Privacy Policy
01Operator and scope
This policy applies to the following, operated by Hagakun (developer name hg.dev on Google Play, Hagakun on the App Store):
- The Tabhand app for Android and iOS (
com.iruyo.tabhand) - This website (tabhand.iru-yo.com)
Tabhand has no accounts. You never sign up on the operator's servers.
02Key points
- The operator does not receive your data.Except reports you send yourself (08).
- Page content is sent only to connections you registered and agreed to.
- You can delete the data on your device at any time in Settings › Data.
03What stays on your device
The following data stays on your device and is cleaned up automatically after the period shown.
| Data | How long it stays |
|---|---|
| Exchanges | Cleaned up automatically 30 days after the request is completed. Unfinished requests are not deleted. |
| Browsing history | 90 days after the visit |
| Memory | 90 days after the last visit |
| Bookmarks | Until you delete them |
| Screenshots | Until the request ends. They are not saved to files. |
| Tokens and keys | Until you log out. They are kept in the OS's secure storage. |
| Cookies, site data and cache | Until you delete them |
Pages opened in agent tabs are not added to browsing history or memory. Agent tabs keep their cookies and site data separate from your tabs.
04What is sent, and where
OpenAI and Anthropic (the agent's connections)
To carry out a request, data is sent to the company of the connection you registered.
- OpenAI: when you connect with an API key. If you use a direct connection with your ChatGPT account, data is also sent to OpenAI.
- Anthropic: when you connect with an API key. If you use a direct connection with your Claude account, data is also sent to Anthropic.
- If you use a bridge connection, data is sent to Anthropic through Claude Code on your PC.
With a key connection, data is sent from this device directly to that company. It does not pass through any Tabhand server.
What is sent:
| Kind | Contents | When |
|---|---|---|
| Request text | The request you wrote, and your follow-up instructions | Sent as is, every time you send. |
| Page addresses and titles | The page being operated on, and all open tabs | Every request includes the current tab and the list of open tabs (addresses and titles). |
| Page text and structure | Text on the screen: headings, body text, buttons, link targets and so on | Each time the agent reads a page, up to 12,000 characters. Also 6,000 characters after pressing a button. It also reads inside same-origin iframes. |
| Entered values | Values in form fields (except passwords and card numbers) | Sent with the page text, up to 80 characters per field. Password and card number values are replaced with •••• and not sent. |
| Screenshots | An image of the visible area, when needed | Taken only when the agent decides it needs to see the page. Whatever is on screen appears as is (including a card number shown on screen). Kept on the device only until the request ends. |
| Browsing history, bookmarks and memory | Parts of pages you saw before that relate to the request | If memory is on, summaries of related pages are added, up to 1,500 characters. When the agent searches history or bookmarks, up to 100 entries of date, title and address are sent. What is sent is the URL, title, summary and visit count of related pages. Page body text is not sent. |
What is never sent:
- Password values: the agent is told the field exists, but the value is replaced with ••••.
- Card number values: card number fields and numbers shaped like card numbers are replaced with ••••. Screenshots show a number that is on screen.
- Invisible fields: hidden fields and elements not shown on screen are not read.
- Cookies and saved login details: the agent does not read them.
- Outside the app: photos, contacts and other apps are not touched.
How each company handles the data it receives (how long it keeps it, and whether it is used for training) follows your account settings and that company's privacy policy. Connections using an API key are not used for training by default.
- OpenAI: Privacy policy · Data settings
- Anthropic: Privacy policy · Data settings
Consent is asked for each connection (07).
Sites you open
As with any browser, the sites you open receive your access. To show a tab's icon (favicon), the app fetches it from the site.
Search engine (Google)
When you search with words typed into the address bar, those words are sent to Google.
Apple and Google (when you buy)
In-app purchases are paid through the Apple or Google store. Each company handles the payment details.
tabhand.iru-yo.com (feature shutdown check)
To check whether a feature needs to be turned off, the app may fetch a JSON file from this site. It sends no query and no cookies, and the User-Agent contains only the app name and version. Cloudflare, which serves this site, can see your IP address. The operator does not keep it.
tabhand.iru-yo.com/api/report (reports)
Sent only when you send a report. See 08 for what it contains.
05Backups and moving to a new device
Only settings and bookmarks are included in device backups and in moving to a new device.
Exchanges, browsing history, memory, cookies and site data, cache, site icons, and tokens and keys are not included in backups or transfers (on both Android and iOS).
On iOS, tokens and keys are erased on the first launch after reinstalling the app.
06How to delete
You can delete data on your device in Settings › Data.
- Memory: delete it with “Delete memory”. Turn off “Remember pages I visit” to stop remembering.
- Browsing history: choose a period (last hour / 24 hours / all) and delete. “Also delete memory for the same period” is on by default.
- Exchanges: clean them up with “Clean up all completed requests”. Unfinished requests are not included.
- Cookies and site data: deleting them logs you out of sites. Agent tab cookies are deleted too.
- Cache: site icons (favicons) are deleted with it.
- Bookmarks: delete them one by one.
Delete all data
Settings › Data › “Delete all data” does the following:
- Stops any running request.
- Logs out of all connections (deletes tokens and keys, and withdraws consent).
- Deletes exchanges, browsing history, bookmarks, memory, settings, cookies and site data, cache and site icons, and returns to the welcome screen.
The following are not deleted:
- Store purchases: they stay with the store, so you can get them back with “Restore purchases”.
- Data kept by each company and by the bridge host: Tabhand cannot delete it. Delete it in each company's settings (OpenAI: Data settings, Anthropic: Data settings). If you use a bridge connection, delete it on your PC.
Deleting the app
Deleting the app also deletes Tabhand's data on your device.
07Consent and withdrawal
When you register a connection, the app shows what will be sent to it and asks for your consent for that connection. Without consent, nothing is sent to that connection.
You can withdraw consent in Settings › Connections › “Withdraw consent and log out”. This deletes the connection's tokens and keys, and nothing more is sent to it.
08What the operator receives
The operator receives only these two things.
Access to the feature shutdown check
When the app fetches the JSON file from tabhand.iru-yo.com, your IP address arrives. It is not kept.
Reports you send
If you think an agent message is a problem, you can send a report from the app. What is sent:
- The reason (offensive, dangerous, an action different from the request, other)
- Free text you write
- The agent message you report (always sent)
- The request text (on by default; you can remove it)
- Connection method, provider, model and app version
- The page address (off by default; you can add it)
Page content, screenshots and other messages are not sent.
Reports are forwarded to the operator by email and are not stored on the site. Your IP address is used only to limit how often you can send, and is not stored. The emails are deleted after 90 days.
The operator reads reports and uses them in later versions to improve how problems are detected and to improve the system prompt. There are no individual replies, except possibly to people who write contact details in the free text.
What is not received
The app contains no analytics, no crash reporting SDK and no ads. Crashes are seen only through aggregated reports in Play Console and App Store Connect.
09Changes
When this policy changes, the date at the top of the page is updated and the change is added to the history below. If a new company is added as a destination, the app asks for your consent again for each connection.
- October 11, 2026: Established
10Contact
Operator: Hagakun
![]()