Privacy Policies for Overflow Tab Manager & Sidebar

Privacy Policy — Overflow Tab Bar

Last updated: 5/10/26


This privacy policy explains what data the Overflow Tab Bar Chrome extension and its companion server collect, how that data is used, who it is shared with, and the choices you have. It is written to be read by the people who use the extension, not just by lawyers.


If you have questions or want your data deleted, contact us at: [email protected]

1. Single purpose of the extension

Overflow Tab Bar's single, declared purpose is to manage your browser tabs. It moves overflowing tabs into a second row below the bookmarks bar and provides an optional second bar (the "Workspace bar") for a curated set of tabs. Every permission the extension requests is in service of that purpose.

2. What data is collected

We have intentionally minimised what crosses the network. The extension reads a lot of local browser data (your tabs, your bookmarks, your tab groups), but almost none of it is ever sent to our server. The full list of data that does leave your machine:



The following data is read by the extension but never sent to our server:

The titles and URLs of your tabs (read locally to render the tab bar)

The contents of any web page (the extension does not read or modify page content beyond positioning its own tab bar near the top of the page)

Your bookmarks (read locally for the "Open bookmark folder into workspace" feature)

Your tab groups

Your browsing history

Your form data, passwords, or any other input

3. How collected data is used

Email and Google account ID: to identify your account, prevent duplicate trials, recognise the same user across multiple installs, and (if you've linked a second Google account) authorise that account for the same Pro features.

API key: to authenticate API requests from your install to our server.

Stripe identifiers: to look up your billing status when our server receives webhook events from Stripe (subscription started, payment failed, subscription cancelled, etc.). Our server polls every hour to refresh subscription state.

IP address: incidental to making HTTP requests. We do not log or analyse IP addresses beyond what your hosting provider does for standard rate-limiting and abuse prevention.

4. Where data is stored

On your device (in chrome.storage.sync): your settings, the IDs of tabs in your workspace bar, the URLs of tabs in your visual bar groups, your API key, and a cached copy of your subscription status. This data syncs across Chrome installs you are signed into via your Chrome profile, but never reaches our server unless explicitly listed in section 2.

On our server: the data listed in section 2, stored in a Postgres database, retained until you delete your account.

Stripe: handles all payment information directly. We do not store credit card numbers, billing addresses, or other payment details on our server. Stripe's privacy policy is at https://stripe.com/privacy.

5. Who data is shared with

We share data only with the following third parties, and only the data that is strictly required:

Google — to verify the OAuth tokens you provide when signing in (read-only profile and email scopes).

Stripe — to process payments and manage subscriptions. Your email is shared with Stripe so receipts can be sent.

Our hosting provider ( Railway ) — runs the server that processes your requests; sees only the data we transmit to our server.

We do not sell, rent, or share your data with advertisers. We do not run analytics on your tab activity.

6. Data retention and deletion

You can request deletion of your account and associated server-side data at any time by emailing [email protected] 

Within 7 days, we will:

Delete your row from the users table (email, Google IDs, API key, Stripe IDs)

Cancel any active subscription via Stripe

Confirm deletion to you by email

Local data on your device is removed when you uninstall the extension or run chrome.storage.sync.clear() in the extension's service worker DevTools console.

If you cancel your subscription via Stripe but do not request account deletion, your row is retained so we can recognise you if you re-subscribe later. Trial-eligibility tracking (the rule that stops the same Google account from starting a new trial) requires retaining your Google account ID for as long as the row exists.

7. Children

Overflow Tab Bar is not directed at children under 13 and we do not knowingly collect data from children under 13. If you believe we have collected data from someone under 13, please contact us and we will delete it.

8. Your rights

If you reside in the European Economic Area, the United Kingdom, or California, you have specific legal rights regarding your personal data, including the right to access, correct, or delete it; the right to data portability; and the right to lodge a complaint with a data protection authority. You can exercise these rights by emailing [email protected].

We do not engage in automated decision-making that produces legal effects. We do not transfer data outside the country where our hosting provider operates beyond what's necessary to serve the request.

9. Security

All API requests between the extension and our server use HTTPS.

Your API key is stored locally in chrome.storage.sync (encrypted in transit by Chrome's sync service).

Our server's database connection uses TLS.

Our server checks a shared secret on every API request, so requests must originate from a properly configured copy of the extension.

We do not store payment details; Stripe handles that.

No system is perfectly secure. If we discover a security breach affecting your data, we will notify you within 72 hours.

10. Changes to this policy

If we change this policy in a way that materially affects what we collect or how we use it, we will update the "Last updated" date at the top and notify users via the extension's update notes and (if you've signed in) by email. Continued use of the extension after the change constitutes acceptance.

11. Contact

Email: [email protected] Postal address (if your jurisdiction requires one): 1980 Kenilworth Cir Apt A, Hoffman Estates, IL 60169


This document is provided as a starting point and may need to be reviewed by a lawyer to comply with your jurisdiction's specific requirements (GDPR, CCPA, PIPEDA, etc.). Do not consider it legal advice.

Privacy Policy — Sidebar Sheet Tabs

NZT Apps

Privacy Policy

Sidebar Sheet Tabs (Chrome Extension) · Effective 6 June 2026

This policy explains what Sidebar Sheet Tabs (“the extension,” “we,” “us”) collects, why, and what we never do with it. We collect as little as possible, and your spreadsheet content stays in your browser.

The short version

  • Your spreadsheet contents and tab names never leave your browser — we don’t see them or send them anywhere.
  • We store your settings locally on your device.
  • If you sign in, we store your Google email to run your trial and subscription.
  • Payments are handled by Stripe; we never see your card details.
  • We do not sell your data, show ads, or track your browsing on other sites.

Data stored on your device only

The following stays in your browser’s local storage and is never transmitted to us. Your spreadsheet content is included here:

  • Your preferences: tab colors, emoji icons, pinned and hidden tabs, sidebar width, appearance settings, dark mode, and the extension’s on/off state.
  • Your in-extension search history and pinned searches.
  • A cached copy of your subscription status and your installation identifier (see below).

To display the sidebar and to power features like cross-sheet search and the IMPORTRANGE picker, the extension reads your Google Sheets tab names and, when you use those features, sheet contents — entirely within your browser, using your existing Google session. This content is never sent to our servers or to any third party.

Data we receive

To provide trials, accounts, and subscriptions, our server (hosted on Railway) receives:

  • Installation identifier. A random ID generated when the extension is installed. On its own it is not linked to your identity.
  • Google account email and basic profile (name). Received only if you choose to sign in with Google, and used to identify your account across devices and to run your free trial and any subscription. We request only the email and profile scopes — we do not request access to your Google Drive or the Google Sheets API.
  • Trial and subscription status associated with your account.
  • Optional survey responses. If you complete the optional post-trial survey, we receive your answers (favorite features, a recommendation score, upgrade intent, team size, use case, and any feedback you write) along with your email so we can follow up. The survey is entirely voluntary.

Payments

Subscriptions and one-time purchases are processed by Stripe. Stripe collects and processes your payment information directly; we never receive or store your full card details. Your use of checkout is subject to Stripe’s Privacy Policy.

How we use what we receive

  • To create and manage your account, free trial, and subscription.
  • To sync your Pro status across devices when you sign in.
  • To send you, by email, transactional information related to your account and (if you opt in via the survey) occasional product follow-ups.
  • To understand which features users value, using aggregated survey feedback.

We do not use your data for advertising, and we do not sell or rent it to anyone.

Permissions, in plain language

  • Access to docs.google.com/spreadsheets — so the sidebar can run on your Google Sheets pages.
  • Storage — to save your settings and cached status on your device.
  • Active tab — to tell whether the page you’re on is a Google Sheet when you open the toolbar popup.
  • Scripting — to read sheet data within your own Google session for cross-sheet search and the IMPORTRANGE picker.
  • Identity — to let you sign in with Google.
  • Alarms — to periodically refresh your subscription status.
  • Notifications — to remind you before your free trial ends.

Data retention and deletion

We keep account data for as long as your account exists. You can request deletion of your account and associated data at any time by emailing us at the address below; we will delete it within 30 days, except where we must retain limited records for legal, tax, or fraud-prevention reasons. You can remove all locally stored data at any time by uninstalling the extension or clearing the extension’s storage in your browser.

Google user data — Limited Use

Our use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We use Google account data only to provide and improve the features described above, do not transfer it except as necessary to provide those features (for example, our hosting and email providers acting on our behalf), do not use it for advertising, and do not allow humans to read it except with your consent, for security, or as required by law.

Service providers

We rely on a small number of providers who process data on our behalf:

  • Railway — application and database hosting.
  • Stripe — payment processing.
  • Google — sign-in (OAuth) and, for survey notifications, email delivery.

Children

This extension is intended for general business and productivity use and is not directed to children under 13.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, through the extension or by email.

Contact

Questions, or a data-deletion request? Email [email protected].

Sidebar Sheet Tabs is an NZT Apps extension. © 2026 NZT Apps. All rights reserved.