Privacy policy
On this page
The short version
TabsPack makes one network request, and only if you ask it to: pressing Send in the Support pane sends the message you wrote and read, to us. Your browser asks your permission the first time, and saying no is fine.
Everything else stays on your computer. Your tabs are never sent anywhere. Nothing you do in TabsPack leaves the machine unless you export a file and send that file somewhere yourself.
There is no account, no sign in, no sync, no analytics, no telemetry, no crash reporting, no advertising and no tracking of any kind. Nothing is collected in the background, sold, shared or disclosed.
What the extension reads
To do its job, TabsPack reads the tabs you are viewing:
| Data | Why | Where it goes |
|---|---|---|
| Tab address and title | They are the content of an export | Into a file you choose to save, or a snapshot in your browser's local extension storage |
| Tab position, pinned, active, muted and discarded state | To restore your session as it was | The same |
| Window position, size and state | To restore your layout | The same |
| Tab group title, colour and collapsed state | To restore your groups | The same |
| When you last looked at a tab, if your browser supplies it | To restore the same detail, and to show you which tabs you have not opened in months | The same. It is read on your machine and shown on your screen, and it is never sent anywhere |
| Favicon address, optional and off by default | Shown in the preview | The same. Imported favicon addresses are never fetched |
| Your settings and snapshots | To remember your preferences and saved sessions | Your browser's local extension storage, on this machine only |
| The recovery copy and your recent sessions, on from install and you can turn them off; automatic snapshots, only if you turn them on | So your tabs can be brought back after a crash, from one of your last five browser sessions, or from earlier in the day | Your browser's local extension storage, on this machine only. The recovery copy is one entry, replaced when your tabs change. Recent sessions are that copy as it stood when each of your last five browser sessions ended; the oldest goes when a new one arrives. Automatic snapshots keep the newest ones and remove older automatic ones; a snapshot you saved or renamed is never removed |
| The browser's recently closed list, only when you open it | To show you what you closed and reopen what you pick | Read on demand, never stored |
What the extension never reads or stores
Cookies. Session tokens. Passwords. Authorization headers. Form contents. Page contents. Local storage or IndexedDB belonging to a website. Browsing history beyond the tabs currently open. Your identity in any form.
An exported file cannot be used to log in as you, anywhere. That is a deliberate property of the format, written into the specification as a requirement, not a side effect of the current implementation.
Storage and retention
Settings and snapshots live in your browser's local extension storage on the machine where you created them. They are not synced across your devices. They stay until you delete them, remove the extension, or clear your browser data. Exported files are ordinary files on your disk, entirely under your control.
Uninstalling the extension removes its local storage. Files you have exported are not touched.
Incognito and private windows
Private windows are excluded from exports by default. TabsPack cannot see them at all unless you explicitly allow the extension in incognito or private mode in your browser's own settings, and you also enable the option inside TabsPack.
Permissions, and why each one exists
| Permission | Why it is needed |
|---|---|
tabs | To read the address and title of your open tabs. The extension cannot work without it |
storage | To save your settings, your snapshots, the recovery copy and your recent sessions, and, if you turn them on, automatic snapshots, on this machine |
alarms | To update the recovery copy about half a minute after your tabs change, and to take automatic snapshots on schedule when you have turned them on. With both off, nothing is scheduled |
downloads | To write the export file you asked for |
tabGroups, optional | Requested the first time you use a feature involving tab groups, and only then |
sessions, optional | Requested only when you press Show recently closed, to read and reopen the browser's own list of what you closed |
https://tabspack-support.palworks.ai/*, optional | Requested the first time you press Send in the Support pane, and only then. It is the address that receives the message |
TabsPack asks for no host permission when you install it, so out of the box it
cannot reach any address at all. The one it can ever be granted is
tabspack-support.palworks.ai, it is granted by you at the moment you press Send, and you can
take it back at any time in your browser's extension settings. TabsPack still cannot read or modify
the content of any web page, ever, because it injects no content script anywhere.
The support form
TabsPack has a Support pane. It is the one place where anything you write is meant to reach us, and the only place TabsPack uses the internet, so it is worth being exact about how. There are two ways to send, and you choose.
Send delivers the message to us directly. The first time, your browser asks whether
TabsPack may connect to tabspack-support.palworks.ai. If you agree, the message is posted there
and forwarded to our inbox. Nothing else goes with it: no identifier, no account, no cookie, no
counter, no record of you having used the extension. We receive the message you wrote, and the
address you typed if you typed one.
Use my email app composes the same message and hands it to your own mail client instead. TabsPack sends nothing and makes no request. This is also where Send falls back to if you decline the permission, if you are offline, or if anything else goes wrong; if no mail app opens, the message goes to your clipboard and the page says so. A message is never lost to a failure.
What travels is what is on the screen and nothing else. If you leave the "include which browser I am using" box ticked, five lines go with it, shown to you in full before you send: the TabsPack version, your browser and operating system, whether the tab groups permission is granted, and two settings. Untick it and they are not included.
No address, title or count of your tabs is ever in a support message. That is enforced by two tests in the build, not by a promise here.
Third parties
No analytics vendor, no advertising network, no tracker, no sub processor of anything to do with your tabs. The extension contains no third party script, font or remote resource: every byte a TabsPack page loads comes from the package itself.
Two services carry a support message you choose to send, and only that:
| Service | What it handles | What it never sees |
|---|---|---|
| Cloudflare Workers | Receives the message at tabspack-support.palworks.ai and passes it on. Stores nothing. Keeps no copy of the message | Anything about your tabs, your settings or your browsing |
| Resend | Delivers that message to our inbox as email | The same |
If you use the mail client route instead, neither is involved and TabsPack makes no request at all.
This website
This site is static HTML hosted on GitHub Pages. It sets no cookies, runs no analytics, embeds nothing, and loads no font, script, stylesheet or image from any other server. There is nothing to consent to, which is why there is no consent banner. The cookie notice says the same thing at greater length, because some jurisdictions expect a page with that title.
GitHub serves the pages and, like any web server, processes the request: your IP address, the page you asked for, your user agent and the time. That is standard server operation, we do not receive it, and it is covered by GitHub's privacy statement.
Your rights
Data protection law gives you rights of access, correction, erasure, portability and objection. They apply to personal data a company holds about you. We hold none, because none is collected: there is no account, no identifier, no profile and no log of your use of the extension. There is nothing to export to you and nothing to delete.
The single exception is a support message you chose to send us, which we keep in an inbox in order to answer it. Ask us at support@palworks.ai and we will delete it.
Everything the extension stores is already yours and already local: it is in your own browser profile, you can read it, and uninstalling removes it.
Children
TabsPack collects no data from anyone, of any age.
Changes to this policy
If a future version ever changes what data is handled, this document changes in the same release, the version and date at the top change, and the change is listed in the changelog. A change that introduces or widens any network transmission requires a new decision record in the repository and is stated plainly in the store listing rather than buried here.
Version 1.1 was such a change: the support form gained a direct Send. Decision record ADR-039
explains why, and what was given up for it. Version 1.3 adds automatic snapshots, the recovery
copy and the recently closed list, with the alarms permission and the optional
sessions permission. Everything they keep stays on your machine: no new transmission.
Version 1.4 turns the recovery copy on from install and adds recent sessions, your last five
browser sessions kept from it. One checkbox on the Snapshots pane turns both off. Still no new
transmission.
Contact
Use the Support pane inside TabsPack, write to support@palworks.ai, or raise a GitHub issue. For a security concern, follow the security page instead.