Privacy

Privacy Policy

Last updated: August 22, 2026

Maark is a link-sharing app. We wrote this document to describe exactly the data the app actually processes, nothing more, nothing less. All of our infrastructure is hosted in France / the European Union.

1. Data controller

Maark is published by an individual. The controller responsible for processing your personal data is:

De La Casa Jérémy
Contact: hello@maark.app

We have not appointed a Data Protection Officer (DPO). For any question about your data, email support@maark.app.

2. Data we process

Maark can be used in guest mode, without an account, in which case no email address is required. Creating an account (via email, Google or Apple) unlocks sharing across devices and with other people. When you upgrade from guest mode to an account, your lists, links, subscriptions, reading history and preferences are transferred to the account, and the guest profile is then deleted.

Account and authentication

Content you create

What others can see

Browser extension

Push notifications

Usage statistics (optional)

Technical diagnostics (error reports)

We do NOT collect: your location (a list's place is typed in by hand, never read from GPS), your phone's address book, your microphone, or any advertising identifier (no IDFA/ATT tracking). Maark shows no ads, offers no purchases and never sells your data.

Processing Purpose Legal basis (Art. 6 GDPR)
Account, email, sign-in (one-time code, Google, Apple) Create and secure your access, recognize you across devices Performance of a contract (Art. 6(1)(b))
Session IP address and user-agent Security, fraud and abuse prevention, rate limiting Legitimate interest (Art. 6(1)(f))
Lists, links, previews, comments, reactions, subscriptions, list and reading history Provide the core functionality of the app Performance of a contract (Art. 6(1)(b))
Public name, @handle and avatar Identify you to the people you share with Performance of a contract (Art. 6(1)(b))
List invitations (by handle, email or link) Deliver the invitation you send and verify membership Legitimate interest (Art. 6(1)(f)), at your request
Push notifications Notify you about activity on your lists (new links, comments, invitations, accepted invitation, deleted list) Consent (system permission) / contract performance
Transactional emails (sign-in code, invitations) Operate the service Performance of a contract (Art. 6(1)(b))
Anonymized usage statistics Understand usage to improve the app Consent (Art. 6(1)(a)), explicit opt-in, revocable
Error / diagnostic reports Detect and fix bugs, ensure stability Legitimate interest (Art. 6(1)(f))
Moderation and reports Handle reported illegal or offensive content Legitimate interest + legal obligation (Art. 6(1)(f) / 6(1)(c))

4. Processors and recipients

We do not sell or rent your data. We rely on a small number of technical providers (processors under the GDPR), chosen wherever possible for European hosting:

Provider Role Data involved Location
Scaleway (France) Hosting of servers, database and avatar storage All application data France (fr-par)
Resend Sending emails (sign-in code, invitations) Recipient email address and email content EU
PostHog (Cloud EU) Usage statistics (only if you consent) Technical account identifier, screens viewed, usage counters EU
Sentry Error diagnostics / crash reports Technical account identifier, technical error details EU
Expo (Push) Delivery of push notifications Notification token, notification title and body United States (Google Cloud)
Google / Apple Social sign-in (only if you choose it) Authentication via your Google / Apple account Outside the EU (see §5)
Preview providers (YouTube, TikTok and the linked site) Fetch the title / preview of a link you save The URL of the link concerned (needed to fetch the preview) Depends on the site

When you save a link, our server visits the corresponding page to extract a preview (title, image). For some platforms (YouTube, TikTok), the URL is sent to their official preview service. We share no other data about you with them.

5. Transfers outside the European Union

Our servers, database and avatar storage are located in France. Statistics (PostHog) and diagnostics (Sentry) use European hosting regions.

Two exceptions may involve a transfer outside the EU:

Where such transfers occur, they are governed by the mechanisms provided for by the GDPR (standard contractual clauses or an adequacy decision). If you prefer no transfer outside the EU, you can use email sign-in and leave push notifications disabled.

6. Retention periods

7. Your rights

Under the GDPR, you have the following rights:

To exercise these rights, email support@maark.app. We respond within a maximum of one month. You may also lodge a complaint with the CNIL (www.cnil.fr), the French supervisory authority, or with the supervisory authority in your country of residence.

8. Account deletion

You can delete your account at any time from the app: Settings → Account → Delete my account. This removes the lists you own and the links they contain, revokes your sessions and notification tokens, and erases your profile picture.

If you no longer have access to the app, send your deletion request to support@maark.app from the email address of your Maark account: we delete the account within 30 days, with the same effects as deleting it from the app.

On deletion, your personal data is immediately anonymized: your email address is replaced with an irreversible random value, and your name, public handle, picture and analytics consent are erased. The access secrets tied to your account (authentication tokens, Google / Apple connections, sign-in codes) as well as any invitations addressed to your email are deleted.

Contributions you left in lists owned by other people (comments, reactions, history entries, read marks, memberships and subscriptions) are kept to preserve the integrity of those lists, but attached to an emptied anonymous profile: they no longer contain any data that could identify you. If you also want them erased, email support@maark.app. This anonymization is permanent and irreversible.

9. Cookies and trackers

The mobile app uses no advertising cookies and embeds no third-party tracking network.

10. Security

Exchanges with our servers are encrypted (HTTPS). Session tokens are stored encrypted on your device. Avatars are served from a dedicated, cookie-free domain. We apply rate limiting and abuse protections.

11. Minors

Maark is not intended for people under 15 (the age of digital consent in France). We do not knowingly collect data about minors below that age. If you believe a minor has provided us with data, contact us so we can delete it.

12. Changes

We may update this policy. For significant changes, we will notify you in the app or by email. The last-updated date appears at the top of this page.

13. Contact

For any question about this policy or your personal data:
support@maark.app