Privacy Policy — TabWay (Chrome Extension)
Effective date: 2026-09-11
TabWay is a browser extension for Chrome that helps you find, organize, and stash your open tabs in Chrome's side panel, and — entirely optionally — lets you hand a question or prompt to the AI service you choose. This policy explains what data the extension processes, how it is used, what it never does, and the controls you have.
1. Summary
- TabWay has no servers of its own. We never receive, store, proxy, or analyze your data.
- TabWay requests no site access at install time. Site access is optional and granted by you, per site, through Chrome's own permission prompts when a feature needs it — and you can revoke it at any time.
- Tab management never reads the content of your web pages.
- The optional "Ask" feature reads page text only from pages you explicitly choose as sources, and sends it — together with your question — directly from your browser to the AI provider you selected, using your own API key.
- The optional "Send to web AI" feature forwards only your prompt — the page's title and URL, filled into your editable prompt template — into the AI website you picked.
- No analytics, no tracking, no advertising, no sale of data, no remote code.
- Your saved data syncs through your own Chrome account (
chrome.storage.sync), not through any TabWay account or service. - Incognito windows are not supported.
2. Data the extension processes
2.1 Tab metadata (browser "web history" data)
When you use TabWay's tab management, the extension reads metadata of tabs open in your Chrome windows: page title, URL, domain, tab position and order, active state, pinned/muted/discard state, and last-access time (as provided by Chrome). This is used to display, search, and filter your tabs, and to act on tabs strictly at your direction (activate, pin, mute, discard, move, close, group, stash, restore, park, or switch workspaces).
TabWay does not use Chrome's history API and does not build or keep a browsing-history database. Tab metadata is read from your currently open tabs only.
2.2 Content you create (read later, workspaces, settings)
Items you save — read-later entries (title, URL, domain, save time, completion state), workspace definitions (names, emoji icons, colors, and saved tab lists used for restoring), and your settings — are stored locally using Chrome's storage APIs. Saved items sync across your own signed-in devices via chrome.storage.sync, which requires you to be signed in to Chrome with sync enabled. We never see this data.
Sync also uses technical record identifiers, update timestamps, and deletion markers so that your devices stay consistent.
2.3 Ask My Tab (optional AI feature — "website content")
The Ask feature does nothing until you configure it and select sources.
- Site access is optional and runtime-granted. The first time you add a page as a source, Chrome itself shows a permission prompt asking whether to allow access to that specific site. TabWay can only read pages on origins you have granted. You can revoke access at any time in Chrome's extension settings ("Site access"); choosing "on all sites" there is a Chrome setting you control, not a TabWay request.
- You may explicitly add up to three (3) open pages as sources. Each time, only on your explicit action (adding or refreshing a source), the extension injects a one-shot extraction script into a tab on an origin you have granted. The extractor reads readable page text — section structure and plain text — and excludes forms, input fields, buttons, editable regions, scripts, styles, and templates. It never reads form values, editor drafts, cookies, login tokens, scroll positions, raw HTML, or page runtime state, and it never runs automatically in the background.
- When you send a question, the extension sends your question, the necessary conversation context, and — for pages you selected as sources — their title, URL, and extracted text (in full within a character budget, otherwise as consecutive excerpts) directly from your browser to the AI provider you selected.
- With no sources selected, only the conversation itself (system prompt, context, your question) is sent. No page content, titles, or URLs are included.
- Supported cloud providers: OpenAI, Anthropic, Google Gemini, DeepSeek, OpenRouter, Alibaba Cloud DashScope (Qwen), Zhipu GLM, Moonshot Kimi, MiniMax, SiliconFlow, and any custom OpenAI-compatible endpoint you configure. When you connect a provider — especially a custom endpoint — Chrome may prompt you to allow access to that provider's API domain; requests then go over HTTPS directly to that endpoint.
- TabWay cannot see these requests: there is no TabWay server, no proxy, no remote embedding, and no remote analytics in this data path.
- Each provider's handling of your data is governed by your relationship and agreement with that provider. TabWay displays which provider/model is selected so you always know the destination.
- YouTube video pages are treated like any ordinary page (readable page text such as title and description); TabWay does not fetch video subtitles.
- Page content is treated as untrusted data: it cannot change TabWay's permissions, read other pages, or trigger actions in your browser.
2.4 Send to web AI (optional)
TabWay can hand a prompt to the web app of an AI service you enable: ChatGPT and Claude (the prompt is placed in the URL when the tab opens), and the web apps of DeepSeek, Kimi, Grok, and Gemini (the site is opened, and after you grant that site's permission, a one-shot script inserts your prompt into the site's message input box — if that fails, the prompt is copied to your clipboard as a fallback).
- What is sent: your prompt only — the title and URL of the tab you used the feature on, filled into a prompt template you can edit in Settings. TabWay does not read any other page content for this feature, does not read the AI website's content or the AI's replies, and does not log these prompts.
- The subsequent conversation happens entirely on the provider's website and is governed by that website's own terms and privacy policy.
2.5 API keys ("authentication information")
If you use the Ask feature, you provide your own API key for the provider you selected. Keys are stored locally as an encrypted envelope (chrome.storage.local); the encryption key is randomly generated on your device and its unlock material is kept only in session memory. Your API key never enters Chrome Sync, exports, logs, or page contexts. You can remove or reset stored keys at any time in Settings.
2.6 Ask session data
Ask conversations, page snapshots, extracted text blocks, and local search indexes are kept only in chrome.storage.session — they are not synced to your Chrome account and not included in exports. They are deleted when the browser session ends, when the extension updates, or when you delete them. A maximum of 30 recent sessions is kept, and older snapshots/sessions are removed as space limits are reached. Ask data is not used to train any model.
3. What TabWay never does
- Does not send anything to TabWay developers — there are no developer servers, model proxies, remote embedding services, or analytics SDKs.
- Does not request site access at install time; all site access is optional, runtime-granted, and revocable.
- Does not sell your data, and does not share or transfer it for advertising or any purpose unrelated to the extension's single purpose.
- Does not use the Chrome history API.
- Does not read page content unless you explicitly select that page as an Ask source — and then only one-shot, on demand, on sites whose access you granted in Chrome's permission prompt.
- Does not read the content of the AI websites that "Send to web AI" hands your prompt to.
- Does not read or store form values, input fields, editor drafts, cookies, login tokens, scroll positions, raw HTML, or page runtime state.
- Does not automatically close, move, or remind about tabs based on age; filters and decisions are always user-initiated.
- Does not run in Incognito mode (declared in the manifest).
4. Limited Use disclosure
TabWay's use of data received from Chrome APIs and from pages you explicitly select complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used only to provide and improve TabWay's single user-facing purpose described above. We do not sell user data to third parties; we do not use or transfer user data for purposes unrelated to TabWay's single purpose — except transmissions you explicitly direct (sending your selected page text and your question to the AI provider you chose, or your prompt to the AI web app you chose); and we do not use or transfer user data to determine creditworthiness or for lending purposes.
5. Data retention, deletion, and your controls
You are always in control of your data:
- Delete items: remove read-later entries (individually or in bulk, including clearing completed items), delete workspaces, and delete Ask sessions individually at any time in the extension UI.
- Export / import: export your read-later and workspace data as a file and re-import it into a clean installation. Ask session data is intentionally excluded from exports.
- Reset API keys and providers: delete or replace stored provider keys, and remove configured providers, at any time in Settings.
- Revoke site access: at any time in Chrome's extension settings ("Site access"), per site or globally.
- Sync: data saved via
chrome.storage.syncis tied to your own Chrome account. Turning off Chrome Sync, signing out, or deleting the extension's synced data through Chrome affects it accordingly. Deleting the extension removes its locally stored data; synced data is managed through your Google account's sync settings.
Failed saves are handled safely: a tab is only closed after its data has been saved successfully.
6. Permissions
- sidePanel — displays TabWay's interface in Chrome's Side Panel.
- tabs — reads titles, URLs, domains, and order of your open tabs; activates, pins, mutes, discards, moves, closes, or groups tabs when you ask.
- tabGroups — creates and manages native Chrome tab groups you create in TabWay.
- storage — saves your read-later items, workspaces, settings, and encrypted API keys locally; syncs user-saved items via your Chrome account.
- scripting and optional http/https site access — allow one-shot, on-demand scripts to run in a tab on a site whose access you granted via Chrome's permission prompt. This happens only when you: add or refresh a tab as an Ask source, send a prompt to an AI web app you enabled, or connect to a cloud provider's API endpoint. TabWay requests no site access at install time. No static content scripts are registered; no page is read in the background; restricted pages (chrome://, file://, Chrome Web Store) are never accessed.
7. Security
All network requests made by the Ask feature use HTTPS directly to the provider you selected. Your API key is stored encrypted at rest. TabWay stores everything on your device (or your own Chrome account's sync); there is no TabWay infrastructure that could be breached.
8. Children
TabWay is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect such data.
9. Changes to this policy
If TabWay's data handling ever changes, we will update this policy at this URL before the corresponding extension update ships, and reflect the change in the Chrome Web Store listing disclosures. Users will be informed of material changes through the store listing and, where appropriate, in-app notices.
10. Contact
Questions or requests about this policy or your data:
Email: smengchao@gmail.com