Controller and contact
Product-support correspondence is handled through Nexamas email services. Do not email passwords, access tokens, one-time codes or exported library backups.
SmartBookmarks is local-first. This policy explains browser-local data, the optional Nexamas account, optional encrypted Cloud Vault synchronization and the service providers involved.
Product-support correspondence is handled through Nexamas email services. Do not email passwords, access tokens, one-time codes or exported library backups.
SmartBookmarks can be used without a Nexamas account. Your bookmark library, folders, tags, notes, saved browser sessions, trash/history records, local backups and preferences are primarily stored on your device using browser extension storage and IndexedDB.
To provide the bookmark/session features, the extension can access browser tab information such as URLs, titles, favicons, window/tab state and, when you use session features, tab-group metadata. SmartBookmarks does not use content scripts to read page-body text or form inputs.
If you choose to sign in, Nexamas processes the information needed to provide and secure the account:
Email-code sign-in uses a temporary six-digit code. Nexamas stores a cryptographic hash of the code, not the raw code. Google and Microsoft are optional identity providers only; they are not SmartBookmarks storage providers. Nexamas does not store Google or Microsoft access tokens.
Google sign-in requests openid and email. Microsoft sign-in requests openid, email and profile; the Microsoft profile scope is used for the durable oid identity claim required by the current account identity contract. Nexamas does not retain the provider display name or profile picture as account profile data.
Cloud synchronization is optional. When Cloud Vault is used, SmartBookmarks creates an encrypted library snapshot in the extension before upload. The library payload is encrypted with AES-256-GCM.
Nexamas Cloud Vault stores:
Nexamas does not store your bookmark URLs, titles, folder names, tags, notes or saved-session content as plaintext Cloud Vault data.
The current key-management model is a Nexamas-managed wrapped Vault key. It is not a zero-knowledge design: Nexamas operates server-side master-key infrastructure capable of unwrapping the stored Vault data key. SmartBookmarks does not require a separate user-held recovery secret.
To prevent abuse and operate authentication/synchronization reliably, Nexamas temporarily processes records such as:
Network and infrastructure providers may also process normal connection/security information needed to deliver and protect the service.
SmartBookmarks currently relies on these service providers when the relevant optional feature is used:
These providers process information needed for their respective service under their own terms/privacy materials and the arrangements applicable to Nexamas.
Current service retention settings are designed as follows:
Operational backups/recovery copies may persist for the period reasonably required to operate and recover the service and are not used to restore a deliberately deleted account as an active account.
You can delete your Nexamas account from SmartBookmarks. Account deletion removes the Nexamas identity/account records, trusted devices, account sessions, wrapped Vault key and encrypted Cloud Vault according to the deletion workflow. Your local SmartBookmarks library is intentionally not deleted from your browser by deleting the Nexamas account.
If you cannot access the account interface, contact SmartBookmarks support. Additional verification may be required before acting on an account request.
Nexamas does not sell SmartBookmarks user data. SmartBookmarks does not use your browsing activity or library content for personalized, retargeted or interest-based advertising, unrelated behavioral profiling, or plaintext library telemetry.
Human access to user data is not permitted except where you specifically authorize access for support, where access is necessary for security/abuse investigation, or where required by law. SmartBookmarks use of data obtained through Chrome extension permissions is limited to providing, securing and improving its disclosed user-facing purpose.
Where data-protection law requires a legal basis, Nexamas generally processes account and synchronization data to provide the service you request, security/abuse-prevention data for legitimate security and operational interests, and data where necessary to comply with legal obligations. Optional sign-in/provider actions are initiated by you.
Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, request data portability, and complain to a competent supervisory authority. Contact contact@nexamas.com for privacy requests.
Some service providers may process data in countries outside your country of residence. Where required, Nexamas uses the applicable contractual or legal safeguards for such processing.
If SmartBookmarks materially changes its user-data practices, Nexamas will update this policy and provide the disclosures/consent required by applicable law and extension-store rules before the changed collection begins.
SmartBookmarks' use of information received from Chrome APIs follows the Chrome Web Store User Data Policy, including the Limited Use requirements. Data accessed through browser permissions is used only for the disclosed SmartBookmarks bookmark/session purpose and related security/reliability operations.
Support-Korrespondenz wird über die E-Mail-Dienste von Nexamas verarbeitet. Senden Sie keine Passwörter, Zugriffstoken, Einmalcodes oder exportierten Bibliotheks-Sicherungen per E-Mail.
SmartBookmarks kann ohne Nexamas-Konto verwendet werden. Lesezeichen, Ordner, Tags, Notizen, gespeicherte Browser-Sitzungen, Papierkorb-/Änderungsdaten, lokale Sicherungen und Einstellungen werden grundsätzlich auf Ihrem Gerät in Browser-Speicher und IndexedDB gespeichert.
Für die Lesezeichen- und Sitzungsfunktionen kann die Erweiterung Browser-Tabdaten wie URL, Titel, Favicon, Fenster-/Tabstatus und – bei entsprechenden Sitzungsfunktionen – Tabgruppen-Metadaten verarbeiten. SmartBookmarks verwendet keine Content Scripts, um Seiteninhalte oder Formulareingaben auszulesen.
Wenn Sie sich anmelden, verarbeitet Nexamas die für Konto und Sicherheit erforderlichen Daten:
Bei Anmeldung per E-Mail wird ein temporärer sechsstelliger Code verwendet. Gespeichert wird ein kryptografischer Hash, nicht der Klartext-Code. Google und Microsoft sind optionale Identitätsanbieter und keine SmartBookmarks-Speicheranbieter. Google-/Microsoft-Zugriffstokens werden nicht bei Nexamas gespeichert.
Google-Anmeldung verwendet openid und email. Microsoft-Anmeldung verwendet openid, email und profile; der Microsoft-profile-Scope wird für den dauerhaften oid-Identitätswert benötigt. Anzeigename und Profilbild des Providers werden nicht als Nexamas-Profilattribute gespeichert.
Cloud-Synchronisierung ist optional. Bei Verwendung des Cloud Vault verschlüsselt die Erweiterung die Bibliothek vor dem Upload mit AES-256-GCM.
Nexamas speichert:
Lesezeichen-URLs/-Titel, Ordnernamen, Tags, Notizen und Sitzungsinhalte werden nicht als Klartext-Vault-Inhalte gespeichert.
Das Schlüsselmodell ist ein von Nexamas verwalteter wrapped Vault key. Es ist kein vollständiges Zero-Knowledge-Modell: Nexamas betreibt eine serverseitige Master-Key-Infrastruktur, die den gespeicherten Vault-Datenschlüssel entpacken kann. Ein separates, vom Nutzer aufzubewahrendes Wiederherstellungsgeheimnis wird nicht verwendet oder benötigt.
Für Authentifizierung, Missbrauchsschutz und zuverlässigen Betrieb verarbeitet Nexamas vorübergehend u. a. E-Mail-Challenge-Daten, OAuth-State/Nonce/PKCE-Daten, kurzlebige Exchange-Tickets, gehashte Rate-Limit-Schlüssel, Vault-Leases, Wartungszeiger sowie Statusdaten des Kontolöschvorgangs.
Je nach gewählter Funktion werden eingesetzt:
Aktuelle technische Aufbewahrungswerte:
Betriebliche Sicherungs-/Recovery-Kopien können für den für Betrieb und Wiederherstellung erforderlichen Zeitraum fortbestehen.
Die Kontolöschung in SmartBookmarks entfernt Nexamas-Konto-/Identitätsdaten, vertrauenswürdige Geräte, Kontositzungen, den wrapped Vault key und den verschlüsselten Cloud Vault gemäß dem Löschworkflow. Die lokale SmartBookmarks-Bibliothek im Browser wird durch die Kontolöschung bewusst nicht gelöscht.
Nexamas verkauft keine SmartBookmarks-Nutzerdaten. Browseraktivität und Bibliotheksinhalte werden nicht für personalisierte/interest-based Werbung, unabhängiges Profiling oder Klartext-Telemetrie verwendet. Menschlicher Zugriff erfolgt nur mit konkreter Einwilligung für Support, wenn er für Sicherheitszwecke erforderlich ist oder gesetzlich verlangt wird.
Soweit erforderlich, erfolgt die Verarbeitung von Konto-/Synchronisierungsdaten zur Bereitstellung der von Ihnen angeforderten Funktionen, Sicherheits-/Missbrauchsschutzdaten auf Grundlage berechtigter Sicherheits- und Betriebsinteressen sowie Daten aufgrund gesetzlicher Pflichten. Optionale Provider-Anmeldungen werden von Ihnen ausgelöst.
Je nach anwendbarem Recht können insbesondere Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Widerspruch und Datenübertragbarkeit sowie ein Beschwerderecht bei einer zuständigen Aufsichtsbehörde bestehen. Kontakt: contact@nexamas.com.
Dienstleister können Daten außerhalb Ihres Aufenthaltsstaates verarbeiten. Soweit erforderlich, setzt Nexamas die dafür vorgesehenen vertraglichen oder gesetzlichen Schutzmechanismen ein.
Bei wesentlichen Änderungen der Datenpraxis aktualisiert Nexamas diese Erklärung und stellt die nach Recht und Store-Regeln erforderlichen Hinweise/Einwilligungen bereit, bevor die geänderte Datenerhebung beginnt.
Die Nutzung von über Chrome-APIs erhaltenen Informationen durch SmartBookmarks folgt der Chrome Web Store User Data Policy einschließlich der Limited-Use-Anforderungen. Die Daten werden nur für den offengelegten Lesezeichen-/Sitzungszweck sowie zugehörige Sicherheits- und Zuverlässigkeitsfunktionen verwendet.