How TabSidecar handles your data.
TabSidecar runs in your browser and keeps your tabs and windows on your device unless you choose a feature that sends them elsewhere, like cloud sync.
Overview
TabSidecar is a tab and window management extension. It helps you organize open tabs, restore windows, auto-park inactive tabs, save browser state, export your own backup files and, if you create an account, back up your tabs and windows to the cloud.
Most extension data stays in your browser, in the extension's own storage. Data leaves your device only when you turn on a feature that needs it, each described below: cloud sync if you sign in to an account, AI-generated window titles if you turn them on, and the update-email list if you join it.
Information we access
Chrome permissions
Permissions
tabstabGroupswindowsalarmsstoragescriptinghistoryfavicondownloadsHost permissions
http://*/*https://*/*127.0.0.1), and exists for the two page scripts below.https://api.tabsidecar.com/* https://quqhdnkypnuxvmibnzhn.supabase.co/* Page scripts, which run on every page as it starts loading
identity-content.jshttps://example.com) if that site cleared the IDs.title-content.jsNeither script reads page contents, keystrokes, form fields, passwords or cookies, and neither sends anything off your device. TabSidecar does not request permissions for cookies, identity, bookmarks, microphone, camera or geolocation.
How information is stored
TabSidecar stores its working data locally in the extension's own IndexedDB database and Chrome extension storage. That data may include open tabs, windows, saved windows, auto-parked tabs, closed URLs, settings, labels, nicknames, saved-for-later items and similar organization metadata. Browsing sessions that TabSidecar tracks for restoring windows stay on your device and are not included in backup files.
Local Bridge, an optional feature for tools running on your own computer, can share a snapshot of your windows, tabs and tab groups with a program listening at 127.0.0.1. It is off by default, needs a secret you paste in to turn it on, and never sends anything off your computer.
When you export backup files, the extension generates them locally and saves them through Chrome's download system. Exported settings leave out the AI install identifier and your sign-in session.
Accounts and cloud sync
An account is optional. Everything except cloud sync works without one.
- Sign-in
- Accounts use an email address and password through Supabase Auth, our database and sign-in provider. To sign up, we email you a one-time code to confirm the address, then you set a password. Changing your password signs out your other sessions. Sign-ups whose email is never confirmed are deleted automatically after a day.
- What a cloud snapshot contains
- Your open tabs (URLs and titles) and windows, window names, saved, kept and closed windows, saved-for-later items, auto-parked tabs, nicknames, labels, priorities, notes, filter rules and extension settings. Each snapshot also records a device ID, a device name such as “Chrome on Windows”, and tab and window counts. Closed-tab history from Chrome and your sign-in session are not included.
- Devices
- For each device we store its random ID, device name, extension version, browser name, platform and when it last synced.
- When it syncs
- While you're signed in, the extension uploads a snapshot automatically (every hour by default; you can change the interval or turn it off) and whenever you sync manually.
- How many are kept
- The extension keeps your 20 most recent snapshots per device and deletes older ones. The database also caps each account at 10 devices and 50 MB of snapshots, removing the oldest snapshots first.
Encryption and who can access your data
AI window titles
AI window titles are off until you turn them on, either during setup or in Settings → Artificial Intelligence. Asking for an AI title for a single window also sends that window's request.
When they're on, the extension sends a request to api.tabsidecar.com containing an install-scoped random identifier, the window's tab titles and the site name of each tab (for example github.com, not the full address), and your existing window titles. If you're signed in, the request also carries your sign-in token so your account gets a higher daily limit. Our server passes the tab titles and site names to Google's Gemini API to generate the title and returns it to the extension.
Our server does not store tab titles or site names. To enforce daily limits it keeps a count of requests per day for your install identifier, account and network address, and deletes those counts after 7 days.
Update emails
If you choose to join the update-email list, the extension sends that email address to our Supabase database. We use it only to send product updates.
Service providers and data sharing
TabSidecar does not sell your personal information and does not include advertising SDKs, behavior analytics, cross-site tracking pixels or general-purpose telemetry. We use two service providers:
- Supabase
- Hosts accounts, sign-in, cloud snapshots, devices and the update-email list, and sends account emails.
- Google (Gemini API)
- Generates AI window titles from the tab titles and site names described above, if you turn them on.
Your choices
You can:
Data retention and deletion
Local data remains in the extension's storage until you delete it, clear the extension's data or uninstall the extension. Exported backup files remain wherever you save them.
Cloud snapshots are kept as described under “Accounts and cloud sync” until you delete your account. To delete it, open Account in the extension and choose to delete your account; you'll be asked for your password. This permanently deletes your account, its cloud snapshots and devices, and your address on the update-email list. Tabs and windows on your device are kept. You can also ask us to delete your data by emailing support@tabsidecar.com.
Security
Account data is protected by the encryption and per-account access rules described above. Deleting an account requires a password sign-in within the last few minutes, so a stolen session alone can't delete it. No software can guarantee absolute security, but TabSidecar keeps most tab-management data on your device unless you use a feature that sends it to a backend service.
Children's privacy
TabSidecar is not directed to children under 13, and we do not knowingly collect personal information from children.
Changes to this policy
We update this policy when the product changes how it handles data, before or when those changes ship. The date at the top of this page shows when it was last updated.
Contact
For privacy questions about TabSidecar, contact support@tabsidecar.com.