Privacy Policy — Clever-marks: Smart Bookmark Manager
Effective date: 2025-10-20
Clever-marks: Smart Bookmark Manager helps you organize and manage your browser bookmarks, provides keyword suggestions for categories, and can export internal categories into native browser bookmark folders. To offer these features, the extension accesses or processes certain data with your consent. Please read this policy before installing or using the extension.
When a privacy policy is required
Per store requirements, we maintain this privacy policy because the extension may access, collect, or transmit personal or device data to the developer or third parties in some modes, and because the extension optionally integrates with third-party services (for backups or advanced NLP). This policy also describes choices you have regarding data collection, and how to contact us for data requests.
Compliance: This privacy policy complies with applicable data protection laws and regulations that apply to us as the app developer, including but not limited to the GDPR and CCPA.
Data we collect and process
We only collect or process the minimum data necessary to provide the extension's features. Collected data may include:
- Bookmark data: URL, title, favicon (if available), and your category associations. This data is stored in your browser storage (
chrome.storage.local or chrome.storage.sync if you enable sync).
- User settings and metadata: category names, keywords, sync preferences, blacklist domains, export history, and other configuration needed to run the extension.
- Page snippets (optional): short excerpts such as the page title or small text snippets may be used to generate keyword suggestions. These snippets are processed locally by default. If you opt into a remote NLP/embedding provider, brief snippets may be transmitted to that provider (see "Third-party services" below) — this will only occur after you explicitly opt in.
- Authentication tokens (optional): if you choose to use the extension's Google Drive backup feature, the extension uses OAuth to authorize access to your Drive files (scopes listed below). OAuth access tokens are stored and used only to perform the backup/restore actions you request.
- Usage and diagnostic information (optional): anonymous usage metrics or error reports may be collected only if you opt in to help improve the product. We do not collect identifiable telemetry by default.
How we use the data
- Provide local keyword extraction and category suggestion to help you organize bookmarks.
- Export bookmarks to browser-native bookmark folders when you request an export.
- Perform backup and restore to Google Drive if you enable and authorize that feature.
- If you opt into remote NLP or embedding features, send brief snippets for processing and return suggestions. Remote processing is opt-in and reversible.
- With explicit opt-in, collect anonymous usage or crash reports to improve reliability and features.
Permissions and platform access
The extension requests only the permissions listed in the extension manifest to perform its functionality. These include:
storage — store bookmarks, categories, and extension settings locally or via browser sync.
bookmarks — create and modify browser-native bookmarks when you use the export feature.
activeTab and content scripts (<all_urls>) — used to read the current page's title and allow keyword suggestion for the page you are actively viewing. Content scripts run at document_idle and only access the page to extract text for local suggestions.
contextMenus and notifications — support in-extension context menu actions and user notifications.
identity / oauth2 — only used if you choose to authorize Google Drive backup/restore. OAuth scopes used by the extension (if you authorize Drive backup) are:
https://www.googleapis.com/auth/drive.file — create and manage files created by this app in your Google Drive.
https://www.googleapis.com/auth/drive.appdata — store application-specific data in a hidden appdata folder (used only for optional backups/settings sync).
host permissions — the manifest includes broad host patterns (for example https://*/*) to support content-script matching (<all_urls>) and optional integration with external APIs. The extension does not transmit page content to third parties unless you opt into a specific remote feature.
Third-party services
By default, the extension does not send your bookmarks or page content to third-party services. The extension includes optional integrations that you must opt into before data is transmitted:
- Google Drive (optional): if you enable backups to Google Drive, the extension will access only the files it creates or the appdata folder, using the Drive OAuth scopes above. Google is a separate data controller for data you store in Drive — please review Google's privacy documentation for Drive when using this feature.
- Remote NLP / embedding providers (optional): advanced semantic suggestion features may use a remote provider if you explicitly enable that mode. When enabled, we will show a clear consent prompt describing what will be sent and which provider will receive it. You can disable the feature at any time and request deletion of remotely-stored snippets (see "Contact" below).
Legal bases and user consent
Where required (for example under GDPR), our lawful basis for processing personal data is one or more of the following:
- Consent — for optional features that transmit snippets or telemetry to third parties (remote NLP, analytics), we rely on your explicit opt-in consent before any such data is transmitted.
- Contractual / performance — processing necessary to perform the service you request (for example exporting bookmarks, or backing up to your Drive after you authorize it).
User rights (GDPR / CCPA guidance)
You have the right to request access to, correction of, or deletion of your personal data that we control. Specifically:
- Access and portability — you may export your category/keyword data via the extension's export features (export to native bookmarks) or request a machine-readable dump by contacting us.
- Deletion — you can delete all local extension data from the Options page (Options → Data Management → Clear all data). For data stored in a third-party service (for example Google Drive or a remote NLP provider), contact us with the details and we will request deletion from the provider on your behalf.
- CCPA — if you are a California resident, you may request information about categories of data collected, the purposes for collection, and request deletion where applicable. We do not sell personal information.
Data retention
Your local extension data is retained until you choose to delete it (for example by clearing data in Options or removing the extension). If you enable browser sync (chrome.storage.sync), data storage and retention may be governed by your browser provider. For remote backups or remote processing, retention depends on the chosen provider; we will disclose retention in the opt-in UI and will act on deletion requests.
Security
We take reasonable technical and organizational measures to protect data stored by the extension. However, no method of transmission or storage is completely secure. If you use third-party services (for example Google Drive), their security practices apply to data stored with those providers.
- Local storage — data stored with
chrome.storage.local is protected by the browser's storage mechanisms and is only accessible to the extension's code and the browser profile that stores it.
- Browser sync — if you enable
chrome.storage.sync, data is synced by your browser provider and subject to the provider's security and retention policies.
- OAuth tokens — OAuth tokens used for Google Drive backups are stored securely by the browser's extension identity APIs and are only transmitted to Google's OAuth endpoints. The extension does not log or expose OAuth tokens.
- Remote transmission — when the extension transmits data to remote services (for example a remote NLP provider), it uses HTTPS/TLS to protect data in transit. We will name the remote provider and describe the exact data transmitted in the opt-in prompt.
Where we display this policy and how you will be asked
- In-app: a link to this privacy policy is available in the Options page so you can review it at any time before enabling optional features. Additionally, on first installation the extension will show a brief welcome screen that includes a link to this privacy policy.
- Store listing: include this public URL in your store product detail page when publishing to the Chrome or Edge store.
- Before collection: for any feature that collects or transmits data to third parties (for example remote NLP or Drive backups), we will show a clear consent prompt that links to this policy and describes what will be shared. The consent prompt will:
- Link to this privacy policy
- Describe exactly which data will be shared and the receiving provider
- Allow you to accept or decline the feature
- Inform you how to withdraw consent later from the Options page
Partner Center / Store listing note
The support or privacy email shown above may be used in the Store listing (Partner Center) when you publish the extension. Make sure the email tankkuo0712@gmail.com (or the address you prefer) is correct and that you are comfortable with it being publicly associated with the extension.
How to request data access, portability, or deletion
To request access to your data, a machine-readable copy, or deletion of data stored by optional remote services, contact us with the subject line "Data Request — Clever-marks: Smart Bookmark Manager" and include the email address associated with your request. We will respond within a reasonable timeframe and provide instructions or confirmation of action.
Contact
If you have privacy concerns or request data removal, please contact: tankkuo0712@gmail.com
Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the effective date at the top of this page and, where appropriate, notify users via the extension's UI.