Privacy Policy
Last updated: August 9, 2026
What we collect
Intent Tab collects the minimum data needed to provide the service:
- Email address — used for account identification and sign-in (via Google OAuth).
- Intent sets, preferences, and Goal Loop records — stored locally in your browser. Goal Loop records include goals, planned sessions, focus-session history, session reflections and evidence, and pending reflections. If you enable cross-device sync (Pro), this data is written to your private Google Drive appDataFolder. Backup contents never pass through or are stored on our servers.
- Sync metadata — when sync is enabled, our backend records only whether a backup exists and the last successful sync timestamp to support the returning-user experience. No intent sets, Goal Loop records, reflections, or other backup contents are stored on our servers.
- Plan status — whether you are on the Free or Pro tier, stored server-side to manage entitlements.
- Usage metrics — aggregate counts (intents viewed, daily activity, streaks) stored locally in your browser. These are never sent to our servers.
What we do NOT collect
- Browsing history
- Websites you visit
- Search queries
- Cookies from other sites
- Personal files or documents
- Location data
How we use your data
- To authenticate you and manage your subscription.
- To enable optional cross-device sync via your private Google Drive appDataFolder (Pro feature). The archive can include intent sets, preferences, Goal Loop goals and plans, focus-session history, session reflections and evidence, and pending reflections. It is written directly to your Google account; we store only backup-availability metadata.
- To process payments securely via our payment partner (Paddle).
- To generate optional AI-assisted intent sets and editable Goal Loop drafts on your behalf (Pro feature). AI does not receive reflection or journal text and does not activate or schedule Goal Loops.
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.
Third-party services
- Google OAuth — for sign-in. We receive your email and profile name. Google’s privacy policy applies to their authentication service.
- Google Drive (appDataFolder) — for optional cross-device sync (Pro). When you enable sync, Intent Tab writes your sets, preferences, Goal Loop goals and plans, focus-session history, session reflections and evidence, and pending reflections to a hidden, app-private folder in your Google Drive. Only Intent Tab can read this archive. Google’s terms and privacy policy apply to Drive storage.
- Paddle — for payment processing. We never see or store your credit card details. Paddle’s privacy policy governs payment data.
- Cloudflare — our backend infrastructure. Request metadata (IP addresses) may be processed for security but are not stored long-term.
- Google Gemini — for optional Pro AI generation. Intent-set requests include the topic or direction you enter. Goal Loop draft requests can include the goal title, success definition, optional reason, target date, weekly minutes, session duration, preferred days, and preferred time window. Daily journal text and session-reflection evidence are not sent to Gemini. Review and edit all generated output before saving or activating it.
Data storage and security
Account and entitlement data is stored in Cloudflare D1 (SQLite) with encryption at rest. Auth tokens are signed with HMAC-SHA256. IP addresses are hashed with a salt before storage for rate-limiting purposes — we cannot reverse them.
Local extension data (intent sets, preferences, activity, Goal Loop goals and plans, focus-session history, session reflections and evidence, and pending reflections) is stored in your browser’s localStorage and chrome.storage.local. This data never leaves your device unless you explicitly enable cross-device sync. With sync enabled, the archive is written directly to your own Google Drive appDataFolder—a hidden folder accessible only to Intent Tab.
Data retention
Account and entitlement data is retained while your account is active. Local Goal Loop and reflection records follow the extension’s on-device retention behavior; focus-session history, session reflections, and pending reflections are maintained as a bounded recent record. If Drive sync is enabled, removing local records does not by itself delete an existing Drive archive until a later synchronization updates it or you remove the archive.
- Auth handoff records are deleted within 24 hours.
- AI usage logs are pruned after 12 months.
- You can delete your account by contacting us at yudhira.apps@gmail.com.
Your rights
You have the right to:
- Access the data we store about you.
- Request deletion of your account and associated data.
- Export your intent sets and Goal Loop records from your locally stored data.
- Opt out of sync at any time by turning off Drive sync in Intent Tab. Turning sync off stops future synchronization but does not automatically delete an existing archive from your Google Drive appDataFolder.
To exercise any of these rights, email yudhira.apps@gmail.com.
Children
Intent Tab is not directed at children under 13. We do not knowingly collect personal information from children.
Changes to this policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. Continued use of Intent Tab after changes constitutes acceptance.
Contact
Questions or concerns? Email us at yudhira.apps@gmail.com.