Privacy Policy
Last updated August 5, 2026
Privacy Policy
This Privacy Policy describes how InTab (“we”, “us”, “our”) handles information when you use the InTab Chrome extension and the website at intab.io (together, the “Service”). InTab is built and operated by Zoy.
We designed InTab to do as much as possible on your device. We do not collect your browsing history, the content of pages you visit, what you type, your selected text, your files, or your messages.
1. What we collect
We collect only what we need to keep InTab working and to understand which features are useful.
On your device, never sent to us:
- Your preferences (theme, language, layout, widgets, enabled features).
- Saved tab sessions, notes, highlights, and reminders you create.
- AI chat history with third-party providers (see Section 4).
- Caches (e.g. YouTube transcripts you summarized).
All of the above is stored locally with chrome.storage.local or browser local storage. You can delete individual items wherever you created them, restore every setting to its default from Options → General → Reset all settings, and remove everything at once by uninstalling the extension.
Sent to us only if you keep analytics on (default ON, one-click off):
- An anonymous random identifier generated on first run.
- Your extension version and browser version.
- Coarse country (derived from your IP via a third-party geo lookup; your IP is not stored).
- Feature-usage event names - for example,
task_created,summarize_completed,tab_saved. We never send URLs, page content, page titles, file contents, selected text, prompts, AI responses, email addresses, or any free-form text you typed.
Sent to us when you ask InTab to do something:
- The text you select before invoking “Summarize / Translate / Rewrite / Ask” (sent to our AI backend so the model can answer).
- The video ID of a YouTube video you ask InTab to summarize (sent to our backend to fetch the transcript).
- The text you submit to InTab’s text-to-speech (sent to our backend, which proxies ElevenLabs).
- Your dictation audio when you press the microphone button (sent to our backend, which proxies Groq’s speech-to-text). Audio is processed and discarded; it is not stored.
We retain these request payloads only as long as needed to return a response (typically seconds), unless an error log is needed for a short period to diagnose a failure.
2. What we do NOT collect
- Your browsing history. The
historypermission is used on your device to power the “Recently visited” widget and search bar; nothing is uploaded. - Your bookmarks. Same as above - read locally to render the bookmarks widget.
- The content, URLs, or titles of pages you visit.
- The text you type into web forms.
- Cookies from third-party sites (with the narrow exception in Section 5).
- Your real IP address. We use it for a one-time country lookup and then forget it.
- Your name, email, password, payment information, or any contact details unless you create an account on intab.io and provide them yourself.
3. Account data (only if you sign in)
If you create an account on intab.io, we store the email address you signed up with and your Google sign-in identifier (sign-in is via Google - we never see or store a password), plus the saved tabs/notes/lists you choose to sync. You can delete your account at any time from intab.io → Settings → Account, which removes all server-side data within 30 days.
4. Third-party AI providers (logged-in sessions)
InTab’s chat side panel can stream responses from ChatGPT (chatgpt.com), Claude (claude.ai), Gemini (gemini.google.com), and Perplexity (perplexity.ai) using your own browser’s logged-in session at each provider. This works because the extension’s background worker sends requests to those providers with their expected Origin and Referer headers - your existing cookies travel with the request automatically, the same way they would if you were on the provider’s tab.
What this means:
- We never see your provider account credentials. We do not collect, transmit, or store usernames, passwords, OAuth tokens, or session cookies for any third-party provider.
- The conversation you have with the provider goes directly from your browser to the provider and back. It does not pass through our servers.
- The provider’s own privacy policy governs what they do with the messages you send them.
- If you are not logged in at a given provider, that provider simply doesn’t work in InTab. Sign in on the provider’s website to enable it.
When you use InTab’s own AI features (“Summarize”, “Translate”, “Rewrite”, “Ask InTab”, grammar check, YouTube summary, text-to-speech, dictation), the request goes through our Cloudflare Workers backend at intab.io / zoy.io. That backend forwards the request to Groq (text generation, speech-to-text) and ElevenLabs (text-to-speech). We do not retain the request body after the response is returned.
5. Cookies and storage
InTab uses Chrome’s cookies API in two narrow places:
- To read our own session cookie on intab.io / zoy.io so the extension and the website stay signed in to the same account. We never read third-party site cookies for any purpose.
- To set a single YouTube
CONSENTcookie on youtube.com so YouTube’s transcript endpoint will serve transcripts when you ask InTab to summarize a video. This cookie is identical to the one YouTube sets itself for users in cookie-consent regions.
InTab uses Chrome’s chrome.storage.local to keep your preferences and on-device data. It uses chrome.storage.session for short-lived runtime state.
6. Third-party services we rely on
- Cloudflare Workers - hosts our backend API and serves intab.io.
- Cloudflare D1 / KV / R2 / Queues - database, cache, file storage, and background-job queue for account features.
- Groq - AI text generation and speech-to-text for InTab’s own AI features.
- ElevenLabs - text-to-speech for the “Listen” / “Read aloud” feature.
- Google Analytics 4 (Measurement Protocol) - anonymous feature-usage events, sent directly from your browser (only if analytics is on).
- PostHog - anonymous product-analytics events (only if analytics is on).
- AWS SES - transactional emails (welcome, billing, invitations) for account holders only.
- Open-Meteo / wttr.in - weather for the new-tab weather widget.
- OpenStreetMap Nominatim / freeipapi / ipinfo / geojs / ipify / ipwho / ipbase / geoplugin / Cloudflare trace - IP-to-country lookup for the weather and prayer-time widgets. We do not store your IP.
- YouTube / Piped / Invidious - public endpoints used to fetch video transcripts when you ask InTab to summarize a video.
- ChatGPT, Claude, Gemini, Perplexity - only when you use the chat side panel and only via your own logged-in session (see Section 4).
- Paddle - payment processing for paid account features. We never see your full card number.
- Advertising measurement partners (intab.io website only) - Google Ads, Meta (Facebook), Microsoft Advertising, X (Twitter) Ads, TikTok, Snapchat, Pinterest, Reddit, and Quora. When you visit intab.io we load their conversion-measurement tags, and after a purchase or sign-up we may send them hashed conversion identifiers (for example a hashed email) so we can measure which ads lead to installs and purchases. These partners never receive your browsing activity, page content, or anything from inside the extension. You can turn this off with the controls on our Cookie Policy page.
Each provider’s own privacy policy applies to data they receive directly.
7. Your choices and rights
- Turn off analytics & advertising measurement. Open the extension’s Options → General → Privacy and toggle “Anonymous analytics” off (the same choice appears as “Anonymous usage analytics” on the welcome page). On intab.io, use the controls on the Cookie Policy page - they stop analytics and advertising events from your browser immediately.
- Clear local data. Options → General → Reset all settings restores every setting to its default (your highlights and bookmarks are kept). Uninstalling the extension removes everything stored on your device.
- Delete your account. Visit intab.io → Settings → Account → Delete account. Server-side data is removed within 30 days.
- Access / export your data. Email us at help@intab.io and we’ll send you a copy of any account data we hold within 30 days.
- Opt out of marketing email. Every email has an unsubscribe link. Transactional emails (password reset, billing receipts) cannot be opted out of while you have an active account.
If you live in the EU/EEA or the UK, the legal basis for processing analytics events is your consent (the toggle described above). The legal basis for account data is the contract you enter into when you sign up. For marketing emails it is consent. You can withdraw consent at any time.
If you live in California, you have the rights described in the CCPA / CPRA, including access, deletion, and opt-out of “sale” or “sharing” of personal information. We do not sell personal information. Our use of the advertising-measurement partners described in Section 6 may count as “sharing” under the CPRA; you can opt out at any time using the controls on our Cookie Policy page, and we honor that choice immediately.
8. Data security
Account data is encrypted in transit (TLS) and at rest on Cloudflare’s infrastructure. We use scoped access tokens for every backend call. We do not log request bodies that contain user text beyond what is needed to return a response.
9. Children
InTab is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, email help@intab.io and we will delete it.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the extension’s “What’s new” panel on the next update after the change. The “Last updated” date at the top of this page always reflects the most recent revision.
11. Limited Use (Chrome Web Store User Data Policy)
InTab’s use and transfer of information received from Google APIs, and of any other user data collected by the InTab browser extension, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Concretely:
- We use the data only to provide or improve user-facing features. Every piece of data described in this policy exists to run a feature you can see and use (your new tab, your saved tabs and highlights, an AI action you invoked, or anonymous counts that tell us which features to improve). We do not use it for anything unrelated to those features.
- We do not transfer the data, except (a) as necessary to provide or improve the user-facing features, and only to service providers acting on our instructions (listed in Section 6); (b) where required for security purposes, such as investigating abuse; © to comply with applicable laws or a valid legal request; or (d) as part of a merger, acquisition, or sale of assets, and then only after we give notice to affected users.
- We do not use or transfer the data for advertising, including personalized, retargeted, or interest-based advertising. The advertising-measurement partners named in Section 6 run on the intab.io website only; they never receive data collected by the extension.
- We do not sell the data, and we do not allow humans to read it, except (a) with your explicit affirmative consent for specific messages, (b) where necessary for security purposes such as investigating abuse, © to comply with applicable laws, or (d) when the data has been aggregated and anonymized so it can no longer identify you.
12. Contact
For privacy questions, data-access requests, or anything else covered by this policy, email help@intab.io.