Website privacy
Website privacy notice
What happens to personal data when you visit the Tab Organizer website, including hosting logs, functional cookies, and optional uninstall feedback.
Switch to DeutschWebsite privacy
What happens to personal data when you visit the Tab Organizer website, including hosting logs, functional cookies, and optional uninstall feedback.
Switch to DeutschThe controller for the processing described here is:
The provider is an individual established in Switzerland. Email is the channel published here for all data protection enquiries. The applicable Swiss law is the Swiss Federal Act on Data Protection (FADP).
This notice applies to visits to www.taborganizer.app. Processing inside the Tab Organizer browser extension is described in the separate extension privacy notice, because the extension runs in your browser and the website has no access to it.
The website has no user accounts, no login, no advertising, no analytics or reach measurement, no social media plugins, no embedded videos, and no external fonts, maps, or chat widgets. It does process the data described below. This notice therefore does not claim that no personal data are processed.
The provider is established in Switzerland and has no establishment in the European Union, so the General Data Protection Regulation can reach this processing only through its Article 3(2)(a), that is only if the website and the extension are offered to people who are in the Union.
The facts that bear on that question are these. The extension is published in the Chrome Web Store without country restriction and can therefore be installed anywhere in the Union. Its interface is translated into nineteen languages, German among them. The Store description advertises that the grouping rules recognise regional sites and gives German consumer email services as its examples. This website publishes a complete German-language version of every page, including this notice. That the product is free of charge does not matter for Article 3(2)(a).
On those facts the provider does not treat the Regulation as inapplicable. This notice is written so that it also gives the information required by Articles 13 and 14, a legal basis under Article 6 is stated for each processing operation described below, and the rights in Articles 15 to 22 are honoured for visitors in the European Economic Area. Where this notice says "where the GDPR applies", it is marking that the point depends on where you are, not reserving the question of whether the Regulation is capable of applying at all.
Article 27 requires a controller in this position to designate a representative in the Union unless the exception in Article 27(2) applies. At the date of this notice no representative has been designated. You can reach the provider directly at the email address above, and the supervisory authority of your country of residence or workplace remains available to you.
The website is delivered by Netlify, operated by Netlify, Inc. in the United States. Every page, image, and script you load produces a request to that infrastructure, which processes the data technically needed to answer it. These data typically include:
This processing is necessary to deliver the site, to keep it stable, to diagnose errors, and to detect and defend against attacks and abuse. The provider relies on its overriding interest in operating a secure and functional website; where the GDPR applies, the legal basis is Article 6(1)(f).
Netlify processes these data on the provider's instructions as a processor, under the data processing agreement that forms part of its subscription terms. Netlify engages its own subprocessors for content delivery and platform operation. Its network is a distributed edge, so the first place your request is handled is normally an edge location near you rather than a single central server; the recipients section sets out what can and cannot be stated about the countries involved.
The provider does not keep a separate copy or long-term archive of these request logs and does not combine them with other data to build visitor profiles.
Only the website-documented edition of the extension, which Google is not distributing, makes these requests; the package the Chrome Web Store is currently distributing makes neither of them. That package contains no address on this website at all: it opens no page here after installation and registers no address for your browser to open after removal, as the extension privacy notice sets out for the artifact it examined. So if you installed from the Store, nothing in this section describes your installation or your removal.
In the website-documented edition, two product events cause your browser to open a page on this website, and therefore produce ordinary website requests as described above:
The two addresses are not the same shape, and this notice states them separately rather than describing them together.
en or de is information about your browser, and this website's infrastructure sees it in the requested path along with the ordinary request data listed above.https://www.taborganizer.app/uninstall. It carries no language segment and no other variable part, and this website resolves it to the English page for every visitor; the German version is reached only if you then follow the language link on that page, which stores no preference.Neither address carries a query string or a fragment, and neither carries a version, an installation identifier, a tab count, or any other information about your browser state.
Because the first of these pages opens by itself rather than because you clicked something, the request it produces is an event that correlates in time with your installation. The same applies to the feedback page and your removal of the extension. What the hosting infrastructure receives in each case is the ordinary request data listed above.
The website sets three first-party cookies. Each one is written only when you actively make the corresponding choice, none of them contains an identifier, and none of them is used for advertising, analytics, or tracking:
| Cookie | Written when | Content | Kept for |
|---|---|---|---|
to-theme-v1 | you switch between the light and dark appearance | the selected appearance | up to 1 year |
to-locale-v1 | you switch the language | the selected language | up to 1 year |
taborganizer_tutorial_seen | you explicitly ask the setup guide to remember that you finished it | a schema version, the opt-in, and the time of the decision | up to 180 days |
The appearance and language controls state at the control itself that the choice will be saved on this device for up to one year, so you have that information before anything is stored. The setup-guide marker is written only after you tick its opt-in.
Because all three cookies are set with a site-wide path, your browser sends them with later requests to this website. The server reads the appearance and language values so the first rendered page already matches your choice. They are not read for any other purpose. The uninstall page is the one exception, and it is described below.
Why there is no cookie banner. In the European Economic Area, storing information on your device needs your consent under Article 5(3) of the ePrivacy Directive unless the storage is strictly necessary in order to provide a service that you have explicitly requested. Each of these three cookies is written only as the direct result of a request you make — you switch the appearance, you switch the language, or you tick the box asking the guide to remember your progress — and each one does nothing except carry out that request. The provider relies on that exemption. The absence of advertising, analytics, and tracking cookies is a separate fact and would not on its own be a sufficient reason: the test is whether the storage is strictly necessary for a service you asked for, not whether it is used for tracking.
You can refuse and delete these cookies at any time in your browser settings, and the setup guide has its own control to clear the completion marker. The website remains fully usable without them; it then falls back to the light appearance and to the language your browser requests.
Apart from these cookies, the website stores nothing on your device beyond the ordinary browser cache. It does not read or write extension storage, and it cannot see your tabs.
No web font is loaded. Pages render in fonts already installed on your device. Images, styles, and scripts are served from this website only. A strict content security policy blocks third-party scripts, frames, and connections.
After you remove the extension, your browser opens a page where you may — entirely optionally — tell the provider why. No feedback response and no feedback record is created or sent unless you submit the form. Opening the page is not nothing, though: it is itself a request to this website, with the ordinary request data described above, and an appearance or language you chose on an earlier visit is still sent with it, for the reason set out in the next paragraph. The form asks for no email address and no account, and the page runs no tracking.
The page and cookies. This one page carries no appearance toggle and no language picker that stores a preference, and the server does not read the appearance or language cookie when rendering it. Displaying the page and submitting the form therefore write no cookie and make no use of a stored preference. What this does not mean: the two preference cookies are set with a site-wide path, so if you chose an appearance or a language on this website earlier, your browser still sends those values with the request. Preventing that would mean giving up the appearance being correct on the first painted page across the whole site. The accurate position is that this page stores nothing and reads nothing, not that no cookie can reach the infrastructure.
What your browser sends when you submit. The submission carries the reason category you selected from a fixed list; your optional free-text comment, limited to 1,000 characters and stripped of control characters; the language of the page; a schema version number; a signed token that the page embedded when it was rendered, which shows that the submission came from a page this website served and was not filled in implausibly fast; and one hidden field that the visible form never fills in, which automated submissions give away by completing it. The application also carries a seam for a managed challenge. In the code it is inert unless a deployment supplies both a verification address and a secret for a challenge provider; where it is active, a challenge response token is sent with the submission and exchanged with that provider. This notice names any challenge provider that is in use, in the recipients section, and is updated before one is switched on. None is named at the date of this notice.
What is checked and then discarded. The signed token and the hidden field are evaluated during the request and are not stored. The address of your connection is used for the rate-limit counter described below and is not stored. Server-side validation rejects any submission that contains a field other than those listed above.
What is kept. The record that leaves the request has five items: the schema version, the reason category, the sanitised free text, the language of the page, and the calendar date of receipt without a time.
What is never there at all. The submission has no field for a tab title, a tab address, a browsing-history entry, an installation identifier, a device identifier, a user-agent string, or a stored IP address. Because the schema rejects unknown fields, none can be added by a later submission without a change to this notice.
About the free-text field. The service does not ask you for identifying details, but a free-text field cannot be anonymous by design. Anything you type is stored and read, so please do not enter your name, email address, telephone number, addresses of pages you visited, other identifiers, or information about other people if you do not want that submitted. If you would like a reply, or if you would like a submitted comment deleted, write to the email address above instead.
Rate limiting. To keep the form usable without a captcha, the server counts submissions per connection over a rolling window, and that window is one hour. For that purpose the connection address is held only in server memory, as a digest with a random salt generated afresh each time the process starts. It is never written into the stored record. A digest of an IP address reduces exposure and prevents entries from being correlated across restarts; it is not irreversible, because the set of possible addresses is small enough to test candidates against.
What that counter holds, and for how long, is a concrete retention period and is stated as one rather than left to an unspecified criterion. The salted source digest and the timestamps of its submissions stay in the memory of the single serverless function instance that handled them for a rolling one hour — or less, because such an instance can end at any moment and takes its memory with it. Timestamps that have aged out of the window are discarded the next time the limiter runs, so an entry can sit unused a little past the hour if no further submission arrives before the instance ends. Nothing of this is shared between instances, and nothing of it is written to storage.
Where the record goes. An accepted record is delivered by one of two paths, and which one applies is a matter of deployment configuration rather than of the code alone:
The purpose is to understand why people stop using the extension and to improve the product. The provider relies on its interest in improving its own product; where the GDPR applies, the legal basis is Article 6(1)(f), and submitting the form is voluntary in every case.
If you write to the provider by email, the message, your email address, and its content are processed to handle your enquiry, and kept as long as needed for that and for any follow-up questions or legal record-keeping. Where the GDPR applies, the legal basis is Article 6(1)(f): the provider's interest in answering an enquiry addressed to it, and your own interest in receiving an answer. Article 6(1)(b) is not relied on for this, and the reason is the one the extension privacy notice gives for not relying on it there — the provider has not established a contract between you and it, relies on none, and does not treat an email about a free product as a step taken at your request before entering into one. Where your message is a request the law requires the provider to answer, such as a request for information or for deletion, the processing needed to handle it rests on Article 6(1)(c) as well.
The mailbox for the published address is hosted by Proton Mail, a service of Proton AG in Geneva, Switzerland; this can be verified from the public mail-exchange and sender-policy records of taborganizer.app. Proton AG is a Swiss company subject to the same Swiss data protection law as the provider, and it publishes the processors it engages and the countries in which they process data in its own privacy policy. Email is transported over the internet and, depending on the parties involved, may not be end-to-end encrypted.
Personal data are not sold, rented, or shared for advertising purposes. Data are disclosed to authorities only where the provider is legally obliged to do so. The recipients are:
Netlify, Inc., United States — hosting, edge delivery, and platform logs. Four questions are answered separately here, because they have different answers and running them together would produce a false one.
Which company is the recipient. Netlify, Inc. is established in the United States. The contract, the data processing agreement, and the corporate recipient of the disclosure are American, and a disclosure to Netlify is therefore a disclosure abroad.
Where Netlify's own subprocessors say they are. Netlify publishes a subprocessor list, described immediately below, and every entry on it gives the United States as its location. That is a statement about those companies' stated locations, taken from Netlify's list. It is not a statement about where a request to this website is physically handled.
Where a request is actually handled first. Netlify describes its network as a global edge: sites are deployed to worldwide edge locations, and its documentation for dynamic processing at the edge says it runs from the worldwide network edge location closest to each user. The address of your connection and the metadata of your request are necessarily processed by the edge that receives them, which is ordinarily the one nearest to you — so for a visitor in Europe that first step ordinarily happens in Europe, not in the United States. Netlify publishes no list of its individual points of presence and no allocation of them to a particular site, and the provider does not state one it cannot read. So the provider does not claim a single receiving state for this chain. What it states is this: the corporate recipient and every listed subprocessor location are in the United States; the edge processing that precedes them is geographically distributed across countries that Netlify does not publish individually; and that limitation is Netlify's published position, not an omission the provider has chosen.
Where the feedback function runs. The serverless function that receives the uninstall-feedback form runs in a region that the customer selects. Netlify's function configuration documentation states that the region is configurable, that an unset region falls back to a documented default, that projects created before 4 October 2023 may carry a different default, and that the value in force has to be read from the project's own configuration. Three things follow, and this notice states all three rather than closing the gap between them.
First, this website's repository contains no platform configuration file and sets no function region, so the value in force is not a fact about the published source and cannot be established from it. Second, the value is not published in what the platform sends you either: the provider examined the live responses for this website, and they identify the platform — server: Netlify, a Netlify edge cache status, and a Netlify request identifier — without naming any function region. Third, the provider does not publish it as verified and names no region here. It will not state the documented fallback as though it were this deployment's answer, because that would put a country in a statutory transfer disclosure on the strength of a default the provider has not confirmed applies. What the notice states positively is what is established: the corporate recipient is established in the United States, every location on the current subprocessor list is the United States, the transfer basis and safeguards set out below cover Netlify's processing wherever it takes place, and the edge step that precedes the function is geographically distributed across countries Netlify does not publish individually. Where the information stops, this notice says so. If the country in which that one processing step runs matters to you, ask at the address above and you will be told what the deployment holds.
Safeguards. Netlify states in its trust centre that it participates in the EU–U.S. and Swiss–U.S. Data Privacy Framework. Netlify's data processing agreement provides that a transfer restricted by the GDPR or the UK GDPR takes place on the basis of the EU–U.S. Data Privacy Framework or its UK extension, and, where that does not apply, on the European Commission's standard contractual clauses, with Module Two applying where the customer is a controller; and that for a transfer protected by Swiss law the same standard contractual clauses apply, with the Federal Data Protection and Information Commissioner as the competent supervisory authority and Swiss law as the governing law. For Swiss law the provider relies on those clauses; the Swiss Federal Council additionally recognises an adequate level of protection for personal data processed by organisations certified under the Swiss–U.S. framework.
Netlify's subprocessors. Netlify engages further processors for platform operation and content delivery, and publishes the current list at netlify.com/legal/subprocessors, which resolves to its trust centre. When the provider retrieved that list on 20 August 2026 it held twenty-two entries and gave the location of every one of them as the United States. Disclosures to those subprocessors are therefore disclosures to the United States, on the transfer basis set out in the paragraph above. That says nothing about the countries in which Netlify's own edge handles a request, which is the separate question answered above.
The list states a role for each entry rather than saying which of them touches which customer's data. The roles that bear on delivering a website and handling its logs are hosting, compute, storage and backup; a further infrastructure provider, named as Google Cloud Platform; serverless computing; database, data services, warehousing and business intelligence; log analysis, error reporting and analytics; identity and access management; and feature flagging. The remaining entries are given as customer relationship management, email for support correspondence, and AI services. Netlify does not publish a breakdown of which subprocessor processes which customer's data, and the provider cannot establish one from outside, so it does not assert a breakdown here. On what Article 19(4) FADP and Article 13(1)(f) GDPR ask for: for the disclosure to Netlify, Inc. and to every entry on its list, the receiving state is the United States and the safeguard is the one set out above; for the distributed edge step, the countries are the ones in which Netlify operates edge locations, which it does not publish individually, and the safeguard is the same data processing agreement, which covers Netlify's processing wherever it takes place. Where the information stops, this notice says so rather than closing the gap with a guess.
Two limits are worth stating. One entry, for hosting, compute, storage and backup, appears on the list without a rendered company name; the same trust centre states separately that Netlify is hosted on Amazon Web Services and on Google Cloud Platform. And the list is Netlify's to change. The date above is the date the provider read it; it is re-read when this notice is reviewed and at least once a year, and a change of receiving state is a reason to update this notice. Netlify's data processing agreement obliges it to impose data protection obligations on every subprocessor that are no less strict than its own, and to verify compliance.
Proton AG, Switzerland — email. For messages you send to the published address, as described above. This is not a disclosure abroad.
Feedback intake — Infomaniak Network SA, Switzerland. This website's production deployment sends each accepted feedback record to Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Acacias, Switzerland, which hosts the provider's kChat workspace. Infomaniak acts as a processor under its published data-processing terms (Art. 9 FADP / Art. 28 GDPR). Infomaniak states, on its data-protection pages, that it stores the data entrusted to it in data centres in Switzerland that it develops and operates, and that it does not transfer those data outside its own infrastructure. The provider retrieved that statement on 23 August 2026. A disclosure to Infomaniak is a disclosure to a recipient in Switzerland. For Swiss law that is not a disclosure abroad. Where the GDPR applies, Switzerland is a country for which the European Commission has adopted an adequacy decision, so the disclosure is not a transfer to a third country that lacks an adequate level of protection.
The payload posted to that workspace is the five-item record described above. It does not include the connection address, the signed token, or the hidden field. Infomaniak retains a channel message for as long as that hosted service keeps it, until the provider deletes it. If the provider takes a copy in order to evaluate the feedback, it keeps that copy only as long as needed for the product-improvement purpose and then deletes it.
Managed challenge. The application still carries a seam for a managed challenge. This notice names any challenge provider that is in use, and is updated before one is switched on. No challenge provider is named at the date of this notice.
Request logs. Kept by the hosting provider for the limited period needed for operations, error diagnosis, and security, and then deleted or overwritten as part of normal platform operation. The provider keeps no separate copy.
Feedback records. On the default path, with no intake configured, the record's lifetime in the platform log is the platform's log retention period described above — at least 24 hours and up to 7 days depending on the plan — and the provider can neither extend nor shorten it for an individual entry. This notice gives that documented range rather than one number because the tier in force on the deployment is a subscription fact the provider does not publish here, and the range is the honest outer bound of it. On this website's production deployment, the record is sent to Infomaniak as described above. The provider keeps any copy it takes only as long as needed for the product-improvement purpose and then deletes it, and it can delete the corresponding kChat message. If you ask for a comment you submitted to be deleted, the provider can delete the copy it holds and the message in that workspace. It cannot reach into a Netlify function log before the platform's period expires, for any record that still took that path.
Rate-limit state. The salted source digests and submission timestamps described under the feedback form are kept in the memory of one serverless function instance for a rolling one-hour window, or less where that instance ends sooner. They are never persisted, never copied elsewhere, and never joined to a stored feedback record. There is accordingly no store from which a single entry could be deleted on request; the period above is the whole of their lifetime.
Email correspondence. Kept for as long as the matter and any statutory retention duties require.
The provider does not state a fixed number of days where a third party operates the storage and publishes none; in those places the criterion above is what applies.
The website is served over HTTPS with HTTP Strict Transport Security. It sends a content security policy that blocks third-party scripts and frames, sets X-Content-Type-Options, Referrer-Policy, a restrictive Permissions-Policy, and frame-ancestor restrictions, and it restricts form submission to its own origin. The feedback endpoint validates every submission against a strict schema, rejects unknown fields, and applies rate limiting. No transmission over the internet can be guaranteed to be completely secure.
Under Swiss law, and where the statutory conditions are met, you can:
Data release and transfer under Article 28 FADP. Swiss law gives you a right to have the personal data you provided released to you in a common electronic format, and to have them transferred to another controller where that takes no disproportionate effort, free of charge. That right applies where the provider processes the data by automated means and processes them either with your consent or in direct connection with the conclusion or performance of a contract between you and the provider.
The provider does not decide that question against you in advance. Feedback is data you supply yourself, deliberately and voluntarily, and it is processed automatically; whether a particular submission also carries your consent for the purposes of Article 28 is a question to be answered on the facts of your request, not settled here by the label the provider puts on its own legal basis. Ask, and the provider will assess it and comply where the conditions are met.
Request logs are a different case, and the reason matters, because the obvious reason is the wrong one. It is not that you did not type them: the implementing ordinance provides that data the controller has collected about you and your behaviour in the course of using a service or a device count as data you disclosed (Article 20(1)(b) DSV), so observed request data are inside the scope of supplied data rather than outside it. Nor is it that the provider keeps no copy of its own: Netlify holds those data as processor on the provider's behalf, which is processing for which the provider is responsible. What ordinarily keeps the right from attaching to them is the second statutory condition. Those data are processed on the provider's overriding interest in delivering and securing the site: no consent is collected for them, and the provider has not established a contract between you and it in connection with which they would be processed and relies on none, so on that footing the condition Article 28 requires alongside automated processing is ordinarily not met. That is the provider's position on the statutory test rather than a decision taken against you by declaration; whether a contract exists between you and the provider is a question of contract formation that this notice does not settle. Data the provider would generate by its own evaluation of supplied or observed data are outside the right in any event (Article 20(2) DSV). If you consider the conditions met for a particular operation, say so and it will be assessed.
The practical limit is real, and it is worth knowing before you write. A stored feedback record carries no account, no identifier, and no time of day — only a reason category, your free text, the page language, a schema version, and the calendar date. So the provider will often be unable to tell which record is yours. Anything you can give it helps: the wording you used, the reason you picked, the language of the page, the day you submitted. Where a record genuinely cannot be matched to you, the request fails for that reason, and this notice says so rather than denying the right in principle.
Where the GDPR applies you have, in addition and on their own terms, the rights of access, rectification, erasure, restriction of processing, objection, and data portability under Articles 15 to 21, and, where processing rests on consent, the right to withdraw it at any time under Article 7(3) without affecting processing that has already taken place.
Use the email address above. Please describe what you are asking about; without a reference point, the provider usually cannot connect a request to a specific record, because the data described here contain no account and no identifier that would let it find you.
The Federal Data Protection and Information Commissioner supervises private controllers in Switzerland. You may report a processing operation to the Commissioner if you believe it breaches data protection rules. The Commissioner opens an investigation where there are sufficient indications of a breach, and informs you of the steps taken and the outcome of any investigation if you made the report (Article 49 FADP). That is a supervisory procedure conducted in the public interest: it is not a claim you win, and the Commissioner does not award you a remedy. Correction, deletion or destruction, a prohibition of processing or of disclosure, and any claim for damages or satisfaction are asserted against the provider directly and, if that does not resolve the matter, in the civil courts.
Where the GDPR applies, you may in addition lodge a complaint with the supervisory authority of your country of residence, your place of work, or the place of the alleged infringement under Article 77, and you have a right to an effective judicial remedy under Article 79.
The website is aimed at people who manage browser tabs, not at children. The provider does not knowingly collect personal data from children and asks that no data about children be entered in the free-text field.
This notice is updated whenever the described processing, the services used, or the legal requirements change. The current version and its effective date are shown at the top of this page.