Tabosmart privacy policy
Effective date: 8 September 2026. Extension version: 1.5.0.
Publisher: Saulius Petreikis. Privacy contact: saulius.developer@gmail.com. This policy covers the Tabosmart extension, its website and voluntary feedback links.
Tabosmart reviews open tabs and available browsing history to suggest ways to organize tabs. Processing and records stay in your browser profile. There is no Tabosmart account, analytics service, advertising service or cloud-AI fallback.
When processing starts
Chrome grants the required tabs, tabGroups, storage, alarms, history and favicon permissions through its normal installation or update process. On a fresh installation without stored Tabosmart state, local tab observation and history analysis start automatically. The workspace shows a nonblocking explanation of this processing. There is no additional onboarding or optional-history permission prompt.
Existing paused or erased states remain paused. Settings & privacy lets you pause observation, turn history insights off, turn optional AI off, or erase Tabosmart data. Dismissing the informational disclosure does not change those settings. Chrome controls whether an installation or update requires another browser permission notice.
Open-tab information
While observation is enabled, Tabosmart reads the titles and exact URLs of regular HTTP and HTTPS tabs, observed first-seen and active times, activation counts, patterns of switching between tabs, and opening relationships supplied by tab-creation events. It queries current native group names and memberships to offer reviewed additions. It uses whether tabs are active, pinned, audible, protected or grouped. Browser tab events are coalesced, and local maintenance runs approximately every 15 minutes. Chrome can suspend workers or delay alarms during sleep.
Tabosmart keeps its own exact-URL use record, including URLs from observed tabs that later close. It also stores current-tab observations, temporary restart context, cached tab/suggestion views and check summaries, settings and AI preference provenance, protected URLs, dismissal fingerprints, saved links and recoverable URLs. These records use extension local storage, not Chrome storage sync. Opening/closing the workspace also uses bounded browser-session tab/window IDs to return to browsing.
Saved for later is an extension-local shelf. It is separate from Chrome bookmarks. Tabosmart does not read page bodies, forms, website storage, passwords, cookies, bookmarks, microphone data or Incognito tabs.
Opening context and grouping choices
Local grouping context stores captured source and child URLs/IDs and opening times, including exact search queries in source URLs; observed activation periods containing exact URLs and times; and names/URL memberships from groups successfully confirmed through Tabosmart. Specific resource keys are derived from those URLs. It does not infer old opening events from restored tabs or import history titles into this context. Source queries are not displayed in suggestion reasons or sent to the naming/discovery model.
Available browsing history
History insights analyze all history available through Chrome's history API, rather than only a recent sample. Initial analysis uses resumable time ranges and retrieves the visits Chrome retains for each URL. New visits and maintenance trigger incremental updates, and periodic full refreshes reconcile the index. Chrome controls availability and retention; deleted, Incognito or otherwise unavailable records cannot be analyzed. The API may include visits synced from another device and non-web URLs such as file, chrome or ftp URLs if Chrome returns them. Only exact matches to current HTTP(S) tabs contribute to suggestions.
The extension temporarily receives history URLs, titles and visit records from Chrome while processing. It retains only a SHA-256 identifier of the exact URL and aggregate evidence in local IndexedDB: visit count, recent visit count, last retained visit time, Chrome's aggregate visit count and analysis time. It also stores progress counters, synchronization times and remaining time ranges so work can resume after worker suspension. Raw history URLs, history titles and individual visit lists are not retained in this index.
Tabosmart matches current open-tab URLs against these identifiers. Visit recency and recent frequency help order comparable suggestions. They do not prove importance, attention, continuous tab age or whether a page is safe to close. These history records are separate from the exact URLs and titles needed for open-tab views, observed URL use, saved links and recovery.
URL hashes are not anonymous and are not encryption. Someone who knows or guesses a URL can compare its digest. Local records are not an encrypted vault or a backup.
Optional Local AI
Core names, suggestions and measured explanations work without AI. Optional assistance defaults on for a fresh or missing preference. Explicit choices are preserved; older saved off values stay off even when their origin is unknown. You can turn AI off in Settings & privacy.
An on preference does not mean the model is ready or silently request a download. Tabosmart's setup controls explain that Chrome may need to download a model. Setup starts through a user gesture. Availability depends on the browser, device, model and supported language.
Initial groups use specific URL resources, Unicode title words, explicit category vocabulary, opening context, recorded usage periods and confirmed grouping choices. Existing-group matches use the current members as evidence. Optional AI can discover additional relationships from up to 24 eligible current titles/domains and bounded observed-use context per request. Every member needs an exact informative title quote; relationships are labeled inferred for review. The selected naming language is stored as a preference. No publisher-domain catalog, page fetch or Translation API is used. Deterministic category matching uses a small multilingual vocabulary; this is separate from the optional model. Titles are capped at 160 characters and domains at 253; raw URL paths/queries, browser-history titles/visit lists and page content are excluded from model input. Existing names use at most ten automatic naming attempts per workspace. Discovery continues in separate bounded automatic passes with caching, cancellation and backoff, including nominated cross-batch comparisons. Opening a review and editing a name protect that choice. Recalled user names and existing native names are excluded from automatic AI naming.
Optional explanation assistance selects only approved equivalent phrasings of measured facts. Invalid or failed output keeps the original explanation. Inferred topic proposals retain their quoted-evidence reason. AI cannot approve or perform tab actions. Discovery inputs, results and semantic hints remain in interface/worker memory; generated proposals are excluded from persisted cached snapshots and reset when relevant metadata changes. Discovery limits and scheduling (MULTILINGUAL-GROUPING.md)
Titles and measured reasons may contain personal information. According to Chrome's built-in AI documentation (https://developer.chrome.com/docs/ai/get-started), model inference runs locally without sending its input to Google or another party. Tabosmart has no remote fallback. Availability, setup outcome and individual request outcome are separate. Workspace AI progress, request results and cached names/wording are held in memory rather than stored as persistent AI records.
Closing the workspace ends its local session and progress reporting. Chrome documents that an already triggered model download continues after its initiating tab closes. Reopening checks actual availability; Tabosmart does not claim unseen progress or successful inference. Turning AI off or erasing Tabosmart data does not uninstall Chrome's model. Chrome model management (https://developer.chrome.com/docs/ai/understand-built-in-model-management#initial_model_download)
Use and sharing
Records are used for the disclosed tab-management features: showing and ordering suggestions, explaining measured reasons, carrying out selected actions, remembering choices and reopening saved/recoverable URLs. Tabosmart does not upload browsing records to the developer, advertisers or an AI provider, sell them, or use them for advertising, lending or credit decisions. The developer has no server-side access to the local records.
Opening or restoring a URL loads that website normally under its own practices. Chrome extension updates and model downloads are controlled by the browser and its provider. This policy does not claim that Chrome has no network activity.
Retention and deletion
The browser-history aggregate index has no arbitrary recent-history cutoff or fixed URL-count cap. It follows the history exposed by Chrome, subject to successful processing and browser storage capacity. A completed full refresh removes aggregates no longer present. A Chrome history-removal event clears the derived index and rebuilds it if active. Errors or a stopped browser can delay reconciliation. Raw history records are temporary, not an archival history copy.
Turning History insights off erases that derived index and checkpoint. Pausing observation stops new tab observation and history processing while keeping existing data and history checkpoints. Resuming restarts processing and gives tab inactivity review a fresh baseline. Deleting Chrome history does not itself delete saved links, recovery entries or Tabosmart's separate observed-tab records; erase those through Tabosmart when wanted.
The separate observed-URL history holds up to 2,000 exact URLs. Records unseen in an open tab for over 90 days are removed when Tabosmart next processes its local records, which can be later while Chrome or the extension is off. Current-session observations cap at 2,000. Up to 1,000 co-use pairs expire after 30 days at the next enabled observation and are removed when a member closes or changes URL. Temporary window-closing context caps at 2,000 records and 90 days, is consumed at the next session and cleared on resume after pause.
Grouping context holds up to 256 opening relationships for one day, 128 completed browsing periods for thirty days, eight unfinished window periods, and 64 confirmed choices for ninety days. A choice holds at most 200 unique URLs; larger choices are not partially learned. A browsing period exceeding twelve distinct URLs is not learned as a truncated set. The entire context is capped at 300,000 serialized UTF-16 characters. Actual storage bytes may differ. Worker restarts preserve validated current-session observations. A new browser session or pause clears opening relationships and unfinished periods; completed periods and confirmed choices retain their bounded lifetime. Expiry is applied when processing or hydration resumes, so stopping Chrome can delay deletion.
After restart, current tab identities and ages begin fresh. An unambiguous exact-URL match in the first populated startup check can reuse previous review evidence after a five-minute grace period. This does not prove the same tab or page stayed open. New, navigated, ambiguous and later-restored tabs receive fresh review eligibility.
Dismissal fingerprints remain until erasure or the 1,500-entry limit. Exact-URL protections apply to every matching copy until removed or erased. Shelf and recovery each hold up to 100 batches and 1,000 URLs until forgotten, erased or uninstalled. A full shelf/recovery list causes a corresponding new operation to be refused rather than silently losing recovery.
Serialized local records have an 8 MiB budget, below Chrome's local-storage quota. Saved links, Recovery and protected URLs share a 4 MiB growth limit; long URLs can reach it before the entry-count limits. Existing saved or protected URLs are never automatically evicted to make room. New additions are refused when the limit is reached. Disposable observation, URL-use, restart, pair, activation and dismissal maps can be pruned earlier under byte limits, retaining recent evidence first. Large cached views may stay only in memory and are rebuilt after a worker restart.
Erase Tabosmart data clears its local tab records, history index and checkpoints, shelf, recovery, protections, dismissals, opening/usage/grouping-choice context and workspace-owned AI caches/pending work. Observation stays off and history insights are disabled until you choose to resume them. Local-record erasure is persisted independently of history-index cleanup; if that cleanup fails, the interface reports it and you can retry erasure. Erasure does not close open tabs, undo native groups, delete Chrome's history or remove its model. Uninstalling removes extension storage. The fresh default AI preference after reset does not restart observation or create a model.
Recovery only reopens stored URLs. It cannot restore unsaved edits, forms, login state or exact page contents. Anyone with access to an unlocked browser profile may be able to inspect locally stored information.
Limited use and contact
Tabosmart uses handled information only for the tab-management features described here, with no unrelated data sale, advertising or creditworthiness use. The extension uses browsing information only to provide and improve the tab-management features described here. It does not transfer browsing records to the publisher or third parties.
Publisher and privacy contact: Saulius Petreikis, saulius.developer@gmail.com.
Website and voluntary feedback
The Tabosmart website does not request or receive your browsing history or extension records. It has no analytics scripts. Its hosting provider may process normal request information, such as IP addresses and request logs, to serve and secure the website. Videos are served directly without a YouTube embed.
Feedback buttons open https://tabosmart.featurebase.app/ in a separate tab. Nothing from your open tabs, history, settings or local AI prompts is attached to that link. If you choose to post feedback, Featurebase processes the account information and content you provide under its own privacy policy. Public posts can be seen by others. Do not include private URLs, personal browsing history or sensitive screenshots. Contact the publisher by email for private concerns; email providers process those messages.
### Website icons
Website favicons are read from Chrome’s local favicon store using the narrow `favicon` permission. This helps identify tabs in suggestions, reviews, saved URLs and recovery. Tabosmart does not contact an external icon service or request access to website content. If Chrome has no icon, a neutral website icon is shown.