LookTab is a new-tab page for Chrome and other Chromium browsers, made by Ahmet Gündüz, an individual developer in İstanbul, Türkiye (“I”, “we”), who is the data controller for the data described here. Contact: support@looktab.app.
1. In short
- You can use LookTab without an account. Then everything you create stays in your browser and nothing about you reaches us.
- If you create an account, the content you choose to sync is stored on our server so it appears on your other devices.
- We do not sell your data, show ads, use analytics or tracking, or read your browsing history. The extension sends no telemetry or crash reports.
2. Without an account
Your boards, widgets, bookmarks, tasks, notes and settings are kept in your browser's storage (IndexedDB). Some widgets ask our server for public information (weather, news, exchange rates — see section 6); these requests carry no account and no cookies.
3. Your account
If you sign up we store:
- your email address and a securely hashed password, or, if you sign in with Google, a link to your Google account (Google tells us your basic profile:
openid,email,profile); - whether your email address is verified;
- your sessions: a device id, a device name made from your browser and operating system (for example “Chrome · Windows”), how you signed in and when the device was last active. Tokens are short-lived and stored only as secure hashes;
- the language of your account emails.
Until you verify your email address you can use LookTab, but nothing is synced. Unverified accounts are not deleted automatically; you can delete one at any time.
4. What syncs (only when signed in and verified)
Boards and their background settings, widgets and their settings (for example the weather city, news feed addresses, the currency watch list and rate alerts, countdown days, the clock's greeting name), bookmarks with their groups, tags, descriptions and custom logos you upload, tasks, notes, and the days you mark in the calendar planner.
5. What never leaves your browser
A custom wallpaper image; the focus timer and its history; which quote collections the text widget uses; the prayer times widget in full (its place, method and reminders) — religious practice is sensitive data, so we keep it on your device only (to find a place, only the city name you type is sent to our server, without your account); recent searches (if you turn them on); read marks and cached copies of news, weather, calendar events and exchange rates; backup and export files you save.
6. Requests our server makes for you
- Weather and city search: the city and coordinates you choose go to our server, which asks Open-Meteo. Open-Meteo does not see your IP address or identity.
- News: the feed addresses go to our server, which downloads the public feeds and keeps one shared copy per feed for 5 minutes in memory. Story images load directly from the news sites (no referrer is sent).
- Embedded pages: when you set an address, our server reads that site's framing headers and title once; the page itself loads directly from its site.
- Bookmarks: while you add or edit a bookmark (signed in), our server fetches a short preview of that page (and, for bookmarks synced from another device, looks up their site icons the same way); when you run a link check, our server checks whether each bookmarked address still works. Private and internal addresses are blocked, and full addresses are never logged.
- Exchange rates and gold: our server downloads public rate files from the European Central Bank, the Central Bank of the Republic of Türkiye and gold-api.com. No information about you is sent to them.
Searches you type go straight from your browser to the search engine you chose, or to the AI assistant you picked; they do not pass through our server.
7. Google Calendar (optional)
If you connect Google Calendar, we ask for two read-only permissions and nothing more: calendar.calendarlist.readonly to list your calendars so you can choose which ones the widget shows, and calendar.events.readonly to read the events on the calendars you choose. Calendar access is separate from signing in. The access tokens are stored only on our server, encrypted, and never in the extension. Event details are shown on your device and cached briefly; they are not synced or logged. Disconnecting stops access (and does not sign you out); you can also revoke it in your Google Account. LookTab's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Your calendar planner marks are LookTab data and are never written to Google Calendar.
8. Plans, free trial and activation codes
LookTab is free; Pro adds more boards, sources, alerts and a few extra features. A new account may get Pro free for a period after its email address is verified. To give each person that trial only once, we keep one-way keyed hashes (they cannot be turned back into the original) of your normalised email address, of the browser installations you signed in from and of a linked Google account. These hashes are kept after an account is deleted, only for this purpose. We record your Pro periods (start, end, whether from the trial, an activation code or a manual grant). For an activation code we store only a keyed hash of the code, its length and when and by whom it was used. LookTab itself does not process card payments; if you buy a code or subscription from a seller or payment provider, that provider handles the payment under its own policy.
9. Emails we send
Only messages about your account: verification and password reset links, a notice if someone signs up with your address, account-deletion confirmation, and Pro trial reminders 30 and 7 days before the trial ends. No newsletters or advertising. Emails are sent from support@looktab.app through our email provider, Hostinger.
10. Sharing
We share data only to run the features you use: Google (sign-in, Calendar if connected), Open-Meteo and the public data sources above (without information about you), and Hostinger, which hosts our server and sends our emails. We do not sell or rent data and do not share it for advertising.
11. Where data is stored and for how long
Our server and database run at Hostinger in a data centre in the European Union (France). Google is located in the United States. Account data is kept until you delete your account. When you delete an item, a deletion marker is kept so your other devices remove it too; the change history itself is cleared after about 104 days. Server logs contain no content, passwords or tokens; web server logs are kept for 7 days, and application logs are kept in a small, size-limited buffer that is overwritten as it fills. Trial-abuse hashes and activation-code records are kept as described in section 8.
12. Your choices and rights
- Delete your account: Account → Delete account removes your account and all synced data from our server at once; on this device you choose whether to delete the local copy or keep it.
- Export: Settings → Privacy and data creates a backup file of your boards; bookmarks can be exported as an HTML file.
- Stop syncing: sign out; disconnect Calendar; turn off optional permissions in Settings.
- Under Türkiye's personal data law (KVKK, Article 11) and, where it applies, the EU GDPR, you can ask to know whether your data is processed, get a copy, correct it, delete it, object to processing or complain to a supervisory authority (in Türkiye, the Kişisel Verileri Koruma Kurumu). Write to support@looktab.app; we answer within 30 days.
13. Security
Passwords are hashed; session tokens are stored as keyed hashes; Calendar tokens are encrypted and kept on the server only; all traffic to our server uses HTTPS.
14. Age
You must be at least 16 years old to create a LookTab account. Using the extension without an account sends us no personal data. We do not knowingly collect personal data from anyone under 16; if you believe a younger person has created an account, write to us and we will delete it.
15. Changes
If this policy changes we update the date above, and for important changes we tell you in the extension before they apply.