Legal
Privacy Policy
Last updated: 22 July 2026 (v1.3.0)
Bookmarkz is a mobile app and browser extension created and operated by Delta 60 Ltd ("we", "us"). This policy explains how we collect, use, and protect your personal data when you use the Bookmarkz app or browser extension, and when you visit or submit information through our website at bookmarkz.app.
1. Who we are
Delta 60 Ltd is a company registered in England and Wales (company number 17049123). Registered office: Lytchett House, Unit 13 Freeland Park, Wareham Road, Lytchett Matravers, Poole, BH16 6FA. You can reach us by emailing hello@delta60.com.
Delta 60 Ltd is the data controller for the personal information we hold about you, for the purposes of UK GDPR and the Data Protection Act 2018. We are registered with the Information Commissioner's Office (ICO). Our registration reference is ZC106781.
2. Information we collect
When you use Bookmarkz, we collect the following categories of information.
Account information. Your email address and, for sign-in via Apple or Google, the basic profile information those providers share.
Bookmarks you create. The links you save and the way you organise them: the URL, title, tags, colour choice, pinned position, and list a bookmark belongs to, and how it was added (typed, pasted from the clipboard, scanned from a QR code, shared from another app, imported from a bookmarks file, or saved from the extension). This is the core content of your account. When you import a browser bookmarks file in the app, the file is read on your device and only the resulting bookmarks are stored.
How you use your own bookmarks. When you open a saved link from the app or the extension, we increase a count on that bookmark and record when it was last opened. This is what makes the Most Popular sort work and lets a row show when you last used it. It is stored on the bookmark itself, in your account, and is deleted with it.
App settings. Your Bookmarkz preferences sync to your account so your devices agree: for example your default sort, whether Tag Lock is on, whether Really Simple Mode is on, and whether the extension is mirroring your pinned links to your browser's bookmarks bar.
Voice recordings. When you use voice entry, the app records audio through your device microphone, with your permission. The audio is sent to our transcription provider, converted to text, and then discarded. We do not retain the audio after transcription, and our agreement with the provider restricts their use of audio to delivering the transcription. The microphone is only active while you are recording.
So that a request interrupted by a bad connection is not transcribed or counted twice when it retries, the result of a successful voice entry (the transcribed text and the title, link, and tags taken from it) is held on our server against that request for 24 hours, then deleted automatically. It is also deleted immediately if you delete your account.
Voice fair-use records. Voice entry is subject to a fair-use allowance. To count it, we store one row per successful voice entry containing your account identifier and the time it happened, and we use rows from the last 30 days to work out your remaining allowance. Rejected or unsuccessful recordings are not counted or kept.
Camera. When you tap the QR scan button to capture a link, the app opens the camera to read the code. The camera is only active while the scanner is open. We do not store or transmit camera images; only the decoded link is used by the app. We always ask for your permission before any access to your camera.
Subscription records. When you subscribe, we store your subscription status, the product identifier, when it expires or renews, whether the purchase was made in a live or test environment, and the identifier and time of the latest update our payment provider sent us. We never see your card details, because payments are handled by the App Store or Google Play directly.
Account and subscription history. We keep a short, append-only record of significant events on an account, such as a subscription starting, renewing, or lapsing, and an account being deleted. Each entry holds an internal account reference, the type of event, the time, and a small amount of technical detail about it. We use this to answer billing questions, to evidence that a deletion was carried out, and to investigate abuse.
Marketing preferences. Your consent choices for email newsletters about Bookmarkz and, separately, other products from Delta 60 Ltd. You can change these at any time in the app under Settings, Marketing Preferences.
Bug reports and feature requests. If you report a problem or send us a feature request in the app, we store the text you submit, your account identifier, and, for both, the platform you are on and the app build you are running. We use this to investigate issues and improve the service.
Website forms. Our website (bookmarkz.app) has two forms, and neither stores anything in a database. The contact form takes your email address, your message, and optionally your name, and emails it to our support address so we can reply. The launch notification form takes your email address and whether you want to hear about the App Store or Google Play release, and emails that to us; it does not add you to a mailing list. If you ask us to delete your account by email rather than in the app, we hold that message for as long as it takes to carry out and evidence the deletion.
Both website forms use Cloudflare Turnstile, an invisible bot-protection check. When you open a page carrying one of them, Cloudflare receives your IP address, browser User-Agent header, a TLS fingerprint, and our site identifier so it can decide whether the traffic is automated. We do not see this information ourselves. We do not use cookies on our website, and we do not run website analytics.
Anti-abuse records. If someone tries to create an account with an email address that already has one, we email the real account holder to tell them. To stop that being used to send repeated emails to somebody, we keep a note of the address we sent to for 7 days, then delete it.
Technical and diagnostic information. Basic device, operating system, app version, request, and diagnostic information needed to run the app reliably, investigate faults, measure voice usage and cost, apply rate limits, and protect the service against abuse.
Crash and error reports. When the app or one of our server-side functions hits an unexpected error, an automated diagnostic report may be sent to our error-monitoring provider. These reports may include the error details, device and OS version, app version, timing and technical context, and a one-way hashed account identifier rather than your email address. They are not intended to contain your email, your bookmarks, or your voice recordings. Although our provider sees your IP address at the moment of delivery, we have configured it not to retain IP addresses within stored crash reports.
Favicons. To show the small site icon next to each saved bookmark, the app and extension load that icon from DuckDuckGo's favicon service (icons.duckduckgo.com). This sends the website's domain to DuckDuckGo, along with your device's IP address (as with any web request). It does not send your email or account identifier. DuckDuckGo is not one of our processors and we have no data-processing agreement with it (none is required); it receives the request as an independent service and states that the service is anonymous and does not build a browsing history. See DuckDuckGo's How DuckDuckGo Keeps Favicons Anonymous page for details.
Browser extension. The extension uses your Bookmarkz account and the same data described above. When you use it to save a page, it reads the address and title of the active tab. It keeps your sign-in session, and a small amount of bookmarks-bar sync state, in your browser's extension storage on your device; signing out clears the session.
If you turn on bar sync, the extension also reads and updates your browser's bookmarks bar so that it mirrors your pinned links, and a link you place on the bar yourself is saved to your account and pinned. Bar sync reads the bookmarks bar only. Separately, if you choose Import All in the extension's Links Manager, it reads your whole browser bookmark tree so you can bring those bookmarks in; that only happens when you ask for it. We do not collect your browsing history.
3. How we use your information
- To provide the app, browser extension, website, and your account.
- To store and sync your bookmarks, lists, tags, and settings across your devices.
- To sort and present your own bookmarks, including by how often you open them.
- To process voice entries through our AI transcription service, and to apply the voice fair-use allowance.
- To process your subscription and manage your access.
- To send transactional emails (account, password, email change, deletion, and operational emails).
- To send marketing emails only if you have consented to the relevant mailing list.
- To answer messages sent through our website contact form.
- To respond to bug reports, feature requests, support requests, and feedback.
- To review reports you submit about AI-generated content, as described in section 6.
- To keep records of account and subscription events for billing queries, evidence of deletion, and abuse investigation.
- To improve the app, detect bugs, prevent fraud and abuse, and keep the service secure. Where we use aggregated data for these purposes, it is not linked back to identifiable individuals.
4. Lawful basis (UK GDPR)
We process your personal data on the following lawful bases.
Contract (Article 6(1)(b) UK GDPR): Creating a Bookmarkz account forms a contract between you and us to deliver the service. We process your account details, bookmarks, settings, voice transcription, and subscription records on this basis because the app would not work without them.
Consent (Article 6(1)(a) UK GDPR): We rely on consent for marketing emails. You can withdraw marketing consent at any time in the app, through unsubscribe links, or by emailing us. If you submit a report about AI-generated content, we treat that as your consent for us to review the report, including the input and output it contains. Device permissions such as microphone and camera are also under your control through the app and your device settings; turning them off stops the relevant feature from using that permission.
Legitimate interests (Article 6(1)(f) UK GDPR): We rely on this for activities where we have a justified business reason that does not override your rights. This includes keeping the app secure, diagnosing crashes and failures, investigating bug reports and support requests, answering website enquiries, preventing fraud and abuse, managing rate limits and the voice fair-use allowance, keeping limited account and subscription audit records, and improving our products using aggregated or minimised data. You can object to processing based on legitimate interests.
Legal obligation (Article 6(1)(c) UK GDPR): We keep certain records because UK law requires us to, principally financial and accounting records connected with subscriptions and tax reporting.
5. Who we share data with
We use the following processors and service providers to run the service. They process your data only on our instructions, under contract, with appropriate safeguards.
- Supabase: secure hosting of your account, bookmarks, and other app data.
- OpenAI: speech-to-text transcription and sorting of voice entries. Audio and text are processed to provide the feature. We configure provider settings, where available, to restrict use of submitted content to providing the service.
- RevenueCat: managing subscription records and entitlements.
- Mailgun: sending transactional and marketing emails on our behalf, and delivering our website form submissions to us.
- Apple and Google: app distribution, sign-in where selected, and payment processing.
- Expo: build and update infrastructure for the app, including delivery of over-the-air app updates to your device.
- Sentry: automated crash and error reporting. Hosted in the European Union (Frankfurt, Germany).
- Vercel: hosting the bookmarkz.app website and website forms.
- Cloudflare: invisible bot-protection (Turnstile) on the pages that carry our website forms. Cloudflare processes your IP address, User-Agent header, TLS fingerprint, and our site identifier as our processor for this purpose. Cloudflare may also retain anonymised signals under its own legitimate interest to improve Turnstile's bot detection. See Cloudflare's Turnstile Privacy Addendum for full details.
Where available, we configure AI providers not to use submitted content for training their general-purpose models. We do not sell your personal information, and we do not disclose your bookmarks to advertisers or data brokers.
Legal and regulatory disclosure: We may disclose personal information where we are required to do so by law, by court order, or by a regulator with legal authority to compel disclosure, and where we reasonably believe disclosure is necessary to comply with a legal obligation, to protect our rights or property, to investigate suspected fraud or abuse, or to prevent serious harm.
6. Reporting AI-generated content
If AI-generated content in the app (such as a voice-entry transcript or the bookmark details produced from it) appears offensive, inaccurate, or otherwise inappropriate, you can report it directly from the screen where it appears. When you submit a report we record the AI's output, the input that produced it (such as your voice transcript), the category you selected, your optional note, and your account identifier. We review reports to improve the app's AI features and safeguards. Reports are kept for up to 12 months and then deleted automatically. If you delete your account, your reports are anonymised so they remain useful for reviewing our AI but are no longer attributable to you by ordinary account lookup.
7. International transfers
Some of our processors (notably our AI provider and our website host) are based in the United States or may process data outside the UK or EEA. We hold a data processing agreement with each of the processors listed in section 5. Where the processor is based outside the UK or EEA, the agreement includes safeguards required by UK GDPR, typically the UK's International Data Transfer Addendum, the EU Standard Contractual Clauses, or another legally recognised transfer mechanism.
8. How long we keep your data
- Bookmarks, lists, tags, and settings: kept while your account is active, and deleted when you delete your account.
- Voice recordings: not intentionally retained after transcription completes.
- Voice transcription results: the short-lived copy held against a request, described in section 2, is deleted automatically after 24 hours, and immediately if you delete your account.
- Voice fair-use records: deleted once they fall outside the rolling 30-day window, and in any case when you delete your account.
- Subscription and financial records: retained in anonymised form for at least 6 years and normally up to 7 years, to meet UK tax and accounting obligations.
- Account and subscription history: retained after account deletion with the account reference replaced by an anonymous marker, so it evidences what happened without identifying you.
- Bug reports and feature requests: deleted automatically 12 months after they are submitted. If you delete your account before then, they are anonymised and the same 12-month deletion still applies.
- AI content reports: deleted automatically 12 months after they are submitted, and anonymised if you delete your account before then.
- Anti-abuse records: the duplicate-signup note described in section 2 is deleted after 7 days.
- Crash and diagnostic records: kept by our error-monitoring provider under its standard retention, which is currently up to 90 days, then deleted.
- Website form messages: kept in our support mailbox for as long as needed to deal with your enquiry and to keep a reasonable record of it.
- Marketing lists: kept until you unsubscribe or ask us to delete them. Bookmarkz account deletion removes you from Bookmarkz marketing lists, but does not automatically remove you from Delta 60 cross-product marketing, because that is a separate consent. You can leave Delta 60 marketing through the unsubscribe link in any Delta 60 marketing email or by contacting us.
- After you delete your account: your account, bookmarks, lists, tags, settings, voice records, and subscription entitlement are deleted. Bug reports, feature requests, AI content reports, and account history are anonymised and then deleted on the timetables above. Limited financial records are retained in anonymised form as described above.
- Backups: deleted data may remain in encrypted backups for a limited period before automatic removal. Backups are restricted to disaster recovery.
We do not delete accounts for inactivity. Your bookmarks stay until you remove them or delete your account.
9. Your rights
Under UK GDPR you have the right to:
- Ask for a copy of the personal information we hold about you. You can also download your data yourself at any time from Settings, Download My Data.
- Correct inaccurate information.
- Delete your account and your data (you can do this from Settings inside the app, or by emailing us).
- Export your bookmarks in a portable format (a standard bookmarks file, a PDF, or CSV files).
- Object to processing or restrict it.
- Withdraw consent for marketing emails and manage optional device permissions such as microphone and camera.
- Ask us to review or delete a support message, bug report, feature request, or content report you have sent us, where that does not conflict with our legal, security, or abuse-prevention obligations.
- Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects on you.
- Complain to the UK Information Commissioner's Office (ico.org.uk).
To exercise any of these rights, email support@bookmarkz.app or hello@delta60.com. We will respond within one month.
10. Children
Bookmarkz is not designed for use by anyone under 16. We do not knowingly collect data from children under that age.
11. Security
We use industry-standard technical and organisational security measures designed to protect personal information, including encryption in transit, encrypted database storage, authenticated access controls, row-level authorisation, and restricted administrative access. No system is perfectly secure. If you believe your account has been compromised, contact us immediately.
Password breach checks: when you set or change a password, we use Supabase's built-in integration with HaveIBeenPwned to check whether your password has appeared in known data breaches. Your password itself is never sent. Only the first five characters of a one-way hash are sent, a fragment that matches many possible passwords and cannot identify you.
Local storage on your device: to speed up app start-up, the app keeps a local copy of your bookmarks, lists, and settings in the device's standard application data storage, protected by your device's operating system encryption (iOS Data Protection and Android File-Based Encryption) when the device is locked. Your sign-in session is additionally encrypted by the app, with its key held in the device's secure keystore. The cached copy is cleared when you sign out, and everything goes when you delete the app. In the browser extension, your sign-in session and bar-sync state are held in your browser's extension storage and cleared when you sign out.
12. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top tells you when it was last updated and published. Material changes will be communicated by email, in-app notice, or another appropriate method.
13. Contact
Delta 60 Ltd, Lytchett House, Unit 13 Freeland Park, Wareham Road, Lytchett Matravers, Poole, BH16 6FA. Company No. 17049123. Email hello@delta60.com.