# ForgetTab Privacy Policy
ForgetTab is local-first software. This document describes exactly what it stores, where, and why.
## The short version
- **Your browsing data stays on your device.** Nothing is uploaded, synced or shared.
- **No accounts.** There is nothing to sign up for.
- **No analytics or telemetry.** ForgetTab contains no tracking code of any kind.
- **No remote AI calls.** Semantic search uses the Needle 3 model, which runs as WebAssembly
inside the extension on your computer. Your history is never sent to an AI API.
- **No network access at runtime.** The model and engine ship inside the extension package. The
only network step is the developer setup command (`npm run needle:setup`) that downloads the
official model before building.
## What is stored
ForgetTab stores its index in the extension's own IndexedDB database (`forgettab`) inside your
Chrome profile. For each page it remembers:
| Data | Details |
| ------------------- | ---------------------------------------------------------------------------------- |
| Page title | As the browser reported it |
| URL | The page address, with tracking parameters (`utm_*`, `gclid`, `fbclid`, …) removed |
| Visit metadata | First/last seen time, visit count, whether it is open, whether ForgetTab closed it |
| Local embedding | A numeric vector computed on your device from the title and URL (float16) |
| Favicon (sometimes) | Only small inline `data:` images, never remote favicon URLs |
It also stores **sessions**: the title and URL of tabs you saved ("save this window as …") and of
every set of tabs ForgetTab closed, so they can be brought back. Automatic sessions are removed
after 30 days by default (configurable). Deleted sessions stay in a trash for a week.
`chrome.storage.local` holds your settings, indexing progress and your last 20 typed commands (for
↑ recall). `chrome.storage.session` holds a temporary tab → URL map, pending command previews and
the undo list. Chrome clears all of it when the browser closes.
**Never recorded:** incognito windows (the extension is not allowed in incognito), and any site on
your "Never record these sites" list (Settings → Privacy).
ForgetTab **never** reads page contents, form data, passwords, cookies, or anything inside the
pages you visit. It works only from titles and URLs, which Chrome already exposes to extensions
with the permissions below.
It only indexes regular web pages (`http:`/`https:`). Browser pages, extension pages and local
files are ignored.
## Chrome permissions and why they are needed
| Permission | Used for |
| ----------- | ------------------------------------------------------------------------------------------------------ |
| `history` | Import the history range you choose during onboarding, then follow new visits |
| `tabs` | Read titles/URLs of open tabs to index them, focus an already-open tab, close tabs you ask to close |
| `tabGroups` | Create and name tab groups when you apply the Organizer |
| `storage` | Save your settings and indexing progress |
| `activeTab` | Show the search palette in the current tab **only** when you press the shortcut |
| `scripting` | Inject that palette on demand (together with `activeTab`) |
| `offscreen` | Run the local Needle 3 engine in a background worker |
| `alarms` | Resume indexing work after Chrome suspends the extension, and free the engine's memory when idle |
| `favicon` | Show site icons from Chrome's own favicon cache, so no third-party favicon service ever sees your URLs |
ForgetTab requests **no host permissions** (no `<all_urls>`) and runs no content script on pages
unless you invoke the palette.
When you delete history in Chrome (a single page or everything), ForgetTab removes the same
entries from its index. Pages that are currently open, or that ForgetTab closed for you, are kept
so Close & Remember never loses your tabs.
## How to delete your data
- **Everything:** open ForgetTab **Settings → Privacy → Delete all ForgetTab data** and confirm.
This erases the IndexedDB index, all embedding vectors, settings and indexing state.
- **Just the index:** **Settings → Indexing → Clear local index** removes pages and vectors but
keeps your settings.
- **Uninstalling** the extension removes all of its data from Chrome.
Deleting ForgetTab data **does not** delete Chrome's own browsing history. Use Chrome's history
settings for that.
## Third parties
None. ForgetTab has no servers and shares data with no one. The Needle 3 model is published by
Cactus Compute under Apache-2.0 and runs entirely offline inside the extension. See