SystemMarks

Privacy Policy

Last updated: September 2026

1. Controller

The person responsible for the processing of personal data in connection with SystemMarks is:

Philipp Spiertz
Email: [email protected]

This Privacy Policy applies to the SystemMarks website and web application as well as the associated browser extensions for Firefox, Chrome/Chromium, and Safari.

2. About SystemMarks

SystemMarks is a privately operated, non-commercial hobby project.

SystemMarks is provided free of charge. There is no advertising and there are no paid plans.

SystemMarks is available exclusively to a limited group of personally invited users. Public registration is not available, and invitations cannot be requested publicly.

This Privacy Policy explains which personal data is processed when using SystemMarks, the purposes for which it is processed, and the rights available to data subjects.

3. General Information on Data Processing

Personal data is processed only where this is necessary to provide and operate SystemMarks, where corresponding features are used, or where another legal basis for processing applies.

Depending on the processing activity, we rely in particular on the following legal bases:

4. Hosting by OVH

SystemMarks is hosted on servers operated by:

OVH GmbH
Oskar-Jäger-Straße 173/K6
50825 Cologne
Germany

The servers used for SystemMarks are located in Frankfurt am Main, Germany.

As part of the hosting service, data required to operate SystemMarks is processed. This includes, in particular, user accounts, stored content, database data, and technical operational data.

Processing for the provision of SystemMarks is based on Art. 6(1)(b) GDPR. Where processing relates to security, stability, and troubleshooting, it is also based on Art. 6(1)(f) GDPR. The legitimate interest is the secure and reliable operation of the service.

OVH is also used to store backups. Further information can be found in the section “Backups”.

5. Cloudflare

Services provided by

Cloudflare, Inc.
101 Townsend St.
San Francisco, CA 94107
USA

are used for the secure and reliable provision of SystemMarks.

SystemMarks uses Cloudflare in particular for:

When SystemMarks is used, technical data may therefore be processed through Cloudflare systems. This may include IP addresses and connection information.

Cloudflare is used in particular to ensure the secure and reliable availability of SystemMarks. In this respect, processing is based on Art. 6(1)(f) GDPR. The legitimate interest is the secure, stable, and reliable operation of the application.

Cloudflare is a company based in the United States. Personal data may therefore be processed outside the European Union or European Economic Area.

According to Cloudflare, it is certified under the EU-U.S. Data Privacy Framework. Depending on the relevant processing activity, additional appropriate safeguards, in particular the European Commission's Standard Contractual Clauses, may also be used for international data transfers.

6. Registration and User Accounts

A user account is required to use SystemMarks.

Public registration is not available. New users can only be invited to SystemMarks by an application administrator.

In particular, the following data is processed when registering and using an account:

Stored user preferences include in particular:

These settings are used exclusively to provide the user interface according to the preferences selected by the user.

Processing is carried out for the creation, administration, and provision of the user account and the settings selected by the user on the basis of Art. 6(1)(b) GDPR.

The data is generally stored for as long as the user account exists or until individual settings are changed or no longer required.

Users can delete their user accounts themselves. Personal data associated exclusively with the user account is generally deleted when the account is deleted unless another legal basis or statutory obligation requires further retention.

When a user account is deleted, the user's personal workspaces and the content stored within them are also deleted. This also applies where a personal workspace was previously shared with other users.

Deleted data may remain in backups for up to seven days.

7. Authentication and Account Security

SystemMarks supports various methods for authentication and securing user accounts:

External login providers such as Google, Apple, or GitHub are not used for authentication.

Passwords are not stored in plain text. They are processed only in a derived form suitable for authentication.

When passkeys are used, the public credential information required for passkey authentication is stored. Private keys remain on the authenticator or device used by the user.

Processing serves to authenticate users, secure user accounts, and prevent unauthorized access.

The legal basis is Art. 6(1)(b) GDPR and, where applicable, Art. 6(1)(f) GDPR. The legitimate interest is the protection of user accounts and the systems used to provide SystemMarks.

8. Invitations

SystemMarks distinguishes between invitations to SystemMarks itself and invitations to teams or workspaces.

Invitations to SystemMarks

SystemMarks does not offer public registration. New users can only be invited by application administrators.

The email address of the invited person is processed for an invitation. It is used exclusively to send and manage the invitation.

Invitations to Teams or Workspaces

Registered users can create invitations to teams or workspaces.

The email address of the invited person is also processed for this purpose. It is used to send and manage the respective invitation.

Invitation data is deleted no later than seven days after the invitation, regardless of the type of invitation.

If an invitation to SystemMarks is accepted, the information provided during registration is subsequently processed as part of the user account.

9. Stored Content, Workspaces, and Collaboration

Users can use SystemMarks to manage bookmarks, systems, and related information.

The data stored may include:

Users generally determine which content they store.

SystemMarks distinguishes in particular between personal workspaces and team workspaces.

Personal workspaces may be shared with other users. However, they remain associated with the respective user account. If the user account is deleted, the personal workspaces and the content stored within them are also deleted. This also applies to personal workspaces that were previously shared with other users.

Team workspaces are available to the respective team members for collaborative use according to their permissions. If an individual user leaves a team, the team's workspaces are not deleted as long as other members remain in the team.

Team workspaces can be deleted. If the final member leaves a team, the workspaces belonging to that team are also deleted.

Processing is carried out to provide the corresponding SystemMarks functionality on the basis of Art. 6(1)(b) GDPR.

Following deletion, the relevant data may remain in backups for up to seven days.

10. Usage Statistics

SystemMarks collects a limited amount of its own usage statistics. No external analytics or tracking services are used for this purpose.

In particular, usage figures from the web application and browser extensions are collected, as well as aggregated figures derived from them regarding the number of active users.

This data is used to understand how SystemMarks is used and to further develop the application.

The data is not used for advertising. Usage statistics are not transferred to advertising networks or external analytics services.

Where personal data is processed in this context, processing is based on Art. 6(1)(f) GDPR. The legitimate interest is to understand the usage and acceptance of SystemMarks and to further develop the service.

11. Personalization of Search Results

SystemMarks may record how frequently a user opens certain stored links.

This information is associated with the respective user account and may be used to improve the user's individual search experience and provide more relevant search results.

Personal click data is used exclusively within SystemMarks to improve search results. It is not used for advertising and is not disclosed to external analytics or advertising services.

Processing is based on Art. 6(1)(f) GDPR. The legitimate interest is to improve the quality and usability of the search functionality based on actual usage.

Users are informed within the application of their ability to object to this processing. Search personalization can be disabled at any time in the SystemMarks settings.

After personalization is disabled, no new personal click data is collected for this purpose. Personal click data already stored for this purpose is deleted and is no longer used to personalize search results.

Irrespective of this, click data associated with a user is deleted no later than when the user account is deleted.

Deleted data may subsequently remain in backups for up to seven days.

Further information on the right to object under Art. 21 GDPR can be found in the section “Right to Object”.

12. Cookies

SystemMarks uses cookies in particular for login purposes and to maintain an authenticated session.

These cookies are used to provide the login and related SystemMarks functionality expressly requested by the user.

SystemMarks does not use cookies or similar technologies for personalized advertising, cross-service tracking, or external web analytics.

13. Browser Extensions

SystemMarks provides browser extensions for Firefox, Chrome/Chromium-based browsers, and Safari.

The Chrome and Firefox extensions are available through the Chrome Web Store and Firefox Add-ons.

The extensions allow users to search their bookmarks stored in SystemMarks and create new bookmarks.

When creating a new bookmark, the URL of the currently open website can be used.

The current URL is not automatically transmitted to SystemMarks. It is only transmitted when the user explicitly initiates or submits the creation of the bookmark.

The extension does not use local extension storage. It does not persist passwords, session cookies, workspace content, or selected workspace IDs in the browser. A SystemMarks address selected in development builds applies only to the currently open popup.

The information transmitted in this way is processed exclusively to provide the functionality initiated by the user.

Where data is associated with a user account, processing is based on Art. 6(1)(b) GDPR.

The other processing activities described in this Privacy Policy also apply to the browser extensions where applicable.

14. Email

SystemMarks sends only functional or transactional emails.

These may include:

SystemMarks does not send advertising or marketing emails.

Cloudflare services are used to send these emails. In particular, the recipient's email address and the respective message content are processed.

Processing is carried out to provide the relevant account and security functionality on the basis of Art. 6(1)(b) GDPR. Where security-related messages are concerned, processing may additionally be based on Art. 6(1)(f) GDPR.

The information regarding international data transfers described in the “Cloudflare” section applies accordingly.

15. Feedback and GitHub

SystemMarks provides a feature for submitting feedback.

When feedback is submitted, the title and description entered by the user are transferred to GitHub. An issue is automatically created from this information in a private GitHub repository.

SystemMarks does not add the user's email address, name, or SystemMarks user ID to the issue.

Users should nevertheless be aware that they may themselves enter personal or other confidential information in the title or description of their feedback.

The issues are technically created through a GitHub account provided by the operator of SystemMarks.

The provider is:

GitHub, Inc.
88 Colin P Kelly Jr St
San Francisco, CA 94107
USA

The transfer is carried out in order to receive submitted feedback and to process and track errors, suggestions for improvement, and resulting changes.

Processing is based on Art. 6(1)(f) GDPR. The legitimate interest is to process user feedback and to improve and troubleshoot SystemMarks.

Feedback content is retained for as long as necessary to process the feedback and to document and track resulting fixes or changes. Feedback content that is no longer required is deleted.

GitHub processes personal data in the United States and other countries. According to GitHub, it is certified under the EU-U.S. Data Privacy Framework. Appropriate safeguards, in particular the European Commission's Standard Contractual Clauses, may also be used for international data transfers.

16. Logging, Monitoring, and Troubleshooting

SystemMarks operates its own observability infrastructure for operation, monitoring, and troubleshooting.

The following systems are used in particular:

The observability infrastructure is self-hosted on the servers designated for this purpose. No external analytics providers are used for this data.

The application does not generally store all HTTP requests for analytics purposes.

As part of operating SystemMarks, application, diagnostic, and error data generated by SystemMarks as well as technical telemetry data may be processed. Traces may also contain technical information relating to the execution of individual requests or application operations.

This data is used to detect and resolve errors and to monitor the stability, performance, and security of SystemMarks.

The following retention periods apply to observability data:

The relevant data is subsequently deleted.

Where personal data is processed in this context, processing is based on Art. 6(1)(f) GDPR. The legitimate interest is the secure, stable, and reliable operation of SystemMarks and the detection and resolution of technical errors.

17. Backups

Regular backups of SystemMarks data are created to protect against data loss.

Backups are stored in S3-compatible object storage provided by OVH GmbH.

Backups are retained for seven days and are subsequently deleted or overwritten.

Backups are used exclusively to restore SystemMarks in the event of data loss, technical problems, or comparable incidents.

Processing is based on Art. 6(1)(f) GDPR. The legitimate interest is to ensure the availability and recoverability of SystemMarks.

Personal data that has been deleted from the production system may therefore remain in backups for up to seven days.

18. No External Analytics or Advertising Services

SystemMarks does not use external services for web analytics, personalized advertising, or cross-service tracking.

Personal usage data is not disclosed to third parties for advertising purposes.

The public landing page also does not integrate external analytics, tracking, or advertising services.

19. Recipients of Personal Data

Personal data may be processed by the following service providers in connection with the processing activities described in this Privacy Policy:

Within SystemMarks, content may also be made available to other registered users and members of a team or workspace in accordance with the intended collaborative functionality.

Personal data is not disclosed for advertising purposes.

20. International Data Transfers

Some service providers used by SystemMarks, in particular Cloudflare and GitHub, are based in the United States.

Personal data may therefore be processed outside the European Union or European Economic Area.

According to their respective statements, Cloudflare and GitHub are certified under the EU-U.S. Data Privacy Framework.

Depending on the relevant processing activity, additional appropriate safeguards, in particular the European Commission's Standard Contractual Clauses, may also be used for international data transfers.

21. Retention Periods

Unless a specific retention period is stated elsewhere in this Privacy Policy, personal data is generally retained only for as long as necessary for the relevant purpose.

The following periods or criteria currently apply in particular:

After data is deleted from the production system, it may remain in backups for up to seven days.

Statutory retention obligations remain unaffected.

22. Data Subject Rights

Where the relevant legal requirements are met, data subjects have in particular the right:

To exercise these rights, please contact:

[email protected]

23. Right to Object

Where personal data is processed on the basis of Art. 6(1)(f) GDPR, data subjects have the right, in accordance with Art. 21 GDPR, to object to such processing on grounds relating to their particular situation.

For the processing of personal click frequencies used to improve individual search results, SystemMarks additionally provides a direct option to disable this functionality in the settings.

Once disabled, no new personal click data is collected for this purpose. Personal click data already stored for this purpose is deleted and is no longer used to personalize search results.

24. Right to Lodge a Complaint with a Supervisory Authority

Under Art. 77 GDPR, data subjects have the right to lodge a complaint with a data protection supervisory authority regarding the processing of their personal data.

In North Rhine-Westphalia, complaints may in particular be addressed to the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, LDI NRW).

This does not restrict the right to contact another competent data protection supervisory authority.

25. Automated Decision-Making

SystemMarks does not carry out decisions based solely on automated processing within the meaning of Art. 22 GDPR that produce legal effects concerning users or similarly significantly affect them.

The use of personal click frequencies to improve individual search results does not have such legal or similarly significant effects.

26. Changes to this Privacy Policy

This Privacy Policy may be updated if the functionality of SystemMarks, the service providers used, or applicable legal requirements change.

The version currently published on the website or within SystemMarks applies.