产品用途Product purpose
签绪用于在桌面 Chrome 中按任务整理、查找、切换、恢复和管理浏览器页签。数据只用于这一单一用途及其安全、稳定运行。签绪不替换主页、默认搜索引擎或地址栏行为。TabToTask helps users organize, find, switch, restore, and manage browser tabs by task in desktop Chrome. Data is used only for this single purpose and its secure, reliable operation. TabToTask does not replace the home page, default search engine, or address-bar behavior.
本机处理的数据Data processed on-device
页签与窗口Tabs and windows
标题、URL、站点图标、窗口、顺序、固定状态与浏览器原生分组。Titles, URLs, favicons, windows, order, pinned state, and browser-native groups.
虚拟任务Virtual tasks
领域、任务、页面关系、手动纠错、撤销与回收站数据。Domains, tasks, page relationships, manual corrections, undo, and recycle-bin data.
行为事件Behavior events
打开来源、激活、停留、切换、关闭、移动、分组与窗口变化。Open source, activation, dwell, switching, closing, moving, grouping, and window changes.
产品设置Product settings
语言、主题、Web Dock、AI 设置、本地激活状态与短期页签预览。Language, theme, Web Dock, AI settings, local activation state, and short-term tab previews.
短期页签预览截图不会发送给云端 AI。签绪不以读取页面正文、表单输入、Cookie、密码、账号令牌或支付信息作为产品功能。Short-term tab preview screenshots are never sent to cloud AI. Reading page bodies, form input, cookies, passwords, account tokens, or payment information is not part of TabToTask’s product function.
官网访问分析Website analytics
官网匿名统计默认关闭,只有你在隐私设置中主动开启后才会发送。开启后,本机会按自然日生成不可跨日关联的随机批次 ID,并只上传官网统计版本和四项绝对计数:页面打开、Chrome 商店入口、离线下载入口、预约提交。它不读取扩展中的页签、浏览历史或页面正文。Website analytics are off by default and are sent only after you enable them in Privacy Settings. Once enabled, the browser creates a random daily batch ID that cannot be linked across days and sends only the analytics version plus four absolute counters: page views, Chrome Web Store entry clicks, offline-download entry clicks, and reservation submissions. It never reads extension tabs, browsing history, or page content.
- 四项统计的业务载荷不包含网址、站内路径、来源、搜索词、逐次时间、会话 ID、邮箱、IP 字段、Cookie、账号或跨站指纹。The four-counter analytics payload contains no URL, on-site path, referrer, search term, per-event timestamp, session ID, email address, IP field, cookie, account data, or cross-site fingerprint.
- 与任何网络请求一样,CDN 或托管服务可能在网络层接收源 IP 与连接元数据以传输和保护请求;网络层信息不属于上述统计业务载荷,我们不会把源 IP 加入四项统计记录或用于跨日识别。As with any network request, the CDN or hosting service may receive source IP and connection metadata at the network layer to deliver and protect the request. That network-layer information is not part of the analytics payload; we do not add source IP to the four-counter analytics records or use it for cross-day recognition.
- Do Not Track 或 Global Privacy Control 开启时,官网不发送统计事件。No analytics event is sent when Do Not Track or Global Privacy Control is enabled.
- 同一天重试复用同一个批次 ID;跨日更换,后台不能用它识别同一浏览器。Retries within one day reuse the same batch ID. It changes across days, so the backend cannot use it to recognize the same browser.
- 关闭统计后立即停止后续请求,并清除本机待上传批次和日批次秘密。Turning analytics off stops future requests immediately and clears the pending local batch and daily-batch secret.
- 原始匿名日批次最多保留 30 天;不含批次身份的月度汇总最多保留 12 个月。Raw anonymous daily batches are retained for up to 30 days. Monthly totals without batch identity are retained for up to 12 months.
- 匿名统计只在香港后端管理面板中汇总展示,公开访客无法读取。Anonymous totals are visible only in the Hong Kong backend admin panel and are not publicly readable.
当你主动提交上线预约时,我们会在香港后端保存你填写的邮箱、触发预约的安装入口、提交时间和语言,用于发送上线通知和兑现预约会员赠送。预约不会附带统计会话、页面路径或日批次 ID,邮箱也不会用于个性化广告或出现在公开页面。When you submit a launch reservation, the Hong Kong backend stores the email you provide, the install entry that opened the reservation, submission time, and language. We use it to send the launch notice and fulfill the membership offer. A reservation is never linked to an analytics session, page path, or daily batch ID, and your email is never used for personalized advertising or shown publicly.
可选扩展匿名统计Optional extension analytics
扩展匿名统计与官网统计分别控制,默认关闭。只有在扩展“隐私与数据”设置中主动开启后,才向 api.tabtotask.top 发送本机按自然日汇总的白名单计数;拒绝或关闭不影响本地核心能力。载荷包含协议版本、日期、随机日批次 ID、快照版本、扩展版本和固定汇总计数,例如工作台打开、网站打开、关闭操作、AI 次数、Token 数与耗时区间,以及上传失败次数。Extension analytics is controlled separately from website analytics and is off by default. Only opting in through the extension's Privacy & Data settings sends allowlisted on-device daily aggregates to api.tabtotask.top; declining or disabling it does not affect local core features. The payload includes schema version, day, random daily batch ID, snapshot revision, extension version, and fixed aggregate counters, such as workspace openings, site openings, close operations, AI requests, token totals, latency buckets, and upload failures.
统计还包含授权状态粗分类:有效(包括有效试用)、无效或未知;不包含许可证 ID、具体套餐 SKU、订单、激活码或设备身份。不会发送网址、域名、网站名、网页标题、搜索词、任务名、页签 ID、截图、提示词、安装凭据、API Key、精确事件时间或原始行为事件。日批次跨日更换,不与许可证或设备账本关联,不建立跨日画像。“活跃安装日”不是登录用户数、真实人数或物理设备数。Analytics also includes a coarse authorization class: active (including a valid trial), inactive, or unknown. It excludes license IDs, specific plan SKUs, orders, activation codes, and device identity. It sends no URLs, domains, site names, page titles, search terms, task names, tab IDs, screenshots, prompts, installation credentials, API keys, precise event timestamps, or raw events. Batch identity changes across days and is not joined with license or device ledgers or used for cross-day profiles. Active installation days are not logged-in users, people, or physical devices.
同一快照重试不重复累计,新的绝对快照替换旧值。可随时关闭统计并清除本机待上传批次;清除后当日暂停重新收集。已接收的匿名日批次最多保留 30 天,不含批次身份的汇总最多保留 12 个月。网络传输所需的源 IP 和连接元数据不属于统计业务载荷,不加入这些计数或用于跨日识别。Retrying a snapshot does not add duplicate counts; newer absolute snapshots replace older values. You can disable analytics and clear pending local batches at any time; clearing pauses collection for the rest of that day. Received anonymous daily batches are retained for up to 30 days, and aggregates without batch identity for up to 12 months. Source IP and connection metadata needed for network transport are not part of the analytics payload or counters and are not used for cross-day identification.
许可证与受控恢复Licensing and controlled recovery
激活、试用、设备绑定和 AI 额度由香港后端处理。兑换核验使用激活码的 HMAC 摘要;可恢复分享码另有服务器密钥保护的加密副本,只用于所属许可证的授权恢复。管理员生成的销售或内部测试批次保留受限文件权限保护的导出文件,供经过认证与审计的下载和发货,不是明文只能导出一次。这些文件不进入公开页面、源码、匿名统计或诊断。The Hong Kong backend handles activation, trials, device binding, and AI quota. Redemption uses HMAC digests of activation codes. Recoverable friend codes also have server-key-protected encrypted copies for authorized recovery by their owning license. Administrator-generated sale or internal-test batches retain export files protected by restricted file permissions for authenticated, audited download and delivery; plaintext export is not limited to one occasion. These files do not enter public pages, source code, anonymous analytics, or diagnostics.
必要的许可证、设备、撤销和额度账本用于提供已购权益、防止重复兑换、执行设备限制及处理退款或滥用;本机注销或清除数据不会自动删除它们。当前不承诺固定删除日期,可通过政策中的联系邮箱请求访问、更正或删除,仍为上述目的或法律义务所必需的记录除外。Necessary license, device, revocation, and quota records support purchased entitlements, prevent duplicate redemption, enforce device limits, and handle refunds or abuse. Local deactivation or data clearing does not automatically delete them. No fixed deletion date is promised. You may request access, correction, or deletion through the contact emails in this policy, subject to records still needed for these purposes or legal obligations.
网站图标的网络访问Network access for site icons
图标优先来自随包目录、本机缓存及 Chrome 图标接口。新增站点或补全缺少图标的站点时,扩展也可能直接访问公开网站的页面元信息和声明的图标地址;不是全部离线获取。扩展探测不带 Cookie 或 Referrer,页面元信息上限 2 MiB、图片上限 4 MiB,并拒绝重定向。所得内容只用于图标发现与显示,不发送给 AI 或匿名统计。Icons prefer bundled assets, local cache, and Chrome's favicon API. When adding sites or filling missing icons, the extension may also directly request public page metadata and declared icon URLs; retrieval is not entirely offline. Extension probes omit cookies and referrers, cap page metadata at 2 MiB and images at 4 MiB, and reject redirects. Retrieved content is used only for icon discovery and display, not sent to AI or analytics.
目标网站、图标主机及网络服务商可在网络层看到请求 URL、源 IP 和连接元数据,适用各自的数据处理规则;签绪不能控制所有第三方网络日志。网页本身或 Chrome 的图标请求与上述扩展探测是不同流程。Destination sites, icon hosts, and network providers may see request URLs, source IP, and connection metadata under their own data practices. TabToTask does not control all third-party network logs. A page's own icon requests and Chrome's icon requests are separate from the extension probes described above.
主动提交的反馈与诊断User-submitted feedback and diagnostics
反馈仅在你主动提交时发送,包含反馈类型、正文及可选回复邮箱,不支持附件,返回可查询编号,最多保留 90 天。管理员回复时记录回复内容、状态和发送时间。请勿在正文中填写密码、激活码或其他敏感信息。Feedback is sent only when you submit it. It contains a category, message, and optional reply email, accepts no attachments, returns a reference number, and is retained for up to 90 days. Administrator replies record the reply, status, and sending time. Do not include passwords, activation codes, or other sensitive information in your message.
发送诊断必须由你主动点击,并在提交前显示准确字段预览。诊断仅含扩展版本、操作系统、Chrome 大版本、错误码、后端请求 ID、AI 阶段耗时、许可证状态码和备用通道标志,最多保留 14 天。不自动附加网址、标题、任务内容、截图、提示词、激活码、安装凭据或真实 Key。Diagnostics requires an explicit action and shows the exact fields before submission. It contains only extension version, operating system, Chrome major version, error codes, backend request ID, AI-stage timings, license status codes, and fallback-channel flags, and is retained for up to 14 days. URLs, titles, task content, screenshots, prompts, activation codes, installation credentials, and real API keys are not automatically attached.
存储位置与保留时间Storage and retention
- 行为事件保存在本机 IndexedDB,滚动保留 30 天;用户可在隐私与数据设置中清除。Behavior events are stored in local IndexedDB on a rolling 30-day basis and can be cleared in Privacy & Data settings.
- 虚拟任务、页面关系与手动纠错保留到用户删除任务或清除全部本地数据。Virtual tasks, page relationships, and manual corrections remain until the user deletes them or clears all local data.
- 少量偏好可进入浏览器同步或本地存储;本机产品数据按功能写入 chrome.storage.local 或 IndexedDB。许可证签名私钥和备份密钥只由香港服务器 Secret 注入,不进入扩展、官网、后台页面或浏览器同步。A small set of preferences may use browser sync or local storage; on-device product data is stored in chrome.storage.local or IndexedDB according to function. License-signing private keys and backup keys are injected only as Hong Kong server secrets and never enter the extension, website, admin pages, or browser sync.
- 预览截图为短期会话缓存,最多 40 项,在会话结束、清除数据或缓存淘汰时删除。Preview screenshots are short-term session cache items, capped at 40 and removed on session end, data clearing, or cache eviction.
- 许可证、随机安装凭据、设备绑定、租约、兑换记录和 AI 额度属于提供已购权益、防止重复兑换、执行设备限制、处理退款欺诈及履行法律义务所必需的业务记录;这些记录在实现上述目的所必需的期间保留,不承诺固定删除期限。后端不建立用户账号,也不采集硬件指纹;扩展只保留当前设备凭据、可公开验签材料和最小权益状态。Licenses, random installation credentials, device bindings, leases, redemption records, and AI quota are necessary business records for delivering purchased entitlements, preventing duplicate redemption, enforcing device limits, addressing refund fraud, and meeting legal obligations. They are retained for as long as necessary for those purposes, with no fixed deletion period promised. The backend creates no user account and collects no hardware fingerprint; the extension keeps only the current device credential, public verification material, and minimum entitlement state.
- 官网原始匿名日批次最多保留 30 天,月度汇总最多保留 12 个月;预约邮箱及其提交记录在最后一次提交后最多保留 90 天,或收到你的删除请求时提前删除。Raw anonymous website daily batches are retained for up to 30 days and monthly totals for up to 12 months. Reservation emails and submission records are retained for up to 90 days after the latest submission, or deleted earlier on request.
由 Neco Api 提供的可选 AIOptional AI provided by Neco Api
用户成功激活“永久版 + 一年 AI”或“一年 AI 升级/续费”后,AI 自动开启,激活前会说明此行为及发送范围。基础版激活、试用领取、普通权益刷新和扩展重载不会自动开启,也不会覆盖你手动关闭的选择。开启后的自动整理也可能发起分析,不要求每次都另点分析按钮;“一句话筛选”仍由你主动提交。连接测试是主动执行的独立请求,不会替你打开 AI,也不等于已成功分析网页。Successful activation of Lifetime + one year of AI or a one-year AI upgrade/renewal enables AI, with this behavior and the data scope disclosed before activation. Basic activation, trial grants, ordinary entitlement refreshes, and extension reloads do not enable AI or override a manual choice to disable it. Enabled automatic organization can also initiate analysis without a separate click for every request; the one-sentence filter still requires explicit submission. A connection test is a separate user-initiated request and neither enables AI nor proves that page analysis succeeded.
AI 已按上述规则开启且具备有效权益和额度时,扩展通过香港网关实时转发分析所需的指令和上下文。上游为 Neco Api(青岛砚隅集科技有限公司;对应关系来自产品所有者转述的客服确认,所提供发票销售方名称一致,未作独立 API 运营关系核验)。CN 路由为 fast.sbbbbbbbbb.xyz,GLOBAL 为 api.sbbbbbbbbb.xyz。候选排序可能发送页面 ID、脱敏标题、注册域、路径类型、有界聚合证据和风险代码,以及候选任务 ID、名称、领域和最多 5 个脱敏核心页面标题。工作区规划还可能发送任务来源、是否允许改名及接收关系。只有“一句话筛选全部页签”发送用户输入的自由文本筛选描述。When AI is enabled under the rules above and has valid entitlement and quota, the extension relays the instructions and context needed for analysis through the Hong Kong gateway. The upstream is Neco Api (青岛砚隅集科技有限公司; this association is based on the product owner's report of support confirmation, with a matching seller name on the supplied invoice, not independent verification of API operation). The CN route is fast.sbbbbbbbbb.xyz and GLOBAL is api.sbbbbbbbbb.xyz. Candidate ranking may send page IDs, redacted titles, registered domains, path types, bounded aggregate evidence and risk codes, plus candidate task IDs, names, domains, and up to five redacted core-page titles. Workspace planning may also send task source and whether renaming or receiving relationships is allowed. Only the one-sentence tab filter sends the user-entered free-text filter description.
工作区规划的任务字段具体包括任务 ID、名称、领域、来源(手动或 AI)、是否允许改名、是否允许接收关系,以及最多 5 个脱敏核心页面标题。若用户修改并启用对应分析的系统提示词,该提示词也会发送。只有用户主动使用“一句话筛选全部页签”时,才会发送用户在筛选框中输入的自由文本描述;候选排序和工作区规划不发送这段描述。Workspace-planning task fields include task ID, name, domain, source (manual or AI), whether it may be renamed, whether it may receive relations, and up to five redacted core-page titles. If a user edits and enables the system prompt for an analysis, that prompt is also sent. Only when the user explicitly uses Filter all tabs with one sentence is the free-text description entered in that filter sent; candidate-ranking and workspace-planning requests do not send that description.
“一句话筛选全部页签”按稳定页面 ID 和去除查询参数与哈希后的安全 URL 合并重复页面,排除已识别的敏感站点和重置密码路径。对每个纳入请求的去重页面,发送页面 ID、脱敏标题、注册域、协议/主机名/可选端口和经脱敏检查的 pathname、路径标签/类型、激活状态,以及保护级别和保护代码。发送副本中的编码邮箱、明显令牌和长秘密标识会被替换,本机打开页面的原网址不变。pathname 可能仍包含未被规则识别的文件名、项目名、人名或对象 ID,不能保证匿名。Filter all tabs with one sentence merges duplicates by stable page ID and safe URL after query and fragment removal, and excludes recognized sensitive sites and password-reset paths. For each deduplicated page included in the request, it sends a page ID, redacted title, registered domain, protocol/hostname/optional port and a checked, redacted pathname, path label/type, active state, and the protection level and protection codes. Encoded emails, obvious tokens, and long secret identifiers are replaced in the outbound copy; the original local navigation URL is unchanged. A pathname may still contain unrecognized file names, project names, personal names, or object IDs; this is not an anonymity guarantee.
不会发送查询参数、哈希、页面正文、表单输入、Cookie、截图、书签、完整浏览历史、浏览器页签/窗口 ID 或原始行为事件流。规则无法保证识别所有敏感路径,请在使用前检查页签范围。我们的香港网关只在请求期间转发 AI 请求指令、上下文和输出,不把它们写入签绪的产品数据库、应用日志、匿名统计、反馈或诊断;这一说明不代表 Neco Api 的上游处理承诺。AI 只调整虚拟任务关系,不移动、关闭、固定、分组或重排真实页签。TabToTask does not send query parameters, fragments, page bodies, form input, cookies, screenshots, bookmarks, complete browsing history, browser tab/window IDs, or raw behavior streams. Rules cannot identify every sensitive path; review the tab scope before use. Our Hong Kong gateway relays AI request instructions, context, and outputs only while the request is active and does not write them to TabToTask product databases, application logs, anonymous analytics, feedback, or diagnostics; this does not represent a promise about Neco Api's upstream handling. AI adjusts virtual task relationships only and never moves, closes, pins, groups, or reorders real tabs.
权限与触发方式Permissions and triggers
分享与有限使用Sharing and Limited Use
签绪不出售或出租用户数据,不将其用于个性化广告,也不授权第三方为这些目的使用浏览数据。AI、可选统计、许可证、主动提交的反馈和诊断仅按本政策分别说明的目的与范围处理;AI 不是数据出售或广告使用的例外。必要数据只在提供页签管理单一用途、遵守法律或处理安全滥用所需范围内使用。Neco Api 尚待核实的处理规则见第 05 节。TabToTask does not sell or rent user data, use it for personalized advertising, or authorize third parties to use browsing data for those purposes. AI, optional analytics, licensing, and user-submitted feedback and diagnostics are handled only for the purposes and scope described separately in this policy. AI is not an exception for data sales or advertising. Necessary data is used only to provide the single tab-management purpose, comply with law, or address security abuse. See Section 05 for upstream handling terms still awaiting verification.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
用户控制与删除User control and deletion
- 不申请或撤销可选书签权限,并随时关闭 AI;history 是安装时必需权限,卸载扩展可撤销。文件页面另需在 Chrome 扩展设置中主动允许文件访问。Decline or revoke optional bookmarks access and turn AI off at any time. History is required at installation and can be revoked by uninstalling. File pages additionally require you to allow file access in Chrome's extension settings.
- 在扩展“隐私与数据”中关闭匿名使用统计或清除待上传批次;自定义壁纸只在本机处理和保存,不上传、不同步、不进入备份或日志,可单独移除或随全部本地数据删除。Disable extension analytics or clear pending batches in Privacy & Data. Custom wallpapers are processed and stored only on-device, never uploaded, synced, backed up, or logged, and can be removed separately or with all local data.
- 清除行为事件或全部本地数据。Clear behavior events or all local data.
- 删除任务、关系、回收站内容并注销本地激活状态。Delete tasks, relationships, recycle-bin items, and deactivate local activation.
- 卸载扩展以删除扩展拥有的本地存储;同步数据由浏览器账户机制管理。Uninstall to remove extension-owned local storage; browser-account mechanisms control synced data.
- 单独开启或关闭官网匿名统计;关闭会清除本机待上传批次。Enable or disable anonymous website analytics separately; turning it off clears the pending local batch.
- 可独立发送数据查阅、更正或删除请求至 Send an access, correction, or deletion request independently to 905405692@qq.com,也可独立发送至 , or independently to Liushuangguang007@gmail.com。.
清除本地数据或卸载扩展不会自动删除后端必要业务记录。你可以提出请求,但为提供权益、防止重复兑换、执行设备限制、处理退款欺诈或履行法律义务仍属必要的记录,可能继续保留到相关目的结束。关闭 AI 不会自动删除上游已处理的数据;截至 2026-09-12,我们尚未核实 Neco Api 的用户删除渠道,可通过本政策联系邮箱提出请求并由我们协调。Clearing local data or uninstalling does not automatically delete necessary backend business records. You may request deletion, but records still necessary for entitlements, redemption safeguards, device limits, refund fraud, or legal obligations may remain until those purposes end. Disabling AI does not automatically delete data already processed upstream. As of September 12, 2026, we have not verified Neco Api's user deletion channel; contact the addresses in this policy so we can coordinate your request.
如果未来版本改变收集字段、用途、保留周期或第三方接收方,签绪会在变更生效前通过产品内醒目提示主动说明,并同步更新本政策与商店隐私披露。If a future version changes collected fields, purposes, retention, or third-party recipients, TabToTask will provide a prominent in-product notice before the change takes effect and will update this policy and the store privacy disclosures.
查看支持与数据请求路径See support and data-request path