# TabEver privacy disclosure

TabEver stores the URL, title, language, a short page summary (up to 600 characters), first capture time and last visit time of eligible HTTP/HTTPS pages in the extension's local IndexedDB. Local semantic vectors are derived from the title and summary. It does not read the Chrome history database, record form inputs, use analytics, or upload page content or queries to an AI service.

Privacy mode and the mature content filter are both on by default, including when upgrading from a version without these settings. Local rules filter recognized disease/health searches, personal health and account/financial/identity/private-message content, and recognized adult content, gambling, graphic violence and self-harm instructions. The classifier transiently considers the full address, title, summary, at most 2000 characters of visible main-page text, and boolean signals for visible password, payment and identity fields or page ratings. It never reads form values. The extra text, full query, rating and rule history are not saved; a rejected new page is not inserted into the archive. If an existing page later becomes sensitive, only two category flags may be added to that existing record. No third-party classifier or remote service is involved.

These are best-effort local rules that only decide what TabEver saves. They are not comprehensive content moderation, a medical judgment, age verification, website blocking or a parental control tool. Unknown wording, content outside the bounded text and pages without recognizable signals may be missed; titles, summaries and pathnames can still contain personal information. Use domain exclusions or pause capture for additional control. Existing matched pages are hidden from results, counts, indexing and exports while the corresponding protection is on; they are retained until normal retention or user deletion, rather than silently deleted by a protection switch. Turning a mode off can make its retained pages visible again and permits new matching captures. Backups made while protection is off may contain category flags; restoring a backup cannot clear an existing true flag. Only a fresh permitted live capture can reassess it.

Capture is enabled by default for supported pages. You can pause capture, exclude domains (including their subdomains), delete one page or clear the archive. Adding an exclusion also deletes already archived pages for that domain. The default retention is 90 days, configurable from 7 to 3650 days. Expired pages are removed at startup and periodic maintenance; this is not an exact wall-clock deletion guarantee. Incognito access is disabled. Saved URLs retain only origin and pathname; query parameters and fragments are omitted. The only exception is the single page-identifying parameter on YouTube watch and playlist pages (`v`, `list`), Hacker News items (`id`) and Taobao/Tmall item pages (`id`), kept only when it is a short value of letters, digits, `-` or `_`. Other sites whose page identity is encoded in a query or fragment may not reopen exactly. Personal information in pathnames and page text is not automatically anonymized. A deleted page is suppressed in its currently open tab until navigation to another path or closing that tab; a later visit can be captured again.

Semantic search uses fixed multilingual embedding and relevance models packaged with the extension (approximately 387 MB of uncompressed model weights, tokenizer data and configuration, excluding executable JavaScript and WASM). All executable JavaScript and WASM, model weights and tokenizer data are local extension files. The extension runtime does not download model assets from a server and does not transmit page summaries or search queries. Preparing smart search initializes the embedding model; the relevance model initializes on the first search. Initialization can take a few seconds and uses local CPU, GPU and memory. Some embedding failures permit keyword matches; other search failures show an error. Chrome's extension installation and update services handle normal package delivery; they are not AI inference endpoints. Cached model files may be retained separately from the archive; clearing archived pages does not remove these model files. Chrome extension removal or clearing extension site data removes local extension data. No account or cloud sync is provided.

JSON export is initiated by you, after confirmation. Large archives are split into independently restorable files of at most 5000 pages and 5 MiB each. Restore each part to recover the whole archive. The files contain readable URLs, titles, summaries and timestamps; treat them as private and share them only intentionally. Exported files are outside TabEver's control and are not removed by clearing the archive. The downloads permission saves these user-requested backup and context files, checks each returned download ID for completion, and waits for one file to finish before starting the next. Split exports open a separate download tab so closing the action popup does not stop the queue; keep that tab open until all parts complete. TabEver does not read unrelated download history.

Result site icons use Chrome's local favicon service. The current page URL is used transiently to look up its cached icon; a bounded PNG image is stored with the sanitized archive record so the icon remains available after closing the page or restarting Chrome. Query parameters and fragments are not stored with the icon. Icons are omitted from backup and context exports. TabEver does not fetch website icon URLs or send archive URLs to a third-party icon service. Missing icons use a bundled placeholder. Opening a result navigates Chrome to that website as a normal browser visit.

Free JSON backup restore and Pro bookmark HTML import are initiated by selecting a local file. The file is parsed locally; only supported HTTP/HTTPS pages are imported, subject to your current protection modes, exclusions and retention period. Newer existing records are preserved. Backup settings are included for reference and are not automatically applied on import. Bookmark import reads links and titles, not full page content or Chrome's complete browsing history. Pro context export produces a local Markdown file containing the same visible archive data, plus source and timestamp information and an untrusted-content warning.

Pro authorization uses an offline signed code, stored in Chrome's local extension storage. Activation and paid operations verify the signature locally using bundled public keys. The signing private key is never shipped. Authorization codes are not included in archive backups or context exports. No license telemetry or online account is provided. A configured purchase link opens the external payment provider only when you click it; that provider's own terms and privacy policy apply. This build has no configured checkout link. Offline permanent authorization cannot immediately detect a refund or online revocation.

Uninstalling, changing the extension ID, deleting the browser profile, or clearing extension data can remove access to the archive. Export before such operations.

The interface uses English by default and supports English, Chinese, German, French, Japanese, Spanish, Korean, Portuguese and Arabic. You can choose another supported language or follow Chrome's UI language in Settings. A saved preference affects TabEver only. Its language setting does not change the browser language or route data to a translation service. Search scoring runs locally and can rank results imperfectly. Support contact: brucehforai@gmail.com.
