Privacy policy
Version 0.0.1. Effective date: October 8, 2026. This document covers the Tabvenir 0.0.1 extension. Contact: service@tabvenir.com.
One purpose: save selected pages
Tabvenir reads open-tab titles and addresses to display your choices, save source links, recover batches and verify whether a saved tab can safely close. It reads selected page content when you start saving. Page text, image addresses, extraction warnings, batch records and the archive index are processed on your device. We do not receive this reading data, sell it, use it for advertising or collect extension analytics.
Local storage and retention
Settings are stored in local browser extension storage, without browser sync. Batch records, article data needed for recovery and image retries, directory handles and archive records are stored in local IndexedDB. ZIP packaging may also use a browser-private temporary file. Completed automatic ZIP downloads clear their staged payload and temporary output. Paused tasks and unconfirmed exports expire after seven days of inactivity; manually confirmed ZIP payloads remain available for seven days after completion.
Reports and archive records remain locally until cleared or the extension is uninstalled. Exported Markdown, images and ZIP files remain in the location you chose. Deleting extension data does not delete your exported files.
Requests to original websites
Saving or retrying images contacts the original website or image host. Those hosts receive ordinary request information such as your IP address and the requested image URL. Cross-site image requests omit cookies. Same-site images may use browser-managed existing cookies when enabled in settings. Credentialed image requests do not follow redirects; a failed request may be tried without cookies. Referer fallback applies only to this extension’s own image requests when needed. Failed images may remain as remote links in the exported note; opening those links or displaying them in another application can contact the original host.
Image URLs on unrelated private-network hosts are filtered before direct requests; final response URLs are checked again. URL filtering cannot verify DNS resolution and is not a guarantee against every network behavior. When you approve reloading a discarded or sleeping tab, the browser makes that page’s normal request using its existing login state.
Permissions and your choices
Site access is requested separately after explaining its purpose. HTTP and HTTPS access supports saving pages and images from different hosts. Article content is read only for a user-started save or retry. Folder access is limited to the folder you choose. Download-management permission is optional; it verifies that a ZIP download completed. Without it, you download and confirm the saved ZIP yourself.
You can revoke site or download permission in the browser, change the save folder, disable automatic tab closing, change same-site cookie settings, clear archive records and clean expired staging in settings. Pinned tabs, unsafe pages and failed saves are kept according to the safety checks and your batch choices.
Diagnostics and verification exports
Diagnostics are optional, generated locally and previewed before download. Diagnostic exports contain aggregate states and recognized error codes, without page titles, URLs, file paths, article HTML, cookies or tokens. There is no automatic upload. The separate file-verification export includes relative filenames and hashes so you can check your own output; inspect it before sharing.
Support and deletion requests
If you choose to email us, your email provider processes that message and we receive what you send. We use voluntary correspondence to respond, do not add you to a marketing list and delete support information when no longer needed. You can request access, correction or deletion of information you sent to service@tabvenir.com. Data kept only on your device is controlled through the extension, browser and exported files.
Limited Use
Tabvenir follows the Chrome Web Store User Data Policy, including its Limited Use requirements, for information received through Google APIs. Browsing information is used only for the disclosed saving, recovery and safety-checking functions. It is not sold, transferred for advertising or sent to a developer-hosted parsing service.
No hosted AI, cloud-sync, account or payment service is included in this version. New data practices will be disclosed before new features are used. This packaged policy is available offline; it does not replace the publicly accessible policy URL required for a store submission. A public website must separately describe its actual hosting, logs and tracking practices.