Updated / 生效日期:2026-10-09
Tasks, lists, notes, excerpts, subtasks, dates, preferences and the optional AI configuration stay in chrome.storage.local. AI API keys are excluded from exported backups and are not sent to the developer. Uninstalling or clearing extension storage deletes local content.
activeTab and scripting collect the page/selection you request; tabs reads the active page and opens saved links; contextMenus and commands provide capture shortcuts; storage saves local records; sidePanel displays the UI. Optional network permission is requested for the AI service address you choose.
You choose OpenAI Chat Completions or Anthropic Messages compatible service, address and model. Only explicit connection tests or AI requests send data directly to that service. AI requests include your instruction and task IDs, titles, dates, completion state and tags; they exclude task URLs, notes and page excerpts. The API key goes only to the selected service, with no redirect following. Requests require HTTPS, except HTTP loopback for local models. That service applies its own retention and pricing policy; Pro does not include AI usage. Review proposed edits before applying.
Pro is an optional one-time purchase through Stripe. Before checkout, you agree to order processing. Stripe handles card details. Each product has an isolated Cloudflare D1 database storing order, Checkout Session, PaymentIntent, product, price and webhook event IDs; amounts, currency, payment/refund/fulfillment state and timestamps. It also stores a keyed hash of the purchase email and a hash of the installation’s activation capability. We do not persist plaintext checkout emails, billing addresses, card details, raw webhook bodies, tasks or saved sessions in D1. The extension connects to its product’s billing origin to check payment or recover purchases. Only that origin’s success page can notify the extension; notifications alone do not grant Pro.
When you request purchase recovery, the address you enter is used in memory to look up its hash and, for an eligible purchase, sent to Resend to deliver a 6-digit verification code. This is separate from Stripe receipt emails. D1 stores hashes of the challenge code and requesting IP, attempts and timestamps. Codes expire after 10 minutes, allow up to 5 guesses and can be used once. Challenge records older than 24 hours are deleted when another recovery request is made. Purchase existence is not disclosed in the normal request response. Resend and Cloudflare may process service metadata under their own policies. Email recovery requires the operator’s sender configuration; the saved license code remains a fallback.
There are no developer usage analytics or cloud task/session sync. Local content stays until you delete it, uninstall, or applicable snapshot cleanup runs. Order records have no automatic expiry and support license retrieval. Email support@tabplugins.top to access, correct or request deletion of order records. Do not send API keys or license codes. Deleting our order record does not delete Stripe’s records and may prevent recovery. Previously activated offline licenses are not automatically revoked after refunds.
When you contact support@tabplugins.top, your address, message, attachments and mail delivery metadata are processed by Cloudflare Email Routing and Google Gmail to deliver and handle your request. Include only the information needed to explain your issue. Support mail is separate from the extension’s local content and purchase-recovery verification emails.
Stripe · Cloudflare · Resend · Google
任务、列表、备注、摘要、子任务、日期、偏好及可选 AI 配置保存在 chrome.storage.local。AI API Key 不进入导出备份、不发送给开发者。卸载扩展或清除扩展存储会删除本地内容。
activeTab 与 scripting 收集你主动选择的网页/选区;tabs 读取当前网页并打开已保存链接;contextMenus 与 commands 提供收集快捷入口;storage 保存本地记录;sidePanel 展示界面。AI 联网权限仅按你选择的服务地址申请。
由你选择 OpenAI Chat Completions 或 Anthropic Messages 兼容服务、地址和模型。只有主动测试连接或发起 AI 请求时直连该服务。AI 请求包含你的指令及任务 ID、标题、日期、完成状态和标签,不包含任务网址、备注或网页摘要。API Key 仅发送至所选服务,请求不跟随重定向。服务地址需为 HTTPS,本机回环模型允许 HTTP。该服务按自己的数据保留与定价政策处理,Pro 不含 AI 用量。修改先预览,再由你确认。
Pro 可选,一次性通过 Stripe 付款;结账前会征求订单数据处理同意。银行卡信息由 Stripe 处理。两个商品各自使用独立 Cloudflare D1,保存订单、Checkout Session、PaymentIntent、商品、价格和回调事件编号,金额、币种、付款/退款/签发状态及时间,另保存购买邮箱的带密钥摘要及本机自动激活凭证摘要。D1 不持久保存明文结账邮箱、账单地址、卡信息、原始回调、任务或标签会话。扩展连接本商品付款服务核对订单或恢复购买;仅该域名的成功页可以通知扩展,通知本身不会授予 Pro。
主动恢复购买时,你输入的邮箱只在内存中用于计算摘要;若有符合条件的订单,邮箱将提交给 Resend 以投递 6 位验证码。这与 Stripe 收据邮件不同。D1 保存验证码和请求 IP 的摘要、尝试次数及时间。验证码 10 分钟过期、最多尝试 5 次、只能成功使用一次;超过 24 小时的挑战记录在后续恢复请求时清理。正常申请响应不会透露该邮箱是否购买。Resend 与 Cloudflare 可能按各自政策处理服务元数据。邮件恢复须由运营方配置发件服务,已有授权码仍可作为备用。
开发者不收集使用统计,也不提供任务/会话云同步。本地内容留存到你删除、卸载或触发相应快照清理。订单记录暂不自动过期,用于授权找回。需要查询、更正或删除订单记录,请发送邮件至 support@tabplugins.top;请勿发送 API Key 或授权码。删除我们的订单记录不影响 Stripe 自己保存的记录,并可能导致无法恢复购买。已激活的离线授权不会因退款自动撤销。
发送邮件至 support@tabplugins.top 时,发件地址、正文、附件及投递元数据会经 Cloudflare Email Routing 和 Google Gmail 处理,用于投递邮件及处理申请。请只提供说明问题所需的信息。支持邮件与插件本地数据、恢复购买的验证码邮件分别处理。
Stripe · Cloudflare · Resend · Google