Skip to the guide
All guides

Privacy, permissions and data

Bookmark Scope has no server, no account and no analytics. The one thing that touches the network is link checking, and only after you grant permission.

app Bookmark Scope 5.2.1checked reading 4 minutes

On this page

The short version

  • Everything Bookmark Scope knows is stored in your browser profile. Nothing is sent to the developer.
  • The extension's own code contains exactly one kind of outgoing request to arbitrary sites: the link-health check of the addresses in your bookmarks. It needs a permission you grant.
  • Your bookmarks stay in Chrome's bookmark store. Bookmark Scope reads and edits them through Chrome's bookmarks API, and keeps tags and other extras separately.

Permissions, and why each is there

These come from the extension's manifest. Chrome's install prompt may group or reword them.

PermissionWhat Bookmark Scope uses it for
bookmarksRead your bookmark tree; create, edit, move and delete bookmarks when you ask it to
tabsRead the address and title of the active tab (for scope matching and the star button) and open tabs
storageKeep settings, tags, saved views, history, caches and journals on this device
alarmsWake the background worker for the optional scheduled link check and review reminders
notificationsShow the three notifications listed in Review reminders and notifications
contextMenusAdd the three right-click entries
clipboardWriteCopy the addresses of selected bookmarks when you press Copy URLs or Copy
faviconAsk Chrome for the small site icons it already has, so rows can show them
Optional: http://*/* and https://*/*Contact bookmarked sites to check whether they still load. Not granted at install. Chrome asks when you first start a check or enable the scheduled scan.

The extension declares no content scripts, so it does not run inside the web pages you visit, and it does not read page content.

What is stored on your device

All of this lives in the extension's local storage for the current browser profile. It is not synced to your Google account and not shared between devices.

DataWhat it containsLimit / retention
PreferencesYour settings, dashboard filter, grouping, theme, languageSmall
TagsA map from bookmark ID to its tags32 characters per tag, 20 tags per bookmark. Removed when the bookmark is deleted
Link-health cachePer page address: status, time, status code, final address, error textIgnored after 7 days; at most 5,000 results
Manual scan jobThe list of addresses in your saved scan and its progressOne job; up to 50,000 addresses
Scheduled-scan stateOn/off, interval, last run, broken count, and the last address it attemptedSmall
Saved viewsSearch text, filters, grouping, tag filterUp to 50
Activity historyCounts, times and short notes about actions Bookmark Scope tookLatest 60 entries
Import and restore journalsThe bookmarks created by an import or restore and their outcomesLatest 20 completed, plus any incomplete ones. Contains your bookmark addresses and titles
Diagnostic eventsTechnical event names and timestamps. A few events can include a bookmark address in this local storeLatest 200 (info, warning, error)

The extension does not use browser sync storage. Clearing the link-health cache, resetting defaults and uninstalling are covered in Installation.

What can leave your browser

  1. Link-health requests (only with your permission). A check sends a HEAD request, or a GET if the site refuses HEAD, directly from your browser to the bookmarked address. The site sees an ordinary request from your computer. Bookmark Scope receives the response status and final address, and nothing else. No proxy, relay or developer server is involved. It happens only if you start a check or enable the scheduled scan.
  2. Links you choose to click. The footer and About screens contain links to the GitHub repository, a support page and a store review page. They open in a new tab only when you click.
  3. Chrome's own extension update checks. These are performed by Chrome, not by Bookmark Scope.

Everything else, including searching, tagging, scanning for duplicates, snapshots and translations, runs locally. The language files are packaged with the extension and read from it, not downloaded.

How this was checked

This statement comes from reading the extension's JavaScript for network calls: the only fetch to outside addresses is the health check, and the only other fetch reads packaged language files. It is not a network traffic capture or an independent security audit.

Sharing files safely

FileContains your bookmarks?
Snapshot (bookmark-scope-snapshot.json)Yes: titles, addresses, folders, tags
Restore or import recovery journalYes
Export visible (bookmark-manager-visible-….json or .csv)Yes
Diagnostic exportNo. See Diagnostics

Controlling access

  • Decline the site-access prompt and link checks simply do not run. Everything else works.
  • Revoke site access later from the extension's Details page in chrome://extensions .
  • Remove the extension to delete its stored data.