01. Introduction
TagTag is a bookmark manager that organizes, syncs, and enriches your bookmarks with AI-powered descriptions and smart tags. We are committed to protecting your privacy and being transparent about how we handle your data.
02. Information We Collect
Personal Information
Authentication Data: When you sign in with Google OAuth, we collect your email address and basic profile information to create and manage your account. TagTag uses Google Sign-In exclusively — no passwords are created or stored.
Bookmark Data
Bookmark Information: We store and process:
- Bookmark URLs and titles
- Folder organization and hierarchy
- Tags (both user-created and AI-generated)
- AI-generated descriptions and summaries
- Bookmark creation and modification dates
- Favicon and thumbnail images
Usage Data
Activity Information: We track:
- Recently viewed bookmarks (visit timestamps)
- Activity is recorded from interactions within TagTag (not browser history)
- Search queries within the extension
- Device information (browser type, operating system) for multi-device sync
Page Content
Content Extraction: When you save a bookmark, we temporarily extract page content (meta descriptions, headings, text) to generate AI-powered descriptions and tags. This content is processed in real-time and not permanently stored.
03. How We Use Your Data
Your data is used exclusively for the following purposes:
- Core Functionality: Managing, organizing, and syncing your bookmarks across devices
- AI Features: Generating smart descriptions and tags using OpenAI to enhance searchability
- Activity Tracking: Recording bookmark visits from TagTag interactions to show recently viewed items
- Search & Organization: Enabling fast search and smart tag grouping
- Duplicate Detection: Identifying and helping you manage duplicate bookmarks
- Dead Link Detection: Checking bookmark validity
We do NOT:
- Sell your personal data or bookmarks to third parties
- Use your data for advertising purposes
- Access or share your full browser history with anyone
- Use your data for purposes unrelated to bookmark management
04. Browser Permissions Explained
TagTag requires the following Chrome permissions:
- bookmarks: Read, create, update, and organize your Chrome bookmarks
- storage: Store preferences, authentication tokens, and cache data locally
- identity: Enable Google OAuth authentication for cloud sync
- tabs: Access current tab URL/title/favicon and matching open tabs for bookmark workflows
- activeTab: Temporary access to the active page when you trigger save/extract actions
- scripting: Extract page metadata (description/Open Graph/headings) used to improve AI summaries
Remote Code: TagTag does NOT execute any remote code. All functionality is bundled within the extension package.
Third-Party Favicon Service: The Domain grouping view loads favicon images from https://www.google.com/s2/favicons by passing the domain name only. No personal data or bookmark URLs are transmitted to this service.
05. Data Storage & Security
Where Your Data is Stored:
- Bookmark data is encrypted and stored securely using Supabase (PostgreSQL database)
- Authentication is handled by Supabase Auth with Google OAuth
- AI processing is performed via OpenAI API (content is not retained by OpenAI)
Security Measures:
- All data transmission uses HTTPS encryption
- Database access is restricted with Row Level Security (RLS) policies
- Authentication tokens are securely stored and automatically refreshed
- Passwords are never stored (OAuth authentication only)
06. Third-Party Services
TagTag uses the following third-party services:
- Supabase: Database and authentication provider - Privacy Policy
- OpenAI: AI description and tag generation - Privacy Policy
- Google OAuth: Authentication service - Privacy Policy
- Cloudflare: API proxy and CDN - Privacy Policy
07. Data Retention & Deletion
How Long We Keep Your Data:
- Active bookmarks are stored indefinitely while your account is active
- Archived bookmarks are soft-deleted and can be restored
- Activity data (recent visits) is retained for convenience
Your Rights:
- You can delete individual bookmarks at any time through the extension
- You can request complete account deletion by contacting [email protected]
- Upon account deletion, all your data is permanently removed within 30 days
- You can export your bookmark data at any time
08. Children's Privacy
TagTag is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child, please contact us immediately.
09. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Significant changes will be announced through the extension or via email.
10. Contact Us
For privacy-related questions, concerns, or requests:
- Email: [email protected]
- General support: [email protected]
11. Google API Limited Use Disclosure
TagTag's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- Google account data is used only to authenticate users and associate bookmark data with their account
- We do not transfer Google user data to third parties except as necessary to provide the service
- We do not use Google user data for advertising or for any purpose unrelated to bookmark management
- We do not allow humans to read Google user data except with the user's explicit consent or as required by law
12. Compliance
TagTag complies with:
- Chrome Web Store Developer Program Policies
- Google API Services User Data Policy
- General Data Protection Regulation (GDPR) principles
- California Consumer Privacy Act (CCPA) requirements