Last updated: August 25, 2026
TabRabbit ("we", "our", or "the extension") is a browser extension that lets you save, organize, and restore browser tabs. This policy explains what data we collect and how we use it.
When you use TabRabbit without signing in, no data leaves your device. Everything is stored locally in your browser.
When you sign in to enable cloud sync, we collect:
When cloud sync is enabled, saved tab data is encrypted before storage using AES-256-GCM. Encryption keys are derived per user. Local-only users keep their data entirely on their device.
Connecting TabRabbit to ChatGPT, Codex, or another compatible client requires you to sign in and approve read-only access. The connected client receives an access token; TabRabbit validates that token and limits every request to the account that approved it. The authorization page keeps its temporary sign-in token only in the browser tab's session storage and clears it when authorization finishes or the tab closes.
You can disconnect TabRabbit from the connected client's app or plugin settings. Disconnecting stops future access but does not control copies already included in conversations or retained by that client under its own policies.
TabRabbit requests certain browser permissions to function. Here is what each permission does:
Optional permission: When you enable smarter categorization, page descriptions, or memory insights, Chrome may ask to "Read data on websites you visit." This allows TabRabbit to read page descriptions and measure tab memory usage. We only read this information — we never modify any website. You can deny this permission and TabRabbit will still work; AI categorization and memory insights will simply use less information.
Local data remains in your browser profile until you delete it, clear extension storage, or uninstall TabRabbit. Cloud account data remains while your account is active and is removed from live service storage when you delete your account from Settings. Service-provider backups expire according to the providers' backup-retention schedules.
TabRabbit does not store the content of MCP responses in a separate analytics database. Server logs record the tool name, outcome, and request duration for reliability and security, but not the search query, saved-tab content, access token, or account identifier. Connected clients may retain conversation content under their own policies and account settings.
TabRabbit is not directed at children under 13 and we do not knowingly collect data from children.
If we make material changes to this policy, we will update the date above. Continued use of the extension after changes constitutes acceptance.
Questions about this policy? Contact us at support@tabrabbit.app.