Uncluttr

Privacy Policy — Uncluttr

Last Updated: October 6th, 2026

This Privacy Policy explains how Nair Development Hub SRL ("Uncluttr", "we", "us") collects, uses, stores, and shares information when you use the Uncluttr browser extension, our website (uncluttr.net), and related services (the "Service").

If you do not agree with this policy, do not use the Service.

Contact: contact@uncluttr.net

1) Who is the controller?

For GDPR purposes, Nair Development Hub SRL, located at Romania, Ilfov, Str Tineretului 63, is the data controller of personal data processed through the Service.

2) What data we process

A) Data stored locally on your device (core extension functionality)

Uncluttr stores most data locally in your browser extension storage so it can provide tab/workspace functionality. This may include:

  • Tab information: tab URLs, tab titles, and tab state (e.g., pinned, muted, active, last activated).
  • Workspace and group information: workspace/group IDs, names, colors, ordering, collapsed state, and timestamps.
  • Mappings: internal IDs that link browser tabs/groups/windows to Uncluttr's stable identifiers.
  • Settings: your preferences and feature toggles.
  • Internal marker tabs (extension pages): Uncluttr may create an internal extension tab to help maintain workspace state; this is not a normal website tab.

Where it's stored: your device (e.g., IndexedDB / extension storage).
We do not need to collect this data on our servers for core functionality.

B) Account and authentication data (optional)

If you choose to sign in, we process:

  • Account identifiers (such as email, depending on your sign-in method)
  • Authentication/session tokens (stored locally to keep you signed in)
  • Plan and entitlement information (free/pro status)

Billing details (optional): If you purchase a paid plan, we (and/or our payment processor) may process billing details such as your name and billing-related identifiers to manage your subscription, invoices, and payment status.

C) AI grouping data (optional; only when you use it)

AI grouping works with or without an account. When you start it, Uncluttr sends to our server:

  • The titles and web addresses of the tabs you group. Web addresses are sent without the query and fragment (the parts after ? or #).
  • The names and colors of your existing groups, to improve suggestions
  • A request identifier and your account or plan status, to enforce usage limits

Our server sends the tab titles, domains and paths to AI models from OpenAI and Google through OpenRouter, an AI routing service, and returns the suggested groups to your extension. We ask OpenRouter to use only providers that do not store or train on this data. The content of your pages is never sent.

AI outputs may be inaccurate. You remain in control of whether to apply suggestions.

To avoid repeating the same AI work, we keep a non-reversible hash of the request, together with the suggested groups, for up to 1 hour. The cached result holds group names, colors and tab identifiers. It does not hold your tab titles or web addresses.

D) Feedback and support (optional)

If you submit feedback or a support request, we process:

  • The message content you submit
  • Contact information you provide (and/or account identifiers if you are signed in)
  • Basic metadata necessary to route/respond (e.g., time submitted)

When you remove the extension, Chrome opens a short survey on our website. If you answer it, we store your reasons, your comment and your email address (only if you enter one) in PostHog. If analytics was on in the extension, your answer is linked to your analytics ID.

E) Subscriptions and billing (optional)

If you purchase a paid plan:

  • Payments are processed by Stripe
  • Stripe may process billing details (e.g., payment method and invoices)
  • We may store subscription status and Stripe identifiers (e.g., customer/subscription IDs) to manage your plan

F) Analytics data (optional; off by default)

To see which features are used and whether the extension works as intended, we use PostHog for product analytics. Analytics is off until you turn it on, on the welcome screen or in the extension Settings ("Help improve Uncluttr"). You can turn it off again at any time.

What we process:

  • Analytics ID: a random ID stored in the extension (analytics_anonymous_id). It is not derived from your account, browser or device. If you sign in, your events are linked to your account ID. We do not send your email address to PostHog.
  • Product events: which features you use, for example install, update, browser start, your settings, panels and buttons you open, and AI grouping requests with their tab counts. Events never contain your tab titles, web addresses or group names.
  • Basic metadata: extension version, timestamps, an environment marker, and an approximate location (country and city) that PostHog derives from your IP address. PostHog does not store the IP address itself.
  • Server events: our server also records a few events under your analytics or account ID: sign-up, AI grouping requests and results, purchases, renewals and plan changes.
  • Uninstall: when you remove the extension, our survey page records an uninstall event. It is linked to your analytics ID only if analytics was on.

When you turn analytics off, the extension drops queued events and sends no more. It also stops sending its analytics ID to our server and to the uninstall survey, and our server records no sign-up or AI grouping events for you. Purchase, renewal and plan-change events are still recorded, because they are part of our billing records.

G) Basic technical logs

When you use network features (sign-in, AI grouping, billing portal, feedback), our servers may process limited technical data such as:

  • IP address, timestamps, request IDs
  • Error logs and security events
  • Rate-limiting signals (to prevent abuse)

H) Website visitors and cookies (uncluttr.net)

On our website we use PostHog to count page views, page exits, and clicks on install buttons, so we know which pages help people find Uncluttr. When you first visit, a banner asks whether you accept cookies.

  • Before you choose, or if you reject: PostHog keeps its data in page memory only. It sets no cookies and writes nothing to your browser storage, and each page view counts as a new anonymous visitor. We also use Vercel Web Analytics, which sets no cookies and reports only aggregated visits.
  • If you accept:
    • PostHog sets one first-party cookie, ph_<project key>_posthog, on uncluttr.net for 365 days, plus matching entries in local storage and session storage. They hold a random visitor ID and a session ID, so we can recognize a returning visitor.
    • We load Ahrefs Web Analytics, which measures site traffic for search optimization.
    • When you click an install button, we send your visitor ID to our server. The server keeps it with your IP address for 15 minutes, so the extension can link the install to your visit. The link is made only if you also turn on analytics in the extension.
  • Our PostHog project discards IP addresses. The legal basis for cookies is your consent (Art. 6(1)(a) GDPR).
  • We save your choice in your browser's local storage (uncluttr_cookie_consent). You can change it at any time with "Cookie settings" at the bottom of every page.

3) Why we process data (purposes)

We process data to:

  1. Provide core extension features (tab/workspace/group management, restore, search, settings)
  2. Provide optional account features (sign-in, plan/entitlements)
  3. Provide optional AI grouping (generate grouping suggestions)
  4. Provide support and handle feedback
  5. Process subscriptions and manage billing
  6. Maintain security, prevent abuse, and improve reliability

4) Legal bases under GDPR

Depending on the feature, we rely on:

  • Contract (Art. 6(1)(b)): to provide the Service and the features you request
  • Legitimate interests (Art. 6(1)(f)): to secure the Service, prevent abuse, and debug/improve reliability
  • Consent (Art. 6(1)(a)): where required or appropriate for optional processing (you may withdraw consent at any time)
  • Legal obligation (Art. 6(1)(c)): for accounting/tax and other compliance obligations (e.g., billing records)

AI data minimization and storage: When you use AI grouping, we process the data needed to generate suggestions (such as tab titles and URLs). We do not build a persistent database of your tab lists or AI grouping requests.
We may retain limited information briefly for:

  • Caching (to avoid repeated AI calls for identical requests), and
  • Security/error logging (to diagnose failures and prevent abuse).

Where feasible, we minimize what is retained (e.g., retaining a hash key instead of raw inputs, and redacting or excluding sensitive values from logs). Retained troubleshooting data is kept only for a short period and then deleted or anonymized.

5) Sharing and third parties (processors)

We share data only as necessary to provide the Service:

  • Supabase for sign-in and account data (email, plan and usage counters)
  • Stripe for subscriptions and billing
  • Loops to deliver feedback, support and data-request messages to us. We do not add you to a mailing list.
  • OpenRouter, OpenAI and Google (only when you use AI grouping) to generate suggestions, as described in §2-C
  • Vercel (hosting of our server and website) and Upstash (rate limiting) to operate and protect the Service
  • PostHog for analytics (§2-F) and website statistics (§2-H). PostHog is hosted in the European Union, and events are routed through our own endpoint (l.uncluttr.net).
  • Ahrefs for website statistics, only if you accept cookies on our website

These providers act as data processors where applicable, under contracts designed to protect your data.

We do not sell your personal data.

6) International data transfers

Our analytics (PostHog) is hosted in the European Union. Our server runs on Vercel in the United States, and other providers (such as Stripe, OpenRouter, OpenAI and Google) may also process personal data outside the EEA/UK. When we transfer personal data internationally, we use appropriate safeguards such as:

  • Standard Contractual Clauses (SCCs)
  • Additional measures where required

You can contact us to request more details about the safeguards used for a specific provider.

7) Data retention

  • Local extension data (tabs/workspaces/groups): retained on your device until you delete it, clear extension data, or uninstall the extension.
  • Account/profile data: retained while your account is active and as needed afterward for security, dispute handling, and legal compliance.
  • AI grouping requests: processed to generate suggestions; we may retain limited metadata such as usage counters and security logs.
  • Feedback/support: retained as long as needed to respond and for reasonable support records.
  • Billing records: retained as required by law and accounting requirements; Stripe retains data under its own policies.
  • Caching (AI grouping): Hash-based cache keys and cached responses, where used, are retained for up to 1 hour and then deleted.
  • Security and error logs: Operational logs used for security, abuse prevention, and debugging are typically retained for a short period of time, unless a longer period is required to investigate abuse or comply with legal obligations.
  • Analytics: Analytics data is retained for as long as necessary to support product development, performance monitoring, and service improvement. When it is no longer required for these purposes, it is deleted or anonymized.

8) Your GDPR rights

If you are in the EEA/UK, you have rights including:

  • Access to your personal data
  • Rectification (correction)
  • Erasure
  • Restriction of processing
  • Objection (where we rely on legitimate interests)
  • Data portability (where applicable)
  • Withdrawal of consent (where we rely on consent)
  • Complaint to your supervisory authority

How to exercise rights: email contact@uncluttr.net. We handle each request by hand and reply within 30 days. A deletion request removes your account and profile (Supabase), your analytics data (PostHog) and any contact entry (Loops). We keep billing records for as long as the law requires.

Local data note: Much of your data (like tab URLs/titles) is stored locally on your device. You can delete it directly by clearing Uncluttr's data or uninstalling.

9) Security

We use reasonable technical and organizational measures to protect data, such as access controls, token validation for protected endpoints, and anti-abuse protections (e.g., rate limiting). No method of transmission or storage is fully secure.

10) Children

The Service is not directed to children under 13 (or the minimum age required by your jurisdiction). We do not knowingly collect personal data from children.

11) Chrome Web Store user data compliance (Limited Use)

Uncluttr's use and transfer to any other app of information received from Chrome browser APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:

  • We only use data to provide or improve the user-facing features described in this policy.
  • We do not transfer data to third parties except as necessary to provide or improve these features, as required by law, or for security purposes.
  • We do not use data for serving advertisements.
  • We do not transfer or sell data to data brokers or other information resellers.
  • We do not use or transfer data to determine creditworthiness or for lending purposes.
  • No humans read your data, except with your explicit consent (e.g., for support), for security investigations, to comply with law, or when data is aggregated and anonymized for internal operations.

12) Changes to this policy

We may update this Privacy Policy. If changes are material, we will update the "Last updated" date and provide additional notice where appropriate.

13) Contact

Controller: Nair Development Hub SRL
Email: contact@uncluttr.net
Address (optional): Romania, Ilfov, Str Tineretului 63

BlogTermsPrivacyContact

© 2026 Uncluttr