Nexamas SmartBookmarks
ProductTermsDelete accountImprint
Privacy policy

Your data, by design.

SmartBookmarks is local-first. This policy explains browser-local data, the optional Nexamas account, optional encrypted Cloud Vault synchronization and the service providers involved.

Effective: 21 August 2026Controller established in GermanyCurrent Cloud Vault architecture
EnglishDeutsch

Controller and contact

Husam Al Masryoperating under the Nexamas brandHopfenstraße 595652 Waldsassen, Germanycontact@nexamas.comsupport_smartbookmarks@nexamas.com

Product-support correspondence is handled through Nexamas email services. Do not email passwords, access tokens, one-time codes or exported library backups.

1. Local-first by default

SmartBookmarks can be used without a Nexamas account. Your bookmark library, folders, tags, notes, saved browser sessions, trash/history records, local backups and preferences are primarily stored on your device using browser extension storage and IndexedDB.

To provide the bookmark/session features, the extension can access browser tab information such as URLs, titles, favicons, window/tab state and, when you use session features, tab-group metadata. SmartBookmarks does not use content scripts to read page-body text or form inputs.

2. Optional Nexamas account

If you choose to sign in, Nexamas processes the information needed to provide and secure the account:

  • an internal account identifier;
  • your verified email address;
  • the sign-in provider and provider-specific subject identifier;
  • trusted-device identifiers, device name/platform and security timestamps;
  • revocable Nexamas session records stored as token hashes and timestamps.

Email-code sign-in uses a temporary six-digit code. Nexamas stores a cryptographic hash of the code, not the raw code. Google and Microsoft are optional identity providers only; they are not SmartBookmarks storage providers. Nexamas does not store Google or Microsoft access tokens.

Google sign-in requests openid and email. Microsoft sign-in requests openid, email and profile; the Microsoft profile scope is used for the durable oid identity claim required by the current account identity contract. Nexamas does not retain the provider display name or profile picture as account profile data.

3. Optional Nexamas Cloud Vault

Cloud synchronization is optional. When Cloud Vault is used, SmartBookmarks creates an encrypted library snapshot in the extension before upload. The library payload is encrypted with AES-256-GCM.

Nexamas Cloud Vault stores:

  • the encrypted Vault object;
  • Vault revision, digest, size and storage metadata;
  • a wrapped Vault data key and key-version metadata.

Nexamas does not store your bookmark URLs, titles, folder names, tags, notes or saved-session content as plaintext Cloud Vault data.

The current key-management model is a Nexamas-managed wrapped Vault key. It is not a zero-knowledge design: Nexamas operates server-side master-key infrastructure capable of unwrapping the stored Vault data key. SmartBookmarks does not require a separate user-held recovery secret.

4. Security and temporary operational data

To prevent abuse and operate authentication/synchronization reliably, Nexamas temporarily processes records such as:

  • email challenge state, locale, attempt count and expiry;
  • OAuth state, nonce, PKCE verifier and short-lived exchange tickets;
  • hashed rate-limit keys and expiry;
  • short-lived Vault operation leases and maintenance cursors;
  • account-deletion workflow state and a short-lived deletion receipt.

Network and infrastructure providers may also process normal connection/security information needed to deliver and protect the service.

5. Service providers

SmartBookmarks currently relies on these service providers when the relevant optional feature is used:

  • Cloudflare — Workers, D1 and R2 for the Account API/account metadata/encrypted Vault storage, and Turnstile for abuse protection.
  • Resend — delivery of one-time sign-in emails.
  • Google — optional Google OpenID Connect sign-in selected by the user.
  • Microsoft — optional Microsoft OpenID Connect sign-in selected by the user.

These providers process information needed for their respective service under their own terms/privacy materials and the arrangements applicable to Nexamas.

6. Retention

Current service retention settings are designed as follows:

  • active Nexamas account and Cloud Vault data: retained while the account exists;
  • Nexamas access session: up to 30 days unless revoked earlier;
  • revoked-session operational history: generally up to 7 days;
  • email sign-in code: expires after 10 minutes;
  • consumed authentication/OAuth operational records: generally up to 24 hours;
  • inactive trusted device without an active session: eligible for cleanup after 180 days;
  • completed account-deletion receipt: generally up to 7 days;
  • orphan Vault object safety grace period: 24 hours;
  • rate-limit and operation-lease records: until their configured expiry.

Operational backups/recovery copies may persist for the period reasonably required to operate and recover the service and are not used to restore a deliberately deleted account as an active account.

7. Account deletion and local data

You can delete your Nexamas account from SmartBookmarks. Account deletion removes the Nexamas identity/account records, trusted devices, account sessions, wrapped Vault key and encrypted Cloud Vault according to the deletion workflow. Your local SmartBookmarks library is intentionally not deleted from your browser by deleting the Nexamas account.

If you cannot access the account interface, contact SmartBookmarks support. Additional verification may be required before acting on an account request.

8. How SmartBookmarks does not use your data

Nexamas does not sell SmartBookmarks user data. SmartBookmarks does not use your browsing activity or library content for personalized, retargeted or interest-based advertising, unrelated behavioral profiling, or plaintext library telemetry.

Human access to user data is not permitted except where you specifically authorize access for support, where access is necessary for security/abuse investigation, or where required by law. SmartBookmarks use of data obtained through Chrome extension permissions is limited to providing, securing and improving its disclosed user-facing purpose.

9. Legal bases and rights in the EEA/UK

Where data-protection law requires a legal basis, Nexamas generally processes account and synchronization data to provide the service you request, security/abuse-prevention data for legitimate security and operational interests, and data where necessary to comply with legal obligations. Optional sign-in/provider actions are initiated by you.

Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, request data portability, and complain to a competent supervisory authority. Contact contact@nexamas.com for privacy requests.

10. International processing

Some service providers may process data in countries outside your country of residence. Where required, Nexamas uses the applicable contractual or legal safeguards for such processing.

11. Changes

If SmartBookmarks materially changes its user-data practices, Nexamas will update this policy and provide the disclosures/consent required by applicable law and extension-store rules before the changed collection begins.

12. Chrome Web Store Limited Use

SmartBookmarks' use of information received from Chrome APIs follows the Chrome Web Store User Data Policy, including the Limited Use requirements. Data accessed through browser permissions is used only for the disclosed SmartBookmarks bookmark/session purpose and related security/reliability operations.

Verantwortlicher und Kontakt

Husam Al Masryhandelnd unter der Marke NexamasHopfenstraße 595652 Waldsassen, Deutschlandcontact@nexamas.comsupport_smartbookmarks@nexamas.com

Support-Korrespondenz wird über die E-Mail-Dienste von Nexamas verarbeitet. Senden Sie keine Passwörter, Zugriffstoken, Einmalcodes oder exportierten Bibliotheks-Sicherungen per E-Mail.

1. Local-first als Standard

SmartBookmarks kann ohne Nexamas-Konto verwendet werden. Lesezeichen, Ordner, Tags, Notizen, gespeicherte Browser-Sitzungen, Papierkorb-/Änderungsdaten, lokale Sicherungen und Einstellungen werden grundsätzlich auf Ihrem Gerät in Browser-Speicher und IndexedDB gespeichert.

Für die Lesezeichen- und Sitzungsfunktionen kann die Erweiterung Browser-Tabdaten wie URL, Titel, Favicon, Fenster-/Tabstatus und – bei entsprechenden Sitzungsfunktionen – Tabgruppen-Metadaten verarbeiten. SmartBookmarks verwendet keine Content Scripts, um Seiteninhalte oder Formulareingaben auszulesen.

2. Optionales Nexamas-Konto

Wenn Sie sich anmelden, verarbeitet Nexamas die für Konto und Sicherheit erforderlichen Daten:

  • interne Benutzer-ID;
  • verifizierte E-Mail-Adresse;
  • Anmeldeanbieter und dessen Subject-ID;
  • Kennung, Name/Plattform und Zeitstempel vertrauenswürdiger Geräte;
  • widerrufbare Nexamas-Sitzungsdatensätze als Token-Hash und Zeitstempel.

Bei Anmeldung per E-Mail wird ein temporärer sechsstelliger Code verwendet. Gespeichert wird ein kryptografischer Hash, nicht der Klartext-Code. Google und Microsoft sind optionale Identitätsanbieter und keine SmartBookmarks-Speicheranbieter. Google-/Microsoft-Zugriffstokens werden nicht bei Nexamas gespeichert.

Google-Anmeldung verwendet openid und email. Microsoft-Anmeldung verwendet openid, email und profile; der Microsoft-profile-Scope wird für den dauerhaften oid-Identitätswert benötigt. Anzeigename und Profilbild des Providers werden nicht als Nexamas-Profilattribute gespeichert.

3. Optionaler Nexamas Cloud Vault

Cloud-Synchronisierung ist optional. Bei Verwendung des Cloud Vault verschlüsselt die Erweiterung die Bibliothek vor dem Upload mit AES-256-GCM.

Nexamas speichert:

  • das verschlüsselte Vault-Objekt;
  • Revision, Digest, Größe und Speicher-Metadaten;
  • einen verpackten (wrapped) Vault-Datenschlüssel und Schlüsselversions-Metadaten.

Lesezeichen-URLs/-Titel, Ordnernamen, Tags, Notizen und Sitzungsinhalte werden nicht als Klartext-Vault-Inhalte gespeichert.

Das Schlüsselmodell ist ein von Nexamas verwalteter wrapped Vault key. Es ist kein vollständiges Zero-Knowledge-Modell: Nexamas betreibt eine serverseitige Master-Key-Infrastruktur, die den gespeicherten Vault-Datenschlüssel entpacken kann. Ein separates, vom Nutzer aufzubewahrendes Wiederherstellungsgeheimnis wird nicht verwendet oder benötigt.

4. Temporäre Sicherheits- und Betriebsdaten

Für Authentifizierung, Missbrauchsschutz und zuverlässigen Betrieb verarbeitet Nexamas vorübergehend u. a. E-Mail-Challenge-Daten, OAuth-State/Nonce/PKCE-Daten, kurzlebige Exchange-Tickets, gehashte Rate-Limit-Schlüssel, Vault-Leases, Wartungszeiger sowie Statusdaten des Kontolöschvorgangs.

5. Dienstleister

Je nach gewählter Funktion werden eingesetzt:

  • Cloudflare — Workers, D1, R2 und Turnstile;
  • Resend — Versand temporärer Anmeldecodes;
  • Google — optionale Google-OIDC-Anmeldung;
  • Microsoft — optionale Microsoft-OIDC-Anmeldung.

6. Aufbewahrung

Aktuelle technische Aufbewahrungswerte:

  • Konto und Cloud Vault: solange das Konto besteht;
  • aktive Nexamas-Sitzung: bis zu 30 Tage, sofern nicht früher widerrufen;
  • widerrufene Sitzungsdaten: grundsätzlich bis zu 7 Tage;
  • E-Mail-Code: 10 Minuten;
  • verbrauchte Auth-/OAuth-Betriebsdaten: grundsätzlich bis zu 24 Stunden;
  • inaktives Gerät ohne aktive Sitzung: nach 180 Tagen zur Bereinigung vorgesehen;
  • Löschbeleg nach abgeschlossener Kontolöschung: grundsätzlich bis zu 7 Tage;
  • Sicherheitsfrist für verwaiste Vault-Objekte: 24 Stunden;
  • Rate-Limit- und Lease-Daten: bis zum jeweiligen Ablauf.

Betriebliche Sicherungs-/Recovery-Kopien können für den für Betrieb und Wiederherstellung erforderlichen Zeitraum fortbestehen.

7. Kontolöschung

Die Kontolöschung in SmartBookmarks entfernt Nexamas-Konto-/Identitätsdaten, vertrauenswürdige Geräte, Kontositzungen, den wrapped Vault key und den verschlüsselten Cloud Vault gemäß dem Löschworkflow. Die lokale SmartBookmarks-Bibliothek im Browser wird durch die Kontolöschung bewusst nicht gelöscht.

8. Keine Werbung/kein Verkauf

Nexamas verkauft keine SmartBookmarks-Nutzerdaten. Browseraktivität und Bibliotheksinhalte werden nicht für personalisierte/interest-based Werbung, unabhängiges Profiling oder Klartext-Telemetrie verwendet. Menschlicher Zugriff erfolgt nur mit konkreter Einwilligung für Support, wenn er für Sicherheitszwecke erforderlich ist oder gesetzlich verlangt wird.

9. Rechtsgrundlagen und Betroffenenrechte

Soweit erforderlich, erfolgt die Verarbeitung von Konto-/Synchronisierungsdaten zur Bereitstellung der von Ihnen angeforderten Funktionen, Sicherheits-/Missbrauchsschutzdaten auf Grundlage berechtigter Sicherheits- und Betriebsinteressen sowie Daten aufgrund gesetzlicher Pflichten. Optionale Provider-Anmeldungen werden von Ihnen ausgelöst.

Je nach anwendbarem Recht können insbesondere Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Widerspruch und Datenübertragbarkeit sowie ein Beschwerderecht bei einer zuständigen Aufsichtsbehörde bestehen. Kontakt: contact@nexamas.com.

10. Internationale Verarbeitung

Dienstleister können Daten außerhalb Ihres Aufenthaltsstaates verarbeiten. Soweit erforderlich, setzt Nexamas die dafür vorgesehenen vertraglichen oder gesetzlichen Schutzmechanismen ein.

11. Änderungen

Bei wesentlichen Änderungen der Datenpraxis aktualisiert Nexamas diese Erklärung und stellt die nach Recht und Store-Regeln erforderlichen Hinweise/Einwilligungen bereit, bevor die geänderte Datenerhebung beginnt.

12. Chrome Web Store Limited Use

Die Nutzung von über Chrome-APIs erhaltenen Informationen durch SmartBookmarks folgt der Chrome Web Store User Data Policy einschließlich der Limited-Use-Anforderungen. Die Daten werden nur für den offengelegten Lesezeichen-/Sitzungszweck sowie zugehörige Sicherheits- und Zuverlässigkeitsfunktionen verwendet.

© NexamasSmartBookmarks · Terms · Delete account · Website privacy · Imprint