Summary
Second Bookmark Bar is a Chrome extension that renders a compact second bookmark row above normal web pages. It reads bookmark data and extension settings so it can show the bar, search bookmarks, save pages into chosen folders, switch between selected folders, show usage-based ranking and favicons, and keep the UI in sync with bookmark changes.
If you choose the optional cloud account layer, the extension also uses Supabase Auth for sign-in and Stripe-backed billing endpoints for subscription checkout and billing management. It does not sell bookmark content, settings, browsing data, or analytics to the developer.
Data we access
- Bookmark folders, bookmark items, bookmark titles, bookmark URLs, and folder structure
- Extension settings stored in
chrome.storage.sync - Local extension state stored in
chrome.storage.local, including refresh state, usage counters, save-target counters, ranking data, sort-recovery snapshots, restore points, and bookmark action history - The URL of the current tab when features such as save current page, adaptive domain rules, or excluded sites need it
- Page URLs passed to Chrome’s favicon API when favicons are enabled
- Optional cloud account data when you sign in, including email address, auth identifiers, auth session tokens, subscription and entitlement status, billing session requests, and first-party cloud security event data used to protect paid cloud features
- When you turn on cloud sync or a shared space, the bookmark folders you choose to sync or share — including their structure, titles, and URLs — so they can be copied to your other signed-in devices or to the people you invite
- Optional, one-time onboarding survey: if you choose to answer it, a bucketed age range, a bucketed occupation (with an optional free-text field if you pick "Other", capped at 120 characters), and an email address — only when you separately tick an unchecked-by-default opt-in checkbox
Optional onboarding survey
At the end of the first-run setup tour, the extension shows a single optional screen asking roughly who uses it: a bucketed age range, a bucketed occupation, and a separate checkbox — unchecked by default — to opt in to occasional email updates. Every field is optional, "Prefer not to say" is offered for both age and occupation, and a one-click Skip button is always shown, equally prominent as the submit button. This screen appears once per install; once you answer it or skip it, it never appears again.
If you answer anything, it is sent anonymously to our Supabase-hosted database and used only for product research — to understand, in rough terms, who uses the extension. It is correlated only with the same anonymous per-install identifier already used for the optional feedback form (no new tracking identifier is created for this). Your email address is collected and stored only if you explicitly tick the opt-in checkbox; if you leave it unchecked, no email is sent anywhere. Skipping this screen has no effect on how the extension works.
How we use it
- Show the selected bookmark folder as a second row
- Switch between configured bookmark folders, including 1 / 2 / 3 slots and adaptive domain rules
- Render bookmark folders, nested menus, bookmark labels, and optional favicons
- Enable bookmark search and optional rank badges
- Enable recent and most-used bookmark sections based on local history
- Support save-to-folder flows for the current page, including undo where available
- Let you rename, sort, delete, or update bookmarks and folders from the extension UI
- Keep local sort snapshots, restore points, and recovery data so accidental cleanup can be reversed
- Show account status, upgrade state, and billing controls in the Account & Cloud settings surface
- Protect optional paid cloud features with device-bound cloud session tokens, server-side revoke, rate limiting, and suspicious-device logging
- Occasionally show a one-time, dismissible in-product prompt asking whether you’re enjoying the extension, with a link to leave a Chrome Web Store review or to send feedback; this relies only on a local counter on your device and does not send any data on its own
How we store it
chrome.storage.syncfor preferences such as selected folders, slots, adaptive rules, excluded sites, theme, language, toolbar toggles, and quick-hide shortcutchrome.storage.localfor usage counters, ranking data, restore points, action history, and optional signed-in cloud auth statechrome.storage.sessionfor short-lived state that Chrome keeps in memory and clears when the browser closes: a temporary list of the address and title of each open web-page tab (up to 400, each removed when its tab closes), used only so the Save all tabs panel can count tabs that have not finished loading. It is never synced, never written to disk, and never sent to us- When cloud sync or a shared space is enabled, the bookmark folders you choose to sync or share are stored in our dedicated first-party Supabase backend so they can reach your other signed-in devices and any members you invite; this happens only for the folders you opt to sync or share, and never for bookmarks you keep local
- First-party cloud security logs and rate-limit counters in the dedicated Supabase backend for optional paid cloud abuse prevention
Sharing
- We do not sell user data to advertisers, data brokers, or analytics providers
- For optional paid cloud features, limited account and billing data is processed by Supabase and Stripe only to provide sign-in, checkout, billing management, entitlement checks, and first-party security protection
- If you publish or join a shared space, the bookmark folders in that space are visible to the other members you invite or who are invited to it — sharing happens only for the spaces you choose to create or accept
- The extension does not use external analytics, advertising SDKs, or tracking pixels, and runs no remote code. One narrow exception: if it detects tampering with its own license data or install integrity, it sends a single anonymous alert (event type and severity only, no bookmark or browsing data) to our backend to detect abuse of the paid tier — this happens even if you're signed out, but does not run during normal use
- When you drag a video from a non-YouTube site into a video folder, the extension fetches a short list of thumbnail-image URLs already on that page (image bytes only, no credentials sent) to confirm which one loads. Those requests go to the site that hosted the page, not to us, and carry no bookmark or account data. YouTube thumbnails are built from the video ID alone and never need this step
- When you explicitly run a Link check from Settings, the extension sends a request to the host of each bookmarked page to see whether it still answers. Those requests carry only the bare origin (scheme and host) of each bookmark — no page content, no query strings, and no browsing history — and go to the sites you've bookmarked, not to us. Link check only runs when you start it from Settings; it never runs automatically or in the background
What we do not collect
The extension does not intentionally collect health information, personal communications, location data, or website content for the developer.
Your controls
- Turn the row on or off and use the quick-hide shortcut
- Choose which bookmark folders appear and which domains are excluded
- Enable or disable search, recent, most used, quick save, favicons, and scroll arrows
- Set theme and language
- Sign in or out of the optional cloud account layer
- Start or stop a paid subscription checkout flow
- Edit, sort, undo a sort, or remove bookmark folders and bookmark items through Chrome or the extension UI
- Create restore points and roll back from them
- Export or import settings and team/shared spaces
- Uninstall the extension at any time
Permissions
- activeTab - To read the URL of the tab you're actively interacting with for save-current-page, adaptive rules, and excluded sites - granted per-interaction by Chrome, not standing background access
- bookmarks - To read and update bookmark folders and items for the bar, search, quick save, and recovery flows
- storage - To persist user preferences and local state on the user’s device
- favicon - To show site favicons on the bar and in search when the user enables favicons
- identity - To open a secure browser sign-in flow for the optional cloud account layer
- alarms - To schedule periodic cloud sync, token refresh, and stale session cleanup
- tabGroups (optional, only requested if you turn on "Save all tabs into a tab group") - To read and create Chrome tab groups
- Supabase host access - To call the dedicated auth, entitlement, checkout, and billing-management backend used by optional paid cloud features, and the anonymous security-alert check described above
- Content script access (every page, injected before the page loads) - To draw the bookmark bar and search UI directly on web pages. This is what produces Chrome's "Read and change all your data on the websites you visit" install prompt. It reads the page only to render the bar and to build the bookmark you ask it to create, such as a video's title, channel, duration, and playback position when you drag it onto the bar - it does not otherwise collect page content or browsing history
Contact
Email: info@secondbookmarkbar.com
Website: secondbookmarkbar.com