Nexamas SmartBookmarks
ProductTermsAccount deletionImprint
Privacy policy

Your data, by design.

This policy explains how Nexamas SmartBookmarks handles local library data, optional account information and encrypted cloud backup. It applies to the browser extension and its supporting account service.

Effective: 3 August 2026Controller established in GermanyPrivate testing release
EnglishDeutsch

1. Controller and contact

Husam Al Masryoperating under the Nexamas brandHopfenstraße 595652 Waldsassen, Germanysupport_smartbookmarks@nexamas.comcontact@nexamas.com

No separate data-protection-officer contact is currently designated. Privacy inquiries may be sent to either address above; this statement will be reviewed if the operation or legal requirements change.

2. Product scope and principles

SmartBookmarks is a local-first browser extension. Its bookmark library can be used without creating an account. Optional account and encrypted-sync features are separate from the local library.

  • No advertising or sale of personal data.
  • No behavioral analytics or third-party tracking SDK is built into the extension.
  • The account API is designed not to receive bookmark URLs, titles, folder names, tags, notes, saved browser sessions, tab details, screenshots, encryption keys or Recovery Keys.
  • Cloud backup is optional and is encrypted on the user's device before upload.

3. Data processed locally in the browser

The extension stores the information needed to provide its local features in browser-managed extension storage and IndexedDB. Depending on use, this can include:

  • bookmarks, URLs, titles, folders, tags and notes;
  • saved browser sessions and their tab/window structure;
  • trash and change records needed for local management and sync;
  • language, theme and product preferences;
  • local device, account and sync state;
  • locally held encryption material needed while an encrypted vault is active.

This data remains on the device unless the user chooses export or encrypted cloud backup. Browser permissions include storage, tabs and alarms, with optional identity and tab-group permissions. SmartBookmarks does not install content scripts that read page contents.

4. Optional Nexamas account data

When an account is used, the Nexamas account service may process:

  • an internal account identifier and verified email address;
  • identity-provider name and provider subject identifier for Google or Microsoft sign-in;
  • an optional display name supplied by the identity provider;
  • trusted-device identifiers and device labels;
  • revocable session records and cryptographic token hashes;
  • short-lived email-code, OAuth state and exchange-ticket records;
  • rate-limit and abuse-prevention identifiers stored as opaque hashes rather than raw IP addresses.

Email sign-in codes are valid for 10 minutes. Nexamas account sessions are issued for up to 30 days and can be revoked earlier. Short-lived challenges are retained only as operationally necessary for validation, security and abuse prevention.

5. Sign-in providers and email delivery

ProviderPurpose and data flow
GoogleOptional authentication and, separately, authorization for Google Drive app-data backup. Google provides identity claims and OAuth authorization directly through its services.
MicrosoftOptional authentication and, separately, OneDrive App Folder authorization. Microsoft provides identity claims and cloud authorization through Microsoft identity and Graph services.
ResendDelivery of one-time email sign-in and security messages where email access codes are used.
FastmailHosting and delivery of product-support and general contact email.

6. Encrypted Google Drive and OneDrive backup

Google Drive

SmartBookmarks requests the narrow https://www.googleapis.com/auth/drive.appdata permission. It is used only to create, inspect, update or delete SmartBookmarks application data in Google's hidden application-data space. It does not grant general access to files in My Drive.

OneDrive

SmartBookmarks uses the delegated Files.ReadWrite.AppFolder permission and the application's dedicated OneDrive App Folder. It does not request general access to all OneDrive files.

Encryption boundary

The library snapshot is encrypted locally before upload. The Recovery Key is shown to the user and is not sent to the Nexamas account service. The selected cloud provider stores the encrypted vault in the user's own account. Losing the Recovery Key may make the vault unrecoverable.

7. Purposes and legal bases

PurposeLegal basis
Provide the local extension and requested account/sync featuresArt. 6(1)(b) GDPR — performance of the user relationship and requested service.
Protect accounts, prevent abuse, maintain service integrity and diagnose failuresArt. 6(1)(f) GDPR — legitimate interests in security, reliability and fraud prevention.
Respond to support and legal requestsArt. 6(1)(b), (c) or (f) GDPR depending on the request.
Optional provider authorizationInitiated by the user to provide the selected feature; provider consent and controls apply separately.

8. Hosting, recipients and international processing

The account API is hosted using Cloudflare Workers and D1. Cloudflare may process technical request and security data as an infrastructure provider. Google, Microsoft, Resend and Fastmail process data under their own terms and privacy documentation when their services are used.

Some providers may process data outside Germany or the European Economic Area. Where required, transfers rely on the safeguards made available by the relevant provider and applicable data-protection law. Nexamas does not disclose library content to advertisers or data brokers.

9. Retention and deletion

  • Local library: retained on the device until the user deletes records, clears extension data or uninstalls the extension.
  • Account: retained until the account is deleted, subject to limited records required by law or for resolving security incidents.
  • Sessions: expire after up to 30 days or earlier when revoked, signed out or invalidated.
  • Short-lived challenges: expire within their configured period and are retained only as operationally necessary for security and abuse prevention.
  • Encrypted cloud vault: retained in the user's cloud account until deleted through SmartBookmarks, through account deletion where applicable, or directly through the cloud provider.
  • Support correspondence: retained as long as needed to respond, document the request and meet applicable legal obligations.

Important: uninstalling the extension removes browser-local extension storage, but it does not by itself delete a Nexamas account or encrypted cloud vault. Use the in-product account deletion flow or contact support.

10. Account deletion

The current deletion flow attempts to delete and verify removal of the encrypted cloud vault before deleting the Nexamas identity, devices and sessions. If cloud deletion cannot be verified, account deletion is stopped rather than reporting false success. The local bookmark library is intentionally left on the device unless the user separately removes it.

Read the account-deletion instructions.

11. Your rights

Subject to the GDPR and applicable conditions, users may request access, rectification, erasure, restriction, portability and objection, and may withdraw consent where processing is based on consent. Requests can be sent to the product-support address.

Users also have the right to lodge a complaint with a supervisory authority. For the controller's establishment in Bavaria, the competent private-sector authority is generally the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).

12. Security and policy changes

Nexamas uses encrypted transport, revocable account sessions, hashed server-side token records, short-lived challenges and client-side vault encryption. No system can be guaranteed risk-free. Material changes to data use will be reflected in this policy and, where required, communicated before the new processing begins.

Datenschutzerklärung — Kurzfassung auf Deutsch

Verantwortlicher ist Husam Al Masry, handelnd unter der Marke Nexamas, Hopfenstraße 5, 95652 Waldsassen, Deutschland. Kontakt: support_smartbookmarks@nexamas.com.

SmartBookmarks ist eine lokal ausgerichtete Browser-Erweiterung. Lesezeichen, URLs, Ordner, Notizen, Tags und gespeicherte Browser-Sitzungen werden grundsätzlich im Browser gespeichert. Die Kernbibliothek kann ohne Konto verwendet werden.

Welche Daten werden verarbeitet?

  • Lokal: Bibliotheksinhalte, Sitzungen, Einstellungen und – bei aktivierter Synchronisierung – lokale Synchronisierungs- und Verschlüsselungsdaten.
  • Optionales Nexamas-Konto: bestätigte E-Mail-Adresse, interne Konto-ID, Identitätsanbieter, Geräte- und widerrufbare Sitzungsdaten sowie kurzlebige Sicherheits- und Anmeldeinformationen.
  • Der Account-Dienst soll keine Lesezeichen-URLs, Titel, Ordner, Tags, Notizen, Tab-Inhalte oder Recovery Keys erhalten.

Verschlüsselte Sicherung

Die Sicherung ist freiwillig. Vor dem Upload wird der Bibliotheks-Snapshot auf dem Gerät verschlüsselt. Bei Google Drive wird ausschließlich der Bereich für anwendungsspezifische Daten (drive.appdata) verwendet. Bei OneDrive wird der App Folder der Anwendung verwendet. Der Recovery Key wird nicht an den Nexamas-Account-Dienst übertragen.

Rechtsgrundlagen, Empfänger und Speicherdauer

Die Verarbeitung erfolgt insbesondere zur Vertragserfüllung bzw. Bereitstellung der angeforderten Funktionen (Art. 6 Abs. 1 lit. b DSGVO) und aufgrund berechtigter Interessen an Sicherheit, Missbrauchsschutz und Zuverlässigkeit (Art. 6 Abs. 1 lit. f DSGVO). Technische Dienstleister können Cloudflare, Google, Microsoft, Resend und Fastmail sein.

Kontodaten werden grundsätzlich bis zur Löschung des Kontos gespeichert. Sitzungen laufen nach höchstens 30 Tagen ab oder werden früher widerrufen. Lokale Daten verbleiben bis zur lokalen Löschung oder Deinstallation. Die verschlüsselte Cloud-Vault verbleibt bis zu ihrer gesonderten Löschung.

Ihre Rechte

Sie haben nach Maßgabe der DSGVO Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch. Beschwerden können an eine Datenschutzaufsichtsbehörde gerichtet werden; für nicht-öffentliche Stellen in Bayern ist grundsätzlich das Bayerische Landesamt für Datenschutzaufsicht zuständig.

Die englische Fassung oben enthält die ausführliche technische Beschreibung. Bei Fragen wenden Sie sich an den Produktsupport.

© NexamasSmartBookmarks · Terms · Website privacy · Imprint