Cookie Policy
Last updated 30 July 2026
This is the plain-language version. The full legal detail on cookies already lives in section 3 of the Privacy Policy — this page exists separately because "what does this cookie actually do, and what does it have to do with my name and email" deserves a straight answer without wading through the rest of a privacy policy to get it.
1. The short version
BookmarkHub sets one cookie, and it exists for exactly one reason: to keep you signed in. A handful of small settings also live in your browser's local storage — never sent to us, never leave your device, and only written at all if you accept the notice on your first visit. There are no advertising cookies and no cross-site tracking. We do run one analytics tool (Umami) to see aggregate site usage, but it's built specifically not to use cookies or write anything to your device — see Cookies from other services for the detail. If that's all you came here to check, you're done.
2. What's stored, and why
| Name | What it is | What it's for | How long |
|---|---|---|---|
bh_session |
HTTP cookie, HttpOnly, SameSite=Lax | The one that actually matters — see below for what it's tied to. | Renews itself while you're active, up to 90 days after your last visit; gone the moment you sign out |
bh.view |
Local storage, device-only — optional | Remembers whether you last had bookmarks in grid or list view. Only written if you accept the cookie notice. | Until you clear your browser's site data |
bh.tourSeen |
Local storage, device-only — optional | Remembers you've already seen the one-time new-account walkthrough, so it doesn't replay every time you log in. Only written if you accept. | Until you clear your browser's site data |
bh.paymentMethod |
Local storage, device-only — optional | Remembers which card brand and last four digits to display on the Manage Subscription screen, so it doesn't have to reload on every visit. Only written if you accept. | Until you clear your browser's site data |
bh.cookieConsent |
Local storage, device-only | Remembers your Accept/Decline choice itself, so the notice stops reappearing and we know whether the three rows above are allowed to be written. Always stored, whichever you choose — that's how your choice gets remembered. | Until you clear your browser's site data |
Everything below the first row is local storage, not a cookie — the distinction matters because none of it is ever transmitted to our server. It sits in your browser, for your browser, and we only see it if you tell us about it.
3. How this connects to your name and email
When you create an account, you give BookmarkHub a name and an email address — either
typed in directly, or handed over by Google if you use "Continue with Google," in which
case Google also confirms it's actually verified. That's the personal data on file. The
bh_session cookie doesn't contain your name or email — it can't be read by
any other website, and even JavaScript on this site can't read it. What it holds is a
random, signed token that means, in effect, "this browser is currently signed in as
the account with this name and email." Every request your browser makes hands that
token back to our server, which looks up the matching account and responds accordingly.
Take the cookie away and the connection between your browser and your account is gone — you'd need to sign in again for us to know who you are. That's the entire mechanism. There's no hidden second purpose: no ad ID stitched to it, no fingerprinting, nothing resold to a data broker. It's a login token, doing a login token's job, tied to the account details you gave us when you signed up. For the complete list of what we collect and why — bookmarks, collections, billing status, and so on — see the Information we collect section of the Privacy Policy.
4. Cookies from other services
If billing is connected to Stripe, upgrading to Pro redirects you to a checkout page hosted by Stripe, which sets its own cookies under its own policy (stripe.com/privacy). Those are set on Stripe's domain, not ours, and we don't control them. A few other third-party requests happen without setting any cookie at all: the analytics tool (Umami) on every page, the Inter typeface from Google Fonts on every page, each bookmark's little site icon fetched from DuckDuckGo's icon service by domain name only, and Cloudflare Turnstile on the sign-up and sign-in page. None of the four sets a cookie; all are described in more detail in the Privacy Policy.
5. Your choices
- The session cookie isn't part of the choice — it's not optional if you want to stay signed in, so there's no toggle to turn it off without also signing you out. Because it's strictly necessary, the law doesn't require asking permission for it either, only disclosing it, which is what this page and the notice on first visit both do.
- The three optional rows above are a real Decline, not a formality —
the notice on your first visit has an actual Accept and Decline button. Click Decline
and
bh.view,bh.tourSeen, andbh.paymentMethodare never written in the first place: your view choice won't be remembered, the walkthrough will show again next time, and Manage Subscription won't cache a payment display. It's not that we store it and then respect a preference not to use it — we just don't write it. - Change your mind any time — reopen the notice with the "Cookie settings" link in the footer of any page and choose again.
6. Changes to this policy
If what's stored here ever changes — for instance, if a future version adds an optional cookie that isn't strictly necessary — this page and the on-site notice will be updated to offer a real opt-in choice before that cookie is set, and the date at the top will change.
7. Contact us
Questions about any of this: [email protected].