Privacy Policy
Product: Nomad Tabs browser extension
Effective date: 2026-07-07 Owner / data
controller: Zhemal Khamidun Contact:
hamidunjemal@gmail.com
Summary (the short version)
- You can use Nomad Tabs without an account. In that
mode, nothing leaves your device — your saved tabs live
in your browser’s local storage.
- We collect data in the cloud only if you choose to create an
account and sign in to sync.
- We never sell or rent your data, and we never use
it for advertising.
- Page text is captured only when you take an action
(a sweep or snapshot), never silently in the background, and only after
you grant page-access permission.
- You can export everything or permanently
delete your account and all its data at any time.
What the extension does
Nomad Tabs saves (“sweeps” or “snapshots”) your open browser tabs
into a searchable vault so you can close them to free up memory and find
them again later. Saving happens in response to an action you take
(clicking Sweep/Snapshot, or a context-menu item). By default everything
is stored locally on your device. If you sign in, your vault also syncs
to our servers so you can reach it from your other browsers and
devices.
What data we process
1. Data
stored locally on your device (no account needed)
When you sweep or snapshot tabs, the extension saves the following in
your browser’s local storage (IndexedDB / extension storage) on your
device:
- Tab metadata: the page URL, page title, favicon
URL, tab group name/color, window/tab position, and pinned state.
- Captured page text (optional): if you have granted
page-access permission and haven’t excluded the site, the readable text
of the page is extracted from the page at the moment you save it, along
with a short excerpt, detected language, and word count. Capture only
runs on the tab you’re saving, on
http(s) pages, and never
on browser system pages. You can turn capture off for any site via
“Never capture content here,” or pause the whole extension for an
hour.
- Extension settings and small local state (e.g. your
per-site “never capture” list, pause timer).
If you never sign in, this data stays on your device
and is not transmitted to us.
2. Data
sent to our servers (only when you sign in to sync)
If you create an account and sign in, the following is sent to and
stored on our servers so it can sync across your devices:
- Account data: your email address (used to sign in
via a one-time email link) and your plan (Free/Pro).
- Device records: a name, browser type, and platform
string for each browser where you’ve signed in (so you can see and
manage your synced devices), plus the authentication tokens that keep
you signed in.
- Your vault: the tab metadata and captured page text
described in section 1, for the tabs you save while signed in (or that
sync up after you sign in).
- Live-tab presence (for cross-device duplicate
detection): while signed in, the extension periodically reports
the URLs and titles of your currently open tabs so it can show you the
same page open in two browsers and let you close the duplicate. This is
ephemeral presence data.
We do not collect your browsing history at large. We
only receive information about the specific tabs you choose to save,
plus the transient open-tab presence used for duplicate detection while
you’re signed in.
3. Data we do NOT collect
- No passwords (sign-in is a passwordless email link).
- No payment card details (see “Payments”).
- No advertising identifiers, no tracking pixels, no
keystroke/mouse/scroll logging.
- No page content is sent to any analytics system. Product telemetry
is off by default; if it is ever enabled it is anonymous and never
includes page content.
4. Standard server logs
Like any web service, our servers process technical request data
(such as IP address and timestamps) transiently to deliver and secure
the API. We do not use this to build a profile of you or to track your
location.
How your data is used
We use the data above only to:
- Save, sync, search, and de-duplicate your tabs — the core function
of the extension.
- Authenticate you (send the sign-in link, keep your session valid,
manage your devices).
- Provide Pro features you opt into (see “Third parties”).
- Operate, secure, and debug the service.
We do not use your data for advertising, profiling,
or credit/lending decisions, and we do not sell or
transfer it to third parties for their own purposes.
Third parties and
sub-processors
We share data only with service providers that help us run the
product, and only as needed:
- Transactional email provider — to send your
one-time sign-in link (receives your email address).
- Cloud hosting provider — where the API and database
run (stores your synced vault).
- AI embedding provider (Pro semantic search only,
e.g. OpenAI): if you are on Pro and use semantic search,
excerpts of your captured page text are sent to an embedding provider to
compute the search index. This does not happen on the Free plan.
- Payment merchant-of-record (Pro subscriptions only,
e.g. Paddle or Lemon Squeezy): if you subscribe to Pro, the
payment provider collects and processes your payment details directly.
We do not receive or store your card number — we only
receive your subscription/plan status.
Each provider processes data only to perform its function for us, not
for its own marketing.
How your data is protected
- Data synced to our servers is transmitted over encrypted
connections (HTTPS/TLS) and stored encrypted at
rest, with the encryption keys held server-side.
- Access is controlled per account: your data is scoped to your user
and reachable only with your authenticated session.
- Important honesty note: v1 is not
end-to-end encrypted and is not “zero-knowledge.”
Because features like full-text and semantic search run on the server,
your page metadata and captured text are readable by the service in
order to index and search them. If we later offer an
end-to-end-encrypted tier, we will describe it separately and clearly.
Any marketing that says otherwise is incorrect and will be
corrected.
Data retention
- Local data: kept on your device until you delete it
(locally, or by uninstalling the extension / clearing browser
data).
- Cloud full page text: on the Free
plan, captured full page text is retained in the cloud for 30
days, then automatically deleted (titles/URLs remain). On
Pro, full text is retained with no time limit.
- Deleted items (“Trash”): items you delete are
recoverable for a 14-day window, then purged.
- Account deletion: deleting your account
hard-deletes your user record and cascades to all your
devices, sweeps, tabs, captured content, and presence data.
Your rights and choices
- Use without an account — full local functionality,
no data sent to us.
- Export your data — download a complete JSON export
of your account (account info, devices, sweeps, tabs, and captured
content) from the app at any time (GDPR Art. 15 / 20).
- Delete your account — permanently erase your
account and all associated data from the app (GDPR Art. 17). This is
self-serve and immediate.
- Control page capture — grant or withhold
page-access permission, exclude specific sites via “Never capture
content here,” or pause the extension.
- Access, correction, objection, and other rights
under GDPR / UK GDPR / CCPA — email us at hamidunjemal@gmail.com and we
will respond. You also have the right to lodge a complaint with your
local data protection authority.
We do not knowingly collect data from children under 13 (or under the
applicable age of digital consent in your region). The service is
intended for general audiences.
Chrome Web Store
Limited Use disclosure
Nomad Tabs’s use of information received from Chrome APIs adheres to
the Chrome
Web Store User Data Policy, including the Limited
Use requirements. Specifically:
- We only collect and use the data described in this policy, solely to
provide and improve the extension’s single purpose (tab & session
management).
- We do not sell or transfer user data to third
parties except to the service providers listed above (as needed to run
the product), for legal reasons, or as part of a merger/acquisition with
equivalent protections.
- We do not use or transfer user data for
advertising, and never for determining creditworthiness or lending.
- We do not allow humans to read your data except with your explicit
consent, to debug a specific problem you report, where required by law,
or on aggregated/anonymized data.
Changes to this policy
If we materially change what we collect or how we use it, we will
update this page, change the effective date, and — for changes that
expand data collection — surface a notice in the product. We will never
silently widen the extension’s permissions.
Zhemal Khamidun — hamidunjemal@gmail.com