Privacy policy for BookmarkTrash - Recycle Bin
BookmarkTrash - Recycle Bin by sovkit
Privacy Policy
This extension does not collect, store, or share any personal or sensitive user data. One optional feature — Site icons, available on Firefox and turned off by default — sends the host name of a bookmark to a third-party icon service. It is described in full below, and your consent is requested before it can be turned on.
Permissions
bookmarks — Core functionality — listens for bookmark deletions to save them in a local recycle bin, reads the bookmark tree for restore operations, and creates bookmarks when restoring.
storage — Used to save user preferences (such as retention period, theme, and click behavior) and license status locally on the device.
alarms — Used to schedule daily cleanup of expired bookmarks, periodic license refresh, checks for product notices, and the optional sync in the background.
sidePanel (Chromium-based browsers only) — Used to open the extension's side panel, which is its only user interface. On Firefox the same interface is provided by sidebar_action, which needs no permission.
favicon (Chromium-based browsers only) — Used to display website icons next to deleted bookmarks in the side panel for easier identification. Icons are read from the browser's own local icon cache; no network request is made. Firefox has no equivalent permission or interface, so a letter tile is shown there unless you turn on Site icons.
Optional data collection (bookmarksInfo, Firefox only) — Requested only when you turn on Site icons, because host names taken from your bookmarks are then sent to a third-party service. Nothing is requested at install time.
Optional host permissions (https:///, http:///) — Requested only if you choose to sync through a storage endpoint of your own. Nothing is requested at install time: the permission is asked for the single origin you enter when you save a storage configuration.
Local data storage
Deleted bookmarks (titles, URLs, folder structure) are stored in a local IndexedDB database on the device and are never transmitted to any server. Expired records are automatically purged based on the user's configured retention period.
On Firefox the extension also keeps a copy of your bookmark tree in that same local database. This is unavoidable there: Firefox reports a deleted folder without any of its contents, so the contents have to be known beforehand or they cannot be recovered at all. The copy stays on the device, is never transmitted, and is not part of the optional sync.
Site icons (Firefox only, optional)
Firefox provides no way for an extension to read the browser's own icon cache, so the only way to show real site icons there is to request them from an outside service. This is offered as a setting that is off by default. Turning it on asks for your consent first, and you can turn it off at any time.
While it is on, the extension requests icons from DuckDuckGo (icons.duckduckgo.com). Only the host name of a bookmark is sent — for example example.com, never the full address, the page title, or when the bookmark was deleted. Requests are sent without a referrer, and host names with no icon available are remembered locally for a day so the same request is not repeated. Bookmarks whose icon cannot be retrieved keep their letter tile. Turning the setting off stops all such requests immediately.
Bring your own storage
Cross-device sync is optional and off by default. When you turn it on, you supply your own storage endpoint, and your settings — retention period, click behavior, folder restore mode, recovery folder name, theme and language — are exchanged directly between your devices and that endpoint. Deleted bookmarks are not synced: they stay on the device that captured them. We operate no sync server, never receive that data, and never see the endpoint's credentials — they are stored only on your device.
Network communication
Apart from a storage endpoint you configure yourself and the optional Site icons feature described above, the extension only communicates with our first-party servers. api.sovkit.com handles optional Pro license management, which occurs when the user explicitly initiates a purchase or activates a license key; the only data sent is the license key, a device identifier, and an email address during checkout. data.sovkit.com hosts a static announcement file that the extension downloads periodically to show product notices; this request sends no data about you and returns the same file for everyone. Apart from the host names sent by the optional Site icons feature described above, no bookmark data, browsing history, or other personal information is ever transmitted.