Privacy Policy
Last updated:
1. Introduction
savemake.app (“we”, “us”, or “our”) operates the website located at https://savemake.app and the savemake.app bookmark-management application (collectively, the “Service”). This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. By accessing or using the Service, you agree to this policy.
If you do not agree with this policy, please do not use the Service. If you have any questions, reach us via our contact page.
2. Information We Collect
We collect information in the following categories:
- (a) Account information — your email address, an optional display name, and a password that is stored only as a one-way bcrypt hash. We never store your password in plain text.
- (b) Content you save — bookmarks (URLs, titles, favicons, notes), boards, columns, ordering data, and flags such as favorite, speed-dial, and shared. This content is stored so it is available on any device where you sign in.
- (c) Saved login credentials (optional) — if you choose to save login details for auto-fill, we store the email/username and password you provide, encrypted at rest (AES-256). Auto-fill runs entirely in your browser via a client-side script; your credentials are never transmitted to our servers during auto-fill.
- (d) Automatically collected information — log data such as IP address, browser type, pages visited, and timestamps, plus aggregate analytics via Google Tag Manager / Google Analytics. Analytics data is anonymized and contains no account identifiers.
- (e) Communications — messages you send us (for example via the contact form), which we keep in order to respond and improve the Service.
3. How We Use Your Information
- To provide, operate, and maintain the Service, including syncing your bookmarks across devices.
- To create and secure your account, authenticate sign-ins, and prevent fraud or abuse.
- To communicate with you about security notices, service updates, and support responses.
- To understand aggregate usage and improve features, performance, and usability.
- To comply with legal obligations and enforce our Terms of Service.
4. Legal Bases for Processing (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on the following bases: performance of our contract with you (operating your account and the Service); our legitimate interests (securing the Service, aggregate analytics, support); compliance with legal obligations; and your consent where specifically requested (for example, optional analytics cookies). You may withdraw consent at any time without affecting prior lawful processing.
7. Data Security
We use administrative, technical, and physical safeguards designed to protect your information, including:
- Encryption in transit — HTTPS/TLS 1.2+ for all traffic.
- Encryption at rest — AES-256 for database backups and stored credentials.
- Password hashing — bcrypt (cost factor 12); plain-text passwords are never stored.
- Session hygiene — HTTP-only, Secure, SameSite=Lax cookies with limited lifetimes.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately via our contact page.
8. Data Retention
- We retain your information for as long as your account is active, plus a reasonable period afterwards as needed to comply with legal obligations, resolve disputes, and enforce agreements.
- You may delete your account at any time from your account settings. Deletion permanently removes your bookmarks, boards, credentials, and profile from our production systems within 30 days; backups expire on a rolling 90-day cycle.
- Accounts inactive for more than 2 years may be scheduled for deletion after email notice to the registered address.
9. Your Privacy Rights
Depending on where you live (including rights under the GDPR, UK GDPR, and the CCPA/CPRA), you may have the right to:
- Access / know — request a copy of the personal information we hold about you.
- Correct — ask us to fix inaccurate or incomplete information.
- Delete — request deletion of your personal information, subject to legal exceptions.
- Portability — receive your data in a structured, machine-readable format (you can also export bookmarks at any time).
- Restrict / object — limit or object to certain processing, and opt out of any sale or sharing of personal information (we do not sell personal information).
- Non-discrimination — you will not be penalized for exercising these rights.
To exercise any of these rights, send us a message via our contact page. We verify requests and respond within 30 days (or as required by applicable law). EEA/UK users may also lodge a complaint with their local supervisory authority.
10. Children’s Privacy
The Service is not directed to children under the age of 13 (or 16 where a higher age of digital consent applies), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
11. Third-Party Links
The Service contains links to third-party websites that you save and open at your own discretion. We are not responsible for the privacy practices of those sites. We encourage you to review the privacy policy of every site you visit.
12. International Data Transfers
Your information may be processed in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers, such as the EU Standard Contractual Clauses, and process data in accordance with this policy regardless of location.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date above will be revised, and for material changes we will notify you by email or a prominent in-app notice at least 30 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.