YOUR DATA, EXPLAINED

Privacy Policy

This policy explains what MarkFlow processes, why it is needed, and the controls available to you.

Effective 28 August 2026
Short version: MarkFlow uses your data to provide bookmark capture, organization and collaboration. We do not sell personal data or use it for targeted advertising.

1. Who this policy covers

This policy applies to the MarkFlow website, web application, API and browser extension. “MarkFlow”, “we” and “our” refer to the operator of the MarkFlow service. Questions can be sent to postmaster.mail@markflow.link.

2. Data we process

3. How we use data

We process data to create and secure accounts, save and synchronize bookmarks, provide search and organization features, operate collaboration and permissions, deliver service email, diagnose failures, prevent duplicate writes and misuse, provide export/deletion controls, and comply with applicable obligations.

4. Browser extension access

MarkFlow browser extensions read the URL and title of pages you choose to save. While you are signed in, the Open Tabs feature also periodically synchronizes the URL, title, tab and window identifiers, order and active state of open HTTP/HTTPS tabs so that you can view them inside MarkFlow. The extension does not read the body content of those pages. Captures are written to local extension storage before syncing. The extension stores a per-device token, not your password. MarkFlow does not sell browsing activity or use it for advertising.

5. Cookies and local storage

The web application uses an essential, HTTP-only session cookie. The extension uses browser storage for its device token, selected Collection, preferences and offline queue. These technologies are required to provide the service; MarkFlow does not currently use advertising cookies.

6. When data is shared

We share data only as needed to operate MarkFlow, respond to lawful requests, protect users and the service, or complete a business transition with appropriate safeguards. Infrastructure may include hosting, network/security and transactional-email providers. Workspace content is also visible to other members according to the permissions you or Workspace administrators select.

7. Retention

Account data and saved content are retained while your account is active. Security, synchronization and operational records are kept only as long as reasonably needed for reliability, fraud prevention, support and legal obligations. Deleted information may remain temporarily in restricted disaster-recovery backups until those backups rotate; backups are not used to restore a deleted account except where required for service-wide disaster recovery.

8. Your choices and rights

You can update your display name and email, manage signed-in devices, enable or disable 2FA, download a full account export, leave eligible organization Workspaces and delete your account from Account Settings. Depending on applicable law, you may also request access, correction, restriction or objection by contacting us.

9. Account deletion

Account deletion removes your account and Personal Workspace from the live service. If you own an organization Workspace, you must transfer ownership or delete it first. Content needed by a Workspace you do not own may be retained and transferred to its owner; activity records may retain an anonymized event. See the Account Deletion Guide.

10. Security

We use HTTPS, hashed passwords and tokens, encrypted TOTP secrets, access controls, isolated Personal Workspaces, backups and device revocation. No service can guarantee absolute security. Protect your recovery codes and report suspected unauthorized access promptly.

11. International use and children

MarkFlow infrastructure and providers may process data in countries other than yours. We use service providers for necessary operations and seek appropriate safeguards. MarkFlow is not directed to children under 13, and we do not knowingly collect their personal data.

12. Changes

We may update this policy as MarkFlow changes. Material updates will be posted here with a revised effective date.