TabVault — Privacy Policy 隐私政策

Updated / 生效日期:2026-10-09

English

Local content

Session titles, page titles/URLs, pinned state, browser-group metadata, project names/colors/notes, session notes/tags, snapshots and preferences stay in chrome.storage.local. JSON backups include these fields. Optional automatic snapshots and the window recovery cache stay local. Free retains 3 recent snapshots; Pro retains up to 30 days, 500 snapshots and 4 MB. Cleanup does not delete manual sessions. Restoring does not save passwords, form inputs or unsaved page state.

Permissions

tabs reads saved window titles/URLs and local recovery information; tabGroups reads and restores group names, colors and collapse state; storage saves local records; alarms schedules opt-in snapshots; sidePanel displays the UI. Incognito windows are excluded from automatic snapshots.

Payments and automatic activation

Pro is an optional one-time purchase through Stripe. Before checkout, you agree to order processing. Stripe handles card details. Each product has an isolated Cloudflare D1 database storing order, Checkout Session, PaymentIntent, product, price and webhook event IDs; amounts, currency, payment/refund/fulfillment state and timestamps. It also stores a keyed hash of the purchase email and a hash of the installation’s activation capability. We do not persist plaintext checkout emails, billing addresses, card details, raw webhook bodies, tasks or saved sessions in D1. The extension connects to its product’s billing origin to check payment or recover purchases. Only that origin’s success page can notify the extension; notifications alone do not grant Pro.

Purchase recovery email

When you request purchase recovery, the address you enter is used in memory to look up its hash and, for an eligible purchase, sent to Resend to deliver a 6-digit verification code. This is separate from Stripe receipt emails. D1 stores hashes of the challenge code and requesting IP, attempts and timestamps. Codes expire after 10 minutes, allow up to 5 guesses and can be used once. Challenge records older than 24 hours are deleted when another recovery request is made. Purchase existence is not disclosed in the normal request response. Resend and Cloudflare may process service metadata under their own policies. Email recovery requires the operator’s sender configuration; the saved license code remains a fallback.

Retention, deletion and analytics

There are no developer usage analytics or cloud task/session sync. Local content stays until you delete it, uninstall, or applicable snapshot cleanup runs. Order records have no automatic expiry and support license retrieval. Email support@tabplugins.top to access, correct or request deletion of order records. Do not send API keys or license codes. Deleting our order record does not delete Stripe’s records and may prevent recovery. Previously activated offline licenses are not automatically revoked after refunds.

Support email

When you contact support@tabplugins.top, your address, message, attachments and mail delivery metadata are processed by Cloudflare Email Routing and Google Gmail to deliver and handle your request. Include only the information needed to explain your issue. Support mail is separate from the extension’s local content and purchase-recovery verification emails.

Service policies

Stripe · Cloudflare · Resend · Google

中文

本地数据

会话名称、网页标题与网址、固定状态、浏览器分组信息、项目名称/颜色/备注、会话备注/标签、快照和偏好保存在 chrome.storage.local。JSON 备份包含这些字段。可选自动快照和窗口恢复缓存均留在本机。免费版保留最近 3 份;Pro 最长 30 天、最多 500 份、快照合计 4 MB。快照清理不会删除手动会话,不保存密码、表单输入或网页未提交状态。

权限

tabs 读取要保存的窗口标题/网址及本地恢复信息;tabGroups 读取和恢复分组名称、颜色及折叠状态;storage 保存本地记录;alarms 为主动开启的快照提供定时器;sidePanel 展示界面。自动快照不包含隐身窗口。

付款与自动激活

Pro 可选,一次性通过 Stripe 付款;结账前会征求订单数据处理同意。银行卡信息由 Stripe 处理。两个商品各自使用独立 Cloudflare D1,保存订单、Checkout Session、PaymentIntent、商品、价格和回调事件编号,金额、币种、付款/退款/签发状态及时间,另保存购买邮箱的带密钥摘要及本机自动激活凭证摘要。D1 不持久保存明文结账邮箱、账单地址、卡信息、原始回调、任务或标签会话。扩展连接本商品付款服务核对订单或恢复购买;仅该域名的成功页可以通知扩展,通知本身不会授予 Pro。

邮件恢复购买

主动恢复购买时,你输入的邮箱只在内存中用于计算摘要;若有符合条件的订单,邮箱将提交给 Resend 以投递 6 位验证码。这与 Stripe 收据邮件不同。D1 保存验证码和请求 IP 的摘要、尝试次数及时间。验证码 10 分钟过期、最多尝试 5 次、只能成功使用一次;超过 24 小时的挑战记录在后续恢复请求时清理。正常申请响应不会透露该邮箱是否购买。Resend 与 Cloudflare 可能按各自政策处理服务元数据。邮件恢复须由运营方配置发件服务,已有授权码仍可作为备用。

保留、删除与统计

开发者不收集使用统计,也不提供任务/会话云同步。本地内容留存到你删除、卸载或触发相应快照清理。订单记录暂不自动过期,用于授权找回。需要查询、更正或删除订单记录,请发送邮件至 support@tabplugins.top;请勿发送 API Key 或授权码。删除我们的订单记录不影响 Stripe 自己保存的记录,并可能导致无法恢复购买。已激活的离线授权不会因退款自动撤销。

支持邮件

发送邮件至 support@tabplugins.top 时,发件地址、正文、附件及投递元数据会经 Cloudflare Email Routing 和 Google Gmail 处理,用于投递邮件及处理申请。请只提供说明问题所需的信息。支持邮件与插件本地数据、恢复购买的验证码邮件分别处理。

服务商政策

Stripe · Cloudflare · Resend · Google