Last updated: 2026-09-16
The controller for all personal data processed by Tabio is:
Cael Rowley, trading as Clorostica
Hermannstraße 18, 12049 Berlin, Germany
clorostica@proton.me
Tabio is a sole proprietorship run by one person (see the imprint); "we" and "us" below mean Cael Rowley. We have not appointed a Data Protection Officer, as none is required for processing of this scale and nature. For all privacy matters, email the address above.
Tabio is designed so that the operator cannot read the contents of your bookmarks. Bookmark titles, URLs, and folder structure are encrypted on your device with AES-256-GCM before they are transmitted. The encryption key is derived from a passphrase you choose and never leaves your device. The server only ever sees ciphertext.
When you set a passphrase, Tabio derives an AES-256 encryption key from it using PBKDF2-SHA256 with a per-account salt. That key, and the passphrase it is derived from, are held only in memory on your device and are never sent to the server.
Every bookmark record is encrypted with AES-256-GCM before being uploaded. The server, the hosting provider, and the operator of this service receive only opaque ciphertext and have no technical means to decrypt it. Even with full access to the database, the contents of your bookmarks cannot be recovered without your passphrase.
This design has a trade-off: if you lose your passphrase, your encrypted bookmarks cannot be recovered by anyone, including us. There is no recovery mechanism by design.
The data we hold falls into two categories:
Encrypted on your device before it reaches our server:
Stored in plaintext (we can read this):
We do not process any personal data on the basis of consent, we send no marketing, and we make no automated decisions about you.
Two browser permissions are used purely on your device and never result in data being sent to our servers:
The extension keeps some data in your browser's local storage. It never leaves your device, but on a shared computer anyone using the same browser profile could read it, so we list it here:
The service runs on the following providers. Each one only sees the data it strictly needs.
LINK.COM*. Stripe holds your billing details (card or bank information, billing address, and any Link account you create) directly under its own privacy policy; Tabio receives only the customer and subscription identifiers, never your payment instrument.Tabio does not load third-party analytics, advertising, or tracking scripts. No personal data is sold or shared for marketing purposes.
Encrypted bookmark data is stored in a Cloudflare D1 database. Cloudflare may replicate data across regions for availability; the ciphertext design means the storage region does not affect the confidentiality of your bookmarks. WorkOS and Stripe each operate their own regional infrastructure as described in their respective privacy policies.
Cloudflare, WorkOS, and Stripe are US-headquartered companies, so the plaintext data they process for us (your email, authentication metadata, and billing details, never your bookmark contents) may be transferred to the United States. These transfers are protected by each provider's certification under the EU-U.S. Data Privacy Framework and/or the European Commission's Standard Contractual Clauses incorporated in their data processing agreements.
We keep your data only while your account exists. You can delete individual bookmarks and profiles from inside the extension at any time; deletions are removed from our database immediately. Deleted rows can persist for up to 30 days in Cloudflare's automatic database backups (used solely for disaster recovery, ciphertext only) before ageing out. Operational error logs are short-lived and contain no identifiers.
Self-service options are available to remove larger sets of data:
Each action requires you to confirm it's really you, by re-entering your account password or, if you signed in with Google or another external provider, by re-authenticating with that provider. None of them require your encryption passphrase. All of these actions are reachable from two surfaces, so they remain accessible whether or not the extension is currently installed:
If neither path works for any reason, email clorostica@proton.me and we will process the request within one month.
Under the GDPR you have the right to access, correct, or delete the personal data we hold about you, the right to receive it in a portable format, and the right to object to or restrict its processing. Bookmark export (Settings → Export bookmarks) gives you your data as a standard HTML file any browser can import; the deletion rights are self-service as described above. For anything else, or if a self-service path fails, contact clorostica@proton.me and we will respond within one month. You may also lodge a complaint with the data protection authority in your country of residence; in Germany this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
If we change this policy in a way that materially affects how we handle your data, we will notify users by email before the change takes effect.
For any privacy question, contact clorostica@proton.me. We do our best to reply within one month, and usually much sooner. For general help, see the support page; the controller's full details are in the imprint.