Data Handling and Retention
What private by default means, the path your data takes through a Tabstack request, what is stored, and for how long.
Tabstack processes data on your behalf: the pages it fetches, the output it produces, and the inputs you send (tasks, queries, schemas, instructions, and any form data). This page documents what happens to that data.
Never trained on. Private by default. Built by Mozilla.
Section titled “Never trained on. Private by default. Built by Mozilla.”Three claims, and what each one actually means.
Never trained on. Your requests and the content Tabstack processes for you are not used to train models.
Private by default. Payloads (the target URL, request parameters, response data, and extracted output) are visible to no one at Tabstack unless your organization opts into detailed data collection, which is off by default. Request metadata is always recorded. Access to what is retained is restricted and audited. See Security.
Built by Mozilla. Tabstack is a Mozilla product, which is why this page states the constraints as plainly as the commitments: what the cache shares across accounts, which certifications are not held, and where content goes when an endpoint applies a model.
Those are the claims. The rest of this page is the mechanism behind them.
The path a request takes
Section titled “The path a request takes”- Your application calls the API with a bearer key. Traffic is TLS 1.2 or higher.
- Tabstack records request metadata: the endpoint, success or failure, credits spent, timestamps, and the organization and key that made the call. This is always recorded, on every plan.
- Tabstack fetches the target page, rendering it in a server-side browser when the page needs one. Direct fetches identify Tabstack with the User-Agent
Mozilla-Tabstack/1.0 (+https://tabstack.ai). - For endpoints that apply a model (
/extract/json,/generate/json,/research,/automate), the content being processed and the instructions you supplied are sent to a contracted model provider to produce the result. For hosted/automatethat includes the task text and the page content the agent reads. - The result returns to you. Fetched page content may be cached (see Caching).
- Payloads are not stored by default and are visible to no one at Tabstack. If your organization opts into detailed data collection, they are retained for 90 days.
Tabstack runs on Google Cloud Platform. The privacy policy is canonical for the subprocessor list.
What is stored
Section titled “What is stored”For every API request, Tabstack stores request metadata: which endpoint was called, whether it succeeded, credits spent, timestamps, and the organization and key that made the call.
The payloads (the target URL, request parameters, response data, and extracted output) are not stored by default. They are retained for 90 days only when an organization opts into detailed data collection. Personal information is kept out of logs.
Per the privacy policy, IP logs are retained 60 days, referral data 30 days, and opt-in browsing history 90 days.
Detailed data collection
Section titled “Detailed data collection”This is an organization-level setting, off by default. Turning it on is what makes payloads visible in the console and retained for 90 days, which is useful for debugging extraction quality and auditing what an agent did. Turning it on is also the point at which the “private by default” description no longer applies to your organization, by your own choice.
With it enabled, these are stored and retained 90 days: the /automate data object, the research query, the extraction schema, and the full task stream.
Caching
Section titled “Caching”Tabstack caches fetched page content by URL to improve performance and reduce redundant fetches, with a short time-to-live. You can bypass the cache for any request by passing nocache: true. See Production Reliability for the behavior.
Inputs and form data
Section titled “Inputs and form data”When you use /automate, you can pass a data object and, in interactive mode, supply form field values mid-task. See Automate Tasks and Interactive Mode.
Inputs follow the same rule as other payloads: not persisted unless detailed data collection is enabled. Interactive form values are narrower still. They are held for the life of the task, expire within minutes, and are not written into the request record even when detailed data collection is on. Request data that appears in error reports is sanitized.
What this does not cover
Section titled “What this does not cover”- Tabstack holds no third-party security certifications today. SOC 2 and ISO 27001 are not currently held.
- There is no air-gapped or self-hosted deployment of the API. Pilo is the self-hosted path for automation only.
- Hosted
/automateworks on public websites, cannot log in on its own, and has no credential store or session management.
Security and abuse controls
Section titled “Security and abuse controls”Encryption, key handling, organization roles, and vulnerability reporting are covered in Security.
Privacy policy and contact
Section titled “Privacy policy and contact”The canonical privacy policy is at https://tabstack.ai/legal/privacy. A Data Protection Officer is reachable at dpo@mozilla.com for privacy questions, and security issues go to security@tabstack.ai.