InTab is built from the ground up on a local-first, zero-telemetry architecture. Your code, API keys, conversations, and data run directly inside your browser and never touch our servers unless you explicitly configure an external connection.
100% Local Execution
Compilers, formatters, diff checks, and WASM runtimes run purely on your device.
Encrypted at Rest
Stored tokens, vaults, and workspace state are sealed with AES-256-GCM.
Your Own Storage
Optional cloud backups sync directly to your private Google Drive or OneDrive.
No Ads or Trackers
Zero third-party trackers, no analytics scripts, and no marketing pixels.
01
Core Architecture: Local-First by Design
InTab (in-tab.se) is a suite of developer utilities designed to operate locally within your browser tab. Unlike traditional developer tools that upload your code, snippets, or JSON payloads to remote servers for processing:
Code Execution: JavaScript, TypeScript, Python (Pyodide WebAssembly), and formatters execute inside sandboxed Web Workers and WebAssembly isolated on your computer.
Network Isolation: The core application communicates with no central backend for its primary functionality. You can inspect the browser’s network monitor at any time to verify that zero payload data leaves your device.
No User Accounts: You do not need to register, provide an email address, or sign in to use InTab's developer tools.
02
Google API Services & Google Drive User Data
InTab provides an optional Cloud Sync feature that allows developers to synchronize their encrypted workspace settings, code snippets, and custom configurations across their devices using their own personal Google Drive account.
Google API Services User Data Policy Compliance
InTab's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Specific Google Scopes Requested
InTab requests the absolute minimum permissions required to provide cloud synchronization:
Scope
Type
Purpose & Access Level
https://www.googleapis.com/auth/drive.appdata
Sensitive
Allows InTab to create, read, update, and delete its own single encrypted snapshot file inside your private Google Drive Application Data folder. InTab has zero access to your personal documents, spreadsheets, photos, or other files in Google Drive.
(no other scope)
—
InTab asks for nothing else: no openid, email, drive.file or full-Drive scope is requested, and a test fails the build if this document names a scope the app does not ask for. The account email shown beside the connection is returned by Drive's own about endpoint under the grant above, and is used only to label which account is connected.
2. Data Collection, Usage & Encryption
Client-Side Encryption (AES-256-GCM): Before any backup snapshot leaves your browser to Google Drive, it is sealed using client-side AES-256-GCM authenticated encryption with a device-derived salt. InTab servers never see your plaintext data, and the data stored on Google Drive is cryptographically unreadable without your local device keys.
No InTab Server Storage: Synchronization occurs directly between your client browser and Google APIs via HTTPS. InTab operates no central database or intermediary servers that store or process your Google user data.
No Human Inspection: No human, employee, or contractor ever reads, inspects, or accesses your Google user data.
Strict Non-Sharing Policy: We do not sell, rent, commercialize, or transfer Google user data to any third parties, advertisers, marketing networks, or data brokers.
No AI/ML Model Training: Google user data is NEVER used to train, retrain, fine-tune, or evaluate artificial intelligence, machine learning, or large language models.
3. Data Retention & User Deletion Rights
You have complete control over your data retention and can delete your information at any time:
In-App Deletion: In InTab, navigate to Settings → Cloud Sync, click “Disconnect Provider”, and select “Remove Cloud Copy”. This immediately sends a DELETE request to Google Drive API to permanently remove your snapshot file from your Google Drive.
Data Retention Period: Data is retained in your Google Drive application folder only for as long as you maintain the Cloud Sync connection. InTab does not retain any copies on its own infrastructure.
03
AI Coding Assistant & External APIs
InTab includes an integrated AI coding assistant. The assistant follows a strict Bring Your Own Key (BYOK) security model:
Direct Transmission: When you converse with the AI, prompts are transmitted directly from your browser to the OpenRouter API over encrypted TLS connections using your personal API key. InTab does not run an intermediate proxy that stores your prompts.
Local Key Storage: Your API keys are encrypted at rest using AES-256-GCM and stored exclusively in your browser’s IndexedDB storage. Keys are never transmitted to InTab developers.
Web Search: When the agent performs web searches to answer technical questions, queries are proxied via /api/search to privacy-preserving search providers (e.g. Tavily). Queries are ephemeral, and search logs are not stored or associated with personal identities.
GitHub Integration: If you connect GitHub to push code or create repositories, authentication is performed via standard OAuth. Your personal access token is encrypted in your local browser vault and used solely for user-initiated Git operations.
04
Data Storage, Encryption & Security
We implement industry-standard cryptographic techniques to secure all information stored by the application:
AES-256-GCM: Data written to browser storage (IndexedDB and localStorage) is encrypted using authenticated AES-256-GCM encryption with device-specific salts.
Content Security Policy (CSP): InTab enforces a strict Content Security Policy restricting unauthorized scripts, framing, and unauthorized network endpoints.
Cross-Origin Isolation: every response carries Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Embedder-Policy: require-corp, which put this page in an isolated context so the sandboxed runtime can use shared memory without exposing memory to other origins.
05
Cookies & Tracking Technologies
InTab respects your privacy and operates without intrusive tracking:
No Advertising Cookies: We do not deploy advertising, marketing, or profiling cookies.
No Third-Party Analytics: We do not embed Google Analytics, Mixpanel, Hotjar, or similar session-recording trackers.
Local Storage Only: We use browser localStorage and IndexedDB solely for essential functionality: saving your theme preference, open tabs, offline workspace files, and encrypted credentials.
06
Data Retention, Control & Deletion
Because your data resides locally on your machine, you have complete control over its retention and deletion:
Immediate Local Wipe: You can wipe all local tokens, chat history, and cache at any time by opening Settings → Storage and clicking “Clear Stored Credentials”, or by clearing your browser storage.
Cloud Sync Deletion: If you use Google Drive or OneDrive sync, you can delete your backups directly from the provider or disconnect your account in InTab Settings.
Revoking Google Access: You can revoke InTab's access to your Google account at any time via Google Account Security Permissions . Once revoked, InTab will be unable to access the application folder.
07
Contact & Data Protection Requests
Questions about this policy, or a request about personal data, go to the contact below. InTab runs on your device and keeps no user database, so there is usually nothing on our side to export or erase — a data request is normally answered by the local and cloud deletion steps in section 06. We respond within 30 days.
Access, correction and erasure: because there is no InTab account and no server-side profile, the copy of your data is the one in your browser storage and, if you enabled Cloud Sync, the encrypted snapshot in your own drive. Section 06 deletes both; nothing further is retained by us.
Third-party recipients you chose: a request about what our AI or search providers hold has to go to that provider — their privacy policies govern the requests you send them with your own credentials.
Supervisory authority: if you are in the EU/UK and a request has not been answered, you may lodge a complaint with your local data protection authority.