What TabAtrium stores, where it is stored, and how to get rid of it.
Last updated 17 September 2026
In shortYour bookmarks, and how to sign in.Titles, URLs, groups and tags are stored in your account so every browser you sign in to shows the same board — plus the email or Google account you sign in with.
In shortNot your browsing.No history, no record of the pages you open from the board, no look at your other tabs. Only the links you saved or imported.
In shortNo ads, no analytics, no tracking.We do not sell your data or record which bookmarks you open. Export or delete everything whenever you like.
01
What this covers
TabAtrium is a browser extension that replaces your new tab page with your own bookmarks.
Your bookmarks are stored in your TabAtrium account so that every browser you sign in to shows the same board. That means they are uploaded to our server and sent back to your other devices.
We do not sell your data, show ads, or run analytics or tracking of any kind.
02
What stays on your device
The extension also keeps the following in your browser's local extension storage, so the page works offline and opens instantly. This part is not sent to us.
A copy of your board — the bookmarks, groups and tags last synced to this browser.
Display preferences — theme, background, which group is selected, which groups are collapsed.
A cache of site icons — favicons, stored as images per domain.
After you sign in — your session token and the name, email address and profile picture URL from your account, so the page can show who is signed in.
03
What our server stores
Your bookmarks. For each link: page title, URL, the group it belongs to, any tags you add, and its position on the board. This is what makes the same board appear on your other devices.
Your account. Your email address, and — if you sign in with Google — your Google account identifier, display name, profile picture URL, and the times the account was created and last used.
Your sessions. For each signed-in browser we store a one-way hash of the session token — never the token itself — with creation, expiry and last-seen times.
Sign-in attempts. While a Google sign-in is in progress we store a random state value, a random nonce and the browser address to return you to. These rows are deleted as soon as the sign-in finishes, and in any case within fifteen minutes. For an emailed sign-in link we store the address it went to, one-way hashes of the link and of the key the extension collects the sign-in with, and, once you confirm, which account it signed in.
Web server logs. Like any website, our server logs each request: IP address, browser user agent, the requested address, the referring address and a timestamp.
What we do not store: your browsing history, the pages you open from the board, and your other tabs. Bookmarks reach our server only because you saved or imported them.
04
Requests the extension makes to other websites
When you save a bookmark, the extension asks that website directly for the page title and its icon, so the bookmark looks right on your board.
Those requests go from your browser to that website, not through us, and they are sent without cookies or credentials. The website you bookmarked sees a request from your IP address, as it would if you visited it.
05
Browser permissions
Storage — to keep everything listed above in your browser.
Active tab — when you open the toolbar popup, the extension reads the current tab's address and title so it can offer to bookmark it. Nothing is read while the popup is closed.
Access to websites — to fetch page titles and icons for the pages you bookmark.
Bookmarks, optional — only if you choose to import your browser's existing bookmarks. It is requested at that moment, used to read them once, and never used to change them.
06
Signing in by email link
If you sign in with an email address, we store that address and send you a link that signs you in. There is no password to set or remember, and we never ask for one.
While a link is outstanding we keep a one-way hash of its single-use token, which stops working once it is used or after two days. After you confirm, the record stays for thirty days so the browser that asked for the link can still pick up its sign-in. The email itself is sent by our mail provider, which sees your address and the message.
07
Signing in with Google
Sign-in uses Google. We ask Google only for your basic profile: your account identifier, email address, name and profile picture. We never see or handle your Google password.
What Google does with the sign-in is covered by Google's own privacy policy. TabAtrium's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Your bookmarks — until you delete them, or until you delete the account they belong to.
Account data — until you ask us to delete it.
Sessions — until you sign out, or 180 days after they were last used. Using the extension keeps its session alive.
Sign-in attempt data — minutes for a Google sign-in; up to two days for an unopened email link, and thirty days after it was confirmed.
Server logs — a short period. Log files rotate, and only the seven most recent are kept.
Anything stored in your browser — until you remove it or uninstall the extension.
09
Your choices
Export. The extension's settings screen exports every bookmark to a standard HTML file that any browser can read.
Sign out. Signing out deletes the session on our server and the copy in your browser.
Delete your account. Email us and we will delete your account, its sessions, and the bookmarks stored with it.
Access or correction. Email us and we will tell you what we hold about you, or correct it.
Uninstall. Removing the extension clears everything it stored in this browser. Your board stays in your account until you delete it, so signing in elsewhere brings it back.
10
Who processes your data
The service runs on a single rented server in Europe. We do not share your data with anyone else, apart from Google as part of a Google sign-in you asked for, and our mail provider when we send you a sign-in link. We do not transfer it outside our hosting provider.
11
Children
TabAtrium is not directed at children under 13, and we do not knowingly create accounts for them.
12
Changes
If this policy changes, the date at the top changes with it.
Material changes — in particular anything that would widen what we store or who can reach it — will be announced in the extension before they take effect.
13
Contact
Questions, deletion requests, access or correction requests — all to info@tabatrium.com.