Privacy Policy

Last updated 19 September 2026. Applies to cust*m Tab 1.3.0.

cust*m Tab does not collect, transmit, store or sell any user data. There is no account, no analytics, no telemetry, no crash reporting, no advertising identifier, and no server operated by this project. Nothing about your browsing is sent anywhere.

This document exists because the extension is not entirely offline: four features send a request, and each happens only because you asked for it. They are listed below in full.

What is stored, and where

Your settings live in your browser's own extension storage, on your device. They are not readable by web pages and never leave the browser unless you turn on the optional sync described below.

Stored Where
Bookmark tiles you created (name and URL) Your device only. Never synced.
Chosen search engine, theme, background, icon mode Your device. Synced only if you opt in.
Redirect URL, if you use redirect mode Your device. Synced only if you opt in.
Your Pexels API key, if you supply one Your device only. Never synced, and removed from any settings export.
A cached page of Pexels photo URLs, if you use photo backgrounds Your device only. Never synced.
A background picture you chose from your own disk Your device only. Never uploaded and never synced, and removed from any settings export. It is re-encoded when you choose it, which discards embedded EXIF metadata such as the GPS coordinates a phone records in a photo.
Clock, greeting and interface preferences, including a name you enter Your device. Synced only if you opt in. A name entered for the greeting is only ever displayed on your own new tab.
Timestamps used to detect that the new tab was replaced Your device only. Never synced.

The four cases where something leaves your browser

1. You run a search

When you press Enter in the search bar, or use the ct keyword in the address bar, your query goes to the search engine you selected, exactly as it would if you had typed it into that engine yourself. Nothing is sent while you type, and nothing is sent to this project. The default engines are DuckDuckGo and Brave, which state that they do not build a profile of their users.

2. You turn on photo backgrounds

This feature is off by default and requires an API key that you obtain yourself from Pexels. When it is on, the extension requests permission to reach api.pexels.com and sends your search term and your key in order to fetch photos. Your key is transmitted only in the request header, never in a URL, and the request refuses to follow redirects so the key cannot be passed to another host.

Pexels will see the request as coming from your key. Their handling of it is governed by the Pexels privacy policy. Turning the feature off removes the host permission again.

3. You choose the remote icon source

Bookmark icons are resolved on your device by default, with locally drawn letter tiles as the fallback. If you explicitly switch the icon source to DuckDuckGo in Settings, the hostname of each bookmark is sent to icons.duckduckgo.com to fetch an icon. The path, query string and fragment of your bookmarks are never sent.

Versions before 1.2.0 sent every bookmark hostname to Google on every new tab. That behaviour has been removed.

4. You choose to load icons from each site directly

This icon source is also off by default. When you select it, your browser requests /favicon.ico from each bookmarked site itself. No third party is involved and nothing is sent to this project — but those sites do see a request, which tells each of them that you opened a new tab. The setting says so where you choose it, so the trade is yours to make rather than ours to make quietly.

Optional sync

Sync is off by default. If you enable it, a limited set of preferences (mode, redirect URL, search engine, icon mode, theme, interface and background settings) is mirrored through your browser's own sync service, operated by Google for Chrome or Mozilla for Firefox, under their respective privacy policies. This project has no access to it.

Your bookmarks, your API key and your own background picture are never synced. Bookmarks are treated as belonging to the device, the API key is a credential and sync leaves the device, and a picture from your disk is both personal and far larger than the sync quota allows.

Permissions, and why each one exists

Permission Reason
storage Save your settings and bookmarks on your device.
alarms Run an hourly check for whether the browser silently reset the new-tab override.
notifications Tell you when that check finds the override has been disabled.
favicon (Chrome only) Read bookmark icons from the browser's own on-device cache, so no icon request goes to a third party. Not present in the Firefox build.
api.pexels.com (optional) Requested only at the moment you enable photo backgrounds, and released when you disable them. Never granted at install.

The extension requests no blanket host access and reads no page you visit. It cannot see your browsing history, your tabs, your cookies or your form input.

Children

The extension collects no data from anyone, including children, and has no age gate because there is nothing to gate.

Changes to this policy

If the extension's data handling ever changes, this page changes with it in the same release, and the change is recorded in the changelog. The full source is public, so any claim here can be checked against the code.

Contact

Questions or corrections: open an issue. For anything security-sensitive, please use private vulnerability reporting rather than a public issue.