ContextTab

Privacy

What we know about you, in full.

Short version: the map of your browsing never leaves your computer, and the only thing our server holds is the answer to “is this account paid for”. The rest of this page is that claim, itemised, so it can be checked rather than believed.

Last updated 30 August 2026. This page describes the ContextTab browser extension and the site you are reading.

The part that never leaves your browser

Everything the extension is for — which page led to which, the titles and addresses of the pages you visited, your notes, highlights, due dates, thread names and settings — is written to your browser's own extension storage on your own machine. There is no sync server for it. We cannot read it, we have no copy of it, and no request that leaves your browser contains any of it.

Deleting it is entirely in your hands: Settings → Delete all ContextTab data erases it, and so does removing the extension. Neither needs our involvement, because we were never holding it.

The part we do hold, and why

Only if you sign in. Signing in with Google is optional and exists for one purpose: so a subscription can follow you to another machine. Using ContextTab without ever signing in is a supported way to use it, and then we hold nothing about you at all.

If you do sign in, our database holds these fields and no others about you:

A salted hash of your Google account id
Your account key. Google's own identifier is never written to our disk, so a copy of our database cannot be joined back to Google profiles.
Your email address
As you typed it, plus a lower-cased copy used to tell Alice@ and alice@ apart as one mailbox. It is here so that a support message about a subscription can be matched to the subscription. It is personal data, it is included in an export, and deleting your account erases it.
Your subscription status and its dates
Trial, active, cancelled or expired; when the trial started and ends; when the paid period started and ends; whether it is set to renew; whether it is billed monthly or yearly.
Stripe's customer and subscription identifiers
So a payment can be matched to an account. The card itself never reaches us — see below.
Timestamps
When the account was created, when it last checked in, when a subscription event last arrived. Used to answer billing disputes and to expire stale sessions.
Session tokens, as hashes
A sign-in issues a refresh token; we store only its SHA-256 hash. A leaked database yields hashes, not sessions.

What is deliberately absent: no page you visited, no title, no search, no note, no highlight, no IP-address log tied to your account, no analytics profile, no advertising identifier. There is no column in which such a thing could be stored.

Google sign-in, specifically

ContextTab's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We request two things from Google and nothing else: your account identifier and your email address. We use them only to run and support your ContextTab subscription. We do not transfer them to anyone else except as needed to provide that service (our hosting and payment providers, below), do not use them for advertising, and do not allow any human to read them except with your explicit permission, for security purposes, or where the law requires it.

Payments

Payments are taken by Stripe. Your card number, expiry and security code are entered on Stripe's own page and never pass through our servers; we could not store them if we wanted to. Stripe tells us that a subscription started, changed or ended, and we write that down. Stripe is a data processor for that payment, and also a controller of its own for fraud prevention — their handling is described in Stripe's privacy policy.

Where it is kept, and for how long

On Cloudflare's platform (Workers and D1), which is where our server code and its database run. Cloudflare acts as a processor and may serve requests from a data centre near you; the database itself has a single home region.

We keep the account record for as long as the account exists. When you ask us to delete it, the personal fields are erased. A minimal record that a subscription existed, and its dates, is retained where tax and accounting law requires a payment record to be kept — typically several years — and it carries no identifier that points back at a person once the account is erased.

This website

The page you are reading sets no cookies, runs no analytics, embeds nothing from anyone else, and makes no network request to any origin but its own. There is no consent banner because there is nothing to consent to. Its content security policy forbids remote origins outright rather than allow-listing them, which is why there is no font, no tag manager and no pixel here to argue about.

Our host keeps ordinary request logs — the address requested, a timestamp, an IP address — for a short period, for security and abuse prevention. They are not joined to any account.

Your rights

If you are in the UK, the EU or another place with comparable law, you have the right to a copy of your data, to correct it, to have it erased, to restrict or object to its processing, and to complain to your data protection authority. Because the browsing map is on your own machine, most of those rights are exercised there directly — but for the account record we hold, write to privacy@context-tab.com and we will answer within 30 days. Ask for an export, or for deletion, and you will get it; there is very little to send, which is the point.

Our lawful bases: performance of a contract, for running a subscription you asked for; legitimate interests, for keeping the service secure and preventing abuse; and legal obligation, for the payment records tax law requires. We do not rely on consent for anything, because we do not do anything that would need it.

Children

ContextTab is not directed at children and we do not knowingly create accounts for anyone under 16. If you believe a child has signed in, write to privacy@context-tab.com and the account will be removed.

Changes

If this page changes in a way that affects what we hold or why, the date at the top changes with it and anyone with an account is told by email before it takes effect.

Contact

ContextTab · privacy@context-tab.com for anything on this page, support@context-tab.com for everything else. The operator's registered details are available on request at either address.