MarkFlow
Back to MarkFlow

Privacy Policy

Last updated: 13 July 2026

MarkFlow respects your privacy. This document explains what personal data we collect, why, on what legal basis, who we share it with, and how you can exercise your rights.

Data controller

The controller responsible for processing your personal data is the operator of MarkFlow. For any privacy question or request, contact privacy@markflow.fyi.

Data we collect

Account identity — when you sign in with Google we store your Google user ID, email address, display name, and avatar URL so we can associate bookmarks with your account. User content — bookmarks, folders, tags, and the title, description, image and favicon extracted from the URLs you save. API keys — if you create keys for the browser extension or other integrations, we store a SHA-256 hash of each key (never the plaintext) together with the name you assigned, the creation time, and the last-used time. Uploaded images — if you save a page via the browser extension and it has no Open Graph image, the extension may capture a screenshot of the visible tab and upload it as the bookmark preview; these images are stored in our object-storage provider and linked to your account. Technical data — your IP address and user-agent string may appear in short-lived reverse-proxy logs for security and debugging; they are not persisted by the application itself.

Legal basis for processing

Account and bookmark data — performance of a contract with you (GDPR Art. 6(1)(b)). Session cookie — strict necessity to provide the service you requested. Google Fonts delivery and short-lived server logs — our legitimate interests in providing consistent typography and securing the service (Art. 6(1)(f)). Optional analytics or marketing categories — your consent (Art. 6(1)(a)); none are installed today.

Recipients and sub-processors

Google LLC — authentication (Google Sign-In), web font delivery (Google Fonts), and favicon fallback service. Our hosting provider — runs the MarkFlow servers and database. Cloudflare, Inc. — S3-compatible object storage (R2) for bookmark preview images, including extension screenshot uploads. We do not sell your data, share it for cross-context behavioral advertising, or transfer it to advertisers.

International data transfers

Personal data may be transferred to the United States through Google LLC. Google relies on the Standard Contractual Clauses approved by the European Commission for such transfers — details at https://policies.google.com/privacy/frameworks.

Data retention

Account and bookmark data are kept until you delete them or delete your account. Session records are removed after 30 days of inactivity. Your cookie-preference record is kept for 180 days and then re-requested. Short-lived reverse-proxy logs are rotated according to our hosting provider's policy.

Cookies and local storage

The table below lists everything the browser stores or requests while you use MarkFlow. Strictly necessary items are active whenever you visit the site (including Google Fonts, which is used to render the interface). Functional, analytics, and marketing items are only active if you opt in. You can review or change your choice any time via "Manage cookies".

Strictly necessary

NamePurposeDurationType
connect.sidAuthentication session30 daysCookie
markflow-consent-v1Cookie preferences180 daysLocal storage
fonts.googleapis.com / fonts.gstatic.comWeb font delivery (Inter) — Google LLCPer requestThird-party request
icons.duckduckgo.comBookmark icon fallback (3rd-party request, DuckDuckGo — no tracking)Per requestThird-party request

Functional

NamePurposeDurationType
markflow-langUI languageUntil clearedLocal storage
themeLight/dark themeUntil clearedLocal storage
markflow-view-prefsGrid/list/headlines view preferenceUntil clearedLocal storage
markflow-sidebar-prefsSidebar folders/tags collapse stateUntil clearedLocal storage
google.com/s2/faviconsBookmark icons (3rd-party request)Third-party request

Analytics

NamePurposeDurationType
stats.kovalnya.comPrivacy-friendly, cookieless analytics (self-hosted Umami) — page views & funnel events. No cookies, no cross-site tracking.Per requestThird-party request

Marketing

No cookies in this category.

Your rights under GDPR

If you are in the EU or EEA you have the right to access your data, correct it, erase it, restrict or object to its processing, and port it to another service. You also have the right to withdraw consent at any time without affecting past processing, and to lodge a complaint with your supervisory authority. To exercise any right, use the buttons in the user menu or email privacy@markflow.fyi.

Your rights under CCPA/CPRA (California)

We do not sell or share personal information for cross-context behavioral advertising and have not done so in the preceding 12 months. Categories of personal information we have collected in the past 12 months: identifiers (Google user ID, email, name), internet/network activity (bookmarks, folders, tags), and technical identifiers (IP, user-agent in transient logs). California residents have the right to know, delete, correct, limit the use of sensitive personal information (we collect none), and not to be discriminated against for exercising these rights. Submit a verifiable request by emailing privacy@markflow.fyi; an authorized agent may act on your behalf with written permission.

Children's privacy

MarkFlow is not directed to children under 16 in the EU or under 13 in the United States, and we do not knowingly collect personal data from them. If you believe a child has signed up, please contact us so we can delete the account.

Security

Traffic is served over HTTPS. Session cookies are HttpOnly, SameSite=Lax, and Secure in production. Sessions are stored server-side in PostgreSQL, not in the browser. We apply a Content Security Policy via Helmet and rely on Google OAuth rather than storing passwords.

Browser extension

The official MarkFlow browser extension is optional. When installed, it communicates with the MarkFlow servers using an API key you generate from Settings → API keys. API keys — keys are shown to you in plaintext only once, at the moment of creation, and are then discarded by the server. We store only a SHA-256 hash of each key, together with the name you chose, its creation time, and the time it was last used to authenticate. Keys travel over HTTPS in the Authorization header; they are never sent as cookies and never transmitted to third parties. You can revoke any key at any time from Settings → API keys — revocation is immediate and irreversible (a new key must be generated to restore access). Screenshots — when you save a page through the extension and that page does not expose an Open Graph image, the extension captures a screenshot of the visible tab, downscales it locally in your browser to at most 1200×630 pixels, and uploads it as the bookmark's preview image. Capture only runs on explicit save, never automatically on page load, and only for pages you actively bookmark. Screenshots are stored in our object-storage provider, attributed to your account, and deleted when you delete the corresponding bookmark or your account. You can delete any screenshot individually by deleting its bookmark. The extension does not collect analytics, telemetry, or any data unrelated to the save action you initiate.

Changes to this policy

Material changes trigger a refreshed consent prompt. The effective date is shown above; minor clarifications are published without a new prompt.

Contact

Questions about this policy or your data? Email us at privacy@markflow.fyi.