Privacy policy

How TabSidecar handles your data.

TabSidecar runs in your browser and keeps your tabs and windows on your device unless you choose a feature that sends them elsewhere, like cloud sync.

Last updated September 27, 2026

At a glance

the short version
Stays on your device
Your tabs, windows, labels and settings live in the extension’s own storage in your browser.
Local
An account is optional
Everything except cloud sync works without one.
Optional
Leaves your device only for features you use
Cloud sync if you sign in, AI window titles if you turn them on or ask for one, and the update-email list if you join it.
3 features
No ads, analytics or tracking
No advertising SDKs, behavior analytics, cross-site tracking pixels or general-purpose telemetry.
None
Doesn’t read what’s on your pages
No page contents, keystrokes, form fields, passwords or cookies.
Never

Overview

TabSidecar is a tab and window management extension. It helps you organize open tabs, restore windows, auto-park inactive tabs, save browser state, export your own backup files and, if you create an account, back up your tabs and windows to the cloud.

Most extension data stays in your browser, in the extension's own storage. Data leaves your device only when you turn on a feature that needs it, each described below: cloud sync if you sign in to an account, AI-generated window titles if you turn them on, and the update-email list if you join it.

Information we access

Open tabs and windows
Open tab and window information, including tab URLs, titles, favicon URLs, pinned state, tab position, tab groups and window grouping.
What you add in TabSidecar
Window metadata created inside the product, such as window names, saved windows, labels, nicknames, notes, priorities and filter rules.
Closed and auto-parked tabs
Closed-tab and auto-park history, including URLs, titles, timestamps and time-accumulation data used for tab management features.
Limited browsing history
Limited Chrome history data used for the extension's closed-URL backfill and history-management features.
Settings and preferences
Settings and preferences you choose inside the extension.
Your account, only if you create one
If you create an account: your email address, your password (handled by our sign-in provider, never stored by the extension in readable form), and the cloud snapshots described below.
A random install ID
An install-scoped random identifier used by the AI title feature for rate limiting.
Your email, only if you ask for updates
An email address you give us for product updates, only if you choose to.

Chrome permissions

Permissions

tabs
Used to read, organize, move, create, focus, pin and close tabs.
tabGroups
Used to read the names and colors of your tab groups for Local Bridge (see below). Nothing else uses it.
windows
Used to inspect, name, restore, focus, create and remove browser windows.
alarms
Used for scheduled tasks such as auto-park checks, automatic backups, automatic cloud sync and delayed processing.
storage
Used to keep window and tab identities, recovery state and diagnostics on your device, so windows can be matched back after a restart.
scripting
Used to add TabSidecar's two page scripts (described below) to tabs that were already open when the extension was installed or updated.
history
Used to search browser history for closed-URL backfill and to support history deletion features you trigger.
favicon
Used to display site icons for tabs and saved items.
downloads
Used to export backup files that you choose to generate.

Host permissions

http://*/*
https://*/*
All websites. This also covers Local Bridge's local address (127.0.0.1), and exists for the two page scripts below.
https://api.tabsidecar.com/*
AI window titles.
https://quqhdnkypnuxvmibnzhn.supabase.co/*
Accounts, cloud sync and the update-email list.

Page scripts, which run on every page as it starts loading

identity-content.js
Stores a random TabSidecar tab and window ID in the page's session storage and navigation history state. Chrome restores these with the tab after a browser restart, which lets TabSidecar match a restored tab to its saved data. The script only reads and writes its own keys and never touches the page's other data. It tells the extension a site's origin (for example https://example.com) if that site cleared the IDs.
title-content.js
Reads the page title and adds a lock symbol to it when you lock a tab in TabSidecar.

Neither script reads page contents, keystrokes, form fields, passwords or cookies, and neither sends anything off your device. TabSidecar does not request permissions for cookies, identity, bookmarks, microphone, camera or geolocation.

How information is stored

TabSidecar stores its working data locally in the extension's own IndexedDB database and Chrome extension storage. That data may include open tabs, windows, saved windows, auto-parked tabs, closed URLs, settings, labels, nicknames, saved-for-later items and similar organization metadata. Browsing sessions that TabSidecar tracks for restoring windows stay on your device and are not included in backup files.

Local Bridge, an optional feature for tools running on your own computer, can share a snapshot of your windows, tabs and tab groups with a program listening at 127.0.0.1. It is off by default, needs a secret you paste in to turn it on, and never sends anything off your computer.

When you export backup files, the extension generates them locally and saves them through Chrome's download system. Exported settings leave out the AI install identifier and your sign-in session.

Accounts and cloud sync

An account is optional. Everything except cloud sync works without one.

Sign-in
Accounts use an email address and password through Supabase Auth, our database and sign-in provider. To sign up, we email you a one-time code to confirm the address, then you set a password. Changing your password signs out your other sessions. Sign-ups whose email is never confirmed are deleted automatically after a day.
What a cloud snapshot contains
Your open tabs (URLs and titles) and windows, window names, saved, kept and closed windows, saved-for-later items, auto-parked tabs, nicknames, labels, priorities, notes, filter rules and extension settings. Each snapshot also records a device ID, a device name such as “Chrome on Windows”, and tab and window counts. Closed-tab history from Chrome and your sign-in session are not included.
Devices
For each device we store its random ID, device name, extension version, browser name, platform and when it last synced.
When it syncs
While you're signed in, the extension uploads a snapshot automatically (every hour by default; you can change the interval or turn it off) and whenever you sync manually.
How many are kept
The extension keeps your 20 most recent snapshots per device and deletes older ones. The database also caps each account at 10 devices and 50 MB of snapshots, removing the oldest snapshots first.

Encryption and who can access your data

Encrypted in transit and at rest
Data is encrypted in transit (HTTPS) and encrypted at rest by our database provider, Supabase.
Not end-to-end encrypted
Cloud snapshots are not end-to-end encrypted. The TabSidecar operator can technically access them, and only does so when needed for support or security.
Only your account
Other users can't access your data. Database access rules restrict every row to the account that owns it.

AI window titles

AI window titles are off until you turn them on, either during setup or in Settings → Artificial Intelligence. Asking for an AI title for a single window also sends that window's request.

When they're on, the extension sends a request to api.tabsidecar.com containing an install-scoped random identifier, the window's tab titles and the site name of each tab (for example github.com, not the full address), and your existing window titles. If you're signed in, the request also carries your sign-in token so your account gets a higher daily limit. Our server passes the tab titles and site names to Google's Gemini API to generate the title and returns it to the extension.

Our server does not store tab titles or site names. To enforce daily limits it keeps a count of requests per day for your install identifier, account and network address, and deletes those counts after 7 days.

Update emails

If you choose to join the update-email list, the extension sends that email address to our Supabase database. We use it only to send product updates.

Service providers and data sharing

TabSidecar does not sell your personal information and does not include advertising SDKs, behavior analytics, cross-site tracking pixels or general-purpose telemetry. We use two service providers:

Supabase
Hosts accounts, sign-in, cloud snapshots, devices and the update-email list, and sends account emails.
Google (Gemini API)
Generates AI window titles from the tab titles and site names described above, if you turn them on.

Your choices

You can:

Use TabSidecar without an account.
Turn automatic cloud sync off or change how often it runs.
Turn AI window titles on or off (they're off unless you turn them on).
Choose whether to join the update-email list.
Export your own backup files locally.
Remove local extension data by uninstalling the extension or clearing its storage through Chrome.
Manage browser history separately through Chrome.

Data retention and deletion

Local data remains in the extension's storage until you delete it, clear the extension's data or uninstall the extension. Exported backup files remain wherever you save them.

Cloud snapshots are kept as described under “Accounts and cloud sync” until you delete your account. To delete it, open Account in the extension and choose to delete your account; you'll be asked for your password. This permanently deletes your account, its cloud snapshots and devices, and your address on the update-email list. Tabs and windows on your device are kept. You can also ask us to delete your data by emailing support@tabsidecar.com.

Security

Account data is protected by the encryption and per-account access rules described above. Deleting an account requires a password sign-in within the last few minutes, so a stolen session alone can't delete it. No software can guarantee absolute security, but TabSidecar keeps most tab-management data on your device unless you use a feature that sends it to a backend service.

Children's privacy

TabSidecar is not directed to children under 13, and we do not knowingly collect personal information from children.

Changes to this policy

We update this policy when the product changes how it handles data, before or when those changes ship. The date at the top of this page shows when it was last updated.

Contact

For privacy questions about TabSidecar, contact support@tabsidecar.com.