Security Policy
Last updated:
Source: docs/Security Policy.md · Security contact: business@savemake.app
1. Security at SaveMake
We take the security of account and bookmark data seriously: protecting user accounts and stored bookmarks, restricting unauthorized access, maintaining secure infrastructure (currently hosted on Hostinger), monitoring for issues, responding to incidents, and continuously improving. Access our Services only via the official site https://savemake.app/ with an updated browser and OS.
2. Account Security
SaveMake supports Google Login and Email Login. We never receive or store your Google password, and we will never ask for it — treat any such request as suspicious. Protect the email or Google account behind your SaveMake account: use a secure account, avoid sharing access, sign out on shared devices, and contact business@savemake.app if you suspect compromise.
3. Bookmark Data, Hosting & Transmission
Bookmarks are tied to your account and are not made public. We apply reasonable technical and organizational measures against unauthorized access, misuse, loss, or disclosure, and use secure communication between your browser and our Services where appropriate. Infrastructure processing may occur via Hostinger under its own terms. Access is limited to authorized individuals/systems for maintenance, troubleshooting, support, security, or legal needs.
4. Monitoring & Third-Party Services
We may use logs, monitoring, and analytics (Google Analytics, Google Search Console, Microsoft Clarity — for usage/performance, not for access to private bookmark collections) to detect suspicious activity, diagnose problems, maintain reliability, prevent abuse, and improve security. Core providers include Hostinger, Google, and Microsoft, each responsible for their own infrastructure security.
5. Retention
We retain account and bookmark information while reasonably necessary to provide SaveMake, plus longer where needed for security, legal compliance, fraud prevention, disputes, operations, or policy enforcement — deleting or anonymizing when no longer required.
6. Security Incidents
If we learn of an incident affecting user information, we assess and respond proportionately: investigate, contain/mitigate, fix the cause, restore services, preserve evidence, and notify affected users or authorities where the law requires.
7. Vulnerability Reporting & Research
Report vulnerabilities to business@savemake.app (subject: "Security Vulnerability Report — SaveMake") with a description, affected feature/URL, reproduction steps, screenshots/technical detail, and impact — without passwords, credentials, or private bookmarks. Avoid accessing or modifying others’ data, disrupting availability, denial-of-service or destructive testing, over-collection, or premature public disclosure. Give us reasonable time to investigate; we appreciate responsible research.
8. Your Responsibilities
Security is shared. Protect your account and email/Google account, use a secure updated device and browser, avoid phishing and suspicious links, never share authentication info, and never store passwords, API keys, tokens, private credentials, card/banking data, or government IDs in bookmark URLs, titles, or descriptions — SaveMake is a bookmark manager, not a password vault. Check destination addresses before entering credentials; we do not control third-party site security.
9. No Absolute Guarantee & Changes
No online service can guarantee absolute security — threats evolve and no transmission or storage method is perfectly secure. We cannot promise incidents, unauthorized access, loss, or insecurity will never occur, but we keep improving. We may update this policy as practices, infrastructure, features, providers, or law evolve, with notice where appropriate.