1. Controller and contact
No separate data-protection-officer contact is currently designated. Privacy inquiries may be sent to either address above; this statement will be reviewed if the operation or legal requirements change.
This policy explains how Nexamas SmartBookmarks handles local library data, optional account information and encrypted cloud backup. It applies to the browser extension and its supporting account service.
No separate data-protection-officer contact is currently designated. Privacy inquiries may be sent to either address above; this statement will be reviewed if the operation or legal requirements change.
SmartBookmarks is a local-first browser extension. Its bookmark library can be used without creating an account. Optional account and encrypted-sync features are separate from the local library.
The extension stores the information needed to provide its local features in browser-managed extension storage and IndexedDB. Depending on use, this can include:
This data remains on the device unless the user chooses export or encrypted cloud backup. Browser permissions include storage, tabs and alarms, with optional identity and tab-group permissions. SmartBookmarks does not install content scripts that read page contents.
When an account is used, the Nexamas account service may process:
Email sign-in codes are valid for 10 minutes. Nexamas account sessions are issued for up to 30 days and can be revoked earlier. Short-lived challenges are retained only as operationally necessary for validation, security and abuse prevention.
| Provider | Purpose and data flow |
|---|---|
| Optional authentication and, separately, authorization for Google Drive app-data backup. Google provides identity claims and OAuth authorization directly through its services. | |
| Microsoft | Optional authentication and, separately, OneDrive App Folder authorization. Microsoft provides identity claims and cloud authorization through Microsoft identity and Graph services. |
| Resend | Delivery of one-time email sign-in and security messages where email access codes are used. |
| Fastmail | Hosting and delivery of product-support and general contact email. |
SmartBookmarks requests the narrow https://www.googleapis.com/auth/drive.appdata permission. It is used only to create, inspect, update or delete SmartBookmarks application data in Google's hidden application-data space. It does not grant general access to files in My Drive.
SmartBookmarks uses the delegated Files.ReadWrite.AppFolder permission and the application's dedicated OneDrive App Folder. It does not request general access to all OneDrive files.
The library snapshot is encrypted locally before upload. The Recovery Key is shown to the user and is not sent to the Nexamas account service. The selected cloud provider stores the encrypted vault in the user's own account. Losing the Recovery Key may make the vault unrecoverable.
| Purpose | Legal basis |
|---|---|
| Provide the local extension and requested account/sync features | Art. 6(1)(b) GDPR — performance of the user relationship and requested service. |
| Protect accounts, prevent abuse, maintain service integrity and diagnose failures | Art. 6(1)(f) GDPR — legitimate interests in security, reliability and fraud prevention. |
| Respond to support and legal requests | Art. 6(1)(b), (c) or (f) GDPR depending on the request. |
| Optional provider authorization | Initiated by the user to provide the selected feature; provider consent and controls apply separately. |
The account API is hosted using Cloudflare Workers and D1. Cloudflare may process technical request and security data as an infrastructure provider. Google, Microsoft, Resend and Fastmail process data under their own terms and privacy documentation when their services are used.
Some providers may process data outside Germany or the European Economic Area. Where required, transfers rely on the safeguards made available by the relevant provider and applicable data-protection law. Nexamas does not disclose library content to advertisers or data brokers.
Important: uninstalling the extension removes browser-local extension storage, but it does not by itself delete a Nexamas account or encrypted cloud vault. Use the in-product account deletion flow or contact support.
The current deletion flow attempts to delete and verify removal of the encrypted cloud vault before deleting the Nexamas identity, devices and sessions. If cloud deletion cannot be verified, account deletion is stopped rather than reporting false success. The local bookmark library is intentionally left on the device unless the user separately removes it.
Subject to the GDPR and applicable conditions, users may request access, rectification, erasure, restriction, portability and objection, and may withdraw consent where processing is based on consent. Requests can be sent to the product-support address.
Users also have the right to lodge a complaint with a supervisory authority. For the controller's establishment in Bavaria, the competent private-sector authority is generally the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).
Nexamas uses encrypted transport, revocable account sessions, hashed server-side token records, short-lived challenges and client-side vault encryption. No system can be guaranteed risk-free. Material changes to data use will be reflected in this policy and, where required, communicated before the new processing begins.
Verantwortlicher ist Husam Al Masry, handelnd unter der Marke Nexamas, Hopfenstraße 5, 95652 Waldsassen, Deutschland. Kontakt: support_smartbookmarks@nexamas.com.
SmartBookmarks ist eine lokal ausgerichtete Browser-Erweiterung. Lesezeichen, URLs, Ordner, Notizen, Tags und gespeicherte Browser-Sitzungen werden grundsätzlich im Browser gespeichert. Die Kernbibliothek kann ohne Konto verwendet werden.
Die Sicherung ist freiwillig. Vor dem Upload wird der Bibliotheks-Snapshot auf dem Gerät verschlüsselt. Bei Google Drive wird ausschließlich der Bereich für anwendungsspezifische Daten (drive.appdata) verwendet. Bei OneDrive wird der App Folder der Anwendung verwendet. Der Recovery Key wird nicht an den Nexamas-Account-Dienst übertragen.
Die Verarbeitung erfolgt insbesondere zur Vertragserfüllung bzw. Bereitstellung der angeforderten Funktionen (Art. 6 Abs. 1 lit. b DSGVO) und aufgrund berechtigter Interessen an Sicherheit, Missbrauchsschutz und Zuverlässigkeit (Art. 6 Abs. 1 lit. f DSGVO). Technische Dienstleister können Cloudflare, Google, Microsoft, Resend und Fastmail sein.
Kontodaten werden grundsätzlich bis zur Löschung des Kontos gespeichert. Sitzungen laufen nach höchstens 30 Tagen ab oder werden früher widerrufen. Lokale Daten verbleiben bis zur lokalen Löschung oder Deinstallation. Die verschlüsselte Cloud-Vault verbleibt bis zu ihrer gesonderten Löschung.
Sie haben nach Maßgabe der DSGVO Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch. Beschwerden können an eine Datenschutzaufsichtsbehörde gerichtet werden; für nicht-öffentliche Stellen in Bayern ist grundsätzlich das Bayerische Landesamt für Datenschutzaufsicht zuständig.
Die englische Fassung oben enthält die ausführliche technische Beschreibung. Bei Fragen wenden Sie sich an den Produktsupport.