BookarBookar/Terms & Conditions
DocsDashboard →

Terms & Conditions

Last updated: July 27, 2025

These terms explain how Bookar works, what data we collect, and what you agree to by using the service. We've written this specifically for what Bookar actually does — not a generic template.

1. What Bookar does

Bookar is a personal bookmark synchronization and AI enrichment service. When you install the Bookar browser extension and link it to your account, the extension sends your browser bookmarks to Bookar's backend. Bookar stores these bookmarks in a database scoped to your account and optionally generates AI-written descriptions of each page using a third-party language model API.

Bookar also runs an MCP (Model Context Protocol) server that allows you to connect AI tools like Claude and ChatGPT to your bookmark collection using API keys you control.

2. What data we collect

By using Bookar, we collect and store:

  • Your Google account email address and display name, obtained via Google Sign-In (OAuth 2.0). We do not store your Google password.
  • Bookmark data you sync through the extension: page URL, page title, folder path, and the timestamp when the bookmark was added.
  • Browser metadata: the name and type of the browser used for each sync session (e.g. 'Chrome', 'Brave'), and a device name you choose when linking.
  • API keys: if you generate a Bookar API key from the Connections page, a cryptographic hash of that key is stored. The raw key is shown to you once and not retained.
  • AI-generated descriptions: when a bookmark is added, we send the page URL and title to NVIDIA's NIM API and store the returned description in your account.

We do not collect your browser history, your browsing activity beyond explicitly bookmarked pages, the contents of web pages, or any payment information (Bookar is free).

3. How AI descriptions are processed

When a bookmark is created, Bookar sends the page URL and title to the NVIDIA NIM API (specifically the meta/llama-3.1-8b-instructmodel). NVIDIA's data handling and privacy practices apply to this request and are governed by NVIDIA's terms of service.

We do not send any content from your bookmarked pages beyond the URL and title. The AI-generated description is stored on your account and is only visible to you (and any AI tools you connect with your own API key).

4. Third-party AI access via API keys

From the Connections & AI page, you can generate a Bookar API key (bk_live_...). This key grants access to your bookmarks via Bookar's MCP server.

You are responsible for your API key. If you add this key to Claude Desktop, ChatGPT, Cursor, or any other MCP-compatible tool, that tool will have the ability to read and search your bookmarks. Bookar does not control what AI tools do with the bookmark data they retrieve.

You can revoke access at any time by deleting the API key from the Connections page. Deleting a key immediately invalidates it.

5. Data storage & security

Your data is stored in a Supabase PostgreSQL database. Row-level security (RLS) policies on the database ensure that API requests can only access data belonging to the authenticated user or matching the API key's associated account.

All data in transit is encrypted via TLS. We do not encrypt bookmark data at rest beyond the protections provided by Supabase's infrastructure.

We do not sell, share, or transfer your bookmark data to any third party beyond the AI description service described above.

6. Your rights

You have the right to:

  • Delete all your data at any time using the Factory Reset option in Settings. This permanently removes all your bookmarks and device connections from our database.
  • Disconnect any browser device from the Connections page, which stops future sync from that device.
  • Revoke AI access by deleting API keys from the Connections page.
  • Export your data — your bookmarks can be searched and copied from the dashboard at any time. Bulk export is on the roadmap.
  • Request account deletion by contacting us at the email below.

7. Data retention

Your data is retained as long as your account exists. If you perform a Factory Reset, your bookmark and device data is permanently deleted immediately. Your Google account authentication record may persist in Supabase Auth for a brief period after deletion; you can contact us to request complete removal.

We do not retain backups of your personal bookmark data beyond what Supabase's standard backup infrastructure maintains.

8. Service availability & liability

Bookar is provided as-is, without warranty of any kind. We make no guarantee of uptime, data durability, or AI description quality. Bookmark data could be lost in the event of a catastrophic infrastructure failure; we recommend not relying on Bookar as your sole bookmark backup.

We are not liable for any loss of data, loss of access, or any consequential damages arising from your use of Bookar.

We reserve the right to modify, suspend, or discontinue the service at any time with reasonable notice. If we discontinue the service, we will provide at least 30 days notice so you can export your data.

9. Changes to these terms

If we make material changes to these terms, we will update the "Last updated" date at the top of this page and may send a notification to your account email. Continued use of Bookar after changes are posted constitutes acceptance.

10. Contact

Questions about these terms or requests for data deletion can be sent to: hello@bookar.app

For technical issues or bug reports, see our troubleshooting guide.