Neatlink is an independent browser extension. This policy covers Neatlink across Chrome, Firefox, Safari, Edge, Brave, Arc, Opera, Vivaldi, and other Chromium-based browsers, the Neatlink macOS companion app, and the neatlink.app website.
Most bookmarks, settings, and favorite favicon images never leave your device unless you choose to sync.
Cloud-sync bookmarks are encrypted client-side with AES-GCM-256 before uploading.
The following data never leaves your device (stored in your browser's local extension storage):
We have no access to this data.
When you enable Cloud Sync, your bookmarks and folders are encrypted on your device using AES-GCM-256 before being uploaded directly to your own Google Drive account (appDataFolder). Favicon images are also encrypted and uploaded directly to your Drive. Backups are stored in a "Neatlink Backups" folder in your Drive as standard HTML bookmark files.
This data goes directly from your browser to Google's servers. It does not pass through our infrastructure. We cannot read, access, or decrypt it.
Our server (oauth.neatlink.app) handles two things:
Your Google OAuth refresh token passes through our server to exchange it for new access tokens. We act as a stateless proxy between your browser and Google's token endpoint and store nothing; this is required because browser extensions cannot securely store OAuth client secrets. Cloudflare keeps standard request logs for our domains for operational debugging.
When you choose to share a folder via a shareable link, the following is sent to our Cloudflare infrastructure:
We cannot decrypt the shared bookmark content. The plaintext metadata is stored to display collection previews and enforce expiration. Shared collections auto-delete after a fixed period (currently 30 days).
Neatlink's use of information received from Google APIs adheres to the Google API Services User Data Policy including the Limited Use requirements. We only use Google API access to:
We do not transfer, sell, or use this data for advertising, analytics, or any purpose other than providing Neatlink's core functionality.
| Permission | Why we need it |
|---|---|
| storage | Store your bookmarks, folders, and settings locally |
| bookmarks | Import bookmarks from your browser (Browser Sync feature) |
| tabs / activeTab | Detect the current page when you save a bookmark |
| alarms | Schedule periodic Cloud Sync operations |
| scripting | Extract favicon images from pages you bookmark |
| identity | Authenticate with Google for Cloud Sync |
| host permissions (all URLs) | Extract favicons from any website you bookmark; redirect-following for favicon resolution |
| contextMenus | Right-click menu to switch between popup and side panel display modes |
| nativeMessaging (Safari) | Communicate with the macOS companion app |
You can request access to, correction of, or deletion of any data associated with your use of Neatlink by contacting contact@neatlink.app.
Neatlink is not directed at children under 13. We do not knowingly collect data from children.
We may update this policy from time to time. Changes will be posted on this page with an updated effective date.