bookmarx

Privacy

Updated 29 September 2026

bookmarx keeps the posts you have bookmarked so you can search them. That is the only reason it collects anything. It shows no ads, sells nothing, and shares your library with no one. This page covers the website at bookmarx.space and the bookmarx browser extension.

What bookmarx stores

  • Your library: the posts you bookmarked on X, Bluesky or Mastodon — their text, author, links, image and video addresses, and the thread around them — along with what bookmarx adds to make them searchable: descriptions of images and videos, previews of linked pages, and the search index itself.
  • Your searches: what you searched for, how many results came back, and which result you opened, so recent searches are there when you return and results you keep choosing rank higher.
  • Your connections: the name, handle and picture of each account you connect, and the credentials that let bookmarx read your bookmarks — X sign-in tokens, a Bluesky app password, a Mastodon token. These are encrypted before they are stored.
  • The extension's key: when you connect the browser extension, bookmarx creates a key for it and stores only a fingerprint of it, so the key itself cannot be read back out of the database.

The browser extension

The extension brings your X bookmarks into bookmarx from your own browser, without bookmarx connecting to X for you. It only works on x.com, and only for the account you are signed in to there. Installing it opens your bookmarks on x.com and sets up your library from that account, with no separate sign-in: the X account signed in to your browser is the one the library belongs to.

  • What it reads: your Bookmarks page on x.com, and only in tabs it opens itself: when it sets up, when you start an import, and for a few seconds in a background tab when you open bookmarx, to bring in what you have saved since. In those tabs it asks x.com for the rest of your bookmarks the way x.com's own page does, reusing the headers that page sent — which include your X session — inside that tab. Those headers never leave your browser and are not stored. It also reads your X user id from x.com's twidcookie, to know which account you're signed in to. Everywhere else on x.com it does nothing. It never reads your X password, and it runs on no site other than x.com and bookmarx.
  • What it sends to bookmarx: the pages of your bookmarks it reads, and your X handle, user id and profile picture address. bookmarx uses them to set up your library, and checks them on every import so one account's bookmarks never land in another account's library. Nothing else you look at on x.com leaves your browser.
  • What it keeps in your browser: its key, and how the last import or sync went, for its menu.
  • Searching from the address bar (typing bx) sends what you type to bookmarx to find matching bookmarks. These in-progress searches are not saved to your search history.

Disconnecting the extension — from its menu, or at /extension/connect — revokes its key and clears what it stored in your browser.

Who else handles your data

  • Google's Gemini API turns posts and searches into the numbers search runs on, describes images and videos, notices dates and to-dos in posts, and names the topics your library falls into. Post text, images, videos and your search queries are sent to it for this, under Google's API terms.
  • Vercel hosts the site and counts page views and page speed through Vercel Web Analytics and Speed Insights. Your searches are removed from the addresses those tools see.
  • Neon hosts the database.
  • Resend delivers a note to bookmarx's admin when someone joins the waitlist, with their email address and X handle, and when an author removes their posts, with their X handle and account id.
  • Linked websites: to preview a link in a post, bookmarx's server requests that page. The site sees a request from bookmarx, not from you.

Cookies

One cookie keeps you signed in. A few more exist for minutes while you connect an account, to complete the sign-in safely, and one holds, for fifteen minutes, which X account you proved is yours at /remove. There are no advertising or tracking cookies.

Your controls

  • Export your whole library as Markdown, JSON or CSV from the account menu.
  • Remove a bookmark with “Remove from library” on its card.
  • Disconnect an account to stop importing from it. What was already imported stays searchable until you delete it.
  • Delete my data, in the account menu, removes your account and everything above from the database at once. Copies may remain in the database provider's backups for a short time before they expire.

If you wrote a post someone saved

bookmarx keeps copies of the posts people bookmark, including yours if someone bookmarked one. To take every copy of your posts out of every library at once, and stop bookmarx saving them again, go to /remove and sign in with X to show they're yours. That sign-in only reads your name and handle: it creates no account and keeps no access to your X account. bookmarx stores your X account id and handle, so it knows to skip your posts from then on.

The waitlist

Joining the waitlist stores your email address, the networks you said you save on, and, if you add it, your X handle, which is how you are let in when your turn comes. They are used for that and nothing else: no newsletter, and never shared. To be taken off the list, ask as below, giving the X handle or the day you joined rather than posting your address in public, and the row is deleted.

The demo

The demo is one shared, read-only library. Searches run in it are not saved, and it holds nothing about the people who visit it.

Questions

bookmarx is a personal project, built in the open. Ask about anything on this page, or ask for your data to be removed, by opening an issue on GitHub.

bookmarx is not affiliated with X Corp., Bluesky, or Mastodon.