Privacy Policy
Last updated: February 8, 2026
BaseTab ("we", "us", or "our") operates the BaseTab Chrome extension and the basetab.ai website. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and profile picture from your authentication provider (Google or email sign-in). This information is stored in our database to identify your account.
Workspace & Widget Data
We store the content you create within BaseTab, including workspaces, widgets, and their configurations. This includes bookmarks, notes, to-do items, kanban boards, calendar events, routines, whiteboard drawings, and any other widget content. This data is synced to our servers so you can access it across devices.
Third-Party Integrations (Optional)
BaseTab allows you to connect third-party services such as Google Calendar and Gmail through widgets. For these integrations:
- You provide your own API credentials. We do not supply or have access to API keys, client IDs, or client secrets. You create your own credentials through the respective service's developer console and enter them into the widget settings.
- Google Calendar — Uses
calendarandcalendar.eventsscopes to read, create, and edit your calendar events. - Gmail — Uses
gmail.modifyandgmail.sendscopes to read, send, and manage your emails.
All OAuth tokens, API credentials, and third-party data are stored locally in your browser's encrypted storage (chrome.storage.local) and are never sent to our servers. Data from third-party services is fetched directly by the extension and is not transmitted to or stored on our servers. The same model applies to any future third-party integrations.
Local Browser Storage
The extension caches data locally in your browser using IndexedDB and localStorage for offline access and performance. This includes a copy of your user profile, workspace data, widget content, and UI preferences (such as your selected theme and background). This data stays on your device.
2. How We Use Your Information
- To provide and maintain the BaseTab service
- To sync your workspaces and widgets across devices
- To authenticate your identity and secure your account
- To process payments and manage subscriptions via Stripe
- To fetch data from third-party APIs you connect (Google Calendar, Gmail)
- To analyze anonymized usage patterns and improve our service (via Google Analytics and Microsoft Clarity)
3. Chrome Extension Permissions
The BaseTab extension requests the following permissions:
- storage — To cache your data locally for offline access and store OAuth tokens securely.
- cookies — To read your authentication session cookie from basetab.ai for API requests.
- identity — To initiate Google OAuth flows for Calendar and Gmail integrations.
4. Third-Party Services
Third-Party API Integrations
Widgets that connect to third-party services (such as Google Calendar and Gmail) communicate directly with those services from your browser. You authenticate using your own API credentials and OAuth consent. We do not act as an intermediary, proxy, or store any data from these services on our servers. You can revoke access at any time from within the widget settings or from your Google Account permissions.
Stripe
We use Stripe for payment processing. When you subscribe to a paid plan, your payment information is handled directly by Stripe. We only store your Stripe customer ID and subscription ID — never your credit card details.
Google Favicon Service
The Bookmark widget uses Google's public favicon service to display website icons. Only the domain name of bookmarked URLs is sent to this service.
5. Data Sharing
We do not sell, trade, or rent your personal information to third parties. Your data is only shared in the following circumstances:
- With your consent — When you explicitly choose to make a workspace public.
- Service providers — Stripe for payment processing, as described above.
- Legal requirements — If required by law or to protect our rights.
6. Analytics
We use the following analytics services to understand how our website and extension are used and to improve the user experience:
- Google Analytics — Collects anonymized usage data such as page views, session duration, and general geographic region. You can opt out via the Google Analytics Opt-out Browser Add-on.
- Microsoft Clarity — Records anonymized session replays and heatmaps to help us understand user interactions. Clarity automatically masks sensitive input fields. Learn more in the Microsoft Privacy Statement.
These services may use cookies and similar technologies. We do not collect browsing history, personal identifiers, or track you across other websites.
7. Data Security
We take reasonable measures to protect your data. Authentication sessions use secure, HTTP-only cookies. Google OAuth tokens are stored in Chrome's encrypted local storage. All communication with our servers is encrypted via HTTPS.
8. Data Retention & Deletion
Your data is retained as long as your account is active. You can delete individual workspaces and widgets at any time. To delete your account and all associated data, contact us at the email below. Google OAuth tokens can be revoked from widget settings at any time, which removes them from your local browser storage.
9. Your Rights
You have the right to:
- Access and export your data
- Correct inaccurate information
- Delete your account and associated data
- Revoke third-party integrations (Google Calendar, Gmail)
- Uninstall the extension at any time to remove all local data
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of BaseTab after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or your data, contact us at: support@basetab.ai