Privacy policy
Last updated: October 7, 2026.
Mark Atlas is provided by sealofcomand. It helps you search, review, and organize your existing Chrome bookmarks. Google sign-in is required to enter the full and compact library. Bookmark records and local search stay on your device; disclosed AI features use the external services described below. Local features continue after hosted AI allowance is exhausted.
Privacy at a glance
- Local-first: Your bookmark library, saved page details, labels, notes, quotes, quote comments, and imported or pasted transcripts are managed in your Chrome profile. Mark Atlas uploads a selected folder snapshot only if you explicitly enable the optional AI connector and click Sync selected folder. Ordinary library use does not synchronize a cloud library. Chrome may synchronize native bookmarks according to your own Chrome settings.
- Google sign-in: A Google account is required to open the full Library or compact view. Free Beta is selected automatically after the disclosed sign-in action. Local search, browsing, and exports remain local and continue when hosted AI allowance is exhausted. The bundled Help & FAQ is available without sign-in.
- Optional cloud AI: AI search, classification, title suggestions, and context enrichment use the external providers described below. Depending on the feature, selected titles, URL context, summaries, excerpts, transcripts, or queries can leave your device and may contain personal information. The backend retains account and usage records and cached answers, as explained below.
- No advertising or product-analytics trackers: The current extension does not send analytics events about app openings, upgrade-button clicks, or local searches. Hosted AI usage is recorded to enforce allowances and protect the shared service budget.
- Controls on your device: You can export local data, disable automatic fetching or classification, choose local-only search, and revoke optional website access in Chrome. Bookmark organization does not request or read browsing history.
- Local and hosted deletion are separate: Signing out or uninstalling does not delete hosted account records. The retention and deletion section explains which data remains and how to request its removal.
This summary describes the current behavior. The sections below explain the data sent by each optional feature, service providers, retention, and user controls in more detail.
Data on your device
Mark Atlas reads your Chrome bookmark titles, URLs, folders, and available bookmark dates. It stores settings, labels, processing queues, and any saved page details or imported/manually pasted transcripts in this Chrome profile. Personal TypeSafe API keys, original bookmark titles and title history, and hosted sign-in tokens are also stored locally. JSON exports contain your bookmarks and saved details but exclude API keys, hosted session, and server quota records. Keep exports secure because they can contain sensitive content.
Smart fill and Suggested rank existing bookmark information locally: current-bar placement, available last-opened dates and save dates. When recent-use information is missing, recently saved pages from different sites fill spare places. Last opened uses Chrome's available bookmark dates, with save dates as a fallback. Mark Atlas does not request the `history` permission, read browsing-history URL/visit records, or monitor browsing events. These suggestions add no activity tracking, storage or AI requests. Bookmark URLs and dates remain part of the local library described above.
The interface language choice is saved locally in this Chrome profile. Automatic language selection reads Chrome’s language preferences. Translations are bundled with the extension, work offline, and do not send your language preference or bookmark content to a translation service.
Chrome may sync your native bookmarks under your Chrome settings. Preparation progress, its automatic-start state, and the once-only feature-unlock message flag stay in this Chrome profile. A local decision to continue with available evidence adds no provider request by itself. Mark Atlas page details, labels, transcripts, and settings are not synced by Mark Atlas between profiles.
Personal notes, keywords, quotes and their comments, previously saved collections, and automation preferences remain in this Chrome profile and are included in local JSON exports. The last search and filters are saved locally, separately for full and compact views, and are not included in JSON exports or synced by Mark Atlas. Remembering them adds no network requests; the existing related-search preference still governs AI requests when a saved search is restored. Personal notes and keywords are excluded from routine AI requests. Saving notes and quotes makes no AI request. The separate Update labels using saved note action sends up to 600 note characters and 240 keyword characters to connected Jev for that bookmark’s classification. Search, automatic bookmark processing, OpenAI quality/context, and Groq title requests exclude these personal fields. Quote text and comments never enter AI payloads. The separate AI connector can include private notes and personal keywords only when you select its additional opt-in; its results then reach your connected AI client. Failed classification retains the local note and keywords. Deleting a bookmark inside Mark Atlas permanently removes it from Chrome and removes its saved local records after confirmation. Recovery is removed. On the next extension reload or view startup, a one-time local migration permanently deletes the tracked legacy Recovery folder and its contents and clears their saved data and old removal records. Links already moved elsewhere keep their saved data. This migration adds no permissions or network requests.
Retrieving saved pages
On first opening, library preparation starts automatically if website access is already granted. Otherwise Chrome requires an explicit click to allow HTTP/HTTPS website access before preparation continues. With that grant, Mark Atlas fetches saved bookmark URLs without cookies and saves titles, descriptions, headings, structured metadata, and bounded readable text locally. Refreshes and newly added bookmarks can reuse the grant. The optional save card checks the active tab URL only when a bookmark is created, to match the newly saved page and show a bundled note/Save for later form. It does not track browsing history or read the open page’s content for this card. Notes and later intent stay local, are included in JSON backups, and are excluded from automatic AI requests. Temporary card authorization records stay in browser-session storage and are excluded from backups. You can disable the card in Preferences. Website operators receive normal network requests, including the requested URL and information such as your IP address. Revoke website access in Chrome settings to stop future page fetching until you grant it again.
Preparation also attempts to retrieve available YouTube captions, including Shorts, before AI classification. These free requests go directly to YouTube without authentication cookies; the extension does not download audio or use a separate transcription service. YouTube receives the requested video ID and normal network metadata. Caption text, its language, and retrieval outcomes stay in this Chrome profile and are included in JSON backups. Existing transcripts are preserved; missing or blocked captions do not prevent setup from finishing. An older completed setup can receive one caption pass after updating and reopening Library. Imported transcripts improve local search and provide bounded samples to existing Jev classification, related-search, and folder-matching operations under the disclosure below. Retrieving captions itself makes no AI request.
Jev and TypeSafe
When you connect a personal TypeSafe key, Jev requests go directly to TypeSafe. When you sign in and enable hosted access, relevant requests pass through our Supabase backend to TypeSafe. Classification can send a bookmark title, URL, folder, cached page details, a bounded page-text excerpt, and a transcript sample. The updated hosted policy retains up to 1,000 excerpt characters within a 4,000-byte provider payload, plus bounded cleaned page titles, headings, types, keywords, and unverified AI inference. Larger context can use more provider credit within the existing account and request limits. Related search sends your query, available Topic/Format names, and compact candidate summaries. Folder matching sends a proposed folder path and bounded bookmark context. Hosted requests sanitize bookmark URLs to hostname/path without embedded credentials, query strings, or fragments; direct personal-key requests may include fuller URLs.
With Jev connected, newly added bookmarks can be classified after their details are saved. By default, related searches run after a 450 ms typing pause for queries of three or more characters. Settings can require an explicit Related search click or restrict results to local search. Automatic page fetching and classification for newly saved bookmarks can be disabled independently. Hosted searches run while search allowance and credit remain and can consume one search allowance per new search; repeated searches reuse cached answers. Provider replies supply suggested labels and related matches. Removing a personal key can switch requests to hosted access if you remain signed in and have consented. Remove the key and sign out to stop new Jev requests.
Validated Jev search/routing answers and hashed request/provider identifiers are cached locally in browser-session storage for reuse across full and compact views. This cache stores no additional query text, request context, or API credentials. It holds at most 64 responses and approximately 512 KB; answers are reusable for six hours and the cache clears on connection/account changes, setup reset, extension reload, or browser restart. Identical active searches share a provider call. Cancelling a view's search does not cancel an already-started provider request; it can finish, consume usage and save its answer locally.
Groq title shortening
Groq is the included provider for optional title shortening through your signed-in beta account. No Groq credential is stored in or requested by the extension. When you explicitly generate a preview for one or more selected bookmarks, Mark Atlas saves missing page details and original titles locally, then sends current bookmark titles, cached page titles (up to 200 characters), and descriptions (up to 180 characters) through the authenticated Mark Atlas backend to Groq. URLs, full page text, transcripts, folder paths, and Jev credentials are omitted from this request. The backend fixes the model and prompt, enforces usage limits, and caches validated title answers and HMAC digests for reuse. These cached answers contain selected bookmark IDs and suggested titles; the request payload is not persisted in the application database.
Title generation can continue in the background while you browse or close Library. Its selected bookmark snapshots, pending queues, preview suggestions and manual preview edits are saved locally in this Chrome profile so you can reopen and review them. Resetting setup clears that job and its previews; applying removes the corresponding preview while retaining original title history.
Your allowance records count Groq batches and shared credit usage. Applying a title happens locally and makes no provider request. Stop prevents later batches and discards late suggestions; an already accepted server request can finish and use quota. Groq's processing and retention controls are described in Your Data in GroqCloud. Legacy personal Groq keys from the previous version are removed locally when the shortening view initializes.
Optional OpenAI quality checks and context enrichment
OpenAI quality checks and context are enabled while signed in and disabled while signed out, with no separate checkbox. Previous checkbox choices no longer control this workflow. After first opening, Google sign-in and hosted consent automatically continue remaining library preparation, including quality checks, context improvement, and Jev classification. Existing page details are reused. Stopped or failed jobs remain paused until you explicitly Continue; reopening does not retry them. These runs send selected gathered hostnames, saved/captured titles (up to 240 characters each), descriptions (400) and bounded captured passages (at most 1,000 body characters, including representative and suspected-noise samples) through authenticated Mark Atlas hosting to OpenAI. This can include personal information. URLs, queries, fragments, credentials, folders and transcripts are omitted. Recognized private/inaccessible pages send hostname only. All selected gathered pages can be audited, including apparently useful pages; videos and usable transcripts are excluded.
Luna audits groups up to 100 and returns quality codes, then describes only flagged or weak pages in groups up to five through Standard processing. Existing accepted Batch jobs remain resumable. Context can rely on supplied evidence or learned title/domain knowledge, without browsing, and may be wrong or outdated. Descriptions are limited to 240 characters and are automatically applied as unverified AI inference, separately from raw capture data. Quality flags affect the derived search/classification view; raw captures remain local and unchanged. Groq title shortening is separate.
Supabase privately persists sanitized selected evidence, job/file identifiers, diagnostic results and usage/reservations to resume and enforce the capped shared OpenAI budget. A retryable Standard failure retains its remaining selected evidence, validated prior results and progress until you continue or cancel the job. Continue resubmits only the unfinished chunk; completed chunks are preserved. Evidence clears on completion, cancellation or a terminal failure; results clear after local saving and acknowledgement. Acknowledgement/settled cancellation deletes known provider files. Unresolved/abandoned jobs require reconciliation; no automatic retention purge is configured. OpenAI's provider processing and retention controls apply independently; stored Standard Responses are deleted after validated outputs are durably saved, and known failed Responses are deleted during retry or cancellation; unresolved Responses may retain normal provider retention. See OpenAI API data controls.
The extension service worker saves progress and advances preparation, with open views accelerating status checks and alarms resuming work after restarts. Closing the page does not cancel accepted work. Signing out prevents further local processing but does not cancel accepted work; use Cancel AI job to request cancellation and cleanup. Accepted requests may still consume credit. Setup reset clears local context/audits and retains a minimal cancellation ticket for outstanding cloud cleanup. Backups include context/audits, not cloud tickets. OpenAI availability follows the signed-in session independently of legacy enrichment consent flags. Account and in-card disclosures describe the provider and automatic application of unverified context.
Optional AI connector
The AI connector is disabled until you choose a folder, accept its disclosure and explicitly sync. It uploads a snapshot of up to 250 HTTP/HTTPS bookmarks and 2 MB to the Mark Atlas Supabase project in Frankfurt: titles, full URLs (including query strings/fragments when present), folder paths, labels, descriptions, original titles, saved page text, captions, and captured keywords. Embedded URL credentials, local files and browser pages are excluded. Private notes and personal keywords are off by default and require a separate checkbox. Quotes and quote comments are excluded. Page text and captions are each limited to the first 12,000 characters; notes to 4,000. Later local changes are uploaded only on another explicit sync.
Your chosen AI client, including Codex, can search this snapshot and read bounded matching content using a read-only access token. It receives search results and requested source fields, and processes them under its own settings and policies. The connector does not call a paid AI provider, fetch websites, or alter bookmarks. Downloaded tokens grant access to anyone holding them. Mark Atlas stores only their hashes on the server; keep downloaded credential files private. A local Codex installation stores its token outside the project in a private credential file. Creating another token revokes the previous token immediately.
Snapshot and token access each expire after seven days. Expired content becomes inaccessible immediately, and an hourly cleanup removes its active database rows. Revoke access stops subsequent connector reads; Delete cloud copy deletes the active snapshot and revokes access. Signing out, uninstalling, resetting setup or editing local bookmarks does not revoke or delete the snapshot. Account deletion removes the linked snapshot. Account/profile identifiers, version and request counters can remain until account deletion. Platform logs/backups and content already received by your AI client have separate retention; deleting a cloud copy does not recall these copies.
Hosted account, allowances, and feedback
Google and Supabase handle the required Google sign-in. Continuing with Google accepts the displayed hosted AI disclosure and selects Free Beta automatically; no additional activation step is required. The extension stores your Supabase session and account ID/email locally. The backend stores account identity, allowance/spending counters, HMAC payload digests, cached answers, and operation/rate records to authenticate requests, reuse answers, enforce limits, and protect the shared beta budget. Outside the separately consented AI connector, the application does not persist a complete bookmark library or search-request payload; selected OpenAI job evidence/results are temporarily stored as described above. Jev and Groq context passes through the backend.
If you explicitly send private feedback, Supabase stores your account ID, selected category, message, extension version, submission time, and reply permission for up to 90 days. With the displayed disclosure, new submissions are also copied to the private GitHub issue tracker: feedback identifier, category, message, version, and timestamp. Account identity, email, and reply permission are not automatically forwarded. GitHub copies remain until removed separately. Bookmarks, keys, transcripts, and diagnostic data are not attached automatically. Messages are kept locally during sign-in and after failed sends without being submitted. Signing in does not automatically submit that draft. A message you choose to send may contain personal information; include only information you intend to share.
The extension checks hosted sign-in availability even before sign-in. These checks and other service requests expose normal network metadata to the service providers, including IP addresses and browser/request information. Hosting and authentication request logs can include an approximate country, region, or city derived from the IP address; these are network-derived estimates, not GPS readings. Supabase documents IP and geographic fields in its platform request logs. Mark Atlas does not request device geolocation or use location to rank bookmarks or target advertising. Provider/platform operational logs are subject to their policies and our configured service arrangements. See Supabase's request-log fields.
Operator-only billing test
A disabled-by-default billing test uses Lemon Squeezy hosted checkout and its customer portal. Only explicitly enabled test accounts can use it. No real payment is taken and existing AI allowances remain unchanged. Checkout runs in a separate browser tab; Lemon Squeezy receives billing details directly. Mark Atlas does not collect card numbers, addresses or payment credentials. The test does not send your bookmarks, notes or search queries to Lemon Squeezy.
The backend stores a random checkout reference linked to your hosted account, its checkout URL until redeemed, provider subscription and latest invoice identifiers, status and relevant dates. Provider names, customer email, addresses, card details and customer-portal links are not stored by this integration. Billing test records remain until operator deletion or hosted Auth-account deletion, which removes their account linkage and records. Provider records and notifications have separate retention. Deleting the Mark Atlas account does not itself cancel a provider subscription. These arrangements must be reviewed before live billing. See Lemon Squeezy's privacy policy.
Service usage and store statistics
The current extension does not send product-analytics events for app openings, upgrade-button clicks, or local searches. Hosted account and AI-operation records are used to provide the service, enforce allowances, reuse cached answers, and prevent abuse. These records do not measure every search performed in the extension: local searches and client-cached answers do not create a new hosted AI-operation record.
We may summarize these existing service records to understand account enrollment, hosted AI usage, spending, and submitted requests for additional allowance, and to plan service capacity. This reporting uses aggregate counts and spending totals, without analyzing bookmark content, search text, cached-answer content, or feedback-message text. It does not add extension activity tracking, installation identifiers, or application-level location collection beyond the network metadata described above. The underlying account-linked service records remain subject to the retention and deletion arrangements below.
For distribution through the Chrome Web Store, Google provides publishers with store statistics such as installs, uninstalls, and installation counts grouped by country and language. These are separate from analytics inside Mark Atlas. The store's installation statistics do not establish whether an installation is actively using the extension. Google's handling of store data is subject to its own policies.
Public website hosting
The public Mark Atlas homepage, privacy policy, and support pages use Cloudflare hosting. Visiting these pages sends normal network information, including your IP address and request/traffic information, to Cloudflare to deliver and protect the website. Cloudflare's operational processing and retention follow its service arrangements and privacy policy. These static pages contain no analytics scripts, advertising, sign-in form, or bookmark-upload functionality. Reading them does not upload your extension library or sign-in session to Cloudflare.
Service providers and use limits
Services used are Google for authentication, Supabase for authentication/backend hosting and records, TypeSafe for Jev processing, Groq for optional title previews, OpenAI for quality checks and AI context, and GitHub for disclosed private feedback delivery. See Google's privacy policy, Supabase's privacy policy, TypeSafe's privacy policy and service agreement, Groq's data controls, OpenAI's API data controls, and GitHub's privacy statement.
TypeSafe states that input is not used to train or fine-tune models. Its public policy describes US processing and retention as reasonably necessary; it does not promise a fixed deletion period for this account. Groq states that inference inputs/outputs are not retained by default, with reliability or abuse exceptions of up to 30 days and separate usage metadata. We do not claim a zero-retention arrangement with either provider. OpenAI normally retains stored Responses for 30 days unless deleted; Mark Atlas deletes known objects after durable validation and retries cleanup on acknowledgement/cancellation. Provider abuse-monitoring retention is separate, and an accepted response whose identifier was lost may remain until provider expiry.
The Mark Atlas database is hosted in Frankfurt. Service providers may process data in other countries. Supabase platform logs and backups have plan-dependent retention; deleting application records does not instantly erase existing platform backups. See Supabase log retention and database backups. Provider processing is subject to the linked policies and the applicable service arrangements.
Mark Atlas uses and transfers user data only to provide and maintain its described bookmark, account, allowance, and feedback functionality. Mark Atlas does not sell user data or use it for advertising, creditworthiness, or lending decisions. Mark Atlas's use of information complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Retention, exports, and deletion
Local details remain in your Chrome profile until removed or the extension is uninstalled. Export a backup before uninstalling or changing profiles. Removing the extension does not remove your native Chrome bookmarks or automatically erase server records.
The hosted application retains accounts, usage counters, and cached answers until account deletion. Rate events older than one day are pruned during new reservations. Hourly housekeeping removes Supabase feedback older than 90 days and feedback-delivery scheduler logs older than seven days. Private GitHub issues remain until removed separately; Supabase expiry does not delete them. OpenAI-job evidence and connector snapshots follow their separate limits above.
Sign-out stops new authenticated operations but does not delete hosted records. To request account deletion, contact sealofcomand@gmail.com. We verify account ownership, revoke sessions, reconcile active AI-job cancellation and provider cleanup, and delete the hosted Auth account and associated internal records. Related GitHub issue references must be located before account deletion so their copies can also be removed. Aggregate shared spending is retained without replenishing the provider budget. Provider operational logs/backups and copies already received by an AI client have separate retention.
Security and changes
Account and AI service requests use HTTPS. The extension keeps credentials out of exported backups and does not automatically attach them to feedback. This policy will be updated when data practices change; the current version will be available at the published privacy URL. Material changes to data use requiring consent will be disclosed before that use.
Contact
Publisher: sealofcomand
Privacy and account deletion: sealofcomand@gmail.com