A GDPR Bookmark Manager Run From Europe

Bookmarks are a quiet kind of personal data. Taken one by one they are harmless links, but the whole collection says what you read, where you bank, which doctor you looked up and which job ads you kept. Add the contacts and the notes that live in the same account and the picture gets sharper. That is the reason this page exists: to say plainly who runs this service, where the data sits and who else gets to see any part of it.

Who is responsible

Bookmax is operated by Webservice Mayer in Vöcklabruck, Austria. That is the controller in the sense of the General Data Protection Regulation, with a postal address you can write to and a person behind it, not a mailbox in a jurisdiction chosen for its silence. The full details are on the contact page, the legal text on the privacy policy.

Where the data is stored

The data needed to run the service is hosted and processed on servers in Berlin, Germany. The hosting provider is W3W, and where they process personal data on our behalf they do so under a data processing agreement as required by Article 28 GDPR. Backups run through the same infrastructure. Nothing is copied to a second continent for convenience.

What is not running on this site

There is no Google Analytics, no AdSense, no Facebook pixel, no Twitter or X widget and no other third party analytics or advertising script, neither on this website nor inside the application. The remaining analytics code was removed in August 2026, and the advertising that used to pay part of the bill is gone as well. Fonts and other resources are served from our own servers, so opening a page does not quietly announce your visit to a font provider.

Cookies are limited to what the service technically needs: keeping you signed in, managing the session, keeping the account secure. IP addresses are not kept in the account database, and where they appear in technical server logs they are anonymized on the server.

The three companies that see anything

W3W provides the hosting. Brevo sends the emails the service has to send: confirmations, security notices, subscription information and the warnings before an inactive account is deleted. Stripe handles payment for a Premium subscription; complete card numbers are processed by Stripe and are never stored here. That is the entire list. Nobody is paid for access to your collection, because nobody is buying it.

Getting your data out again

A service you cannot leave is not really yours. Every account, free or Premium, can export its bookmarks as a standard bookmarks file that any browser reads back, described on the page about import and export. Premium accounts can additionally export contacts as vCard, lists as CSV or Excel, notes as CSV, documents as text files and feed subscriptions as OPML, each in the format the receiving application expects. The modules are described on the page about everything in one account.

Deletion, and what happens to accounts nobody uses

You can delete your account, and deletion means deletion: bookmarks, folders, lists, contacts, notes, documents, feeds, tags and uploaded files go with it and cannot be restored afterwards.

Accounts that are never used are removed as well, because storing a stranger's collection forever is not caring for it. The procedure starts after eleven months without a login and involves three warning emails to the address in the account, the first of which names the exact deletion date. There is always at least a month between the first warning and that date, and a single login stops the whole procedure. On the deletion date the account is locked rather than erased, and for one further month a message to us brings it back. Accounts that ever paid for Premium are not deleted for inactivity at all.

Your rights

Under the GDPR you can ask what data we hold about you, have it corrected, have it deleted, have its processing restricted, receive it in a machine-readable form and object to processing based on our legitimate interests. Write to mail@bookmax.net and say what you want. If you think we are handling your data unlawfully you can complain to a supervisory authority; ours is the Österreichische Datenschutzbehörde in Vienna.

What this page does not claim

This is a small operation, not a company with a compliance department. There is no ISO 27001 certificate on the wall and no auditor's stamp, and the service is provided as-is, as the terms say. What there is: European jurisdiction, German servers, a named controller, no trackers, no advertising, an export for everything and a deletion that actually deletes. Some of that is a legal obligation and some of it is simply how a service run by one developer since 2003 has always worked. You can look at the whole thing without giving an address, by signing in as demo with the password demo on the login page, or register with nothing but an email address. The functions are listed under features.