Legal · Rippre Pocket-Bookmarks
Privacy Policy
The short version
Pocket Bookmarks has no servers, no accounts and no analytics. It does not collect or sell your data, and none of it reaches us: there is nowhere for it to go. Everything the extension stores stays on your own device or in your browser's own bookmark store. The one exception, explained below, is the optional site check, which lets each saved site see that it was asked.
Two things are worth understanding clearly, and both are explained in full below. Your bookmarks are real browser bookmarks, so if you have browser sync switched on, your browser — not this extension — syncs them the same way it syncs every other bookmark you have. And apart from the page you are saving fetching its own images for the offline copy, the extension makes one kind of network request of its own, only if you turn it on: asking a saved site's server whether it still answers.
What the extension stores, and where
Your bookmarks live in your browser's own bookmark store. Saving a page creates an ordinary bookmark, identical to one you made yourself with the star button. The extension reads and writes that store through the browser's bookmarks API. It never keeps its own copy on a server.
Everything else stays on your device, in your browser's local IndexedDB storage for this extension:
- tags, notes and highlights you create, and the tags the extension adds on its own when you save a page — worked out on this device from the site's name, the keywords the page declares about itself and the tags you already use (off with one switch in Settings)
- the offline reader cache — the readable text and images of articles you chose to save for reading later
- page copies you asked for — a screenshot and a self-contained copy of a page, kept for the day the site is gone
- reading progress and reading status
- the local search index built from the above, and any searches you saved as smart folders
- the results of the optional site check described below, one line per site
- a one-line record of each import you run — where it came from, the folder it went into, and how many bookmarks it added, skipped as duplicates or could not add
- your settings, and a local undo history
- whether you left the library in two panes, and which folder the right-hand pane showed, so that it reopens the way you left it
- after an update, the version you updated from, so that the extension can show what has changed since — kept only until you have read or dismissed it
- the date you set the extension up and how you answered its one request for a rating, so that it asks once — after a week and a couple of dozen saves — and not again if you say no
None of this is transmitted anywhere. It is readable only by this extension, on this device.
Automatic backups are files on your computer. If you leave them on (they are weekly by default, and can be set to daily, monthly, every three months, yearly or off), the extension writes a backup file into a "Pocket Bookmarks" folder inside your browser's Downloads folder. That file contains your bookmark tree, tags, notes, highlights and — unless you turn that off — the cached articles. The extension keeps the last five and removes older ones it wrote itself. The files are yours: anything that syncs your Downloads folder, such as a cloud drive, will carry them the way it carries any other file.
Browser sync — the one way bookmarks leave your device
Because your saved links are ordinary browser bookmarks, they participate in your browser's sync exactly like the rest of your bookmarks. If you are signed into Chrome, Edge or Firefox and it syncs your bookmarks, your browser uploads them to your own account with that browser vendor and copies them to your other devices. Where Chrome keeps synced and device-only bookmarks apart, the extension creates its folders among the synced ones.
This is the point of the design — it is how your library follows you without this extension needing an account — but it should be stated plainly:
- The transfer is performed by your browser, not by Pocket Bookmarks.
- It goes to your Google, Microsoft or Mozilla account, under that vendor's privacy policy, not to the authors of this extension.
- It covers bookmarks only. Your tags, notes, highlights, reader cache and page copies are not synced and never leave the device they were created on.
- Turning off browser sync stops it entirely, and the extension keeps working.
Page content, the reader, and page copies
When you save a page for reading later, the extension can extract that page's readable text so you can read it offline, folding the article's images into the copy where the page itself could load them; images it cannot fold in are left out. This runs inside the page you are already looking at: to fold its images and stylesheets in, the page fetches them again from the addresses it gives them, including images further down that you had not scrolled to yet, at the moment you save. The result is stored locally. No page content is sent anywhere, and opening a saved article or page copy fetches nothing from the web.
If you tick "Keep a copy of this page" when saving (or turn that on by default in Settings), the extension also stores a screenshot of what you saw in the tab and a copy of the page itself — its text, layout and images, folded into one file with everything that could run removed. Both are taken at the moment you save, inside your own click, and stored only on this device. You can view or delete them from the reader, and delete all of them in Settings.
Extraction and the page copy require the optional scripting permission, which is requested the first time you use either and can be declined. If you decline, saving still works — only the offline copies are skipped. You can revoke the permission at any time in your browser's extension settings.
The extension only ever looks at a page when you explicitly act on it — by clicking the toolbar icon, using a keyboard shortcut, or choosing a context-menu item. It does not read pages in the background, does not observe your browsing, and does not read your browser history.
Checking whether saved sites are still online
Apart from saving a page's images with it (above), this is the extension's only network request of its own, and it is off unless you turn it on in Settings.
When it is on, once a day the extension asks each saved site's own server whether it
still answers: one HEAD request to the site's address, sent over HTTPS
and without cookies, whose reply is never read beyond "did a server
answer"; if the site redirects it, the request follows, still over HTTPS. Sites saved
only with http:// addresses are not checked, so nothing goes out
unencrypted. A site is marked as unreachable in your library only after failing on two
different days. Each daily run checks up to 25 sites, the ones checked longest ago
first; you can also start a run yourself in Settings, or check a single site on demand.
What this means for you: each site you have saved receives a request from your browser, so that site's server sees your IP address, exactly as it would if you visited it, and can tell that it is on someone's list. Nothing else about your library — not the URL you saved, not your notes, not the other sites you have — is sent to it, to us or to anyone else. There is no "us" to send it to.
On Firefox, switching the check on first asks for Firefox's permission to share bookmark
information, since each site checked learns that it is on your list. You can withdraw it
in about:addons, and the check stops.
Importing from the browser's Reading List
On Chrome and Edge you can import the browser's built-in Reading List. The extension reads that list only when you choose to import it, turns the entries into bookmarks, and never changes the list itself.
Permissions, and why each exists
- bookmarks — Read and write your bookmarks. This is the core of the product.
- activeTab — Read the URL and title of the page you are saving, at the moment you save it, and — only when you ask for a page copy — take the screenshot and read the page.
- tabs — Read titles and URLs when you choose "save all open tabs".
- contextMenus — Add the right-click save options.
- unlimitedStorage — Let the local data listed above grow past the browser's small default quota: the offline reader cache and page copies can be large.
- downloads — Save exported files to your computer when you ask for an export, and write the automatic backups you have scheduled.
- alarms — Wake the extension once an hour to see whether a backup or a site check is due.
- sidePanel — Draw the side-panel interface (Chromium browsers).
- favicon — Show site icons for saved pages, using icons your browser has already cached. This makes no network request.
- readingList — Read the browser's Reading List when you choose to import it (Chromium browsers). Read only.
- scripting (optional) — Extract article text and take the page copy, for offline reading. Requested only when you first use either, and declinable.
The extension requests no host permissions, so it has no standing access to any website. The address-bar keyword (pb) is a manifest entry, not a permission, and searches only your local library.
What the extension does not do
- No accounts, no sign-in, no user profiles.
- No analytics, telemetry, crash reporting or usage statistics of any kind.
- No advertising, and no data sold, rented or shared with anyone, apart from the optional site check letting each site it asks see that it was asked.
- No remote code: all code is bundled in the package you install, and nothing is downloaded or executed at runtime.
- No tracking of your browsing, and no access to your browser history. The only web addresses it handles are those of pages you save or ask it to open.
- No network requests of its own, other than the optional site check described above, which is off unless you turn it on, and a page you are saving fetching its own images and stylesheets for the copy.
Chrome Web Store User Data Policy
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Your data, and deleting it
You are always in control:
- Export your library at any time from the extension, as a file on your computer. Automatic backups are files in your Downloads folder; delete them like any other file.
- Deleting a bookmark removes the browser bookmark immediately. Its notes, tags, highlights, cached article and page copy are kept on your device, detached from the deleted bookmark, so that undo can restore them and so that a bookmark which reappears through browser sync gets its notes back rather than losing them. They are not shown in your library while detached, and they are not sent anywhere — but they are retained locally rather than erased. See below for how to remove them.
- Remove data from deleted bookmarks, in Settings, permanently erases everything detached in this way — notes, tags, highlights, cached articles and page copies — after telling you how many deleted bookmarks are affected. It cannot be undone, and undoing an earlier delete afterwards brings the bookmark back without its notes.
- Clearing the reader cache and deleting all page copies, in Settings, remove the offline copies, including detached ones, without touching your bookmarks or notes.
- Turning off the site check stops the requests; the results already recorded stay on your device until you uninstall.
- Uninstalling the extension removes all of its local data from your device, detached notes, cached articles and page copies included. Your bookmarks remain, because they belong to your browser rather than to this extension, and so do any backup files you chose to keep.
There is no data held by us to request, correct or delete, because none is collected. Rights under the GDPR, UK GDPR and CCPA are satisfied on the basis that no personal data is processed by the extension's authors.
Children
The extension collects no data from anyone, including children under 13, and is not directed at children.
Changes to this policy
If a future version changes what is stored or introduces any transmission of data, this policy will be updated before that version is released, and the change will be described in the release notes. The "last updated" date above will change accordingly.
Contact
Questions about this policy: legal (at) rippre (dot) com.