Privacy, in plain English
TabMerger is an indie product. We collect only what we need to operate the service, we never sell it, and you can delete all of it at any time. Questions? Contact us.
1. What We Collect and Why
Account information
Your email address, stored via Supabase Auth. Used to identify your account, send transactional emails (e.g. password reset), and link your subscription to your data.
Tab and group data
Tab URLs, titles, and favicon URLs so you can organize and restore them. On the free tier this data lives in your browser's IndexedDB and is not transmitted to our servers, except as described under "Page previews" below if you turn that feature on. Showing a tab's icon can contact Google's favicon service; see Site icons below. Pro subscribers who enable cloud sync have this data end-to-end encrypted on your device before it is ever sent to our servers. We store only ciphertext in Supabase: the encryption key is derived from a passphrase that only you know, is never transmitted to us, and is never recoverable by TabMerger. This means we cannot read your stored or synced group or tab data, and neither could anyone who gained unauthorized access to our database.
Site icons (favicons)
TabMerger shows a small site icon next to each tab. When your browser supplies the icon, it is loaded from the address the site itself uses for it. When your browser doesn't supply one, TabMerger asks Google's favicon service for it: your browser then sends that site's domain (for example example.com; never the full page address, the tab's title or anything on the page) to Google whenever the icon is shown, in the extension, on your dashboard or on a shared link's page. The request goes straight from your browser to Google, so Google sees your IP address as any website you load does. It carries no TabMerger account or identifier, and it never passes through our servers.
Page previews (off by default)
Off by default. When you turn on preview images — in the extension's Settings, or on a shared link's page — hovering a tab sends that tab's web address to TabMerger's preview service, which fetches the page's preview image and description and returns them to you. The address isn't linked to your account, isn't logged, and isn't stored. You can turn this off at any time. See Page previews below for details.
Subscription and billing
Your Stripe customer ID and subscription status (tier, billing period, status). We never see or store your card number, CVV, or full payment details — those are handled entirely by Stripe.
AI features (Pro AI tier only)
When you use AI features, the titles and URLs of your open tabs are sent to the Anthropic Claude API to generate a response over an encrypted connection. Anthropic does not use API request content to train its models and does not retain it beyond their standard API data handling terms. Tab content is not stored by us beyond what you have already saved in your groups.
Analytics
We use Google Analytics 4 on the web app to collect aggregate usage patterns (page views, feature usage). GA4 assigns an anonymous client identifier and we do not link this data to your account identity. No personally identifiable information is sent to Google. We also use PostHog for product analytics and session replay on the web app, with all form inputs masked by default; this data is likewise not linked to your account beyond what's needed to improve the product. On the web app we also use Vercel Web Analytics, which counts page views without cookies, and Vercel Speed Insights, which measures how fast pages load; neither is linked to your account.
2. Page Previews
Page previews let you see a small image and description of a tab's page when you hover over it — in the extension's tab preview tooltip, or on a shared link's page. This feature is off by default and must be explicitly turned on, either in the extension's Settings or via the "Show page previews" switch on a shared link's page.
When turned on, hovering a tab sends that tab's web address to TabMerger's preview service (a serverless function we run on Vercel). That service fetches the page's og:image and description on your behalf and returns them to you. The address you send:
- is sent without your account or any other identifier attached. Like any web request it reaches our host, Vercel, from your IP address, but we don't record or associate the two. The page itself is fetched by our server, so the site you're previewing sees our server, not you,
- is not logged anywhere by us,
- is not cached or stored, even temporarily — every preview request fetches the page fresh.
You can turn page previews off at any time; when off, hovering a tab shows only information already available locally (title, URL, favicon, and any preview image already saved with that tab) and never contacts the preview service.
3. How Data Is Stored
4. Third-Party Processors
We share data with the following processors only to the extent necessary to operate the service.
We do not sell your data to any third party.
5. Data Retention
We retain your account data for as long as your account is active. If you delete your account, all associated data stored in Supabase — including your profile, groups, and sessions — is permanently deleted.
Local IndexedDB data remains in your browser until you clear it via browser settings or the TabMerger extension.
Stripe may retain billing records for tax and compliance purposes in accordance with their own policies.
6. Your Rights
Depending on where you reside, you may have rights under laws such as the GDPR (EU/UK) or CCPA (California):
- AccessRequest a copy of the personal data we hold about you.
- CorrectionAsk us to correct inaccurate data.
- DeletionRequest deletion of your account and associated data.
- PortabilityRequest your data in a portable format.
- ObjectionObject to certain processing activities.
To exercise any of these rights, contact us. We will respond within 30 days.
8. Children's Privacy
TabMerger is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy as the product evolves. Material changes will be communicated via email or a notice in the app. The "last updated" date at the top of this page will always reflect the most recent revision. Continued use of TabMerger after changes constitutes acceptance of the revised policy.
10. Contact
For privacy-related questions or requests, use our contact page.