Effective date: August 9, 2026
This policy covers the current TabPlex Chrome and Edge extension. TabPlex is a local-first workspace and recovery tool. Its single purpose is to let you save, organize, switch, and recover browser workspaces.
TabPlex handles browser tab metadata and content you add to a workspace because that data is required to provide its visible workspace and recovery features. Workspace data is processed on your device. The extension has no TabPlex account system, remote workspace API, analytics client, advertising SDK, or background upload path.
To provide its single purpose, TabPlex may read, create, update, and store:
The extension does not read page bodies, form entries, passwords, authentication cookies, or other website storage. It has no host permissions and injects no content scripts into websites. The tabs permission is used for the tab metadata needed by the visible workspace features described above.
TabPlex uses this data only to:
TabPlex does not use this data for advertising, profiling, behavioral analysis, credit decisions, sale, or any unrelated purpose.
chrome.storage.local: stores workspace content, notes, linked resources, timeline snapshots, Trash state, recovery state, local-only settings, onboarding state, pending actions, and diagnostic errors. This data remains in the browser profile until you edit or delete it, clear extension storage, or uninstall the extension, subject to the bounded histories described in this policy.chrome.storage.session: stores temporary per-window bindings and tab-loading jobs used while the browser session is running. It is not the long-term source of workspace content.chrome.storage.sync: current versions write only portable preferences: theme, language, accent color, keyboard shortcuts, and workspace sort order. If browser sync is enabled, the browser vendor may synchronize those preferences under the user's browser account; they are not sent to a TabPlex service. Older TabPlex versions may have left legacy workspace or runtime-state entries in browser-managed sync storage. The current version can read those legacy entries to migrate them into local storage and does not create new workspace-content records in sync storage. Retention of browser-managed sync data is controlled by the browser vendor and the user's sync settings.The unlimitedStorage permission removes Chrome's fixed extension-local-storage quota. It does not grant TabPlex access to website content, arbitrary device files, or a network service. Available device storage still limits capacity.
TabPlex creates an exported backup only after you choose the export action. The backup can include workspace metadata, tab metadata, timeline snapshots, notes, linked resources, and portable settings. Your browser then saves the JSON file to the location you choose. TabPlex does not upload that file.
Backup files include a SHA-256 integrity check to detect corruption. The checksum is not encryption. Anyone who can read an exported backup file may be able to read its contents, so you are responsible for storing and deleting that file safely.
Importing a backup reads the file you choose and processes it locally. Copying diagnostics or opening a feedback email is also user-initiated. Diagnostic text is placed on the clipboard only after you select that action; it is sent to TabPlex only if you then choose to include it in a message. Review and remove private URLs or other sensitive details before sharing diagnostics or a backup.
The current extension:
Normal browser requests made when you open a saved URL are requests by the browser to that website, not uploads of workspace data to TabPlex.
Agent Control is off by default. Chrome requests the optional Native Messaging permission only when you enable the feature. Enabling it also requires a separately installed Native Messaging host that is bound to the exact extension ID. While enabled, a local CLI or another process running as the same operating-system user can send validated commands to read or change TabPlex data through the extension.
The currently supported macOS host uses an owner-only Unix socket and exposes no HTTP, WebSocket, or TCP port. Native Messaging stays on the same computer. TabPlex does not route Agent Control data through a TabPlex server.
Turn off Agent Control in TabPlex settings to disconnect the Native Messaging host immediately and remove the optional browser permission. Do not enable it on an operating-system account shared with people or software you do not trust. Removing the Native Host is a separate operating-system action.
TabPlex does not receive or share your locally stored workspace data by default, and the developer cannot inspect it remotely. Data can leave the extension only through a boundary described above:
TabPlex personnel will not read extension user data unless you explicitly provide specific data for support, it is necessary to investigate a security issue, or disclosure is required by law. TabPlex never uses or transfers extension user data for personalized advertising or lending decisions.
You control the data stored by the extension. You can edit workspaces and notes, move workspaces to Trash, restore them, permanently delete individual workspaces, or empty Trash after confirmation. Timeline history is automatically limited to the most recent 15 snapshots per workspace, and diagnostic storage is automatically limited to the most recent 100 warning or error entries.
You can also clear TabPlex extension storage in the browser or uninstall the extension. The developer cannot delete local data remotely because TabPlex has no user account or remote workspace service. Browser-managed sync data must be managed through your browser account and sync settings. Exported backup files and copied diagnostics remain wherever you placed them until you delete them.
Disabling Agent Control closes its active local connection. Uninstalling the extension does not automatically uninstall a separately installed Native Messaging host; remove that host through the operating-system installation method if you no longer need it.
TabPlex relies on Chrome or Edge extension-storage isolation and your operating-system account boundary. Local extension data and exported backup files are not represented as being encrypted by TabPlex. Keep your browser profile, operating-system account, backups, and Agent components protected.
TabPlex uses a restrictive extension-page Content Security Policy, does not inject code into websites, validates imported backups and Agent commands, and limits recovery and diagnostic histories. No storage or security system can eliminate every risk.
tabs, tabGroups, and windows: read and restore the current normal window's tab and group structure for user-visible workspaces.storage and unlimitedStorage: keep workspaces, settings, recovery state, and bounded local diagnostics on the device.alarms: resume bounded recovery and maintenance work after the Manifest V3 service worker stops.nativeMessaging: connect to the optional local Agent component only after the user enables Agent Control.TabPlex requests no host permissions.
TabPlex limits every collection, use, and transfer of extension user data to the single purpose and user-visible features disclosed in this policy. It does not use or transfer the data for advertising, profiling, resale, or unrelated purposes, and it does not permit human access except with the user's explicit consent for specific support, for security, or when required by law.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
See the official Chrome Web Store User Data Policy.
Material changes will be posted on this page with a new effective date. If a future extension version changes what data is handled or why, TabPlex will also make a prominent disclosure in the extension and Chrome Web Store materials before the new practice takes effect, as required.
Questions about this policy can be sent to contact@tabplex.com. For a security issue, follow the private reporting guidance in the TabPlex security policy. Do not include private URLs, backups, credentials, or Agent connection material in a public issue.