Політика приватності для SystemMarks
SystemMarks автор Philipp Spiertz
Last updated: September 2026
The person responsible for the processing of personal data in connection with SystemMarks is:
Philipp Spiertz
Email: contact@systemmarks.dev
This Privacy Policy applies to the SystemMarks website and web application as well as the associated browser extensions for Firefox, Chrome/Chromium, and Safari.
SystemMarks is a privately operated, non-commercial hobby project.
SystemMarks is provided free of charge. There is no advertising and there are no paid plans.
SystemMarks is available exclusively to a limited group of personally invited users. Public registration is not available, and invitations cannot be requested publicly.
This Privacy Policy explains which personal data is processed when using SystemMarks, the purposes for which it is processed, and the rights available to data subjects.
Personal data is processed only where this is necessary to provide and operate SystemMarks, where corresponding features are used, or where another legal basis for processing applies.
Depending on the processing activity, we rely in particular on the following legal bases:
- Art. 6(1)(b) GDPR where processing is necessary for the provision and use of SystemMarks,
- Art. 6(1)(f) GDPR where processing is necessary for legitimate interests and those interests are not overridden by the interests or rights of the data subject,
- Art. 6(1)(c) GDPR where processing is necessary to comply with a legal obligation.
SystemMarks is hosted on servers operated by:
OVH GmbH
Oskar-Jäger-Straße 173/K6
50825 Cologne
Germany
The servers used for SystemMarks are located in Frankfurt am Main, Germany.
As part of the hosting service, data required to operate SystemMarks is processed. This includes, in particular, user accounts, stored content, database data, and technical operational data.
Processing for the provision of SystemMarks is based on Art. 6(1)(b) GDPR. Where processing relates to security, stability, and troubleshooting, it is also based on Art. 6(1)(f) GDPR. The legitimate interest is the secure and reliable operation of the service.
OVH is also used to store backups. Further information can be found in the section “Backups”.
Services provided by
Cloudflare, Inc.
101 Townsend St.
San Francisco, CA 94107
USA
are used for the secure and reliable provision of SystemMarks.
SystemMarks uses Cloudflare in particular for:
- DNS resolution for the domains used by SystemMarks,
- Cloudflare Tunnel and the delivery of the application over the internet,
- sending transactional emails.
When SystemMarks is used, technical data may therefore be processed through Cloudflare systems. This may include IP addresses and connection information.
Cloudflare is used in particular to ensure the secure and reliable availability of SystemMarks. In this respect, processing is based on Art. 6(1)(f) GDPR. The legitimate interest is the secure, stable, and reliable operation of the application.
Cloudflare is a company based in the United States. Personal data may therefore be processed outside the European Union or European Economic Area.
According to Cloudflare, it is certified under the EU-U.S. Data Privacy Framework. Depending on the relevant processing activity, additional appropriate safeguards, in particular the European Commission's Standard Contractual Clauses, may also be used for international data transfers.
A user account is required to use SystemMarks.
Public registration is not available. New users can only be invited to SystemMarks by an application administrator.
In particular, the following data is processed when registering and using an account:
- a name chosen by the user,
- email address,
- technical account ID,
- data required for authentication,
- technical information required to manage the user account,
- user interface settings associated with the user account.
Stored user preferences include in particular:
- the selected language,
- the preference for usage-based improvements to search,
- the read and dismissal status of notifications about new features.
These settings are used exclusively to provide the user interface according to the preferences selected by the user.
Processing is carried out for the creation, administration, and provision of the user account and the settings selected by the user on the basis of Art. 6(1)(b) GDPR.
The data is generally stored for as long as the user account exists or until individual settings are changed or no longer required.
Users can delete their user accounts themselves. Personal data associated exclusively with the user account is generally deleted when the account is deleted unless another legal basis or statutory obligation requires further retention.
When a user account is deleted, the user's personal workspaces and the content stored within them are also deleted. This also applies where a personal workspace was previously shared with other users.
Deleted data may remain in backups for up to seven days.
SystemMarks supports various methods for authentication and securing user accounts:
- login using an email address and password,
- passkeys,
- two-factor authentication using an authenticator app (TOTP),
- recovery codes,
- password reset,
- confirmation and modification of the email address.
External login providers such as Google, Apple, or GitHub are not used for authentication.
Passwords are not stored in plain text. They are processed only in a derived form suitable for authentication.
When passkeys are used, the public credential information required for passkey authentication is stored. Private keys remain on the authenticator or device used by the user.
Processing serves to authenticate users, secure user accounts, and prevent unauthorized access.
The legal basis is Art. 6(1)(b) GDPR and, where applicable, Art. 6(1)(f) GDPR. The legitimate interest is the protection of user accounts and the systems used to provide SystemMarks.
SystemMarks distinguishes between invitations to SystemMarks itself and invitations to teams or workspaces.
SystemMarks does not offer public registration. New users can only be invited by application administrators.
The email address of the invited person is processed for an invitation. It is used exclusively to send and manage the invitation.
Registered users can create invitations to teams or workspaces.
The email address of the invited person is also processed for this purpose. It is used to send and manage the respective invitation.
Invitation data is deleted no later than seven days after the invitation, regardless of the type of invitation.
If an invitation to SystemMarks is accepted, the information provided during registration is subsequently processed as part of the user account.
Users can use SystemMarks to manage bookmarks, systems, and related information.
The data stored may include:
- URLs,
- titles,
- systems,
- environments and related information,
- assignments to workspaces or teams.
Users generally determine which content they store.
SystemMarks distinguishes in particular between personal workspaces and team workspaces.
Personal workspaces may be shared with other users. However, they remain associated with the respective user account. If the user account is deleted, the personal workspaces and the content stored within them are also deleted. This also applies to personal workspaces that were previously shared with other users.
Team workspaces are available to the respective team members for collaborative use according to their permissions. If an individual user leaves a team, the team's workspaces are not deleted as long as other members remain in the team.
Team workspaces can be deleted. If the final member leaves a team, the workspaces belonging to that team are also deleted.
Processing is carried out to provide the corresponding SystemMarks functionality on the basis of Art. 6(1)(b) GDPR.
Following deletion, the relevant data may remain in backups for up to seven days.
SystemMarks collects a limited amount of its own usage statistics. No external analytics or tracking services are used for this purpose.
In particular, usage figures from the web application and browser extensions are collected, as well as aggregated figures derived from them regarding the number of active users.
This data is used to understand how SystemMarks is used and to further develop the application.
The data is not used for advertising. Usage statistics are not transferred to advertising networks or external analytics services.
Where personal data is processed in this context, processing is based on Art. 6(1)(f) GDPR. The legitimate interest is to understand the usage and acceptance of SystemMarks and to further develop the service.
SystemMarks may record how frequently a user opens certain stored links.
This information is associated with the respective user account and may be used to improve the user's individual search experience and provide more relevant search results.
Personal click data is used exclusively within SystemMarks to improve search results. It is not used for advertising and is not disclosed to external analytics or advertising services.
Processing is based on Art. 6(1)(f) GDPR. The legitimate interest is to improve the quality and usability of the search functionality based on actual usage.
Users are informed within the application of their ability to object to this processing. Search personalization can be disabled at any time in the SystemMarks settings.
After personalization is disabled, no new personal click data is collected for this purpose. Personal click data already stored for this purpose is deleted and is no longer used to personalize search results.
Irrespective of this, click data associated with a user is deleted no later than when the user account is deleted.
Deleted data may subsequently remain in backups for up to seven days.
Further information on the right to object under Art. 21 GDPR can be found in the section “Right to Object”.
SystemMarks uses cookies in particular for login purposes and to maintain an authenticated session.
These cookies are used to provide the login and related SystemMarks functionality expressly requested by the user.
SystemMarks does not use cookies or similar technologies for personalized advertising, cross-service tracking, or external web analytics.
SystemMarks provides browser extensions for Firefox, Chrome/Chromium-based browsers, and Safari.
The extensions are currently not available through official browser extension stores.
The extensions allow users to search their bookmarks stored in SystemMarks and create new bookmarks.
When creating a new bookmark, the URL of the currently open website can be used.
The current URL is not automatically transmitted to SystemMarks. It is only transmitted when the user explicitly initiates or submits the creation of the bookmark.
The extension does not use local extension storage. It does not persist passwords, session cookies, workspace content, or selected workspace IDs in the browser. A SystemMarks address selected in development builds applies only to the currently open popup.
The information transmitted in this way is processed exclusively to provide the functionality initiated by the user.
Where data is associated with a user account, processing is based on Art. 6(1)(b) GDPR.
The other processing activities described in this Privacy Policy also apply to the browser extensions where applicable.
SystemMarks sends only functional or transactional emails.
These may include:
- invitations to SystemMarks,
- invitations to teams or workspaces,
- confirmation of an email address,
- changes to an email address,
- password resets,
- security and account-related notifications.
SystemMarks does not send advertising or marketing emails.
Cloudflare services are used to send these emails. In particular, the recipient's email address and the respective message content are processed.
Processing is carried out to provide the relevant account and security functionality on the basis of Art. 6(1)(b) GDPR. Where security-related messages are concerned, processing may additionally be based on Art. 6(1)(f) GDPR.
The information regarding international data transfers described in the “Cloudflare” section applies accordingly.
SystemMarks provides a feature for submitting feedback.
When feedback is submitted, the title and description entered by the user are transferred to GitHub. An issue is automatically created from this information in a private GitHub repository.
SystemMarks does not add the user's email address, name, or SystemMarks user ID to the issue.
Users should nevertheless be aware that they may themselves enter personal or other confidential information in the title or description of their feedback.
The issues are technically created through a GitHub account provided by the operator of SystemMarks.
The provider is:
GitHub, Inc.
88 Colin P Kelly Jr St
San Francisco, CA 94107
USA
The transfer is carried out in order to receive submitted feedback and to process and track errors, suggestions for improvement, and resulting changes.
Processing is based on Art. 6(1)(f) GDPR. The legitimate interest is to process user feedback and to improve and troubleshoot SystemMarks.
Feedback content is retained for as long as necessary to process the feedback and to document and track resulting fixes or changes. Feedback content that is no longer required is deleted.
GitHub processes personal data in the United States and other countries. According to GitHub, it is certified under the EU-U.S. Data Privacy Framework. Appropriate safeguards, in particular the European Commission's Standard Contractual Clauses, may also be used for international data transfers.
SystemMarks operates its own observability infrastructure for operation, monitoring, and troubleshooting.
The following systems are used in particular:
- Grafana for visualization and analysis,
- Loki for application logs,
- Tempo for traces,
- Prometheus for technical metrics.
The observability infrastructure is self-hosted on the servers designated for this purpose. No external analytics providers are used for this data.
The application does not generally store all HTTP requests for analytics purposes.
As part of operating SystemMarks, application, diagnostic, and error data generated by SystemMarks as well as technical telemetry data may be processed. Traces may also contain technical information relating to the execution of individual requests or application operations.
This data is used to detect and resolve errors and to monitor the stability, performance, and security of SystemMarks.
The following retention periods apply to observability data:
- Loki: 30 days,
- Tempo: 30 days,
- Prometheus: 30 days.
The relevant data is subsequently deleted.
Where personal data is processed in this context, processing is based on Art. 6(1)(f) GDPR. The legitimate interest is the secure, stable, and reliable operation of SystemMarks and the detection and resolution of technical errors.
Regular backups of SystemMarks data are created to protect against data loss.
Backups are stored in S3-compatible object storage provided by OVH GmbH.
Backups are retained for seven days and are subsequently deleted or overwritten.
Backups are used exclusively to restore SystemMarks in the event of data loss, technical problems, or comparable incidents.
Processing is based on Art. 6(1)(f) GDPR. The legitimate interest is to ensure the availability and recoverability of SystemMarks.
Personal data that has been deleted from the production system may therefore remain in backups for up to seven days.
SystemMarks does not use external services for web analytics, personalized advertising, or cross-service tracking.
Personal usage data is not disclosed to third parties for advertising purposes.
The public landing page also does not integrate external analytics, tracking, or advertising services.
Personal data may be processed by the following service providers in connection with the processing activities described in this Privacy Policy:
- OVH GmbH – hosting and S3-compatible object storage for backups,
- Cloudflare, Inc. – DNS, delivery of the application, and transactional email,
- GitHub, Inc. – feedback content entered by the user when the feedback feature is used.
Within SystemMarks, content may also be made available to other registered users and members of a team or workspace in accordance with the intended collaborative functionality.
Personal data is not disclosed for advertising purposes.
Some service providers used by SystemMarks, in particular Cloudflare and GitHub, are based in the United States.
Personal data may therefore be processed outside the European Union or European Economic Area.
According to their respective statements, Cloudflare and GitHub are certified under the EU-U.S. Data Privacy Framework.
Depending on the relevant processing activity, additional appropriate safeguards, in particular the European Commission's Standard Contractual Clauses, may also be used for international data transfers.
Unless a specific retention period is stated elsewhere in this Privacy Policy, personal data is generally retained only for as long as necessary for the relevant purpose.
The following periods or criteria currently apply in particular:
- user accounts and personal data exclusively associated with them: generally until deletion of the user account or until the relevant purpose ceases to apply,
- user preferences: generally until they are changed, no longer required, or the user account is deleted,
- personal workspaces and their content: until the workspace or associated user account is deleted,
- team workspaces and their content: until the respective workspace is deleted or the final member leaves the associated team,
- personal click data used for search personalization: until the feature is disabled or, at the latest, until the user account is deleted,
- invitation data: no more than seven days,
- feedback content on GitHub: for as long as required to process, document, or track the feedback or resulting changes,
- Loki data: 30 days,
- Tempo data: 30 days,
- Prometheus data: 30 days,
- backups: seven days.
After data is deleted from the production system, it may remain in backups for up to seven days.
Statutory retention obligations remain unaffected.
Where the relevant legal requirements are met, data subjects have in particular the right:
- under Art. 15 GDPR, to obtain information about personal data processed concerning them,
- under Art. 16 GDPR, to request the correction of inaccurate data,
- under Art. 17 GDPR, to request the deletion of personal data,
- under Art. 18 GDPR, to request restriction of processing,
- under Art. 20 GDPR, to receive certain data they have provided in a structured, commonly used, and machine-readable format,
- under Art. 21 GDPR, to object to processing based on Art. 6(1)(f) GDPR.
To exercise these rights, please contact:
contact@systemmarks.dev
Where personal data is processed on the basis of Art. 6(1)(f) GDPR, data subjects have the right, in accordance with Art. 21 GDPR, to object to such processing on grounds relating to their particular situation.
For the processing of personal click frequencies used to improve individual search results, SystemMarks additionally provides a direct option to disable this functionality in the settings.
Once disabled, no new personal click data is collected for this purpose. Personal click data already stored for this purpose is deleted and is no longer used to personalize search results.
Under Art. 77 GDPR, data subjects have the right to lodge a complaint with a data protection supervisory authority regarding the processing of their personal data.
In North Rhine-Westphalia, complaints may in particular be addressed to the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, LDI NRW).
This does not restrict the right to contact another competent data protection supervisory authority.
SystemMarks does not carry out decisions based solely on automated processing within the meaning of Art. 22 GDPR that produce legal effects concerning users or similarly significantly affect them.
The use of personal click frequencies to improve individual search results does not have such legal or similarly significant effects.
This Privacy Policy may be updated if the functionality of SystemMarks, the service providers used, or applicable legal requirements change.
The version currently published on the website or within SystemMarks applies.