This is the privacy policy for Stowl, a Chrome extension for saving and organizing browser tabs. It explains what data Stowl collects, why, and what your rights are.
Stowl is built by an independent developer. There is no team, no investors, no ad network, and no data broker involved. If anything here is unclear, email getstowl@gmail.com.
Stowl is operated by an independent developer based in California, United States. For any privacy question, correction request, or deletion request, contact getstowl@gmail.com.
Stowl collects different data depending on how you use it.
Nothing leaves your device. All your collections, tab metadata, and settings are stored locally in your browser's storage. Stowl has no way to see what you have saved because it never leaves your machine.
When you sign in with your email address to enable sync, Stowl stores the following on our backend so your collections can be available on your other computers:
Stowl does not store your browsing history, tabs you have not saved, page contents, cookies, form data, passwords, or any information about tabs open in incognito windows.
Only one thing: syncing your saved collections across the computers you sign into. Your data is not used to profile you, personalize ads, train models, or generate analytics about your behavior.
Under the EU General Data Protection Regulation (GDPR), the legal basis for Stowl's processing of your data is your consent, which you give by signing in and enabling sync. You may withdraw consent at any time by deleting your account.
Stowl does not sell, rent, or share your data with third parties for marketing, advertising, or analytics purposes.
Stowl uses Supabase, a third-party service based in the United States, to store synced data and handle authentication. Supabase acts as a data processor on behalf of Stowl and is contractually restricted to that role. You can review Supabase's privacy practices at supabase.com/privacy.
Stowl may disclose data if legally required by a valid court order, subpoena, or government request, and only the minimum data necessary to comply.
For the purposes of the California Consumer Privacy Act (CCPA), Stowl does not sell or share personal information as those terms are defined by the CCPA.
Synced data is stored on Supabase infrastructure in the United States. By using Stowl's sync feature, you consent to this storage location. If you are outside the United States, your data will be transferred to and stored there.
For users in the European Union or United Kingdom, this transfer to the United States is enabled by Supabase's Standard Contractual Clauses (SCCs) with data importers, a transfer mechanism recognized under GDPR Article 46.
Synced data is kept as long as your account exists. If you delete your account, all associated data is permanently removed from Supabase within 30 days.
You can request account deletion anytime by emailing getstowl@gmail.com from the address you registered with.
Your data is yours. You can access it, export it, correct it, or delete it at any time.
The easiest way to handle most of these is through Stowl directly. Sign in, open your collections, and export or delete whatever you want.
If you'd rather have Stowl handle a request for you, or if you don't have access to your account for some reason, email getstowl@gmail.com from your registered address. Stowl will respond within 30 days.
If you live in the European Union, United Kingdom, or California, you have specific rights under GDPR and CCPA. Those laws also give you the right to file a complaint with your local data protection authority if you feel your rights weren't respected.
Stowl uses HTTPS for all data transmission between your browser and the backend. Synced data is stored in Supabase with row-level security, meaning your account's data is isolated from every other user's data at the database level. Authentication uses industry-standard token handling with automatic expiration and refresh.
No system is completely secure, but Stowl takes reasonable steps to protect your data. If a breach ever occurs that affects your data, Stowl will notify affected users by email within 72 hours of confirming the breach.
The Stowl marketing website at getstowl.com does not use cookies, tracking pixels, session recording, or any third-party analytics.
The Stowl extension itself uses your browser's local storage APIs to save your data on your device. This is not a cookie in the tracking sense, it is required storage for the app to function.
Stowl does not currently respond to Do Not Track browser signals because Stowl does not track users across websites in the first place. There is nothing to opt out of.
Stowl is not directed at users under the age of 13. Stowl does not knowingly collect data from anyone under 13. If you believe a child has provided data to Stowl, email getstowl@gmail.com and it will be deleted.
If this privacy policy changes materially, the change will be posted to this page with an updated effective date. If you have a synced account, you may also receive an email notification for significant changes.
For any privacy question, complaint, or data request, email getstowl@gmail.com.