Privacy

OnePage Tabs Privacy Policy

The OnePage Tabs extension for Chrome and Firefox is a local-first tab organizer with no OnePage user account, advertising, automatic telemetry, or analytics SDK. Local features keep data in your current browser profile, and Google Drive sync starts only after you connect it. When a clear error appears, a minimal categorized report is sent only after you click report and confirm again. The official website uses Google Analytics 4 as described below. Website analytics is separate from the extension and does not receive saved tab content, Google access tokens, files, screenshots, or extension device identifiers.

Applies to OnePage Tabs V1.2 and later releases that do not materially change how data is handled.Last updated: September 11, 2026

1. Core commitment

Your saved tabs, groups, notes, settings, and reminder plans stay in the extension database for your current browser profile by default. Continue Later uses local browser scheduling and system notifications rather than a remote push service.

Google Drive sync starts only after you connect it and authorize the drive.appdata scope. The extension writes encrypted sync data and the key needed to decrypt it directly to your own Google Drive app-data folder. OnePage does not operate a relay server.

Opening and closing behavior keeps only normal-window tab structure, the active tab, and recent-use order for the current browser session. This state contains no URLs, titles, or page content and is cleared when the session ends.

OnePage Tabs does not continuously record your browsing history. Browsing data enters the library only when you actively save, restore, organize, import, or export tabs.

2. Data handled by the extension

To provide its local features, OnePage Tabs may process the following data:

  • URLs, page titles, domains, tab order, pinned state, and available native browser tab-group details for tabs you actively save
  • Group names, notes, pinned or protected state, and other organization choices you create
  • Temporary tab IDs, window IDs, operation records, and result states needed for reliable saving and restoring
  • Normal-window tab IDs, order, pinned and group state, active tab, and recent-use order kept for the current browser session to apply new-tab position, foreground/background, after-close focus, and the previous-tab shortcut
  • Return times, reminder revisions, notification delivery state, and reminder-related settings
  • Imported local files and exported data that you explicitly choose to process
  • Local settings and schema versions needed to display and migrate data safely
  • After you enable Google Drive sync: a device identifier, change versions, conflict state, encrypted sync batches, checkpoints, a standard-sync key file, and one daily backup created after the first successful automatic sync on each local date, with the latest 7 retained; Drive metadata does not contain saved URLs, titles, group names, or notes in plaintext
  • After you explicitly confirm an error report: the error category, affected feature, extension version, browser family and major version, and operating-system family; no tab title or URL, group, note, search, Google account, file, screenshot, browsing history, or device identifier

3. Storage, use, and sharing

Saved tabs, settings, reminders, and operation records are stored in IndexedDB under the OnePage Tabs extension origin for your current browser profile. Tab-behavior runtime state is stored in the browser’s extension session storage only for the current browser session and is cleared when that session ends.

This data is used only to show, search, organize, restore, delete, import, export, and remind you about saved tabs; verify interrupted operations safely; and apply the opening and closing behavior you configure.

Local features do not automatically send saved URLs, titles, notes, searches, operation records, reminder plans, tab-behavior session state, or crash information. If you enable Google Drive sync, sync files go directly to your own Drive. If you confirm an error report, minimal categories go to Feedback Hub, where the raw report is kept for at most 30 days and can be deleted from the current confirmation window. Neither optional extension network feature sends tab content or Google access tokens to OnePage.

The official website uses Google Analytics 4 (measurement ID G-K2S1V341C5) to understand aggregate visits. GA4 may process the page path, referrer path, approximate region, device and browser category, browser-generated pseudonymous identifiers, and basic session interactions. OnePage removes query strings from page and referrer addresses before configuration, disables Google Signals and advertising personalization signals, and does not send saved tabs or other extension data. Google may use cookies or similar browser storage and processes analytics data under its own terms and privacy policy.

4. Permission details

OnePage Tabs requests only the browser permissions needed for the features described below.

PermissionPurpose
tabsReads the title, URL, order, and pinned state of tabs you actively choose to save; closes original tabs only after a reliable commit; reopens tabs when you request a restore; and applies your new-tab position, foreground/background, after-close focus, and previous-tab shortcut choices.
tabGroupsOn desktop browsers that expose native tab groups, saves and restores the title, color, collapsed state, and membership where possible. Firefox for Android keeps OnePage group metadata but restores pages as regular tabs.
contextMenusProvides user-triggered commands for saving the current tab, tabs to the left or right, other tabs, or the current window.
clipboardWriteWrites selected tab links as text or Markdown only after you choose a copy action.
unlimitedStorageReduces the risk of a local save failing because of the default extension storage quota. This permission applies to the local database; optional Drive sync still starts only after you connect it.
favicon (Chrome only)The Chrome build uses Chrome’s built-in Favicon API to display icons for saved URLs without directly contacting websites or a third-party icon service. The Firefox build does not request this permission.
Firefox tab icons (no favicon permission)Firefox supplies icon image data for tabs that are already open. OnePage may cache up to 256 non-private, browser-provided data-image icons by site origin in local extension storage; it ignores private tabs and does not contact the website or any third-party icon service. If no safe image is available, it shows a domain initial.
alarms (required)Wakes the extension while the browser is running to check return times and create the day’s single cloud backup after the local date changes. If the browser or device is off, it checks whether today already has a backup after the browser resumes.
storageUses the browser’s extension session-storage API for normal-window tab structure and recent-use order during the current browser session, so tab-behavior settings still work after the background process is reclaimed. It does not store URLs, titles, or page content.
notifications (optional)Shows local system notifications only after you set Continue Later and grant permission. Declining or revoking it does not delete reminders or due items.
https://feedback.downyes.com/* (optional)Temporarily granted only after you choose to report an error and confirm again. It sends one minimal categorized report or deletes the report just sent, then is removed. Declining does not affect other features.
identity (platform-specific)Chrome requests identity as an optional permission when you connect. The Firefox package declares identity so desktop Firefox can open Google Web OAuth through identity.launchWebAuthFlow; Firefox for Android does not expose that API and instead opens a dedicated authorization tab that accepts only the exact loopback callback and matching state. No platform starts Google sign-in until you choose Connect, and the access token is kept only in browser session storage and is never sent to OnePage.
https://www.googleapis.com/* (optional)Requested only after you choose to connect sync. Calls the Google Drive API to list, upload, download, and delete OnePage sync files using only the drive.appdata scope. It cannot read your normal Drive files. Disconnecting clears the token and revokes this host permission.
Firefox data permissions (optional)The Firefox manifest declares no required data collection. When you connect Google Drive, Firefox asks for the optional browsingActivity and websiteContent categories because saved URLs, titles, groups, notes, and reminders are synchronized to your own Drive. technicalAndInteraction is requested only when you explicitly confirm an error report. Declining these permissions leaves local tab management available.

5. Your controls and data retention

You can view, search, rename, annotate, protect, restore, move to trash, permanently delete, import, and export your local data. Active and trashed items remain until you take an action that removes them.

Reminder plans stay with their group or tab. Device-only delivery state, such as whether a notification has already appeared, is not included in a portable export. Exported files are stored wherever you choose and remain under your control.

Uninstalling the extension, clearing extension data, or deleting the browser profile may remove the local database. Export important work before troubleshooting or making browser changes.

You can disconnect this device or permanently delete the current sync library from Google Drive. Disconnecting clears the local sync key and authorization cache but keeps local tabs and remote files. Permanent cloud deletion removes that library’s sync key file, checkpoints, change batches, and daily backups, but keeps local tabs. Daily backups do not promise a fixed clock time: one is created after the first successful sync on each local date, and no entry is fabricated for a day when the browser never ran.

Uninstalling or clearing extension data removes the local database and local key, but does not automatically delete encrypted files already stored in Google Drive. Deletions are retained as encrypted tombstones for up to 90 days so an old offline device cannot restore them.

Error reports are sent only after a clear error and a second confirmation. There is no automatic monitoring, background queue, or silent retry. Raw reports are kept for at most 30 days, and de-identified category counts for at most 90 days.

You can limit official website analytics with browser cookie or storage controls and content blockers. Doing so does not affect the extension’s local features.

6. Data safety

OnePage Tabs uses transactions, revisions, operation records, validation, protected-item rules, version vectors, and encrypted checkpoints to reduce the risk of corruption during saving, syncing, restoring, cleanup, import, or migration. Import and recovery data is checked before it is merged in a local transaction.

Google Drive sync uses a random 32-byte master key and AES-256-GCM. Encrypted data and its decryption key are stored in the same Drive app-data folder, so another device can continue after connecting the same Google account and Google may technically access the content.

No application can guarantee absolute safety. Keep a separate OnePage JSON backup for important tabs. The extension cannot continue uploading while the browser or device is fully closed; queued local changes resume after the browser starts again.

7. Children’s privacy

OnePage Tabs is a general browser utility and is not directed at children. The current version does not create accounts or ask for age information, and the developer does not receive your saved tab data.

8. Changes to this policy

Google Drive sync uploads only after you connect it. If a future release adds OnePage accounts, OnePage-hosted servers, or another feature that changes data handling, this policy and the applicable Chrome Web Store and Firefox Add-ons disclosures will be updated before the feature is enabled.

9. Contact

OnePage Tabs is operated by the OnePage Tabs team. For privacy, data-handling, or product-support questions, email [email protected].

10. Limited use

OnePage Tabs uses browser data only for the single purpose clearly described to users and follows the Chrome Web Store User Data Policy and Mozilla Add-on Policies for transparent disclosure, minimum permissions, and user control. OnePage Tabs’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.