Last updated: 2026-08-17
Tabmit is a browser extension that sends the content of the current browser tab (or, for bookmark-folder profiles, a batch of bookmarked tabs) to a destination of your choice: your default e-mail client, Gmail, Notion, Google Drive, OneDrive, Dropbox, or a TabMitTag server you control. Every submission is initiated explicitly by you — either by clicking the toolbar button, using the right-click menu, or manually running a bookmark-folder profile. Tabmit never acts automatically or in the background on its own. Tabmit does not collect any user data for the developer's own purposes.
When you invoke a profile, Tabmit reads the following data from the active tab (or, for a binary file such as a PDF, downloads the file itself) and forwards it to the service configured in that profile:
| Data | Destination |
|---|---|
| Page title | Every destination |
| Page URL | Every destination (when "Include page URL" is enabled) |
| Page content (HTML and/or plain text, or extracted PDF text) | Every destination |
| Extracted keywords/tags | Notion, and other destinations that support tagging |
| Images and stylesheets embedded in the page | Inlined into the email body (Gmail/clipboard profiles only); never sent to Tabmit |
| The bookmarked page's URL, and (for bookmark-folder profiles) actions taken on the bookmark itself (kept, moved, or deleted) | Your own browser's bookmarks, not transmitted anywhere external |
The destination is always a service that you control and authenticate to directly:
mailto:) — data is passed to your
operating system's default mail application via a mailto: URL. It never leaves
your device until you click Send.mail.google.com/gmail.googleapis.com to pre-fill a compose window or
draft, using an OAuth token scoped to gmail.compose only. Tabmit does not use a
server intermediary.api.notion.com, either using an
Integration Token you created and provided, or (in "cookie mode") your existing Notion browser
session. Pages/blocks are created in the workspace and database you selected.googleapis.com (Drive and, for folder selection, Picker APIs) using an OAuth token
scoped to drive.file only — this scope limits Tabmit's access to files/folders you
explicitly select through Google's own folder picker; it cannot see or list the rest of your
Drive.graph.microsoft.com) using an OAuth token obtained via Microsoft's own sign-in
flow, scoped to the folder you configure.api.dropboxapi.com/content.dropboxapi.com) using an OAuth token
obtained via Dropbox's own sign-in flow (Authorization Code + PKCE).Tabmit stores the following data in your browser's chrome.storage.local (or
browser.storage.local on Firefox), which stays on the device it was created on and is
not synced across your devices:
| Item | Purpose |
|---|---|
| Profile definitions (name, client type, destination folder/recipient/database, format and other options) | Remembers your configured profiles |
| Notion integration token | Authenticates requests to the Notion API; stored encrypted with a passphrase you set |
| TabMitTag server URL and, in API-key mode, the API key you provide | Authenticates requests to your own TabMitTag server |
| Default profile selection | Determines which profile is invoked by default |
| Recent submission log (URL + timestamp, overall and per-profile) | Powers the toolbar icon submission indicator and the "skip already submitted" bookmark-folder option |
| Bookmark-folder processing log | Records success/failure/skip status per bookmark for the report shown after a bookmark-folder run |
| Paywall-detection rules and custom global settings (timeouts, PDF-text limits, etc.) | Lets you customize extension behavior |
OAuth access tokens for Gmail, Google Drive, OneDrive, and Dropbox are managed by the browser's own identity APIs (or Dropbox/OneDrive/Google's own sign-in flow) and are not written into Tabmit's own storage.
This data is stored only on your own device(s). The developer has no access to it.
When you use a Gmail, Google Drive, OneDrive, Dropbox, Notion, or TabMitTag profile, data is transmitted to that service. Their own privacy policies apply:
| Permission | Why it is needed |
|---|---|
activeTab | Read the current tab's title, URL, and content when you click the toolbar button |
scripting | Inject a one-shot script to capture the live page DOM (title, URL, HTML, selected text) |
storage | Persist your profiles and settings in chrome.storage.local |
contextMenus | Add profiles to the browser right-click menu |
clipboardWrite | Write self-contained HTML to the clipboard for clipboard-mode profiles |
notifications | Show a brief confirmation notice after a page is submitted |
bookmarks | Read bookmarks from a user-selected folder to submit multiple pages in sequence, and move/delete processed bookmarks (bookmark-folder profiles) |
declarativeNetRequestWithHostAccess | Set a mobile User-Agent for a bookmarked page's tab when a bookmark-folder profile requests the site's mobile version, so simplified mobile markup can be captured |
offscreen | Run a hidden document with DOM access so the service worker can parse and inline HTML (Chrome only) |
identity | Obtain OAuth tokens to authenticate Gmail API and Google Drive API calls, each scoped to only the API being used (Chrome only) |
sandbox (Chrome only) | Load Google's own Picker widget in an isolated page so you can choose a Google Drive folder without granting Tabmit broad Drive access |
host_permissions: <all_urls> | Fetch images/stylesheets for inlining into Gmail/clipboard email bodies, and upload binary tabs (e.g. PDFs) to your chosen destination |
host_permissions: api.notion.com | Send page content to the Notion API using the integration token or session you provided |
cookies (optional) | Read your existing Notion session cookie when you opt into Notion "cookie mode", requested only when you enable that option |
Questions or concerns: github.com/tomtom/tabmit/issues