Privacy notice
Website and free website accounts · 28 September 2026
Hosting and security
The website runs on an OVH server behind Cloudflare. Technically necessary connection data, including IP addresses and requested resources, is processed to deliver and protect the website. Cloudflare Turnstile checks registration, login, code requests and contact form submissions to prevent automated abuse.
Accounts and verification
We store your email address, a salted password hash, account creation time, language and the accepted version of the terms. Unconfirmed registration data and hashed verification codes expire after 10 minutes and are removed within another minute. Codes are single-use, with a limited number of attempts.
Signing in with Google or GitHub
When provider sign-in is enabled, you can use Google or GitHub. The provider supplies its account identifier and your verified primary email address. TabGecko stores the link to your account and its creation time. Linking an existing account requires its TabGecko password and any enabled second factor. Provider access tokens are used only for the immediate identity check and are not stored. The secure HTTP-only __Host-tabgecko_oauth cookie and encrypted sign-in state expire after ten minutes. Expired states are removed within another minute. The selected provider processes the redirected sign-in under its own privacy notice.
Cookies and sessions
The tabgecko_language cookie saves your chosen language for one year. The tabgecko_theme cookie saves your light or dark theme choice for one year and also applies to the documentation subdomain. The secure, HTTP-only session cookie signs you in. Sessions expire after 12 hours or, with Remember me, after 30 days. Signing out invalidates the current session. Resetting a password invalidates all sessions. No marketing or analytics cookies are used by this website. Cloudflare may use necessary security mechanisms.
Connected desktop devices
Device linking stores the device name, account assignment, creation and expiry times, last connection and a hashed device token for up to 30 days. Device codes expire after ten minutes. If you enable profile control in the desktop app, profile IDs, names and runtime states are stored for display in your account. Disabling it removes these profile details on the next successful connection. Start/stop requests and their results are retained for up to 24 hours. Device disconnection or password reset revokes access and removes the device details. Expired entries are removed within another minute. Cookies, browser passwords, proxy credentials, fingerprints and browser folders are not uploaded through this connection.
Contact form
Name, email address, subject and message are sent to info@tabgecko.com to process your enquiry. Do not include passwords or other credentials. Contact messages are retained for handling the enquiry and any applicable retention obligations.
Abuse prevention
The contact form allows one message per IP address every 30 minutes. It stores an HMAC-derived IP key for at most 65 minutes. Account request limits use pseudonymised keys and expire within 61 minutes. Passwords and verification codes are never stored as plain text.
Your data
Account data is retained while your account remains active. Contact info@tabgecko.com to request access, correction, deletion or restriction, or to object to processing where applicable. You may complain to a competent data protection authority.