Legal
Privacy Policy
Effective date: July 22, 2026 · Last updated: July 26, 2026
This Policy explains how TabTar processes information when you visit tabtar.com, use the TabTar desktop App, purchase or activate a license, or contact us.
TabTar is designed as a local-first browser Context and Clipboard manager. Most content remains on your device unless you explicitly use a feature that communicates with a third party.
1. Information stored locally by the App
TabTar may store the following information in an App-managed SQLite database on your device:
- saved Contexts, including page titles, sanitized URLs, selected Page Tags, mnemonic tags, categories, timestamps, and local screenshot metadata;
- textual Clipboard history, including text, timestamps, formats, and occurrence counts;
- App settings, interface language, organization history, trial timestamps, and activation state;
- model name and endpoint settings; and
- a signed activation receipt and the email address used to activate the App.
TabTar keeps every Clipboard item last seen within the previous 90 days, plus up to 10,000 of the most recent older items. Clipboard text, Context data, and a saved model API key are stored as plaintext in the local SQLite database. TabTar restricts its local runtime files to the current operating-system user but does not encrypt this database.
Local data remains until you delete it through TabTar or remove the App data yourself. Uninstalling the App may not automatically remove its data directory.
2. Page and Clipboard capture
TabTar observes textual Clipboard content while the App is running unless Clipboard capture is paused. It cannot recover Clipboard history created before TabTar started.
Page capture begins only when you explicitly start Create Context. TabTar reads the foreground Chrome or Safari page identity, removes URL credentials and sensitive URL parameters, and may save one screenshot of that exact browser window. It does not inspect the page DOM or form fields. You should still review captured information before confirming it.
Page screenshots are stored as local plaintext image files with access restricted to the current operating-system user.
TabTar does not silently upload Contexts or Clipboard history to TabTar servers.
3. User-provided model endpoints
TabTar contacts a model endpoint only when you configure an OpenAI-compatible endpoint and explicitly test it or start AI Content Organization.
A connection test sends an authenticated request to the configured endpoint's /models route. AI Content Organization may send Context identifiers, display names, page titles, sanitized URL hostnames and paths, selected Page Tags, and mnemonic tags to the configured endpoint.
Clipboard text, page screenshots, and legacy form data are not sent for AI organization. The API key is sent only in the authorization header to the endpoint you selected and is not included in organization content or App logs.
The endpoint operator processes these requests under its own privacy policy and terms. You are responsible for selecting and trusting that provider.
4. Website, purchase, and activation information
When you visit the website or use online features, TabTar and its infrastructure providers may process network and technical information such as IP address, browser or device information, request timestamps, security signals, rate-limit data, and error information.
When you purchase, redeem a gift code, or activate TabTar, we may process:
- your email address and selected payment method;
- currency, amount, order status, and timestamps;
- provider checkout, order, payment, refund, or dispute identifiers;
- license status and activation attempts; and
- gift-code batch, availability or redemption status, a short code hint, the bound email address, and redemption timestamps; and
- activation-email delivery status, attempts, provider message identifiers, and limited delivery errors.
The gift-code and activation services process the email address and code you submit. The server stores cryptographic digests rather than plaintext gift or activation codes.
Full card details and WeChat payment credentials are entered with the payment provider and are not received or stored by TabTar.
The homepage loads a Product Hunt badge image from api.producthunt.com. Product Hunt may receive standard request information such as your IP address, browser or device information, and request timestamp; the badge image is requested without a referrer.
5. Support communications
If you contact service@tabtar.com, we process your sender address, message, attachments, and related delivery metadata. Support email may be routed through Cloudflare and delivered to a separate mailbox provider used by TabTar.
6. How we use information
We use information to:
- provide downloads, purchases, activation, activation-code resend, and support;
- maintain trial and license status;
- confirm payments, handle refunds or disputes, and prevent duplicate purchases;
- protect the website and APIs against abuse, fraud, and unauthorized access;
- deliver transactional activation emails;
- diagnose failures and improve reliability; and
- comply with legal, tax, accounting, and regulatory obligations.
We do not sell personal information or use App content for advertising.
7. Service providers and disclosure
We may disclose limited information when necessary to:
- Cloudflare for website hosting, data storage, security, rate limiting, email sending, and email routing;
- Creem for international card checkout;
- ZPay and its connected payment channel for WeChat Pay;
- Product Hunt for the homepage launch badge and linked TabTar listing;
- the model endpoint that you configure;
- email and support-service providers; and
- regulators, courts, law enforcement, or other parties when required by law or necessary to protect legal rights.
These providers process information under their own terms and privacy policies.
8. Retention
Local App content is retained on your device until you delete it. Clipboard history follows the rolling 90-day and 10,000-item older-history policy described above.
Purchase, gift-code redemption, payment-event, license, activation, email-delivery, security, and support records are retained for as long as reasonably necessary to provide the license, handle support and disputes, prevent fraud, and meet legal, tax, or accounting obligations. We may keep records that applicable law requires us to retain even after a deletion request.
9. Security
We use reasonable safeguards such as HTTPS, restricted infrastructure bindings, signed payment webhooks, rate limiting, private local runtime file permissions, hashed activation codes, and signed activation receipts.
No storage or transmission method is completely secure. You are responsible for protecting your device, email account, activation code, model credentials, and local backups.
10. Your choices and rights
You can pause Clipboard capture for the current App session, delete Clipboard records, clear saved Clipboard history, edit or delete Contexts, and remove local App data.
Depending on applicable law, you may request access to, correction of, or deletion of personal information processed by TabTar, or object to or restrict certain processing. Contact service@tabtar.com to make a request. We may need to verify your request and may retain information where legally required.
11. International processing
Cloud infrastructure, payment providers, email providers, and a model endpoint selected by you may process information in countries or regions other than your own. Their processing is governed by their own policies and applicable safeguards.
12. Children
TabTar is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can take appropriate action.
13. Changes and contact
We may update this Policy to reflect changes to TabTar, our providers, or legal requirements. We will publish the updated Policy with a revised effective date.
For privacy questions or requests, email service@tabtar.com.