Privacy Policy

Last updated: August 25, 2026

TabRabbit ("we", "our", or "the extension") is a browser extension that lets you save, organize, and restore browser tabs. This policy explains what data we collect and how we use it.

1. What We Collect

When you use TabRabbit without signing in, no data leaves your device. Everything is stored locally in your browser.

When you sign in to enable cloud sync, we collect:

2. Encryption

When cloud sync is enabled, saved tab data is encrypted before storage using AES-256-GCM. Encryption keys are derived per user. Local-only users keep their data entirely on their device.

3. What We Do Not Collect

4. Third-Party Services

5. Connected AI Clients and OAuth

Connecting TabRabbit to ChatGPT, Codex, or another compatible client requires you to sign in and approve read-only access. The connected client receives an access token; TabRabbit validates that token and limits every request to the account that approved it. The authorization page keeps its temporary sign-in token only in the browser tab's session storage and clears it when authorization finishes or the tab closes.

You can disconnect TabRabbit from the connected client's app or plugin settings. Disconnecting stops future access but does not control copies already included in conversations or retained by that client under its own policies.

6. Browser Permissions

TabRabbit requests certain browser permissions to function. Here is what each permission does:

Optional permission: When you enable smarter categorization, page descriptions, or memory insights, Chrome may ask to "Read data on websites you visit." This allows TabRabbit to read page descriptions and measure tab memory usage. We only read this information — we never modify any website. You can deny this permission and TabRabbit will still work; AI categorization and memory insights will simply use less information.

7. Data Retention & Deletion

Local data remains in your browser profile until you delete it, clear extension storage, or uninstall TabRabbit. Cloud account data remains while your account is active and is removed from live service storage when you delete your account from Settings. Service-provider backups expire according to the providers' backup-retention schedules.

TabRabbit does not store the content of MCP responses in a separate analytics database. Server logs record the tool name, outcome, and request duration for reliability and security, but not the search query, saved-tab content, access token, or account identifier. Connected clients may retain conversation content under their own policies and account settings.

8. Children's Privacy

TabRabbit is not directed at children under 13 and we do not knowingly collect data from children.

9. Changes to This Policy

If we make material changes to this policy, we will update the date above. Continued use of the extension after changes constitutes acceptance.

10. Contact

Questions about this policy? Contact us at support@tabrabbit.app.