Security
What zTab keeps private, and what it cannot.
Plain answers to six questions: what is private, who can open it, what the AI receives, what is end-to-end encrypted, what the Community shares, and how to revoke or delete.
What is private, and who can open it.
Everything you build in zTab starts private. Access is something you grant, one surface at a time — and an approved private View is not the same thing as a public Community design.
A private View
A View you create belongs to your account. It is not in the Community gallery and no one browses to it; it opens for you and for the devices you approved.
Devices you approved
A new browser or Extension has to be approved from an account you are already signed in to. Revoking one stops it syncing from that moment on.
A published Community design
Publishing sends a sanitized copy of the layout and look to the gallery. The View itself is not published: your shortcuts, the exact weather location and your account details do not travel with it.
End-to-end encryption
Notes and Tasks are encrypted on your device.
E2EE covers Notes and Tasks, and nothing else. Everything else that syncs is access-controlled but readable by our servers — a real protection, but a different one.
What is covered
Note and Task content is encrypted in your browser before it is sent. zTab stores the ciphertext. Your PIN never reaches zTab, and zTab does not store the plaintext key.
What is not covered
Account and device records, timestamps, revision numbers, ciphertext size, sync status and security logs stay readable to us. Shortcuts, Pet, Focus and ordinary widget state are not end-to-end encrypted.
The keys are yours
You hold the PIN and the recovery key. Lose every unlocked device and that key, and the encrypted content cannot be recovered — not by you, and not by us.
Notes and Tasks are not in the widget catalog you can add from today. This describes how their data is protected wherever it already exists.
Read the full clause in the Privacy Policy →Who can open what.
| Data | Who can open it | Status |
|---|---|---|
| Notes and Tasks | You, on a device you unlocked with your PIN | End-to-end encrypted; zTab stores ciphertext only |
| Bookmarks, shortcuts, Pet, widget and layout state | You, your paired Extensions and the browsers you approved | Access-controlled and readable by the server; shortcuts, Pet and widget state are stripped from Community snapshots |
| Account, device and operational metadata | You, and zTab systems that run the service | Readable by the server; retention windows are listed in the Privacy Policy |
“Private” here means access-controlled. Outside Notes and Tasks it does not mean the server cannot read the data.
AI
What the AI receives.
AI summaries and Ask zTab are the one place where your content leaves zTab servers, and they receive more than your question.
What is sent
For a summary: the text of the page, its title and its address. For a question: the question itself, along with the titles and addresses of your saved bookmarks. An AI provider under contract to zTab processes them.
Where answers come from
Ask zTab answers from the bookmarks you saved and nothing else. It does not search the web on your behalf.
Turning it off
Bookmark sync stays off until you turn it on and pair a browser. Turning enrichment off stops new summaries, and deleting a bookmark or its server copy removes the summary built from it.
Collection
What zTab stores, and what it does not.
Your browsing history
zTab does not collect the pages you visit. There is no history feed, and opening a new tab does not report where you go next.
The bookmarks you chose to sync
Once sync is on, zTab stores those bookmarks — titles, addresses, folder paths, your own tags and notes, and how often you open them. That is bookmark data, kept under your account and readable by the server.
Operational records
Accounts, devices, sync status, usage counters and security logs are kept so the service can run and plan limits can be applied. The Privacy Policy lists them and how long each is kept.
Your controls
Revoking and deleting.
Revoke a device
Account → Devices lists every paired Extension and trusted browser. Revoking one stops future sync; it cannot erase what that device already decrypted and stored locally.
Delete PIN and recovery key
This permanently removes synced Notes and Tasks, including older encrypted data that was never migrated. It cannot be undone.
Delete your account
You can request account deletion at any time, which starts the removal of your data from our active systems.
Under the hood
What we do on our side.
Encrypted in transit
Traffic between your browser, the Extension and zTab uses TLS. Notes and Tasks are encrypted before they leave the device at all.
Collected for a reason
We store what running your homepage needs — your account, your devices and what you chose to sync — and we do not build a profile of the pages you browse.
Report an issue
Found something? Write to security@ztab.app. We answer within two business days.