Tab Space

Privacy Policy

How Tab Space handles your data

Last updated: July 30, 2026

This policy applies to the Tab Space apps for Mac, iPhone, and iPad; their browser extensions; the Tab Space dashboard; and the public website at mytab.space.

Information stored by the apps

Saved sessions can include page titles, URLs, tags, timestamps, and the names you give your sessions. This information is stored in a native app database on your device. Tab Space does not require an account operated by the developer.

If you enable iCloud, Apple CloudKit syncs your sessions through the Apple Account signed in on your devices. The developer does not receive or have access to the contents of your iCloud database. Apple's handling of that data is governed by Apple's Privacy Policy and your iCloud settings.

Browser extension access

Safari may warn that the extension can read information on webpages because Tab Space provides shortcuts and tab-management actions on the pages you visit. To perform actions you request, the extension may process page titles, URLs, and Safari tab or window state. It processes selected text only when you invoke a feature that uses that selection. This processing happens on your device and is not sent to the developer.

The companion extensions for Chrome, Microsoft Edge, and Firefox request access to open tabs and local extension storage. When you ask Tab Space to save or restore tabs, they process tab titles, URLs, and tab or window state. They do not read the body of the webpages you visit. Browser-local storage holds a random client identifier and an issued authentication token.

The dashboard at app.mytab.space communicates with the installed browser extension to display and edit your sessions. On Mac, companion extensions connect to the Tab Space background helper only through the local loopback interface after a one-time pairing step; the matching credential is kept in the Mac Keychain. The helper keeps the shared CloudKit container active so it can relay iCloud session changes to connected browsers. Session content is used on your device for these purposes and is not uploaded to servers operated by the developer.

Optional AI organizing

AI organizing is off until you turn it on. Before the first AI request, Tab Space shows you what would be sent, who receives it, and how it affects your weekly allowance, and asks you to agree. Nothing is sent unless you do, and turning AI off again in Settings stops it. Automatic AI naming of newly saved sessions is a separate switch that is also off by default.

Every plan includes a weekly allowance of AI requests, and a Tab Space Pro subscription removes that limit. To perform the requested operation, Tab Space sends the selected session name, tab titles and URLs, existing tags, and relevant tag preferences to the Tab Space AI service hosted on Cloudflare. Tab Space does not send webpage body content, cookies, passwords, or your complete browsing history.

Each request carries a random account identifier, used only to count your usage against the weekly allowance. If your device supplies Apple-signed transaction information, the service verifies it and lifts the weekly limit for an active App Store Pro subscription; requests without a verified subscription are still served within the allowance. The service then forwards the minimum request content to Google Gemini as the primary model provider or Cloudflare Workers AI as a fallback. Those providers process the content to return an organizing result. Their handling is governed by Google's Privacy Policy and Cloudflare's Privacy Policy.

The developer does not intentionally store AI request content or model output on the AI service, and content logging is disabled. Requests are processed transiently; infrastructure providers may retain limited security and abuse-prevention records under their own policies. The returned title, tags, or grouping are stored only in your app after you accept or apply them and may then sync through your iCloud. You can delete those results by editing or deleting the affected sessions. Because the service keeps no developer-operated copy of request content, there is no separate server copy for the developer to retrieve or delete.

Backups, retention, and deletion

Sessions remain in the app until you delete them. Items in Trash remain there until they are permanently deleted. Automatic backups are stored in the app's local container and rotated using the app's hourly, daily, weekly, and monthly retention schedule. If iCloud sync is enabled, session changes and deletions are synchronized through CloudKit and may remain in Apple's systems according to Apple's retention practices.

Because the developer does not operate a Tab Space account or receive your session database, the developer cannot retrieve or delete that data for you. You can manage local data in the app, remove the app and its data through the operating system, and manage iCloud data through your Apple Account settings.

Website icons

To show a recognizable icon next to a saved tab, Tab Space requests that site's icon. The Safari extension's tab list requests icons from Google's public favicon service, which means the domain name of that tab (for example example.com) is sent to Google, without the full URL, the page title, or any account identifier. Google's handling is governed by Google's Privacy Policy. Elsewhere Tab Space requests the icon directly from the site itself, which means the site's own server sees that request. Icons are cached on your device.

Data the developer does not collect

Except for the specific session information you choose to submit to optional AI organizing, the Tab Space apps do not send the developer your saved sessions, browsing history, page contents, iCloud records, contacts, location, or advertising identifiers. The apps contain no advertising or developer-run behavioral tracking.

Public website analytics

The public marketing pages on mytab.space use Cloudflare Web Analytics to understand aggregate website usage and performance. It reports metrics such as page visits, referrers, general browser, device, operating system, and country information, page-load timing, and Core Web Vitals. Its analytics beacon does not use cookies or local storage, fingerprint visitors, or track individuals across websites. Website analytics is separate from the Tab Space apps and never includes your saved sessions. We do not combine it with app data or use it for advertising. Learn more in the Cloudflare Web Analytics documentation.

Children's privacy

Tab Space does not knowingly collect personal information from children.

Changes and contact

We may update this policy when Tab Space's features or data practices change. The date above identifies the latest revision. For privacy questions, contact support@mytab.space.


隐私政策

Tab Space 如何处理你的数据

最后更新:2026 年 7 月 30 日

本政策适用于 Mac、iPhone 和 iPad 版 Tab Space、相应的浏览器扩展、Tab Space Dashboard, 以及 mytab.space 官网。

App 保存的信息

保存的会话可能包含网页标题、URL、标签、时间以及你为会话设置的名称。这些信息保存在设备上的原生 App 数据库中。Tab Space 不要求注册由开发者运营的账号。

如果你启用 iCloud,Apple CloudKit 会通过设备上登录的 Apple 账户同步会话。开发者不会收到、也无法访问你的 iCloud 数据库内容。Apple 对这些数据的处理受 Apple 隐私政策 和你的 iCloud 设置约束。

浏览器扩展访问权限

Safari 可能提示扩展能够读取网页信息,这是因为 Tab Space 会在你访问的页面上提供快捷键和标签页管理操作。 为执行你主动触发的操作,扩展可能在设备上处理网页标题、URL 以及 Safari 标签页或窗口状态;只有在你调用相关功能时, 才会处理选中的文字。这些处理在设备本地完成,不会发送给开发者。

Chrome、Microsoft Edge 和 Firefox 配套扩展会申请访问已打开标签页和扩展本地存储。只有在你要求 Tab Space 保存或恢复标签页时,扩展才会处理标题、URL 以及标签页或窗口状态;它们不会读取网页正文。 扩展本地存储只保存随机客户端标识和 App 签发的认证令牌。

app.mytab.space 上的 Dashboard 会与已安装的浏览器扩展通信, 用于显示和编辑会话。在 Mac 上,配套扩展完成一次性配对后,只通过本机回环接口连接 Tab Space 后台 Helper; 对应凭据保存在 Mac 钥匙串中。Helper 会保持共享 CloudKit 容器运行,并把 iCloud 会话变化通知给已连接的浏览器。 会话内容只在你的设备上用于这些功能,不会上传到开发者运营的服务器。

可选的 AI 整理

AI 整理默认关闭,需由你主动开启。在发出第一次 AI 请求之前,Tab Space 会明确告知将要发送的内容、 接收方以及对每周额度的影响,并请你确认。未经确认不会发送任何内容;在设置中重新关闭 AI 即可停止发送。 保存标签页后自动用 AI 命名会话是一个单独的开关,同样默认关闭。

所有档位每周都包含一定次数的 AI 请求额度,订阅 Tab Space Pro 可解除该限制。为完成所选操作, Tab Space 会把所选会话名称、标签页标题和 URL、已有标签及相关标签偏好发送到托管在 Cloudflare 上的 Tab Space AI 服务。Tab Space 不会发送网页正文、Cookie、密码或你的完整浏览历史。

每次请求都会附带一个随机账号标识,仅用于统计你在每周额度内的使用次数。如果你的设备提供了 Apple 签名的交易信息,该服务会进行验证,并为有效的 App Store Pro 订阅解除每周限制; 未通过订阅验证的请求仍会在额度范围内正常处理。随后该服务会把完成请求所需的最少内容转发给 主要模型提供方 Google Gemini,或在需要时使用 Cloudflare Workers AI 作为备用。相关数据处理受 Google 隐私政策Cloudflare 隐私政策 约束。

开发者不会在 AI 服务中主动保存 AI 请求内容或模型输出,并已关闭内容日志。请求只做临时处理; 基础设施提供方可能依其政策保留有限的安全与防滥用记录。返回的标题、标签或分组只有在你接受或应用后才会保存到 App 中,并可能通过你的 iCloud 同步。你可以通过编辑或删除相关会话来删除这些结果。由于服务不保留由开发者运营的 请求内容副本,因此没有另一份服务器副本可供开发者读取或删除。

备份、保留与删除

会话会一直保留到你将其删除;废纸篓中的项目会保留到被永久删除。自动备份保存在 App 的本地容器中, 并按照小时、天、周、月的保留计划轮换。如果启用了 iCloud,同步和删除操作会通过 CloudKit 传播; Apple 可能依照其保留政策在系统中保留相关数据。

由于开发者不运营 Tab Space 账号,也不会收到你的会话数据库,因此无法代你读取或删除这些数据。 你可以在 App 中管理本地数据、通过操作系统移除 App 及其数据,并在 Apple 账户设置中管理 iCloud 数据。

网站图标

为了在已保存的标签页旁显示可识别的网站图标,Tab Space 会请求该网站的图标。Safari 扩展的标签页列表 使用 Google 的公共 favicon 服务,因此该标签页的域名(例如 example.com)会被发送给 Google, 但不包含完整 URL、页面标题或任何账号标识。Google 的数据处理受 Google 隐私政策约束。 在其他位置,Tab Space 会直接向网站本身请求图标,因此该网站的服务器会看到这次请求。图标会缓存在你的设备上。

开发者不收集的数据

除你主动提交给可选 AI 整理功能的特定会话信息外,Tab Space App 不会向开发者发送你保存的会话、 浏览历史、网页内容、iCloud 记录、通讯录、位置或广告标识符。App 不包含广告,也不进行由开发者运营的行为追踪。

官网分析

mytab.space 的公开营销页面使用 Cloudflare Web Analytics 了解整体访问情况和页面性能。它会报告页面访问、来源、 浏览器、设备、操作系统和国家或地区等一般信息,以及页面加载时间和 Core Web Vitals。其分析信标不使用 Cookie 或本地存储,不对访客进行指纹识别,也不跨网站追踪个人。网站分析与 Tab Space App 相互独立,绝不包含你保存的会话。 我们不会把网站分析与 App 数据结合,也不会将其用于广告。详情请参阅 Cloudflare Web Analytics 文档

儿童隐私

Tab Space 不会有意收集儿童的个人信息。

政策变更与联系

当 Tab Space 的功能或数据处理方式发生变化时,我们可能更新本政策。页面顶部日期表示最近一次修订时间。 如有隐私问题,请联系 support@mytab.space