@gmail.com.