Privacy Policy

Last updated:

This Policy explains what data TitleTab processes, why it is used, where it is stored, and how you can manage it.

We aim to process only the data needed to operate the features you choose, keep the service secure, and improve it. TitleTab does not sell personal data, use advertising networks, or create browser fingerprints.

Contents

1. About this document

This Policy applies to the titletab.com website, the TitleTab web application, including its installed version (PWA), official TitleTab browser extensions, and other service features. Data processing within TitleTab is organised by the service administration, referred to below as “TitleTab”, “we”, or the “Controller”.

TitleTab is a speed-dial dashboard where you can save links, organise them into folders and spaces, synchronise data across devices, and optionally publish a space. The scope of processing depends on whether you use the service anonymously, create an account, publish a space, or enable additional features.

This Policy does not govern data processing by websites you save in TitleTab, search engines, or other third-party resources. Those parties determine their own data processing terms.

You can contact the Controller at info@titletab.com or through the “Contact us” page.

2. Data we process

2.1. Use without an account

In anonymous mode, the contents of spaces, folders, and links, together with core settings, are stored primarily on your device. TitleTab does not create an account for this data or synchronise it across devices unless you create an account and transfer the local data to it.

Certain interface settings may be sent to the server so that the page appears in your chosen form immediately. The full contents of anonymous spaces are not sent to the server for this purpose.

The address of a link you add may be sent to the server to retrieve or update publicly available information about the relevant page, such as its title, icon, colour scheme, or image. This request does not by itself create an account or associate the local grid with a user identifier.

2.2. Account and profile

When you register, sign in, or complete your profile, we process:

  • an internal account identifier, email address, sign-in method, and email verification status;
  • first and last name, telephone number, biographical details, avatar, country, region, city, address, postal code, and selected language, but only if you complete the relevant fields;
  • when you sign in with Google, the profile identifier, name, photo, locale, and verified email address supplied by Google with your permission;
  • data needed for authentication and to maintain a secure session. Your account password is processed by the authentication service and is not stored by TitleTab in readable form.

An email address and authentication data are required to create and protect an account; account and synchronisation features are unavailable without them. Other profile fields are optional. You can use the service without an account, subject to the anonymous-mode limitations described in section 2.1.

2.3. User content, settings, and files

To synchronise an account, we store space names and icons, folders, link URLs and titles, item order, selected colours and images, pinned links, interface and search settings, trash data, publication settings, and the time of the latest changes. Imported bookmarks are processed in the same form.

Uploaded tile images, avatars, backgrounds, and support attachments are stored in cloud infrastructure and may be delivered through a CDN. A file available through a direct link without additional authorisation should be treated as accessible to anyone who obtains that link. Do not upload passwords, payment details, documents, or other information requiring strictly confidential storage.

Data is transmitted over a secure connection and stored in cloud infrastructure with storage-level encryption and access controls. A hidden-space password undergoes a one-way cryptographic transformation. However, a hidden space is not end-to-end encrypted storage and is not intended for passwords or other highly sensitive information.

2.4. Enquiries, emails, and reviews

  • when you contact us through the contact form or support, the name and email you provide, the message content and category, correspondence, request status, language, dates, and attached images;
  • when you submit a review, your name, email, language, text, and ratings. After moderation, the name, text, ratings, date, and administration response may be published; the account identifier and email are not displayed publicly;
  • when service emails are sent, the recipient's email and the content of the relevant notification.

2.5. Technical data and analytics

Technical data is generated automatically when you use the website: IP address, browser, device and operating-system information, language, approximate location, request date and time, requested address, referrer, and error logs. For signed-in users, some of this information is included in sign-in history and used for new-device notifications.

Analytics data includes page views, interaction with the interface, registration, and use of individual features. TitleTab does not send the analytics service your email address or use the internal account identifier as an analytics identifier.

3. Purposes and legal bases for processing

We use the data described above to:

  • create an account, maintain a session, and verify identity;
  • store and synchronise spaces, settings, and files;
  • enable import, export, restoration from trash, and publication of a selected space;
  • enhance saved URLs with metadata, logos, favicons, and page images;
  • respond to enquiries, moderate reviews, and send service notifications;
  • protect the service, limit automated requests, investigate errors, and identify suspicious sign-ins;
  • understand feature usage and improve performance and the interface through analytics.
Legal basisWhen it applies
Performance of a contract or requestRegistration and sign-in, synchronisation, content storage, import and export, publication at your request, support, and other features you request.
ConsentOptional features and technologies for which applicable law requires consent. Consent may be withdrawn for the future without affecting the lawfulness of earlier processing.
Legitimate interestsService and account security, abuse prevention, diagnostics, availability, limited product analytics, and improvement of TitleTab, provided that the user's rights do not override those interests.
Legal obligationsCompliance with binding requirements, protection of rights, and handling lawful requests from public authorities.

TitleTab does not make solely automated decisions that produce legal or similarly significant effects for users.

4. Public materials

Personal spaces are private by default. Publication occurs only after you create a public space and choose a unique nickname. Once published, the space name, description, nickname, links, titles, images, and design are available to anyone at the public address and may be indexed by search engines.

A review published after moderation also becomes publicly available in the form described in section 2.4. Before publishing, make sure that you have the right to disclose the material and that it does not contain another person's personal data or confidential information.

Hiding or deleting public material stops TitleTab from displaying it, but previously stored copies may remain for some time in browser, CDN, and search-engine caches or with third parties.

5. Recipients and data transfers

TitleTab does not sell personal data or provide it to advertising networks. Data is accessible only to the Controller, authorised providers, and third-party services selected by the user, to the extent necessary for the relevant purpose.

Recipient categoryPurpose of transfer
Cloud infrastructureHosting, authentication, databases, file storage and delivery, backups, technical logs, and service security. These providers receive only the data needed to operate the relevant component.
User-selected integrationsSign-in with Google, AI import using OpenAI, and retrieval of public metadata for saved pages. The data transferred is, respectively, the profile data listed in section 2.2, text supplied for AI import, or the page URL. Transfer occurs only when the relevant feature is used.
AnalyticsGoogle Analytics 4 receives technical information, page views, and feature-usage events without an email address or internal account identifier.
CommunicationsEmail and other communication providers receive the recipient's address and the message content needed to deliver a service email or support response.
Services opened by the userSearch engines and browser speech-recognition features process submitted queries under their own terms and may act as independent controllers.

Text submitted through the web-search field, including a value not recognised by TitleTab as an internal command, is sent to the selected search engine. Do not enter confidential information in the web-search field. Voice input starts only at the user's request and with browser permission; audio may be processed by the browser manufacturer or its speech-recognition provider, while TitleTab receives the returned text.

Providers may process data in countries other than the user's country, including countries in the European Economic Area and the United States. Where applicable law requires specific safeguards for an international transfer, the legal mechanisms and contractual measures provided by that law are used. Information about safeguards applicable to a particular transfer may be requested using the contact details in section 12.

We may change a provider without changing the purpose of processing. This Policy will be updated if the categories of recipients or the nature of a transfer change materially.

6. Cookies and local storage

TitleTab uses cookies and similar browser technologies to support sign-in, protect accounts, remember settings, store anonymous data, and obtain statistics. Their composition depends on the features used and browser settings.

CategoryPurposeTypical duration
EssentialAuthentication, session maintenance, identity re-verification, request protection, and access control for hidden spaces.From several minutes for one-time checks to 14 days for a session; access to a hidden space ends after inactivity or when the browser closes.
Preferences and local dataSelected language, theme, background, element positions, and other interface settings. In anonymous mode, spaces, folders, and links stored only on the device.Preferences are generally kept for up to one year; local content remains until the user deletes it, clears site data, or the browser removes it.
AnalyticsDistinguishing visits, measuring interaction with the interface, and compiling service statistics.According to the analytics provider's settings and applicable browser restrictions.

Essential technologies are required for requested features and security. Analytics technologies are used on a basis permitted by applicable law; where consent is required, user consent is that basis.

You can delete cookies and local data in your browser settings, restrict third-party technologies, or use analytics-blocking tools. Blocking essential cookies may disrupt sign-in and certain features. Clearing local storage may permanently erase anonymous data that was not transferred to an account or exported.

7. Retention and deletion

  • Active-account data and content are stored while the account is in use or until you delete the relevant items. Deleted links, folders, and standard spaces may remain in trash for up to 30 days for restoration unless you permanently delete them sooner.
  • Enquiries, service messages, and technical logs are retained for as long as needed to respond, confirm delivery, maintain security, diagnose issues, and resolve disputes, after which they are deleted or anonymised. Cookie and local-data periods are described in section 6.
  • Once account deletion is confirmed, access ends: the authentication account is deleted, active sessions are revoked, and the data is no longer used for ordinary service operation.
  • A limited copy of the profile and standard and public spaces is placed in an isolated service archive for 30 calendar days. During this period, the copy is not used to provide the service, for analytics, or for marketing, and is accessible only for technical recovery and incident resolution.
  • Hidden spaces, trash, sign-in history, support enquiries, and reviews are not included in the service archive and are deleted during account closure. The archived copy and uploaded files associated with the deleted account are automatically and irreversibly deleted no later than 30 calendar days after account deletion. No separate request is required.
  • Deleting an account does not clear IndexedDB, localStorage, or cookies on other devices and does not control copies held by search engines or other independent recipients. You can remove such local data through the relevant browser or device settings.

Data may be retained longer only to the extent and for the period expressly required by applicable law or a binding order from a competent authority. In that case, it is isolated from ordinary use and deleted when the basis for retention ends.

8. Your rights and control over data

Subject to applicable law, you may:

  • obtain information about your data and request a copy;
  • correct profile data and settings through your account;
  • export spaces in TitleTab JSON or browser-bookmark format;
  • hide or delete a public space, individual content, a review, an enquiry, or the entire account;
  • object to processing or request restriction, deletion, or portability where the law provides such a right;
  • withdraw prior consent without affecting the lawfulness of processing before withdrawal and lodge a complaint with a competent data-protection authority.

Send a request to info@titletab.com or through support. State the subject of the request and provide information that allows us to locate the account. We will not ask you to send your password. Our response and the scope of action depend on our ability to verify identity and the requirements of applicable law.

9. Data security

TitleTab applies technical and organisational measures appropriate to the nature of the data and processing risks. Data is transmitted over HTTPS and stored in cloud infrastructure with storage-level encryption. Access to private data is restricted and requires server-side verification of user permissions.

Session data is protected from access by client-side scripts, state-changing requests undergo origin checks, and suspicious activity is rate-limited. Account passwords are not stored by TitleTab in readable form; hidden-space passwords undergo a one-way cryptographic transformation with a unique salt. Uploaded files are checked by type and size.

No transmission or storage method eliminates risk completely. The limitations of direct file links and the absence of end-to-end encryption for hidden spaces are expressly described in section 2 so that users can make informed choices about what they store.

If you suspect unauthorised access, change your password, sign out on untrusted devices, and contact us.

10. Children

TitleTab is not specifically directed at children and does not knowingly request special categories of data from them. If you believe a child has provided personal data without the necessary permission, tell us so that we can review the report and take appropriate action.

11. Changes to this Policy

We may update this document when features, providers, storage methods, or legal requirements change. The current version is published on this page with a new update date. Material changes may also be announced in the interface or by service email.

12. Contact details

Service
TitleTab — Speed Dial Dashboard
Privacy email
info@titletab.com
Contact form
Contact us