Privacy policy for Tab Manager - Duplicates & Merge | OpenTabs
Tab Manager - Duplicates & Merge | OpenTabs by OpenTabs
Privacy
Short, because there is not much to describe.
The extension
The extension itself has no account, no analytics and no telemetry. Your configuration — every group, every source, every to-do — is stored in your own browser profile and is never sent anywhere unless you turn on Sync (below), and even then only end-to-end encrypted, so no server can read it. The extension makes network requests only to fill the groups you turned on, and it asks for a site's permission at the moment it first needs it rather than at install. A group you never enable never asks for a site and never makes a request.
- opentabs.app: The apps catalogue and the trending list, as two static files. Only if one of those groups is on.
- market.opentabs.app: The pack marketplace. Only when you open it.
- auth.opentabs.app: Sign-in, for the two things that need an account. Only if you choose to sign in.
- Sites you added: A feed, a weather API, a calendar address, a market quote — whatever the groups you configured need. You granted each one. Your open tabs are read by the extension and never leave the browser. They are the page's content, not data collected about you.
Sync (optional, off by default)
If you turn on Sync in Settings, your settings, to-dos, Focus list, calendar addresses and API keys are end-to-end encrypted on your device before they leave it. The encrypted bytes are stored on a relay: by default the OpenSync relay at relay.opensync.network, or a relay you run yourself. The relay holds only ciphertext and a public key, with no name, email or account, and nothing on it can decrypt your data.
X search (optional)
If you add an X search as a topic, the extension opens that search on x.com in a tab using your own X session and reads the results into your Topics. Nothing from it is sent to OpenTabs.
Signing in
An account is optional and buys two things: publishing a pack to the marketplace, and liking one. It is never used to store your settings, and nothing about your configuration is uploaded when you sign in. The session lives in memory for the browser session and is never written to disk or synced between devices.
The marketplace
Browsing and installing need no account and set no cookie. Install counts are a number on the pack, incremented anonymously — nothing identifies who fetched it. A like does need an account, and here the design is worth stating precisely. A like is stored as HMAC-SHA256(server secret, account id ‖ pack id) and the account id itself is not stored beside it. The likes table has no user column, so the question "what has this account liked" has no query that answers it — the server can check whether you liked this pack, because it can recompute that one digest, and it cannot enumerate anything. That is a property of the schema, asserted by a test that reads the table's columns, rather than a promise about how the data is used. A pack you publish is public by definition: its name, description, tags, the author handle you typed and the sources it contains. Your API keys, calendar addresses, coordinates and card sizes are stripped out before it leaves your browser, and stripped again on the server — the second time is not redundancy, it is where the boundary actually is.
This website
Everything above is about the extension. This site — the pages at opentabs.app — is a different thing, and it counts visits: which pages were opened, roughly which country the request came from, which browser and screen size, and which link led here. The counter is self-hosted on our own server, not a service anyone else runs. It sets no cookie, stores no cross-site identifier, and keeps nothing that names a reader or follows one from here to anywhere else. What it produces is a count of pages, not a record of people, and none of it is sold or handed on. market.opentabs.app, where packs are published and installed, is counted the same way and by the same counter. It was the one part of OpenTabs still using Google Analytics; since 21 September 2026 it is not. It stops at the site either way. The extension itself carries no analytics code at all — not disabled, not present, and a test over the built extension fails the release if any ever appears in it. Nothing counted here is joined to anything you do inside the extension, because there is nothing coming from the extension to join it to. Any content blocker stops it, and the site works exactly the same without it.
Payments
OpenTabs charges for nothing, so there are none.
Changes
If this ever describes something more than it does today, the change lands in the public repository first, and the extension asks before doing anything new that needs a permission it does not already hold.