Privacy Policy

Effective date: April 10, 2026

Tabtrix ("we," "us," or "the Company") complies with applicable privacy laws and regulations and processes personal data securely. Contact: tjehdqls12@gmail.com

Article 1 — Data We Collect and How

We collect only the minimum personal data necessary to provide the Service, as follows:

DataCollection MethodPurpose
Email addressNotion OAuth authenticationAccount identification, service notices, payment processing
Notion OAuth access tokenNotion OAuth authenticationAuto-saving analysis results to Notion
Credit usage history and service usage metrics (analysis count, characters used per analysis)Automatic service loggingBilling, analysis history management, service improvement
Web page text contentChrome extension extractionAI analysis processing (temporary — discarded immediately after analysis)
Payment information (email, subscription ID)Automatic webhook from Polar.shPayment processing, subscription status management
Server access logs (IP, timestamp, request path)Automatic service loggingIncident response, security monitoring

We do not collect sensitive data such as health information, religious beliefs, or political views.

Article 2 — Purpose of Processing

Collected personal data is processed only for the following purposes:

Article 3 — Retention Periods

DataRetention PeriodBasis
Account information (email, token, credits)Deactivated immediately upon account deletion; permanently deleted within 30 days via automated processUser consent
Service usage metrics (analysis logs)User identifier (user_id) anonymized 30 days after account deletion; aggregate metrics (characters used, plan, analysis count) retained permanently in anonymized formService operational purpose (aggregate analytics)
Web page textDiscarded immediately after analysis; never stored on our serversUser consent
Payment-related records5 yearsApplicable commercial law
Server access logsAutomatically deleted after 30 daysUser consent
Deletion record (for abuse prevention)Permanently deleted 30 days after account deletion via automated processService operational purpose

Article 4 — Third-Party Disclosure

We do not provide User personal data to third parties as a general rule. The sole exception is Notion, to which Users directly grant access via Notion OAuth for the core function of the Service:

RecipientPurposeData SharedRetention
Notion Labs, Inc.Saving analysis results to the User's Notion workspace (authorized directly by the User via OAuth)AI analysis result textUntil deleted by the User in Notion

Article 5 — Data Processing Subcontractors

We engage the following subcontractors to operate the Service. Subcontractors process data only as directed by us and are bound by contractual obligations prohibiting use beyond the delegated purpose.

SubcontractorTaskData ProcessedCountry
Supabase, Inc.Database and authentication servicesEmail, token, credit informationUnited States
Railway Corp.Backend server hostingEmail, access logsUnited States
Cloudflare, Inc.Landing page hosting and CDNAccess logsUnited States
Google LLC (Gemini API)AI text analysis processingWeb page text, user-entered prompts (discarded immediately after analysis)United States
Polar.shPayment processingEmail address (card information is handled directly by Polar.sh)United States

Article 6 — International Data Transfers

The Service transfers User personal data outside the country of origin as described below. By using the Service, you consent to these international transfers.

You may object to international data transfers by emailing tjehdqls12@gmail.com. However, because our core infrastructure is located abroad, objecting to transfers will make the Service unavailable and will result in account deletion.

RecipientCountryDataPurposeSafeguards
Supabase, Inc.United StatesEmail, token, credit informationDatabase and authenticationSupabase Privacy Policy and DPA
Railway Corp.United StatesEmail, access logsServer hostingRailway Privacy Policy
Google LLCUnited StatesWeb page text, user promptsAI analysisGoogle Cloud Data Processing Agreement (DPA)
Notion Labs, Inc.United StatesAI analysis resultsNotion document storageNotion Privacy Policy and DPA
Polar.shUnited StatesEmail addressPayment processingPolar.sh Privacy Policy

Article 7 — Data Deletion Procedures

  1. Upon a deletion request, email, Notion token, credit information, and settings data are deleted without delay.
  2. Web page text is discarded immediately after AI analysis is complete and is never stored on our servers.
  3. Personal data in electronic file form is permanently deleted using technical methods that make recovery impossible.
  4. Information required to be retained by applicable law (such as payment records) is stored separately for the legally prescribed period before deletion.

Article 8 — Your Rights

You may exercise the following rights at any time under applicable privacy law:

To exercise these rights, email us at tjehdqls12@gmail.com. Requests will be processed within 10 business days. You may also delete your account at any time to have all data removed immediately.

Article 9 — Cookies and Automatic Data Collection

  1. The Tabtrix extension does not use cookies.
  2. The landing page does not use tracking cookies.
  3. The Chrome extension stores authentication tokens and settings in chrome.storage.local. This data is stored only on your device and is not automatically transmitted to our servers.
  4. Our servers retain access logs (IP address, timestamp, request path) for 30 days for technical purposes (incident response, security monitoring), after which they are automatically deleted.

Article 10 — Security Measures

We implement the following technical and administrative measures to protect personal data:

Article 11 — Children Under 14

This Service is not directed at children under 14, and we do not knowingly collect personal data from them. If we become aware that a child under 14 has registered, we will immediately delete their account and personal data. If you believe a child's data has been collected, please notify us by email.

Article 12 — Privacy Contact

For inquiries, complaints, or to seek remedies regarding privacy, please contact us at:

Article 13 — Regulatory Contacts

If you believe your privacy rights have been violated, you may also contact the following authorities (Korea-based regulators; international users may contact their local data protection authority):

Article 14 — Policy Changes

  1. If this Privacy Policy is amended, the reason and content of the change will be announced on the landing page at least 30 days before the effective date.
  2. Changes that materially affect your rights will also be notified separately to your registered email address.