Skip to content

Search is only available in production builds. Try building and previewing the site to test it out locally.

Privacy & security

Effective: 2026-07-05 (Last updated: 2026-09-03). This is the privacy policy for TabBoy, the Chrome extension published by FlowCrate. It covers the extension as it ships today (V1: local-first, free, no account). Sections below marked “future optional tiers” describe features that do not exist yet and will not take effect until they ship. This page will be updated before that happens, not after.

  • Tab, window, and group data is processed inside the extension, on your device.
  • Suggestions and saved data (rules, collections, saved groups, scan metadata) stay in local browser storage.
  • JSON exports are user-triggered downloads; TabBoy never uploads them.
  • TabBoy has no hosted backend, no account, and no telemetry in V1.
  • By default, TabBoy makes zero outgoing network requests. During normal operation (tab scanning, rule evaluation, duplicate cleanup, and session restoration), no tab URL, title, or page content leaves your device.
  • The only network traffic that can occur is strictly opt-in and initiated by you when using optional features:
    • Bring-your-own-key (BYOK) AI summaries: requests are sent directly from your browser to your configured AI provider (see below).
  • For disk locations, storage keys, and local data guarantees, see Where your data lives.
  • For our architectural commitments and the 6 Golden Rules, read the Trust Charter.

Current Chrome permissions and what they’re used for:

  • storage: local rules, collections, saved groups, scan metadata, and suggestions.
  • tabs: read tabs/windows, open the dashboard, close after confirmation, and restore tabs.
  • tabGroups: read, create, update, and restore Chrome tab groups.
  • contextMenus: expose the local “Scan with TabBoy” action in the browser context menu.
  • pageCapture: take offline, local MHTML snapshots solely as an emergency safety net before destructive tab actions (stored strictly in local IndexedDB, never transmitted).
  • sidePanel: display the TabBoy side panel inside Chrome.

None of these standard permissions are used to transmit data off your device. TabBoy requires no mandatory host_permissions.

TabBoy declares optional permissions in its manifest that are never granted at installation and only requested with explicit user consent:

  • scripting and exact-origin HTTPS host permissions: optionally requested when you explicitly choose to extract reading-queue article content locally. Only the exact origin of the queued page is requested, never a wildcard grant.
  • Configured AI provider host permission: when configuring a BYOK endpoint in Options, TabBoy requests permission solely for the exact origin of your provider (e.g. https://api.openai.com/*).

Optional AI summaries: Bring-your-own-key (BYOK)

Section titled “ Optional AI summaries: Bring-your-own-key (BYOK)”

TabBoy includes an optional, privacy-respecting AI summary feature for items in your reading queue:

  • Strictly opt-in: BYOK is completely inactive until you explicitly configure your own API key and endpoint in Options.
  • Direct browser-to-provider connection: Requests are sent directly from your extension to the OpenAI-compatible endpoint you specify (such as OpenAI, OpenRouter, or Groq). FlowCrate servers are never in the network path. FlowCrate never sees, intercepts, or logs your API key, tab titles, URLs, or summaries.
  • Ephemeral credential storage: Your BYOK API key is stored exclusively in ephemeral browser session memory (chrome.storage.session). It is never written to disk, is never included in backups or diagnostic exports, and is wiped automatically when your browser closes.
  • Minimal payload: Outbound summary requests are bounded to a maximum of 12,000 characters of extracted text. TabBoy never transmits your browsing history or other tabs.
  • Independence: BYOK is and will always remain free, unlimited, and independent of any future TabBoy Pro subscription.

Future optional tiers (not yet available)

Section titled “ Future optional tiers (not yet available)”

TabBoy may later offer hosted sync features:

  • TabBoy Pro (hosted): an optional paid subscription for multi-device sync under zero-knowledge end-to-end encryption (E2EE). Your data is encrypted on your device before it leaves it, and FlowCrate servers only relay ciphertext: they never see unencrypted URLs, page contents, or collection titles. FlowCrate does not send your data to an AI provider, does not fetch page content on your behalf, and keeps no server-side cache of your pages. This tier does not exist yet; this policy will be updated with its concrete terms before it ships. Account and billing data for this tier (email, subscription, credit ledger) is processed by FlowCrate under FlowCrate’s own privacy policy, not this one (linked from your account settings once this tier exists).
  • Either tier will always be strictly opt-in and free from any requirement to use the other: BYOK never requires a FlowCrate subscription.
  • No hidden destructive browser actions.
  • Destructive close, save-for-later, and delete flows require confirmation.
  • Imported backups and rule presets are validated with Zod before use.
  • Rules are data only: $where, functions, arbitrary JavaScript, and remote code are blocked.
  • Browser APIs stay behind wrapper modules for testability and portability.

Bug investigation starts with a local diagnostic export. TabBoy never uploads diagnostics automatically. You review a summary before downloading JSON and decide whether to share it (for example, by attaching it to a GitHub issue).

Diagnostic exports must not include full tab URLs, page titles, favicons, domains, collection contents, cookies, tokens, or user identifiers.

Because TabBoy has no user accounts, collects no telemetry, and transmits no personal data to FlowCrate servers, FlowCrate holds no personal data to access, correct, or delete on your behalf. Your data lives in your own browser storage, and you control it directly (export, import, or clear it from Chrome’s extension settings).

For privacy questions, or if an optional tier above is live and you have a request about data FlowCrate does hold for that tier, use GitHub Issues. Account and billing data requests for a TabBoy Pro subscription, once that tier exists, are handled through your FlowCrate account settings instead.

Security vulnerabilities must be reported privately through our Security Policy or via GitHub Security Advisories. Do not post unpatched security details in public issues.

Material changes (especially anything that adds a new outgoing network call or a new optional tier) are reflected here before the corresponding feature ships, and called out in the changelog.