Privacy policy

Effective October 1, 2026 · Applies to the Marked extension for Chrome and Firefox, and to this website.

In short

  • Your library stays in your browser. There is no Marked account and no Marked server.
  • Marked has no analytics, no tracking, and no ads. It doesn't sell or share your data.
  • It contacts a few outside services, listed below, only for the feature that needs them. Most only happen when you ask: downloading the chat model, semantic search, downloading page text, and importing from X, and tagging that import if you choose.

1. What stays on your device

Everything Marked saves is kept in your browser's storage for the extension, on your computer:

None of this is sent to the developer of Marked or to anyone else, except the specific pieces listed in the next section.

2. Access to the pages you visit

Marked can read the web pages you visit, but only if you allow it. It asks in its own page, which opens once you install it, not in the browser's install prompt, and you can turn it off at any time in Settings → Browsing or in your browser's extension settings. Turned off, Marked leaves every page at once, including pages already open: their highlight marks, ✓, and Highlight button go away. Everything you saved stays in Marked.

3. What Marked contacts, and when

Like any web request, each of these lets the service see your IP address and basic browser information. Beyond that, here is exactly what goes to each one.

Hugging Face

When
Only when you choose to download the local chat model. Marked asks for your browser's permission to reach Hugging Face first.
What's sent
Requests for the model's files (about 2.3 GB, downloaded once). Nothing from your library, and nothing you ask the chat.
Their policy
huggingface.co/privacy

X

When
In the gallery, to show posts you saved from X as embedded posts. And when you choose Import → Bookmarks from X, which opens your X bookmarks in a tab.
What's sent
For embeds, the ID of each saved post that's shown, with X's do-not-track option set. For the import, the tab loads X as you normally would, signed in as you; Marked scrolls that page so X loads your bookmarks, reads the posts shown, and saves them in your library. It adds nothing of its own to what X receives. If you choose to tag the import, the posts also go to TypeSafe, as described below.
Their policy
x.com/en/privacy

Hacker News and GitHub

When
When you save a Hacker News story or comment, or a GitHub repository, issue, or pull request, or when you download text for one. Never just because you visit one.
What's sent
A request to the site's public API (hacker-news.firebaseio.com or api.github.com) for that item, to show its card and keep the discussion or README as its text. No cookies or sign-in go with it.
Their policy
GitHub privacy statement; Hacker News's API is served by Google Firebase (policies.google.com/privacy)

TypeSafe (semantic search and tagging imports from X)

When
Only if you add your own TypeSafe Jev API key in Settings, and only when you click Semantic, or import your bookmarks from X with Tag each post with the tags that fit it ticked. Tagging starts off.
What's sent
For a search: your search, and for each bookmark its title and abstract. Its note and up to three highlights go too only if you turn on Include notes or Include highlights in Settings → Semantic search; both start off. Never addresses, folders, or tags. For a tagged import: the text of each post that isn't in your library yet (not who posted it), with the text of any post it quotes, the descriptions its images have, and what its link preview shows (usually the site and the page's title); and the names of your tags, so Jev can choose tags for each post. Never the images themselves. Nothing else from your library. Your API key goes with each request so TypeSafe can authorize it. Preview requests without sending them shows you what would be sent.
Their policy
See TypeSafe's terms and privacy policy at typesafe.ai.

The sites you bookmarked

When
When you download text in Settings → Page text, or when the reader offers to download a bookmark's text and you accept, to get the text of pages saved before Marked kept it.
What's sent
A normal request for each page's address. No cookies go with it, so you aren't signed in to the site when Marked reads it.

4. Why Marked asks for its permissions

5. What Marked doesn't do

6. Your control over your data

Because your data never reaches us, we can't see, recover, or delete it for you. It's entirely in your hands.

7. This website

This site is a set of static pages. It sets no cookies and runs no analytics. It loads the Inter font from Google Fonts. The company hosting the site may keep standard server logs, such as IP addresses and the pages requested, for security and operations.

8. Changes and contact

If Marked starts handling data differently, this page will be updated before the change ships, and the effective date above will change.

Questions or concerns? Open an issue at github.com/shinoss/marked/issues.