Legal

Privacy policy

Last updated: 31 May 2026

This policy describes how Tabwise (“we”, “the service”) handles information when you use the Chrome extension and any website or API we operate. The extension is designed to answer questions about the page you are viewing; that requires sending page-derived content to Tabwise servers so we can generate an answer.

What we collect

Account data

If you register, we store your email address, a hashed password (for email sign-in), and verification status. Google sign-in stores your Google account identifier and email via our OAuth integration. Authentication tokens (access and refresh JWTs) are kept in extension local storage on your device.

Page and question data

When you ask a question, the extension may send some or all of the following to the Tabwise API: page title, URL, extracted text (full page, selection, viewport, or transcript on supported sites), your question, and optional conversation history for that tab. We do not intentionally collect passwords, payment card fields, or other fields marked as sensitive by the browser—though any text visible on the page could be included if it is part of the extracted content you chose to send.

Voice input

On plans where voice is enabled, audio is recorded locally in the browser, encoded, and sent to the backend for transcription before your question is processed. We do not retain raw audio after transcription unless we state otherwise in product settings.

Technical data

Our servers may log IP address, request timestamps, HTTP status codes, and error messages for security and rate limiting. Redis may hold short-lived OAuth state and exchange codes.

How we use data

  • Authenticate you and enforce plan limits.
  • Send your question and page context to the configured LLM provider (e.g. OpenRouter) to generate an answer.
  • Send transactional email (verification, password reset) when email is configured.
  • Operate, secure, and debug the service.

Where data goes

Page content and questions are processed on Tabwise infrastructure. We forward prompts to third-party model providers (such as OpenRouter) under their terms. We act as processor for account and usage data tied to your subscription.

Retention

Account records persist until you delete your account. Page content sent with a question is not stored as a permanent archive by default—it exists in memory and provider logs only for the duration needed to answer. Server logs may be retained for a limited period for security.

Your choices

  • Use selection or viewport scope instead of the full page when asking.
  • Sign out to clear tokens from the extension; request account deletion by email.

Contact

Privacy questions: [email protected]. For EU/UK requests, include “privacy request” in the subject and the email on your account.