Privacy Policy
Last updated 30 July 2026
This policy describes what BookmarkHub actually does today, field by field. Where something is a known gap (for example, there's no self-serve "delete my account" button yet), it says so rather than pretending otherwise.
It's written in good faith to align with the GDPR, UK GDPR, the ePrivacy Directive,
and the CCPA/CPRA. Bracketed text like [legal entity name] marks the one
placeholder still waiting on a real answer.
1. Who this covers
This policy applies to BookmarkHub ([legal entity name], "BookmarkHub,"
"we," "us"), the bookmark-saving service at this domain, its browser extension, and any
collection someone shares from it. BookmarkHub is the data controller for the personal
data described below — the entity that decides what's collected and why.
2. Information we collect
We collect exactly what the product needs to work, and nothing decorative, and store it in our own database — not with an ad network, not with an analytics vendor, nowhere else:
- Account details — your name and email address, plus either a password (stored as a salted hash, never in readable form) or, if you create your account with the "Continue with Google" option, confirmation from Google of your name, email, and that Google has verified it. We never see or store a Google password — Google handles that authentication step entirely on its own side.
- Your bookmarks — each saved URL, its domain, the title (usually fetched automatically from the page), any note or tags you add, which collection it's in, whether it's a favourite, and the timestamps for when you saved and last edited it.
- Collections — the names you give them, and a random share token if you turn sharing on for one.
- Billing status — whether you're on the Free or Pro plan. If Pro is purchased through Stripe, we store a Stripe customer ID and subscription ID so we know your plan is active. We do not receive, process, or store your card number — Stripe handles that directly.
- IP address — read transiently to rate-limit login, sign-up, and password-reset attempts so an automated attacker can't hammer those endpoints. It isn't logged long-term, stored against your account, or used to profile or track you.
We run one analytics tool, Umami, chosen specifically because it's built not to identify you — no ad pixels, no session recording, no cookies, and no advertising here to profile you for in the first place. What it tells us is aggregate: how many people visited, roughly which country from, what pages, what device and browser, and how they got here — never anything tied back to an individual visitor.
A few exceptions worth naming directly. Every page loads the Inter typeface from Google Fonts — a request your browser makes straight to Google's servers for a font file. It doesn't set a cookie and Google's font-serving endpoint doesn't log personal data tied to it, but your IP address is still visible to Google the way it would be for any file hosted somewhere that isn't us. Every page also loads Umami for the aggregate analytics described above — it doesn't set a cookie or write anything to your device, and your IP address is used only momentarily, to work out a rough country, never stored. Separately, inside the app itself, each bookmark's little site icon is fetched from DuckDuckGo's icon service by domain name only (never the full URL, your note, or anything else about the bookmark) — if one fails to load you get a plain coloured monogram instead, nothing is retried or tracked. The sign-up and sign-in page also loads Cloudflare Turnstile, a small challenge widget that checks you're not a bot before the form submits — Cloudflare sees your IP address and some device signals for that check, under Cloudflare's own privacy policy, and it isn't used for advertising. These are the only third-party requests this site makes, and each is written down here rather than left unmentioned.
The browser extension only ever reads the tab you're actively on, and
only when you click its icon (Chrome's activeTab permission, which grants
nothing until that click). It doesn't run in the background, doesn't see your browsing
history, and doesn't read any other open tab. What it sends when you save something is
exactly what you'd type into the app by hand: the page's title and URL, and whatever
note or tags you add.
3. Cookies & local storage
One cookie. That's the whole list — no analytics cookies, no advertising cookies, no cross-site tracking pixels. The table below is the complete technical reference; the Cookie Policy covers the same ground in plainer language, including how the session cookie connects to the name and email on your account.
| Name | What it is | Purpose | Lifetime |
|---|---|---|---|
bh_session |
HTTP cookie, HttpOnly, SameSite=Lax | Keeps you signed in. Strictly necessary — this is what "being logged in" means technically, so it isn't optional the way an analytics cookie would be. | Renews itself while you're an active user, up to 90 days after your last visit; ends immediately if you sign out |
bh.view |
Browser local storage — not a cookie, never sent to our servers | Remembers whether you last used grid or list view. Optional — only written if you accept the cookie notice. | Until you clear your browser's site data |
bh.tourSeen |
Browser local storage — not a cookie, never sent to our servers | Remembers you've already seen the one-time new-account walkthrough. Optional — only written if you accept. | Until you clear your browser's site data |
bh.paymentMethod |
Browser local storage — not a cookie, never sent to our servers | Remembers which card brand and last four digits to show on the Manage Subscription screen. Optional — only written if you accept. | Until you clear your browser's site data |
bh.cookieConsent |
Browser local storage — not a cookie, never sent to our servers | Remembers your Accept/Decline choice so the notice doesn't reappear, and so we know whether the three rows above are allowed to be written. Always stored, whichever you choose. | Until you clear your browser's site data |
If billing is connected to Stripe, upgrading redirects you to a checkout page hosted by Stripe, which sets its own cookies under its own privacy policy (stripe.com/privacy) — we don't control those and they're never set on this domain.
The session cookie is strictly necessary, so the law doesn't actually require asking
your permission for it — only telling you about it, which is what the notice on this
site and this section do. bh.view, bh.tourSeen, and
bh.paymentMethod are a different story: the notice gives you a real Accept
and Decline, and Decline is honoured — those three are never written to your device in
the first place, not stored and then ignored. (bh.cookieConsent, which just
remembers that choice, is stored either way — otherwise we couldn't remember you
declined.)
4. How we use it
- To create and secure your account, and to keep you signed in.
- To let you sign in with a Google account instead of a password, if you choose that option, and to match it to an existing account by email if you already have one.
- To store, search, and display your bookmarks and collections back to you.
- To fetch a page's title when you save it — only the
<head>, capped at six seconds and 256 KB, purely to read the title and description. If it fails or times out, saving still goes through with the domain as the title instead. - To send account-related email: password resets and email verification. No marketing email is sent, because none exists.
- To process payment and manage your subscription, if and when Stripe billing is connected.
- To rate-limit authentication endpoints against abuse.
We do not use your data to train any model, ours or anyone else's.
5. Who we share it with
We do not sell personal information, and have not in the preceding 12 months. We do not share it for cross-context behavioural advertising, because we don't do advertising. The only sharing that happens:
- Stripe, our payment processor — only if and when billing is connected, and only the minimum needed to process a payment (your email and the charge amount). Stripe is a PCI-compliant processor with its own privacy obligations.
- Umami, for the aggregate analytics described above — page visits, rough location, device and browser type. Not anything that identifies you.
- A collection you explicitly share — turning sharing on for a collection makes it visible, read-only, at a URL containing a random token, to anyone you give that link to. Nothing else in your account is reachable from it, and turning sharing back off makes the link return a 404 immediately.
- Law enforcement or legal process, only if we're legally compelled to and only to the extent required.
6. Our legal basis for processing
For users in the UK, EU, or EEA, we rely on:
- Performance of a contract — most of what's described above, since it's what's needed to provide the service you signed up for.
- Legitimate interests — rate-limiting and abuse prevention, and understanding aggregate site usage through privacy-focused analytics (see Information we collect), each weighed against your rights and kept to the minimum needed.
- Consent — only where we'd ever ask for it separately; nothing in the current product relies on consent as its basis, since there's no individual tracking to consent to.
7. How long we keep it
We keep your account and bookmark data for as long as your account exists. There is currently no self-serve "delete my account" control in the product — to request deletion or correction of your data, contact us using the details below and we'll action it manually (exporting is self-serve — see Your rights). Sessions expire automatically after 90 days of inactivity; using the app at all resets that clock, so an account you keep coming back to effectively never signs itself out. Rate-limit tracking for IP addresses is held only in memory and clears on its own shortly after the limiting window ends.
8. Your rights
If you're in the UK, EU, or EEA, you have the right to access, correct, delete, or export a copy of your personal data, to object to or restrict how we process it, and to withdraw consent where consent is the basis for processing. You can also lodge a complaint with your local data protection authority — in the UK, that's the ICO.
If you're a California resident, the CCPA/CPRA gives you the right to know what personal information we hold, to delete it, to correct it, and to opt out of its sale or sharing — which, as above, we don't do. We also honour the Global Privacy Control signal as a valid opt-out request, though since nothing here is sold or shared in the first place, sending it won't change what you see. Exercising any of these rights won't result in different treatment or degraded service.
Exporting your data doesn't require asking us — Export bookmarks in the account menu gives you an HTML or JSON copy of everything on the spot, no request or wait involved.
Deleting your account is still a request, for now: email us, and we'll verify it's really you before acting on it. Today that verification and the resulting deletion are handled manually rather than through an automated flow — we'll say so plainly here once that changes.
9. How we protect it
We use industry-standard technical and organizational measures to protect your account and data, and review them as the product evolves. We don't publish the specifics of our security architecture here — that's deliberate, not an oversight. No system is perfectly secure; if you believe you've found a vulnerability, contact us using the details below.
10. Children's privacy
BookmarkHub isn't directed at children, and we don't knowingly collect personal information from anyone under 16. If you believe a child has created an account, contact us and we'll remove it.
11. International users
BookmarkHub is a hosted, publicly reachable service — your data is processed in the United Kingdom, where it's hosted. If you're accessing it from outside the UK, transfers rely on the safeguards required by your local law — for EU users, that typically means the UK's adequacy status under the GDPR, which permits data to flow to the UK without additional safeguards.
12. Changes to this policy
If this policy changes in a way that meaningfully affects what we collect or how we use it, we'll update the date at the top and, where required, tell you directly rather than relying on you to re-check this page.
13. Contact us
Questions, or a request to access, correct, export, or delete your data: [email protected].