Tabhand
Privacy

Privacy Policy

Last updated: October 11, 2026 (effective October 11, 2026)

01Operator and scope

This policy applies to the following, operated by Hagakun (developer name hg.dev on Google Play, Hagakun on the App Store):

Tabhand has no accounts. You never sign up on the operator's servers.

02Key points

  1. The operator does not receive your data.Except reports you send yourself (08).
  2. Page content is sent only to connections you registered and agreed to.
  3. You can delete the data on your device at any time in Settings › Data.

03What stays on your device

The following data stays on your device and is cleaned up automatically after the period shown.

DataHow long it stays
ExchangesCleaned up automatically 30 days after the request is completed. Unfinished requests are not deleted.
Browsing history90 days after the visit
Memory90 days after the last visit
BookmarksUntil you delete them
ScreenshotsUntil the request ends. They are not saved to files.
Tokens and keysUntil you log out. They are kept in the OS's secure storage.
Cookies, site data and cacheUntil you delete them

Pages opened in agent tabs are not added to browsing history or memory. Agent tabs keep their cookies and site data separate from your tabs.

04What is sent, and where

OpenAI and Anthropic (the agent's connections)

To carry out a request, data is sent to the company of the connection you registered.

With a key connection, data is sent from this device directly to that company. It does not pass through any Tabhand server.

What is sent:

KindContentsWhen
Request textThe request you wrote, and your follow-up instructionsSent as is, every time you send.
Page addresses and titlesThe page being operated on, and all open tabsEvery request includes the current tab and the list of open tabs (addresses and titles).
Page text and structureText on the screen: headings, body text, buttons, link targets and so onEach time the agent reads a page, up to 12,000 characters. Also 6,000 characters after pressing a button. It also reads inside same-origin iframes.
Entered valuesValues in form fields (except passwords and card numbers)Sent with the page text, up to 80 characters per field. Password and card number values are replaced with •••• and not sent.
ScreenshotsAn image of the visible area, when neededTaken only when the agent decides it needs to see the page. Whatever is on screen appears as is (including a card number shown on screen). Kept on the device only until the request ends.
Browsing history, bookmarks and memoryParts of pages you saw before that relate to the requestIf memory is on, summaries of related pages are added, up to 1,500 characters. When the agent searches history or bookmarks, up to 100 entries of date, title and address are sent. What is sent is the URL, title, summary and visit count of related pages. Page body text is not sent.

What is never sent:

How each company handles the data it receives (how long it keeps it, and whether it is used for training) follows your account settings and that company's privacy policy. Connections using an API key are not used for training by default.

Consent is asked for each connection (07).

Sites you open

As with any browser, the sites you open receive your access. To show a tab's icon (favicon), the app fetches it from the site.

Search engine (Google)

When you search with words typed into the address bar, those words are sent to Google.

Apple and Google (when you buy)

In-app purchases are paid through the Apple or Google store. Each company handles the payment details.

tabhand.iru-yo.com (feature shutdown check)

To check whether a feature needs to be turned off, the app may fetch a JSON file from this site. It sends no query and no cookies, and the User-Agent contains only the app name and version. Cloudflare, which serves this site, can see your IP address. The operator does not keep it.

tabhand.iru-yo.com/api/report (reports)

Sent only when you send a report. See 08 for what it contains.

05Backups and moving to a new device

Only settings and bookmarks are included in device backups and in moving to a new device.

Exchanges, browsing history, memory, cookies and site data, cache, site icons, and tokens and keys are not included in backups or transfers (on both Android and iOS).

On iOS, tokens and keys are erased on the first launch after reinstalling the app.

06How to delete

You can delete data on your device in Settings › Data.

Delete all data

Settings › Data › “Delete all data” does the following:

  1. Stops any running request.
  2. Logs out of all connections (deletes tokens and keys, and withdraws consent).
  3. Deletes exchanges, browsing history, bookmarks, memory, settings, cookies and site data, cache and site icons, and returns to the welcome screen.

The following are not deleted:

Deleting the app

Deleting the app also deletes Tabhand's data on your device.

When you register a connection, the app shows what will be sent to it and asks for your consent for that connection. Without consent, nothing is sent to that connection.

You can withdraw consent in Settings › Connections › “Withdraw consent and log out”. This deletes the connection's tokens and keys, and nothing more is sent to it.

08What the operator receives

The operator receives only these two things.

Access to the feature shutdown check

When the app fetches the JSON file from tabhand.iru-yo.com, your IP address arrives. It is not kept.

Reports you send

If you think an agent message is a problem, you can send a report from the app. What is sent:

Page content, screenshots and other messages are not sent.

Reports are forwarded to the operator by email and are not stored on the site. Your IP address is used only to limit how often you can send, and is not stored. The emails are deleted after 90 days.

The operator reads reports and uses them in later versions to improve how problems are detected and to improve the system prompt. There are no individual replies, except possibly to people who write contact details in the free text.

What is not received

The app contains no analytics, no crash reporting SDK and no ads. Crashes are seen only through aggregated reports in Play Console and App Store Connect.

09Changes

When this policy changes, the date at the top of the page is updated and the change is added to the history below. If a new company is added as a destination, the app asks for your consent again for each connection.

10Contact

Operator: Hagakun