SmartAINewTab
DocsPrivacyTermsSupportDelete account

Privacy Policy

Privacy Policy

Local by default, with explicit boundaries for every network request, AI operation, and cloud save.

Effective / updated: August 8, 2026

Scope and single purpose

This policy applies to the SmartAINewTab Chrome extension, sync Worker, and official website. The product’s single purpose is to help users search, organize, maintain, and back up their own Chrome bookmarks. We do not sell user data or use advertising or user-profiling SDKs.

Language and IP country information

The website uses the country or region code supplied by Cloudflare at request time to choose an initial language. The code is used only to localize that response, and SmartAINewTab does not store the raw IP address. A manual language choice is stored only in browser local storage and a functional language cookie; it is never used for advertising, analytics, or profiling.

Data we process

Through Chrome’s bookmarks permission, the extension reads bookmark IDs, titles, URLs, parent folders, folder paths, and creation times. It also stores categories, groups, ordering, manual and AI tags, optional summaries, job records, bookmark health results, recovery snapshots, interface and widget settings, and user-uploaded backgrounds locally.

The Provider endpoint, model, API Key, Google session, end-to-end encryption key wrapper, and sync revision are stored in extension-local storage. The API Key is excluded from source code, exported backups, and cloud backups. Browser extension storage is not an operating-system keychain; use a separate, limited, revocable Key.

Page head metadata and favicons

When AI tagging or icon discovery needs metadata, the extension may read up to the first 96 KB of a bookmarked page’s HTML. It parses only the final URL, title, description, keywords, site name, application name, Open Graph title and description, and icon URLs. Parsing stops when the page body begins, and page-body content is not saved. Intranet, localhost, and credential-bearing URLs are skipped.

Page head and favicon requests use credentials: omit and no-referrer, so login cookies are not sent. Favicons are limited to same-origin public HTTP(S) URLs, manual redirects, a 30-second timeout, and 256 KB. Cross-site icon redirects are not followed. Failures fall back to Chrome’s internal favicon service. SmartAINewTab does not request the cookies permission and cannot read, display, or save cookies. A destination site may still log an anonymous request’s IP address, User-Agent, and time.

Data sent to your selected AI Provider

The extension connects directly to the selected OpenAI-compatible endpoint only after you configure and enable a Provider and actively use AI search, tagging, organization, or natural-language commands, or explicitly enable automatic tagging for new bookmarks. A request may include the user query or command, candidate bookmark IDs, titles, URLs, domains, folder paths, manual and AI tags, summaries, current categories and groups, category plans, and the head metadata described above. It does not include page bodies or favicon images.

The API Key is sent directly to that Provider as authentication. The Provider’s logging, training, and retention practices are governed by its privacy policy and your account settings; SmartAINewTab cannot control a third-party Provider on your behalf.

Google sign-in

After you choose to sign in, we receive a stable Google account identifier, verified email address, display name, and avatar URL. These are used only to create, identify, and display the sync account and associate encrypted backups with the correct user. SmartAINewTab does not request access to Gmail, Google Drive, contacts, or calendars and does not read your Google password. Google’s sign-in page may use Google’s own cookies; the extension receives only a one-time authorization code.

Cloudflare storage and retention

DataLocationRetention
Stable Google ID, email, display name, avatar URLD1Until the user deletes the cloud account
SHA-256 session-token hashD1Expires seven days after sign-in, then removed by the ten-minute maintenance task
OAuth state and exchange-code hashes, nonce, callback URL, extension random state, PKCE challengeD1Expires after ten minutes, then cleaned up
One-way SHA-256 rate-limit key derived from the Cloudflare connection IPD1Stored only with the OAuth flow for ten minutes; the original IP is not stored
objectKey, revision, ciphertext SHA-256 checksum, size, updatedAt, userIdD1Until the backup is replaced or deleted, or the account is deleted
End-to-end encrypted backupThe vaults/ namespace of a dedicated private R2 VAULTS bucketUntil replacement, backup deletion, or account deletion; deletion intent is persisted first and retried every ten minutes after a failure
Method, path, and error category for failed requestsWorkers LogsThree or seven days by plan, never more than seven days

Cloud backups are encrypted in the browser with AES-GCM before upload. The server does not hold the recovery password and cannot read the ciphertext. Worker invocation logs are disabled, and request bodies, bookmark content, email addresses, Tokens, and recovery passwords are not written to application logs. Cloudflare may still process IP addresses, User-Agents, and basic request metadata for transmission, security, and platform operations.

D1 Time Travel disaster-recovery copies may be retained for up to seven days on Free plans or 30 days on Paid plans. Deletion removes data from active application tables immediately. Private R2 ciphertext is deleted at the same time when R2 is available; temporary failures are retried every ten minutes by a persisted background task. Deleted D1 metadata may remain for up to 30 days in disaster-recovery copies that the extension cannot access, after which it ages out.

Cookies and authenticated rechecks

The website and extension do not set advertising or analytics cookies. Page head, favicon, network-widget, and ordinary or automatic bookmark health requests use credentials: omit. Only after restricted entries are found, and only when the user chooses “Recheck all with cookies,” reviews the URL list, and confirms again, does the extension use credentials: include for that same-origin GET recheck. The request does not follow cross-site redirects. The extension stores only status codes, final URLs, redirect chains, and error summaries—not response bodies or cookies.

Third-party processors and Limited Use

When providing a user-selected feature, data may be sent to the selected AI Provider, Google, Cloudflare, bookmarked destination sites, and public widget data sources. Otherwise, we do not sell or transfer user data to advertising platforms, data brokers, or information resellers, and do not use it for personalized advertising or credit assessment. Human access is prohibited except with the user’s explicit support authorization for specific data, for security investigations, where legally required, or for compliant anonymized aggregate operations.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

See the Chrome Web Store Limited Use policy for details.

Export, deletion, and policy changes

  • “Settings → Backup and restore → Export full backup” creates a local JSON export without the API Key, session tokens, recovery password, or cloud data key.
  • “Settings → Account and cloud sync → Delete cloud backup” removes R2 ciphertext and D1 backup metadata. A failed deletion is persisted and retried every ten minutes. New uploads are blocked during deletion, and local Chrome bookmarks are not removed.
  • “Delete cloud account” on the same page removes Google account details, sessions, OAuth records, backup metadata, and R2 ciphertext, then signs out. Permanent deletion requires a fresh Google sign-in within the previous ten minutes.
  • Uninstalling the extension or clearing extension data in Chrome removes local extension data. Users remain responsible for exported files.

See Account deletion for step-by-step instructions. If our data practices change materially, we will provide a prominent notice in the extension and this policy before collection and obtain renewed consent where required.

SmartAINewTabEvery new tab brings what matters a little closer.
DocsOpen sourcePrivacyTermsSupportAccount deletion

© 2026 SmartAINewTab

Privacy Policy|SmartAINewTab