Effective August 2026

Privacy,
in plain language.

Your library stays on your device. AI and X requests only run when you start them, and Polar handles Pro checkout and license verification.

What the extension accesses

When you enable Chrome bookmark access, the extension reads bookmark titles, URLs, folders, and saved dates on your device. The New Tab workspace is disclosed during setup and the first time it appears.

Related bookmarks is optional. When enabled, it compares the current public page URL with your bookmarks locally; it does not read page content, keep a browsing log, or send visited URLs anywhere. Connecting X is also optional and uses read-only access to your profile and saved Posts. Notifications stay off until you enable them.

How that information is used

Bookmark organization and search happen locally. When you request an AI summary, the service safely retrieves the selected public page and sends a limited amount of extracted text to Gemini. Ask AI sends your question and short excerpts from the most relevant bookmarks. Supabase carries these requests without retaining their content.

When you choose X Sync, your short-lived X access token passes through Supabase to api.x.com so the request can be completed and counted against your plan. Chrome bookmark data is never included. The optional dead-link checker contacts only the saved URLs you ask it to test.

What is stored

Settings, bookmark categories, daily-pick history, notes, tags, projects, AI results, license records, and imported X Posts are stored in Chrome local storage and IndexedDB (BookmarksUnchainedDB).

When Chrome Sync is available, Pro can keep an encrypted recovery index containing only X Post IDs, order, dates, and links—not Post text, authors, credentials, or your license key. Supabase stores protected entitlement identifiers and quota counters, including the cumulative initial-import balance. It does not store prompts, OAuth tokens, returned Posts, or bookmark content.

Chrome launch waitlist

If you join the waitlist on this website, we store the email address you enter in a private Supabase table and use it only to send the Chrome Web Store approval notice. It is not added to a newsletter, sold, or combined with your extension library.

Resend delivers the signup notification to the product owner’s Gmail inbox. We retain the waitlist until the launch notice is sent, then delete it within 90 days. You can ask us to remove your address sooner by emailing info@anilkaraca.com.

Plans, metering, and payment

Pro AI actions reset on the first day of each UTC month. Initial X import limits are cumulative and do not reset; monthly X sync limits reset each month. X counts Posts returned, so the number newly added can be lower.

Polar is the merchant of record, and the extension never sees your card details. Your purchaser email and license activation details may be stored locally to identify the active license.

Permission and control

Favicons come from Chrome’s local icon cache and do not contact bookmarked sites. Bookmark, X identity, notification, idle, public-site, and service access are optional and requested when you choose the feature that needs them.

X Sync never runs automatically and does not use a refresh token. Settings lets you disconnect X, deactivate a license, export or clear local data, remove optional access, and erase the encrypted recovery index. Cancelling Pro stops new paid requests but never locks or removes bookmarks already on your device.

Sharing, selling, and advertising

BookmarksUnchained does not sell your data, use it for advertising, or collect behavioral analytics. Supabase keeps content-free operational totals for up to 400 days so usage, cost, limits, and failures can be monitored. Those totals never contain bookmark URLs, Post text, prompts, authors, X credentials, raw license keys, or IP addresses.

Supabase and Gemini process AI requests you start. Supabase and X process X sync requests you start. Polar processes licensing and payment. A sync can return author, avatar, Article/link-title, and attached-media fields; visible X-owned images load from pbs.twimg.com. X oEmbed remains a public author-name fallback for older incomplete records.

Chrome Web Store Limited Use

The use of information received from Google APIs adheres strictly to the Chrome Web Store User Data Policy, including Limited Use requirements.

Changes and contact

If our privacy practices ever change, this policy will be updated before new behavior is released. Questions can be sent to info@anilkaraca.com.