Privacy policy

Last updated: 9 September 2026 · Effective: 7 September 2026

Who we are

LinkMartin is a bookmark manager consisting of a browser extension and an optional web service. It is operated by Nextmeta Group LLC, 254 West Street Road, Unit A, Warminster, PA 18974, United States ("LinkMartin", "we", "us"). For data protection law, Nextmeta Group LLC is the data controller for the data described here.

Questions or requests about this policy: support@linkmartin.com.

In short

  • LinkMartin is local-first. If you never sign in, your bookmarks, the page text LinkMartin captures, and your screenshots stay in your browser's local storage. We never receive them.
  • Signing in turns on sync. From that moment your bookmark records — including the URLs you save and the page text snippet — are stored on our servers so they reach your other devices.
  • AI features stay off until you create an account. Creating an account switches them on for that account, and you can turn them off at any time in settings. With AI on, the page title, URL and up to 2,000 characters of page text are sent through our server to our AI provider — to write tags and a description, and to compute the similarity vector behind "Related bookmarks". With AI off, no page content is sent to any AI provider and no vector is computed. See section 2.2.
  • Site icons are loaded from Google's public favicon service, which means Google sees the domains of the pages LinkMartin shows you. This happens even without an account. See section 2.5.
  • We collect first-party usage statistics — which features are used, never what you save — and keep them in our own database. The extension and the web app contain no third-party analytics or advertising SDKs and no trackers. See section 2.9.
  • Marketing emails are opt-in: you get them only if you tick the box at sign-up, every one carries an unsubscribe link, and unsubscribing is recorded on our side too. Service emails — verification, password, your credits — go to everyone with an account. See section 2.8.
  • We show no ads, and we never sell or rent your data.
  • You can export everything to a .zip file, delete anything at any time, and delete your account yourself. See section 6.

This website

The rest of this policy is about the LinkMartin extension and web service. This section is the exception: it covers what happens when you simply visit linkmartin.com.

We count visits using Vercel Web Analytics. It is cookieless — no cookie is set, nothing is stored in your browser, and no profile is built. We see aggregate page views, and the script is served from our own domain rather than a third party's. Visiting this website involves no account, no extension, and no bookmark data.

1. What LinkMartin keeps on your device

The extension stores the following in your browser's own storage (IndexedDB and extension storage). None of it is transmitted anywhere unless a case in section 2 applies.

Bookmark records

  • the page URL and its domain;
  • the page title;
  • tags, a description, your own rich-text notes, and a category;
  • a favicon URL;
  • a text snippet of the page — up to 2,000 characters taken from the page's visible text at the moment you save it;
  • a screenshot of the visible area of the tab, downscaled to a thumbnail (about 360×180 points) and re-encoded as a JPEG;
  • created / updated / deleted timestamps;
  • how many times you opened the bookmark from LinkMartin and when you last did.

Settings and state

  • your category list, theme, layout, whether AI is on, the language AI should write descriptions in, your custom AI instructions (Pro), and whether the "from your bookmarks" block on Google results is enabled;
  • if you use your own AI key (Pro): the key and the provider's address, kept in the extension's local storage only — they are sent from your browser straight to the provider you chose and never reach our servers;
  • if you signed in: your session token and a sync watermark (the timestamp of your last successful sync);
  • before you create an account: a small local log of feature-usage events (see section 2.9) — at most 5,000 events or 90 days, whichever comes first. It stays on your device; if you later sign up it is sent to us with the rest of your usage statistics, otherwise it is simply overwritten.

Search queries. What you type into LinkMartin's search box or into Google's search box (see section 2.5) is matched against your locally stored bookmarks inside the extension. It is processed in memory, is not written to disk by us, and is never sent to our servers.

Imported browser bookmarks. If you grant the optional bookmarks permission and run an import, LinkMartin reads your Chrome bookmarks and turns them into LinkMartin records. They then behave like any other record, including sync.

2. When data leaves your device

2.1 Sync — only after you create an account and sign in

Sync is off until you create an account and sign in. There is no anonymous or silent upload.

To sign in you give us your email address and a password, and optionally a name. We store your email, whether it is verified, your name, a cryptographic hash of your password (never the password itself), and the date we sent you the welcome message. Each session record also stores your IP address and browser user-agent string, which is how we and you can tell sessions apart and how we detect abuse.

Once signed in, every bookmark record you create or change is uploaded to our servers and stored against your account: URL, domain, title, tags, description, your rich-text notes, category, favicon URL, the 2,000-character page text snippet, the screenshot (see 2.4), open count, last-opened time, timestamps, and a marker of where the bookmark came from (saved by hand or imported). Deletions are synced as tombstones — a deleted record keeps its row with a deletion timestamp until it is purged, so that the deletion reaches your other devices. Your category list syncs the same way.

Settings that sync with your account: sort order and layout, theme, whether AI is on, the language AI should write in, your custom AI instructions (Pro), and — if you use your own AI key — only the provider name and the model name, never the key or its address.

The web app uses only essential session cookies to keep you signed in, plus your browser's local storage for display preferences and the usage-event buffer described in section 2.9.

We do this to provide the sync feature you asked for; nothing about your bookmarks is used for any other purpose.

2.2 AI tags and descriptions — on for accounts, off without one

AI features are off until you have an account: without one, the extension never sends page content to any AI provider. When you create an account, we switch AI on for that account, and every device you sign in to picks the setting up. You can turn it off at any time — in the extension's settings or in the web app under Account — and the change syncs to your other devices. Accounts created before September 2026 were not changed: if you never touched the switch, it stays off.

With AI on, saving a page sends the page title, its URL, up to 2,000 characters of its text, your chosen description language, your category list and — on Pro — your custom AI instructions to our server, which forwards them to our AI provider and returns suggested tags, a description, and a category. We do not store the request; we store only the result, as part of the bookmark record. To apply your plan we also keep how many AI credits you spent in each 30-day period counted from the day you registered, any credit grants you redeemed with a promotion code (amount, remaining balance, expiry, the code's identifier), and per-month token counts per AI model that we use to track our own costs.

Our AI provider for this feature is OpenAI. Under its API terms, OpenAI does not use data submitted through the API to train its models. We do not use your data to train models either.

Your own AI key (Pro). If you bring your own key, enrichment calls go from your browser straight to the provider you configured — OpenAI, Anthropic, or any OpenAI-compatible endpoint — under that provider's terms. Our server is not involved, sees none of the page content, and does not count those calls against your credits. The key itself never reaches us (section 1).

2.3 Similarity vectors ("Related bookmarks")

The "Related bookmarks" list is powered by a numeric vector computed from each bookmark's text. When AI features are on and you are signed in, each time a record's text changes we send its title, domain, category, tags, description and page text snippet to OpenAI's embedding model and store the resulting vector next to the record on our servers. The vector is a set of numbers; it is used only to find your own similar bookmarks.

With AI features off, or without an account, no page content is sent to any AI provider and no vector is computed. Your device tells our server whether AI is on with every sync, and the server skips the embedding step when it is off.

2.4 Screenshots

With sync on, thumbnails are uploaded from your browser straight to our object storage (Cloudflare R2) using a short-lived upload link issued by our server. The image bytes do not pass through our application server.

Screenshots are private. Nobody can open one by its address: the only way to view a screenshot is through our server, while signed in to the account that owns the bookmark, and the link our server issues expires after one hour. Deleting a bookmark removes its screenshot in our clean-up job.

2.5 Favicons are fetched from Google

To show a site icon next to a bookmark, the extension loads it from Google's public favicon service (https://www.google.com/s2/favicons?domain=…). This means Google receives the domain names of the pages LinkMartin shows you — and this happens even if you never sign in, because your browser makes the request directly. It does not include the full URL, the page content, or any account identifier of ours. Google's handling of that request is governed by Google's own privacy policy.

The same applies to the optional block LinkMartin injects into Google search results: the block is built inside your browser from your local bookmarks — your search query never reaches us — but the icons in it are loaded from Google.

2.6 Payments

If you buy a subscription, the payment is taken by Stripe on Stripe's own pages. We never see or store your card details. We store your Stripe customer and subscription identifiers, the plan, its status, the current period dates, and a history of plan changes, so we know whether to lift your AI limit.

2.7 Server and hosting logs

Our servers run on Vercel with a Neon Postgres database. As with any web service, our providers process technical request logs — IP address, user-agent, timestamp, requested path — for operation, security, and abuse prevention. We do not use these logs to profile you and do not combine them with your bookmark data.

2.8 Emails we send, and marketing consent

We send email through Loops. There are two kinds. Service emails go to everyone with an account and cannot be switched off: email verification (required to sign in; you can ask for a new link at most once every five minutes), password reset and password-changed notices, notice of an email address change, account-deletion confirmation, the welcome message after you verify your address, and short notices about your AI credits — starter credits about to expire, credits used up, credits renewed. The credit notices go to everyone; if you have opted in to marketing they may come with tips, otherwise they carry only the facts about your account.

Marketing emails — tips on features you have not tried and news about plans — go only to people who ticked the marketing box at sign-up. The box is unticked by default.

Withdrawing consent. Every marketing email has an unsubscribe link. Using it stops marketing emails at once, and Loops notifies our server, so the withdrawal is recorded on our side as well; as a backstop, we also compare our records with Loops every night. You can also withdraw by writing to support@linkmartin.com. We keep the date you consented, the wording you agreed to, and the date you withdrew, so that we can show both if asked. If you later re-subscribe through Loops' own preferences page, we treat that as new consent given at that moment. Withdrawing consent never affects service emails.

To make this work we keep a contact record for you at Loops: your email address, name, whether you are subscribed to marketing, when and to which wording you consented, and a handful of account attributes used to choose the right email — your plan (free or Pro), remaining AI credits and the date they renew, whether you have tried AI enrichment, custom AI instructions or your own AI key, and how many categories you have. If your email address changes, the contact record moves to the new address. No bookmark content is ever sent to Loops.

2.9 Usage statistics (first-party analytics)

To understand which features are used and where people get stuck, LinkMartin records feature-usage events — for example "bookmark saved", "import completed", "search performed", "AI enrichment used", "category created", "export performed", "extension installed". Each event carries only its name, the time it happened, whether it came from the extension or the web app, and a fixed set of non-identifying attributes such as a source (web / extension / import) or a count.

What is never in these events, by design: URLs, page titles, page text, tag names, category names, descriptions, notes, search queries, or anything you typed. The server accepts only a fixed list of event names and attributes and discards everything else.

Events are stored in our own database, linked to your account, and deleted 365 days after we receive them, or immediately when your account is purged. Events recorded on your device before you signed up are marked as such when they arrive. Nothing is sent to any third-party analytics service, and we set no tracking cookies. We use these statistics to improve the product and, if you have opted in to marketing emails, to pick which tips to send you (section 2.8).

2.10 The support form

If you write to us through the form on linkmartin.com/support or in the extension, your name, email and message are filed as a ticket in Linear, our issue tracker, and you receive a confirmation email through Loops. The form is rate-limited by IP address; the counter is kept for a few minutes and is not stored.

3. What we do not do

  • We do not show ads and we do not sell, rent, or trade your data.
  • We do not use third-party analytics, tracking, or attribution SDKs. The extension and the web app contain no such code; the only usage statistics are our own, described in section 2.9, and they never contain what you save.
  • We do not read your browsing history. LinkMartin only records the pages you explicitly save. Chrome lists the tabs permission as "read your browsing history"; what it actually grants here is the title and address of the tab you are saving (section 11).
  • We do not capture page text or screenshots in the background. Both happen only when you invoke a save.
  • We do not transfer your data for advertising, credit scoring, or lending decisions.

4. Purposes and legal bases

Where the GDPR applies, we rely on:

Legal bases by data category
WhatWhyLegal basis
Bookmark records, categories, screenshotsto provide the sync you enabledperformance of a contract
Email, password hash, session (incl. IP, user-agent)to run your account and keep it secureperformance of a contract; legitimate interests (security)
Page title/URL/text sent to the AI providerto produce the tags, description and related-bookmark suggestions for your accountperformance of a contract (a feature of the account, which you can switch off)
AI credit usage, credit grants, token countsto apply your plan's limits and track our costsperformance of a contract; legitimate interests
Stripe identifiers and subscription stateto bill you and apply your planperformance of a contract; legal obligation (accounting)
Feature-usage events (section 2.9)to understand how the product is used and improve itlegitimate interests
Marketing email preferences and the emails themselvesto send you tips and news you asked forconsent, withdrawable at any time
Support requests (section 2.10)to answer youlegitimate interests; performance of a contract where you have an account
Technical logsto keep the service available and prevent abuselegitimate interests

5. Service providers

We share data only with the providers needed to run LinkMartin:

Sub-processors
ProviderWhat it processesWhere
Vercelhosting, request logs, cookieless visit counting on linkmartin.comUS/EU
NeonPostgres database — account data, synced bookmarks, usage statisticsUS
Cloudflare R2screenshot files (private; readable only by their owner through short-lived signed links)global
OpenAItitle, URL, page text snippet, category list, custom instructions, tags, description — for writing descriptions and tags, and for similarity vectorsUS
Stripepayment and subscription data, promotion codesUS/EU
Loopsemail delivery and marketing preferences — email, name, subscription status, consent and withdrawal dates, the account attributes listed in section 2.8US
Linearsupport requests — the name, email and message you send through the support formUS
Google (favicon service)the domain of pages shown in the extensionglobal

Each acts under its own terms and, where required, a data processing agreement.

6. Retention and deletion

  • On your device: data stays until you delete a bookmark, clear the extension's storage, or uninstall the extension. Uninstalling removes the local database.
  • On our servers: a deleted bookmark keeps a tombstone row so the deletion can propagate to your devices; our clean-up jobs then purge the row, its similarity vector, and its screenshot file. Feature-usage events are deleted 365 days after we receive them.
  • Your account: you can delete it yourself in the web app, under Account → Delete account. The account closes immediately — you are signed out on all devices and any paid subscription is cancelled right away — and we email you a confirmation with the erasure date. All server-side data (bookmarks, screenshots, categories, settings, usage events) is permanently erased after a 30-day grace period; during those 30 days you can ask us to restore the account at support@linkmartin.com, after which the deletion is irreversible. If you prefer, write to the same address and we will do it for you. Records we must keep for accounting (payment records) are retained for the statutory period.
  • What outlives the erasure: to stop a deleted address from being immediately re-registered, we keep the email address itself on a block list until you ask us to lift it. And our administrative audit log — a record of account actions taken by our staff, such as a suspension or an email change — keeps the email addresses involved, so that we can account for those actions later.
  • Export: the extension can export all bookmarks and screenshots to a .zip file at any time, so you are never locked in.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your data, to object to processing based on legitimate interests, and to withdraw consent. If you are in the EEA or the UK you may also lodge a complaint with your supervisory authority. If you are a California resident, note that we do not sell or share personal information as those terms are defined by the CCPA/CPRA.

Write to support@linkmartin.com and we will respond within 30 days. Most of your data is also directly under your control: export or delete it from within the extension, and delete your account from the web app (section 6). You can withdraw your consent to marketing emails at any time (section 2.8); nothing else about the service changes when you do.

8. Security

Traffic between the extension, the web app, and our servers uses HTTPS. Passwords are stored only as hashes. Sessions use bearer tokens with expiry. Screenshots live in private storage and are uploaded and read only through short-lived signed links issued to their owner. Database and object storage credentials are held server-side only, and access to production data is restricted to the operator. An account that we believe is being abused can be suspended; a suspended account cannot sign in or sync. No system is perfectly secure; if you believe you have found a vulnerability, write to support@linkmartin.com.

9. Children

LinkMartin is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children.

10. International transfers

Nextmeta Group LLC is based in the United States, and our providers listed in section 5 operate in the United States and the European Union. If you use LinkMartin from the EEA, the UK, or Switzerland, your data is transferred to the United States. Those transfers rely on the European Commission's standard contractual clauses or another approved transfer mechanism, as provided in each provider's terms.

11. Browser permissions and why LinkMartin needs them

Permissions
PermissionWhy
storagekeep your bookmarks and settings in the browser
activeTab, tabsread the URL and title of the tab you are saving, and of tabs you highlight for a batch save — Chrome shows this as "read your browsing history"; no history is read
scriptingrun a one-off script in the page you are saving to read its visible text
sidePanelshow LinkMartin's interface in the browser side panel
alarmsrun background sync on a schedule
bookmarks (optional, asked for only on demand)import your existing browser bookmarks
host access (all sites)capture the page you save — any page, which is why the browser words it as access to all websites; LinkMartin reads a page only when you save it — and reach the sync server
content script on Google search pagesbuild the "from your bookmarks" block from your local data; can be switched off in settings

LinkMartin executes no remote code: it ships all of its own logic and only calls the APIs described above.

12. Changes to this policy

If we change how we handle your data we will update this page and its "last updated" date, and — for changes that materially affect you — notify you in the extension or by email before they take effect.

13. Contact

Nextmeta Group LLC
254 West Street Road, Unit A, Warminster, PA 18974, United States
support@linkmartin.com