# Privacy Policy

Last updated: September 26, 2026

This Policy explains how the operator of
[Bookmark.gallery](https://bookmark.gallery) ("we", "us", or "our") handles
information when you use the Service, including the Bookmark Gallery Chrome
extension (the "Extension") and the optional paid Bookmark.gallery Pro
subscription ("Pro").

## Information we collect

- **Account information:** when you sign in with X, which is the only sign-in
  method, we receive your X user ID, profile information such as your display
  name and profile image, and your verified email address if X provides it. If X
  does not provide an email, our authentication system uses an internal
  placeholder address. We never receive your X password.
- **Authorization information:** X access tokens, refresh tokens, granted
  permissions, and token expiration information from X sign-in. If you use Pro,
  this includes the additional read-only access to your bookmarks and likes that
  you grant when connecting X.
- **Imported posts:** when you sync, we store the posts you have bookmarked or
  liked on X. This includes post text, language, dates, reply and quote
  references, sensitivity labels, links to media and link previews, the name,
  handle, avatar, and verification status of each post's author, and the raw post
  data X returned so we can display it accurately. We also record which
  collection each post belongs to, X's ordering, when we first and last saw it,
  and whether it was later removed on X or archived by you.
- **Import records:** the start and finish time of each sync, whether it ran
  through the Extension or Pro, how it ended, page and post counts, and, for Pro,
  how much of the monthly sync allowance it used.
- **Tags:** the tags you create, their descriptions, which posts you tag, and,
  if you use Pro, the scores our AI tagging returns for each post and tag.
- **AI search index:** if you use Pro, text descriptions of the images in your
  saved posts (a short caption and any legible text in the image) and a
  numerical representation of each post's content used for search. Image
  descriptions are derived from the image itself, not from your account, so one
  copy is kept per image and reused for anyone who saved the same image; search
  representations are kept per account.
- **Subscription information:** if you buy Pro, we receive from Paddle your
  Paddle customer and subscription identifiers, the plan, the subscription
  status, and its start, renewal, and cancellation dates. Paddle collects your
  payment details, billing address, and tax information directly; we never
  receive your full card number.
- **Session and technical information:** session identifiers, session dates and
  expiration times, IP addresses, browser or device information, and information
  processed by our hosting provider to deliver and protect requests.
- **Usage information:** which pages you visit and which features you use, such
  as starting a sync, opening settings, or searching, recorded as counts and
  categories rather than the content involved. A sample of sessions is also
  recorded to show how the interface is used, as described under
  [Analytics](#analytics).
- **Preferences and correspondence:** your appearance preference, which one-time
  messages and tips you have dismissed, and information you provide when
  contacting us.

## How the Extension works

The Extension imports your bookmarks and likes using your existing X session in
Chrome. It acts only when a signed-in Bookmark.gallery page asks it to sync, and
it does not run in incognito windows.

- It reads your X session cookies (`twid`, `ct0`, and `viewer_act_as`) inside
  your browser to confirm you are signed in to X with your own account and to
  make requests to x.com as you. These cookies are never sent to us or stored by
  the Extension.
- It requests X's web app and its public assets from x.com and abs.twimg.com to
  find the current request format, then your Bookmarks and Likes timelines from
  x.com. It requests nothing else from X.
- It passes the posts it receives, unmodified, to the Bookmark.gallery page,
  which sends them to your account for storage.
- It keeps a cache of X's public web configuration in Chrome's local extension
  storage so later syncs start faster. This cache contains no personal data.
- It does not read direct messages, publish posts, like, follow, or change
  anything on your X account, and it does not access any other website.

## How Pro works

Pro keeps your gallery up to date without the Extension. When you upgrade and
connect X, you grant Bookmark.gallery read-only access to your bookmarks and
likes (`bookmark.read` and `like.read`) through X's official API.

- Our servers use your stored X tokens to request your most recent bookmarks and
  likes from X when you open or return to the gallery, at most every 5 minutes
  for bookmarks and once a day for likes.
- To show new likes within seconds, we ask X to notify our server each time you
  like a post. X then sends us that post and its author. This notification is
  removed when your Pro subscription ends.
- Pro cannot publish posts, like, follow, send messages, or change anything on
  your X account.

## How we use information

We use this information to authenticate you, maintain sessions, build and display
your gallery, keep it in sync with what you have saved on X, tag and search your
posts, provide and bill for Pro, remember preferences, understand and improve how the
Service is used, protect the Service, and respond to requests. Your imported
posts are visible only to you. We do not use them for advertising or profiling,
and neither we nor our AI providers use them to train models.

## Cookies and local storage

We use authentication cookies to keep you signed in and protect the sign-in flow,
and a preference cookie to remember your appearance setting. Gallery
filters are saved in your browser's local storage. You can clear these through
your browser, although doing so may sign you out or reset preferences. Our
analytics does not use cookies. The Service does not include advertising.

## Analytics

We run our own instance of [Umami](https://umami.is), an open-source analytics
tool, to count page views and feature use. Events record categories and counts,
such as which collection was synced or how many posts were saved, and never post
text, tag names, or search terms.

Umami also records about 15% of browsing sessions, for up to five minutes each,
so we can see how the interface is used and find problems. Recordings capture
page layout and interactions, with text you type into fields masked. They may
show what was on screen, including posts in your gallery. Recordings are
available only to us.

## Sharing and service providers

We use the following providers to operate the Service:

- **Cloudflare:** website hosting, request delivery, and infrastructure security.
- **Neon:** storage of account, session, authorization, subscription, tag,
  imported post, and AI search index records.
- **Paddle:** our reseller and Merchant of Record for Pro. Paddle processes
  payments, taxes, invoices, and refunds and handles your billing information
  under its own [Privacy Policy](https://www.paddle.com/legal/privacy).
- **Google (Gemini API):** AI search for Pro. For each image in a post being
  indexed, we send Google the image so it can return a short description and any
  legible text. We then send Google the post text with links removed, the text
  of a quoted post, the title and description of any link preview, and those
  image descriptions, and it returns a numerical representation used for
  search. When you search with Pro, we send Google your search text to compare
  it with your posts. We use Google's paid Gemini API, which does not use this
  data to improve Google's products.
- **TypeSafe:** AI tagging for Pro. For each post being tagged, we send TypeSafe
  the post text with links removed, the author's handle and name, the title,
  description, and domain of any link preview, the text of a quoted post, the
  types of media attached, the descriptions of attached images, and the names
  and descriptions of your tags. It
  returns a score for each tag. Posts X marks as possibly sensitive are never
  sent.
- **X:** sign-in, and the source of imported posts. When you sync with the
  Extension, your browser requests your bookmarks and likes from X directly.
  With Pro, our servers request them from X's official API and receive
  notifications of new likes, as described above. When you view your gallery,
  your browser loads images and videos from X's servers, so X receives the
  request information needed to deliver them. X handles data under its own
  [Privacy Policy](https://x.com/en/privacy).

We do not sell personal information or share it for targeted advertising. We may
disclose information where required by law or necessary to address fraud, abuse,
or threats to the rights and security of users and the Service.

Our providers may process information in countries other than where you live.
Applicable data protection requirements continue to apply to that processing.

## Retention and security

Account, authorization, subscription, tag, and imported post records are kept
while your account exists, including the search representations of your posts.
Image descriptions are tied to images on X rather than accounts and may be kept
after your account is deleted while other users have saved the same images. Paddle keeps its own billing records as required for
tax and accounting purposes. A post you remove from your bookmarks or likes on X is marked as removed
after a full sync rather than erased. Signing out ends the current session; it
does not delete your account or stored records.

You may request deletion using the contact below. We will verify the request and
remove your account and imported posts, subject to applicable legal obligations
and limited security or dispute-resolution needs. Residual copies may remain in
provider backups until those backups expire under their retention schedules.

We use authentication and access controls to protect information. No internet
service or storage system can guarantee absolute security.

## Your choices and requests

You can stop syncing at any time by not starting a sync or by removing the
Extension. You can cancel Pro at any time from Settings; automatic syncing and
like notifications stop when your subscription ends. You can revoke the
Service's X authorization in your X connected-app settings, which also stops Pro
from syncing. None of these actions automatically deletes data already stored by
Bookmark.gallery or ends every Bookmark.gallery session.

Contact us to request account deletion, access to your information, or correction
of inaccurate information. There is currently no self-service account deletion
screen. Depending on applicable law, you may also have rights to data portability,
restriction, objection, or withdrawal of consent, and to complain to a relevant
data protection authority. We may request information necessary to verify that a
request concerns your own account. Do not send passwords, cookies, or access
tokens.

## Children and changes

The Service is not intended for children under 13. Contact us if you believe a
child has provided personal information so that we can investigate and address it.

We will update this Policy and its date when our practices change. Where required,
we will provide additional notice or request consent before materially different
processing begins.

## Contact

For privacy questions or requests concerning your information, contact:

[contact@bookmark.gallery](mailto:contact@bookmark.gallery)
