Terms of Service
Preamble and Recitals
WHEREAS, the operator, Gabriel Sgroi, residing at Charlottenstr. 47, 73230 Kirchheim unter Teck, Germany (hereinafter referred to as the "Operator", "we", "us", or "our"), has developed, owns, and operates a complex, multi-layered digital ecosystem comprised of, inter alia, a comprehensive bookmark management and social discovery platform (Bookmer Core), an integrated, centralized identity and authentication infrastructure (Bookmer ID) utilizing OAuth 2.0 and OpenID Connect protocols, and associated developer toolkits, browser extensions, and mobile applications;
WHEREAS, the Services are designed to facilitate the collection, organization, synchronization, customization, public sharing, and algorithmic discovery of hyperlinks, folders, collections, visual assets, and textual metadata, while simultaneously providing a universal single sign-on layer for third-party applications, developers, and end-users seeking secure, passwordless, or multi-factor authentication mechanisms;
WHEREAS, the Operator provides these Services on a global scale, which necessitates compliance with a diverse and occasionally conflicting array of legal frameworks, including but not limited to the Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR), the German Telemedia Act (Telemediengesetz - TMG), the German Telecommunications Act (Telekommunikationsgesetz - TKG), the ePrivacy Directive (2002/58/EC), the European Digital Services Act (Regulation 2022/2065 - DSA), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (CCPA/CPRA), the United States Digital Millennium Copyright Act (DMCA, 17 U.S.C. § 512), and the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501-6506);
WHEREAS, the Operator expressly intends to create a binding, legally enforceable contract with every User, Developer, and third-party integrator who accesses or utilizes any facet of the Services, thereby establishing mutual rights, obligations, limitations of liability, and indemnification frameworks under both German substantive law (Bürgerliches Gesetzbuch - BGB) and applicable international private law;
NOW, THEREFORE, in consideration of the mutual covenants, representations, warranties, and conditions contained herein, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Operator and the User (as defined herein) agree to be legally bound by the following Terms of Service (hereinafter referred to as "These Terms" or "This Agreement"), which shall govern the User's access, registration, use, and interaction with the Bookmer ecosystem in perpetuity, subject to the modification clauses stipulated herein.
Definitions, Interpretation, and Legal Hierarchy
Definitions
For the purposes of this Agreement, the following terms, whether used in the singular or plural, shall have the meanings ascribed to them below, unless the context explicitly requires otherwise:
"Bookmer Core" shall mean that distinct, integral component of the Services which provides end-users with the technological infrastructure, software interfaces, and algorithmic backend systems necessary to collect, import, export, tag, categorize, folderize, filter, search, customize (including but not limited to wallpapers, layouts, thumbnails, and descriptions), publicly disseminate, and receive algorithmic recommendations for hyperlinks, Uniform Resource Locators (URLs), web-based content, and associated metadata, all of which are stored within the Operator's secure database architecture.
"Bookmer ID" shall mean the proprietary, centralized identification, authentication, and authorization infrastructure operated by the Operator, which issues and manages user profiles, passkeys, multi-factor authentication tokens, magic links, one-time passwords (OTPs), session management, email forwarding aliases, and OAuth 2.0/OpenID Connect consent flows, thereby enabling both direct authentication for Bookmer Core and delegated third-party authentication ("Social Login") for external Developer Applications.
"Services" shall be a collective, umbrella term that encompasses, without limitation, Bookmer Core, Bookmer ID, the Operator's public-facing websites, mobile applications (iOS and Android distributions), browser extensions (including but not limited to Chromium-based, Firefox-based, and Safari-based add-ons), Application Programming Interfaces (APIs), Software Development Kits (SDKs), developer portals, documentation, and any other related software, subdomains, or digital platforms that are owned, controlled, or hosted by the Operator.
"User" shall mean any natural person, legal entity, unincorporated association, partnership, governmental body, or other organization that accesses, browses, registers for, subscribes to, or utilizes any component of the Services, whether as a casual visitor, a registered account holder, a paying subscriber, a developer, a system administrator, or a data subject. This term expressly excludes the Operator and its employees.
"Developer" shall mean a specific sub-category of User who registers via the Bookmer ID Developer Console for the express and explicit purpose of integrating, embedding, or interfacing the Bookmer ID OAuth/OpenID Connect capabilities into their own proprietary software, websites, mobile applications, or desktop environments for the authentication of End-Users.
"End-User" shall mean a distinct natural person who, without necessarily being a direct contractual party to these Terms (except insofar as they are a User of Bookmer ID), utilizes a Developer Application and authenticates their identity through the Bookmer ID infrastructure.
"User Content" shall mean any and all forms of data, information, textual descriptions, nicknames, aliases, visual assets (including raster and vector images), audio-visual material, HTML/CSS customizations, folder structures, tagging taxonomies, bookmarked URL strings, notes, annotations, public profile information, and any other digital artifacts that are generated, uploaded, submitted, transmitted, stored, or made publicly available via the Services by a User.
"Prohibited Content" shall have the meaning ascribed to it in Article IX herein, and shall be interpreted expansively to include any User Content that violates applicable statutory law, contravenes these Terms, infringes upon third-party intellectual property or personality rights, or fails to conform to the Operator's Community Standards.
"Personal Data" shall be interpreted strictly in accordance with Article 4(1) of the GDPR, meaning any information relating to an identified or identifiable natural person, and shall also incorporate the broader, expanded definitions of "personal information" as defined under Section 1798.140(o) of the California Civil Code for the purposes of CCPA/CPRA compliance.
Interpretation, Headings, and Gender
The headings and captions utilized within these Terms are inserted for convenience of reference only and shall not define, limit, extend, or construe the scope or intent of any provision herein. All references to the singular shall include the plural and vice versa, and references to the masculine gender shall be deemed to include the feminine and neuter genders, wherever appropriate. The use of the terms "including", "includes", "such as", or "e.g." shall be construed as illustrative and not as a limitation upon the scope of the general terms that precede or follow them.
Hierarchy and Incorporation by Reference
These Terms constitute the principal, overarching legal agreement governing the relationship between the User and the Operator. They are supplemented by, and shall be read in conjunction with, the following incorporated documents, which are deemed to form an indivisible, integral part of this Agreement:
The Privacy Policy, which elaborates upon the specific data processing activities, legal bases under Art. 6 GDPR, storage durations, and data subject rights;
The Community Standards, which provide granular, detailed parameters for acceptable User behavior and content suitability;
The Cookie Policy, which delineates the use of tracking technologies in compliance with the ePrivacy Directive.
In the event of a direct, irreconcilable conflict between these Terms and an explicitly signed, individualized Master Services Agreement executed between the Operator and a commercial enterprise, the Master Services Agreement shall govern solely with respect to the specific operational or financial terms detailed therein.
Acceptance, Binding Effect, and Modifications
Affirmative Acceptance and Manifestation of Assent
By accessing the Services, clicking the "I Agree," "Sign Up," or "Log In" buttons, or by continuing to navigate the Operator's websites after having been provided with a conspicuous hyperlink to these Terms, the User unequivocally and unconditionally manifests its assent to be bound by all provisions, covenants, and restrictions contained herein. The User expressly acknowledges that this assent constitutes a legally valid and enforceable contract under Section 145 et seq. of the German Civil Code (BGB) and applicable international treaty law, without the necessity of a handwritten signature.
Modification and Revision Authority
The Operator expressly reserves the unilateral, absolute, and discretionary right to revise, amend, update, supplement, or replace these Terms, in whole or in part, at any time and from time to time, in response to changes in the applicable legal framework (including but not limited to judicial rulings from the Court of Justice of the European Union, the German Federal Court of Justice (BGH), or the US Supreme Court), technological developments, or shifts in the Operator's business model. In the event of a material modification, the Operator shall provide the User with reasonable, advance notification via the email address associated with the User's account, as well as through a conspicuous notification displayed within the User's account dashboard or upon the next login attempt.
Temporal Effectiveness and Contemporaneous Objection
Any and all modifications to these Terms shall become binding and effective thirty (30) calendar days following the aforementioned notification date, or upon the User's subsequent login, whichever occurs first. Should the User object to the modified Terms and decline to accept them, the User's sole and exclusive remedy shall be to terminate this Agreement and permanently delete their account prior to the effective date of the modifications. Continued, active use of the Services after the effective modification date shall constitute the User's unequivocal, informed consent to the revised Terms, and the User shall be estopped from later disputing the validity of such modifications.
No Oral Modifications
No oral representation, agreement, or understanding outside the four corners of this written document shall have any force or effect in altering, interpreting, or supplementing these Terms. Only a formal, written amendment signed by an authorized representative of the Operator shall suffice to effectuate a non-unilateral change to this Agreement.
Eligibility, Age Restrictions, and Legal Capacity
Minimum Age and Capacity Requirements (EU & US)
In strict compliance with Article 8 of the GDPR and Section 130a of the BGB, as well as the US COPPA regulations (15 U.S.C. §§ 6501-6506), the User represents, warrants, and covenants that they are: (a) at least sixteen (16) years of age if accessing the Services from within the European Economic Area (EEA); or (b) at least thirteen (13) years of age if accessing from outside the EEA, provided that parental or legal guardian consent has been obtained for Users between the ages of thirteen (13) and the age of majority in their respective jurisdictions. The Operator reserves the right to implement technical age-verification mechanisms and to demand documentary proof of legal age or parental consent. The Services are not directed at children under thirteen (13) years of age, and the Operator does not knowingly collect, store, or process Personal Data from children under this age. If the Operator becomes aware that such data has been inadvertently collected, it shall be expeditiously purged from the active databases in accordance with a reasonable, commercially feasible timeline.
Legal Capacity to Contract
The User further warrants and attests that they possess the full, unencumbered legal capacity, right, power, and authority to enter into this binding Agreement and to perform all obligations and undertakings stipulated herein. If the User is accepting these Terms on behalf of a corporate entity, unincorporated association, or other legal person, the User explicitly represents that they are a duly authorized signatory, officer, or agent vested with the requisite authority to bind such legal person to the provisions of this Agreement.
Excluded Persons and Sanctions Lists
The User affirms that they are not located in, and are not a national or resident of, any country, territory, or region that is subject to comprehensive trade or economic sanctions imposed by the United Nations, the European Union, the German Federal Office for Economic Affairs and Export Control (BAFA), or the United States Office of Foreign Assets Control (OFAC) (including, but not limited to, the Crimea region, the Donetsk and Luhansk People's Republics, Iran, North Korea, and Syria). The User further confirms that they are not named on any applicable prohibited parties, debarment, or denied persons lists, and that the use of the Services does not violate any export control laws or arms embargoes.
Account Registration, Security, and Liability for Credentials
Registration Data Accuracy and Updating Duty
As a mandatory prerequisite for accessing the full spectrum of account-based functionalities, the User must provide complete, current, truthful, and accurate information during the registration process, including a valid, reachable email address, a secure password (or passkey), and, where applicable, billing information. The User undertakes an affirmative, ongoing obligation to update such information without undue delay whenever there is a change in their circumstances (e.g., change of legal name, email address, or billing credit card), as the Operator relies upon the accuracy of this data for the execution of this Agreement and for the fulfillment of statutory disclosure requirements.
Credential Confidentiality and Sole Responsibility
The User acknowledges and accepts that they bear the absolute, non-delegable duty to maintain the strict confidentiality, integrity, and security of their login credentials, including passwords, passkeys, recovery codes, and one-time authentication tokens. The User shall not disclose, share, loan, or otherwise make available their credentials to any third party, nor shall they permit concurrent logins from geographically disparate locations in a manner that suggests credential sharing. The User explicitly assumes full, strict, and vicarious liability for all actions, transactions, modifications, and communications that occur under their account, irrespective of whether such actions are authorized by the User, unless and until the User can demonstrate, by clear and convincing evidence, that the unauthorized activity was directly caused by a security breach attributable to the Operator's gross negligence.
Immediate Notification of Breach
In the event that the User becomes aware of or reasonably suspects any unauthorized access, credential compromise, account takeover, or security incident affecting their account, the User is obligated to notify the Operator immediately via the contact mechanisms established in Article XXII herein. Such notification shall not relieve the User of their underlying responsibility for all activities occurring prior to the Operator's actual receipt and reasonable opportunity to act upon such notification.
Account Non-Transferability and Commercial Exploitation Prohibition
Accounts are inherently personal, non-transferable, and non-assignable. The User is strictly prohibited from selling, renting, leasing, licensing, sublicensing, gifting, trading, or commercially exploiting their account credentials, associated usernames, vanity URLs, subdomains, custom domains, or Bookmer ID aliases to any third party, whether for monetary compensation or for barter. Any attempted transfer, delegation, or assignment shall be deemed null, void, and without legal effect, and shall constitute a material breach of these Terms, justifying immediate, summary termination of the account without the necessity of prior warning.
Passkeys and Multi-Factor Authentication (MFA)
The Operator strongly recommends and facilitates the use of FIDO2-compliant passkeys, authenticator applications, and hardware security keys as an additional layer of security. The User acknowledges that if they lose physical or logical access to their registered passkey device and have not configured fallback recovery mechanisms, account recovery may become permanently, technically infeasible, and the Operator shall bear no liability for the resultant loss of access to User Content.
Comprehensive Functionalities of Bookmer Core
Structural Description of Bookmarking and Organization
The Bookmer Core platform provides the User with a powerful, multi-tenant, cloud-based repository for the persistent storage, granular classification, and dynamic manipulation of web bookmarks. This includes, but is not limited to, the creation of infinite-depth hierarchical folder structures, the application of user-defined tags, full-text search within stored notes and titles, advanced filtering algorithms, and the ability to import data via Netscape HTML bookmarks file format, as well as to export such data in machine-readable JSON, CSV, or HTML structures, subject to the fair use limitations set forth in Article VII herein.
Customization and Personalization Environment
Depending upon the User's specific subscription tier and active payment status, the Services grant the User access to comprehensive, granular customization tools that permit the alteration and aesthetic enhancement of their individual public and private landing pages. Such customization may include the modification of CSS-influenced variables, background wallpapers, accent colors, typography, avatar selection, and the arrangement of content modules. The User expressly acknowledges and agrees that any customization that violates third-party intellectual property rights (including the unlicensed use of copyrighted images) remains the sole legal and financial responsibility of the User, and the Operator shall not be liable for any resulting takedown notices, cease-and-desist communications, or judicial actions.
Public Sharing, Discovery, and Algorithmic Curation
The Services include a unique, proprietary social discovery engine designed to expose publicly shared collections, trending links, and popular content to the broader User community. This discovery feature is powered by automated, algorithmic recommendation systems that analyze aggregate interaction data, including click-through rates, public collection additions, and user engagement metrics, to surface relevant content. The User explicitly acknowledges that such algorithmic suggestions are generated on an objective, statistical basis and do not constitute an endorsement, guarantee, or warranty by the Operator regarding the quality, accuracy, safety, or legality of the recommended external websites. The Operator reserves the right to modify the parameters of the discovery algorithm at any time, in its sole and absolute discretion, to enhance user experience or to moderate and filter out content that is deemed, by the Operator's internal moderation teams, to be in violation of the Community Standards.
Browser Extensions and Integration with Third-Party Browsers
In order to facilitate seamless link saving and management, the Operator provides browser extensions that interact with the User's local browser environment. These extensions possess permissions to read the User's current browser URL, page title, and metadata for the sole purpose of creating bookmarks. The User acknowledges that the functionality of these extensions is inherently dependent upon the ongoing compatibility of, and the policies imposed by, third-party browser vendors (including Google LLC for Chrome, Mozilla Corporation for Firefox, and Apple Inc. for Safari), and the Operator explicitly disclaims any liability for the temporary or permanent discontinuation, revocation, or disabling of such extensions by the browser vendors' respective app stores.
Broken Link Handling and Automated Metadata Refresh
The Services employ automated system daemons that periodically ping, scan, and validate the HTTP/S status codes of stored URLs to identify broken or inactive links. Furthermore, the system attempts to refresh metadata (Open Graph tags, titles, descriptions, and favicons) from the source websites. The User understands and agrees that such processes are best-effort background operations and that: (i) certain websites may block automated scraping via robots.txt, thereby preventing metadata retrieval; (ii) the refresh intervals are dynamic and subject to system load; and (iii) the Operator shall not be liable for the continued availability, accuracy, or legal compliance of external resources linked by the User.
Bookmer ID - Identity Layer, OAuth, and Federated Authentication
Nature and Purpose of the Unified Identity Layer
Bookmer ID constitutes a comprehensive, centralized identity and access management (IAM) system that issues a persistent, globally unique digital identifier to each registered User. This identity layer serves a dual purpose: (a) authenticating the User into the Bookmer Core ecosystem; and (b) enabling the User to leverage their Bookmer ID credentials as a trusted, third-party identity provider for external Developer Applications through the implementation of standardized OAuth 2.0 and OpenID Connect (OIDC) protocols.
Authentication Modalities and Granular Consent
The User may authenticate their identity via a variety of modalities, including traditional password-based login, email-based "Magic Links," SMS/authenticator-based one-time passwords (OTPs), and FIDO2 passkeys. When authenticating to an external Developer Application, the User is presented with a transparent consent screen that enumerates the specific categories of data (scopes) requested by the Developer, including but not limited to the User's email address, display name, profile image URL, and Bookmer ID account identifier. The User bears the sole and exclusive responsibility for reviewing the content and scope of the consent screen and for authorizing or denying the requested permissions. By granting such permissions, the User effectively instructs the Operator to transmit the designated attributes to the Developer Application.
Developer Applications and Data Recipient Liability
The Operator acts solely as an intermediary conduit for the transmission of User-authorized data to the Developer Application. Upon the successful completion of the OAuth consent flow, the Developer Application becomes an independent, separate data controller or data processor, as the case may be, and the Operator assumes no control, oversight, or liability over the Developer's subsequent storage, processing, transfer, or misuse of the User's Personal Data. The User is strongly urged to review the Developer's separate privacy policy and terms of service prior to authorizing a Bookmer ID login and is advised that the revocation of the Developer's access via the Bookmer ID settings dashboard does not automatically compel the Developer to delete previously transferred data; the User must direct any deletion request directly to the Developer.
Email Alias, Forwarding, and Disposable Addresses
Bookmer ID may offer the User the ability to create unique, randomized, or user-defined email aliases that forward communications to the User's primary inbox. The User acknowledges that such aliases are subject to the Operator's acceptable use policies and shall not be utilized to engage in spamming, phishing, unsolicited commercial communications, or the circumvention of platform bans. The Operator reserves the right to disable, suspend, or permanently remove any email alias that generates excessive bounce rates, spam complaints, or is flagged by third-party abuse reporting systems (e.g., Spamhaus).
Developer Terms, API Usage, and OAuth Integration
Developer Registration, App Review, and Approval
Any User wishing to integrate Bookmer ID into their software ecosystem must register as a Developer via the dedicated Developer Console. This registration requires the submission of a verified corporate or individual identity, a valid support email address, a detailed description of the intended application, the exact redirect URIs (uniform resource identifiers) or deep-link handlers, and a functioning privacy policy URL. The Operator operates a stringent, internal App Review process, during which the Developer Application is scrutinized for security posture, compliance with these Terms, and the proportionality of requested OAuth scopes. The Operator reserves the unilateral right to reject, conditionally approve, or postpone the approval of any Developer Application in its absolute discretion, without the need to provide a substantive rationale.
Grant of Limited API License and Permitted Scope of Use
Subject to the Developer's strict, ongoing compliance with these Terms, the Operator grants the Developer a limited, non-exclusive, non-transferable, non-sublicensable, personal, and revocable license to access, interface with, and call the Operator's public and private APIs solely for the purpose of enabling authentication, authorization, and profile retrieval for End-Users who explicitly consent via the OAuth flow. This license does not permit the Developer to store or cache authentication tokens beyond the technical refresh lifecycles defined in the API documentation, nor does it permit the use of the API for any purpose other than identity verification (e.g., the Developer may not use the API to build a competing identity provider, to perform user profiling for advertising algorithms, or to perform data mining).
Strict Prohibitions and Anti-Abuse Provisions for Developers
The Developer expressly agrees, covenants, and warrants that they shall not, under any circumstances:
Request or extract OAuth scopes (permissions) that are manifestly excessive, unnecessary, or unrelated to the core, disclosed functionality of the Developer Application;
Sell, lease, license, trade, or otherwise commercialize the Personal Data of End-Users obtained through the Bookmer ID integration, unless such commercialization is done on an aggregated, completely anonymized basis that prevents re-identification;
Combine End-User data obtained via Bookmer ID with data obtained from other sources (e.g., data brokers) for the purpose of creating enhanced user profiles, cross-site tracking, or behavioral advertising, unless such processing is grounded in a separate, explicit, and granular lawful basis disclosed to the End-User;
Transmit, store, or process malware, viruses, or malicious code through the OAuth redirect flow;
Engage in "token stuffing" or attempts to brute-force authorization codes.
Data Retention, Deletion, and Audit Rights
The Developer shall implement and enforce a data retention policy that provides for the deletion or anonymization of all Personal Data obtained via Bookmer ID within a commercially reasonable timeframe, not to exceed ninety (90) days following: (a) the End-User's revocation of access; or (b) the termination of the Developer's API credentials. The Operator reserves the right, upon fourteen (14) days' prior written notice, to conduct a technical or documentary audit of the Developer's data handling practices to verify compliance with this Article. Should the Developer fail the audit, the Operator may summarily suspend or permanently revoke the Developer's API access without incurring any liability for resultant disruption.
API Rate Limiting and Throttling
To ensure the equitable distribution of server resources and the maintenance of system availability for all Users, the Operator imposes dynamic, real-time rate limits on API calls made by Developers (typically measured in requests per second, minute, or hour). These limits are contingent upon the Developer's subscription tier (free, professional, or enterprise). The Operator may throttle, delay, or block API requests originating from an IP address or Developer ID that consistently exceeds these limits or exhibits traffic patterns characteristic of a distributed denial-of-service (DDoS) attack, automated scraping, or unauthorized load testing.
User Content - Proprietary Ownership and Grant of Operational Licenses
Retention of Intellectual Property Rights
The Operator acknowledges, respects, and agrees that the User retains all right, title, and interest in and to their User Content, including all associated copyrights, trademark rights, patent rights, and database rights, to the fullest extent recognized under the Berne Convention, the German Urheberrechtsgesetz (Copyright Act), and the US Copyright Act of 1976. Nothing in this Agreement shall be construed to transfer, assign, or convey ownership of any User Content to the Operator.
Necessity and Scope of the Operational License (Hosting and Processing)
By submitting, uploading, publishing, or otherwise making User Content available through the Services, the User grants the Operator a perpetual (for the duration of the User's account plus a commercially reasonable post-termination transition period), worldwide, non-exclusive, royalty-free, fully paid-up, sublicensable (solely to third-party cloud hosting and content delivery network providers), and transferable license to host, store, cache, encode, decode, reformat, adapt, display, publicly perform, transmit, distribute via CDN, and otherwise technically process the User Content solely to the extent strictly necessary to operate, improve, secure, and deliver the Services in accordance with the User's designated privacy settings (Public, Unlisted, or Private). This license terminates irrevocably, and the Operator shall cease all active processing of the User Content, within a commercially reasonable time frame (not to exceed thirty (30) days) after the User deletes the specific content or initiates a permanent account deletion process.
Public Content - Grant to Other Users
If the User expressly designates a folder, collection, bookmark, or profile as "Public," the User grants all other Users of Bookmer a non-exclusive, non-transferable, revocable (by the User deleting the content) license to access, view, share via social media embedding, and link to such Public Content, provided that such use: (a) does not constitute commercial exploitation without the User's separate, written consent; and (b) does not misattribute or distort the origin of the content.
Feedback and Submissions
In the event that the User voluntarily submits feedback, suggestions, enhancement requests, bug reports, or ideas to the Operator (collectively, "Feedback"), the User acknowledges and agrees that such Feedback is provided on a non-confidential, gratuitous basis. The Operator shall have the unrestricted, perpetual, irrevocable, worldwide, royalty-free right to use, implement, commercialize, modify, and exploit the Feedback without any attribution, payment, or compensation to the User, and the User waives any moral rights to the extent permissible under applicable law.
Prohibited Conduct and Content (Community Standards Incorporation)
Absolute Prohibition of Unlawful and Harmful Conduct
The User agrees, undertakes, and covenants that they shall not, and shall not permit any third party or affiliate acting on their behalf to, utilize the Services for any purpose, activity, or endeavor that is: (a) illegal, criminal, tortious, or otherwise contrary to the applicable public policy of the Federal Republic of Germany, the European Union, or the United States; (b) defamatory, libelous, obscene, or pornographic (specifically excluding non-consensual intimate imagery and CSAM); (c) infringing upon the intellectual property, privacy, publicity, or personality rights of any third party; (d) fraudulent, deceptive, or designed to phish, scam, or socially engineer other Users; or (e) involving the distribution of malware, ransomware, spyware, Trojan horses, rootkits, or any other malicious code designed to compromise digital security.
Specific Enumeration of Prohibited Content Types
The User shall not transmit, publish, store, or share any of the following categories of User Content:
CSAM and Exploitation: Any depiction of child sexual abuse material (as defined by 18 U.S.C. § 2256 and the EU Directive 2011/92/EU), or any material that depicts sexual violence or non-consensual sexual acts;
Hate Speech: Content that promotes violence, incites discrimination, or advocates hatred against individuals or groups based upon race, color, ethnicity, national origin, religion, gender identity, sexual orientation, disability, or age, where such content is intended to or likely to stir up violence or prejudice;
Terrorism and Extremism: Content that provides instructions for the manufacture of weapons, explosives, or chemical agents, that promotes terrorist organizations (as designated by the EU or US State Department), or that glorifies terrorist acts;
Doxxing and Harassment: Personal, private, and confidential information about other individuals (including physical addresses, government identification numbers, or private phone numbers) published without explicit consent for the purpose of harassment, intimidation, or stalking.
System Abuse and Technical Violations
The User shall not engage in any conduct that interferes with, disrupts, burdens, or compromises the technical infrastructure, security protocols, or operational performance of the Services. This includes, but is not limited to, conducting denial-of-service attacks, high-volume automated crawling or scraping (except for public search engine indexing), credential stuffing, password spraying, reverse engineering of the client-side software, bypassing rate limits, or circumventing regional access controls through the use of virtual private networks (VPNs) or proxy servers, unless such use is for a legitimate business purpose and does not circumvent payment restrictions.
Consequences and Operational Remedies
In the event of a violation of this Article, the Operator, in its sole and absolute judgment, may apply a graduated spectrum of operational remedies, ranging from the removal of the specific offending content and the issuance of a written warning, to the temporary suspension of specific features (e.g., public sharing), and ultimately to the immediate, summary, and permanent termination of the User's entire account and all associated Bookmer ID privileges. The Operator may also refer matters to the appropriate law enforcement agencies, regulatory bodies (including the German Bundesamt für Justiz or the US National Center for Missing and Exploited Children), and shall cooperate with judicial investigations.
Moderation, Reporting Mechanisms, and DMCA/DSA Compliance
Active and Proactive Moderation (DSA Compliance)
In compliance with the European Digital Services Act (Regulation 2022/2065), the Operator operates a legally mandated notice-and-action mechanism and employs a blended system of automated AI-driven detection tools (to flag potential Prohibited Content) and human expert moderators to review flagged content. The Operator maintains a comprehensive, transparent moderation policy, and decisions on content removal are taken in a timely, non-arbitrary, and objective manner, respecting the fundamental rights of the User to freedom of expression.
User Reporting Mechanism
The User may report suspected violations of these Terms, the Community Standards, or applicable law by utilizing the "Report" button located on specific content items (bookmarks, collections, profiles, or public pages) or by submitting a formal, detailed complaint to the Operator's designated legal contact. The complaint must contain, at a minimum: (a) the specific URL(s) or account(s) to which the complaint relates; (b) a clear description of the alleged violation and the legal basis thereof; (c) the complainant's contact information for follow-up; and (d) any supporting evidence or documentation.
DMCA Takedown Notices (17 U.S.C. § 512). For Users in the United States and globally, the Operator complies with the Digital Millennium Copyright Act. If you believe in good faith that copyrighted material has been infringed upon via the Services, you must submit a physical or electronic signature, identification of the copyrighted work, identification of the infringing material (including the specific URL), contact details, a statement of good faith belief, and a statement under penalty of perjury that the information is accurate. The Operator's designated agent for DMCA notices is the legal contact specified in Article XXII. Upon receipt of a valid DMCA notice, the Operator will expeditiously remove or disable access to the material and, in appropriate circumstances, will terminate the accounts of repeat infringers under a "three-strikes" policy.
Right of Appeal and Internal Dispute Resolution
If the User's content has been removed or their account has been restricted, the User has the right to appeal the moderation decision. The appeal must be submitted within thirty (30) calendar days of the restrictive action being communicated to the User. The appeal will be reviewed by a senior moderator or legal officer of the Operator who was not involved in the initial decision. The Operator will provide a reasoned, written response to the appeal within a reasonable timeframe (not exceeding ninety (90) days for complex cases), outlining the final decision and the judicial or out-of-court redress avenues available to the User.
Subscriptions, Fees, Billing, and Taxation
Subscription Tiers and Commercial Features
The Services are offered across a spectrum of subscription models, including a free, limited-feature tier, and multiple paid tiers (e.g., Professional, Business, and Enterprise), each providing varying capacity, storage limits, API access quotas, customization options, and customer support SLAs. The specific features associated with each tier are described on the Operator's Pricing Page, and the Operator reserves the right to change, upgrade, or phase out features within a tier, provided that material downgrades to a User's existing paid plan are subject to the notice provisions in Section 2.2.
Third-Party Payment Processing (Stripe, PayPal, Apple, Google)
The Operator utilizes reputable, third-party payment service providers (including Stripe, Inc., PayPal (Europe) S.à r.l. et Cie, S.C.A., Apple Inc., and Google LLC) to process credit card, debit card, digital wallet, and direct debit payments. The Operator does not store the User's full Primary Account Number (PAN) or CVV code on its own servers; the payment data is tokenized and held by the payment processor. The User agrees to abide by the terms and conditions of these third-party processors, and the Operator disclaims all liability for any data breach or payment failure that occurs on the processor's side.
Billing Cycles, Payment Prepayment, and Recurring Billing
Unless the User has purchased a one-time lifetime license, all paid subscriptions are billed in advance on a monthly or annual recurring basis. The User authorizes the Operator to charge the provided payment method for the full subscription fee at the start of each billing period. The subscription shall automatically renew indefinitely until the User cancels via their account settings prior to the renewal date. The Operator will send a reminder notification regarding upcoming renewals at least fourteen (14) days in advance, as required by Section 312g of the BGB.
Price Adjustments and Tax Liability
The Operator reserves the right to increase the subscription fees for existing Users upon thirty (30) days' prior written notice. In the event of a price increase, the User has the right to terminate their subscription without penalty before the new pricing takes effect. All stated fees are exclusive of any applicable Value Added Tax (VAT/USt.), sales tax, or goods and services tax (GST), which shall be calculated and added at the prevailing statutory rate based on the User's jurisdiction and applicable tax treaties. The User is responsible for providing a valid VAT ID for reverse-charge mechanisms where applicable.
Statutory Right of Withdrawal (EU Consumer Protection)
Enhanced Withdrawal Rights under EU Law
If the User is a natural person acting for purposes which are outside their trade, business, craft, or profession (a "Consumer") and habitually resides in the European Union, the User possesses the statutory right of withdrawal under Section 312g of the BGB and the Consumer Rights Directive (2011/83/EU). The User has the right to withdraw from this contract within fourteen (14) days of purchase without giving any reason and without incurring any penalty, subject to the specific exception for digital content provided in Section 12.2 below.
Explicit Consent to Immediate Performance (Waiver of Cooling-Off)
The User explicitly acknowledges and agrees that by clicking the "Subscribe" or "Purchase" button during the checkout process, the User expressly requests that the Operator commence the performance of the Services (including immediate provision of the paid Bookmer ID and Core features) immediately. Consequently, the User is informed and agrees that: (a) they will lose their right of withdrawal (cooling-off period) under Section 312g(2) No. 1 BGB once the Operator has fully performed the digital service contract by providing full access to the paid features; and (b) in the event of a withdrawal request submitted after the full performance has commenced, the User shall be liable to pay a reasonable pro-rata amount for the Services already provided up to the point of withdrawal.
Account Termination, Data Export, and Post-Termination Retention
Voluntary Termination by User
The User retains the unilateral right to terminate their account and this Agreement at any time, without cause or penalty, by navigating to the account settings and initiating the "Permanent Deletion" function. The User is strongly encouraged to exercise their right to data portability via the export function prior to deletion, as the deletion process is automated, irreversible, and prevents any future restoration of the account or its associated content.
Termination for Cause by the Operator
The Operator retains the unilateral, discretionary right to terminate this Agreement and suspend or permanently delete the User's account with immediate effect (without any prior grace period) if: (a) the User commits a material breach of any provision of these Terms or the Community Standards; (b) the User's use of the Services exposes the Operator to civil or criminal legal liability; (c) the User becomes subject to a bankruptcy, insolvency, or similar proceeding; (d) the User fails to remit overdue payment following a fifteen (15) day cure period; or (e) the Operator is required to do so by a judicial or administrative authority.
Data Retention, Segregation, and Legal Holds
Upon the effective date of termination (whether by User or Operator), the Operator's active databases shall be instructed to purge all User Content and Personal Data in accordance with standard operational procedures. However, the User acknowledges that the Operator may retain limited, isolated copies of User Data in its backup archives and security logs for a period not exceeding the statutory limitation periods prescribed by German commercial and tax law (generally up to ten (10) years, per §§ 147 AO and 257 HGB), provided that such retained data shall be segregated, encrypted, and shall not be processed for any purpose other than fulfilling legal compliance, fraud detection, and dispute resolution.
Intellectual Property Rights of the Operator
Proprietary Rights in the Platform
The User acknowledges and agrees that the Services, including but not limited to the source code, object code, algorithms, user interfaces, graphical design elements, layout templates, typography, logos, trademarks, service marks, business names (including "Bookmer" and "Bookmer ID"), and any related documentation, are the exclusive, proprietary intellectual property of the Operator and its affiliated third-party licensors. These assets are protected by international copyright laws, the German UrhG, the EU Software Directive, US copyright law, and trademark treaties (including the Madrid Protocol).
Reservation of Rights and Prohibition on Reverse Engineering
Except for the limited operational license explicitly granted in these Terms, no right, title, or interest in the Services is transferred to the User. The User is expressly forbidden from: (a) reverse engineering, decompiling, disassembling, or attempting to derive the source code of the Services, except to the extent explicitly permitted by mandatory law (e.g., interoperability under § 69e UrhG) and only after first requesting such information from the Operator; (b) framing, scraping, or extracting proprietary database contents; (c) using the Operator's trademarks or trade names in any manner that would cause confusion, dilution, or disparagement of the Operator's brand.
Disclaimer of Warranties and "as-Is" Basis
Exclusion of Implied Warranties
TO THE MAXIMUM EXTENT PERMITTED BY THE MANDATORY PROVISIONS OF GERMAN AND EU CONSUMER LAW, THE SERVICES ARE PROVIDED TO THE USER STRICTLY AND EXCLUSIVELY ON AN "AS-IS," "WHERE-IS," AND "AS-AVAILABLE" BASIS, WITHOUT ANY WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. THE OPERATOR SPECIFICALLY DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING BUT NOT LIMITED TO: (A) IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT; (B) WARRANTIES THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, OR FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS; AND (C) WARRANTIES THAT THE CONTENT, BOOKMARKS, OR ALGORITHMIC RECOMMENDATIONS PROVIDED ARE ACCURATE, RELIABLE, CURRENT, COMPLETE, OR COMPLIANT WITH THE LAWS OF THE USER'S SPECIFIC JURISDICTION.
Reliance on Third-Party Content
The Operator explicitly disclaims any and all responsibility for the legality, accuracy, safety, or quality of the external websites, hyperlinks, or web-based content that are saved, shared, or published by Users. The Operator does not monitor or control the external internet, and the User accesses external links solely at their own risk.
Limitation of Liability and Cap on Damages
Unlimited Liability for Intent, Gross Negligence, and Inherent Statutory Duties
Nothing contained in these Terms shall serve to exclude or limit the Operator's liability where such exclusion or limitation would be prohibited by mandatory statutory provisions, including: (a) liability for damages resulting from the Operator's willful misconduct (Vorsatz) or gross negligence (grobe Fahrlässigkeit); (b) liability for personal injury, death, or damage to health; or (c) liability arising under mandatory product liability legislation (ProdHaftG) or for fraudulent concealment of defects.
Significant Reduction for Simple Negligence (Cardinal Obligations)
In the event of the Operator's ordinary negligence (einfache Fahrlässigkeit), the Operator shall be liable only for the breach of those fundamental contractual obligations (Kardinalpflichten) whose fulfillment is essential for the proper execution of these Terms and upon whose performance the User regularly relies. In such cases, the Operator's liability shall be strictly limited to the reasonably foreseeable and typical direct damages, as contemplated at the time the contract was concluded. The aggregate, cumulative liability of the Operator for all claims arising out of or related to these Terms during any single contract year shall be capped at the total fees actually paid by the User to the Operator in the twelve (12) calendar months immediately preceding the event giving rise to the claim, or at a minimum of EUR 500.00, whichever is higher.
Explicit Exclusion of Consequential and Indirect Damages
TO THE FULLEST EXTENT PERMISSIBLE UNDER APPLICABLE LAW, THE OPERATOR SHALL NOT BE LIABLE TO ANY USER FOR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, INCLUDING, BUT NOT LIMITED TO, LOST PROFITS, LOST REVENUE, LOST DATA, LOST GOODWILL, BUSINESS INTERRUPTION, REPUTATIONAL HARM, OR COSTS OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, IRRESPECTIVE OF WHETHER THE OPERATOR WAS ADVISED OF THE POSSIBILITY OF SUCH DAMAGES IN ADVANCE.
Indemnification and Defense
Broad Indemnity Obligation
The User agrees to defend, indemnify, and hold harmless the Operator, its direct and indirect parent entities, subsidiaries, affiliates, officers, directors, employees, agents, contractors, and third-party service providers from and against any and all third-party claims, demands, lawsuits, administrative proceedings, losses, liabilities, damages, judgments, fines, penalties, and costs (including, but not limited to, reasonable external and internal attorney's fees, court costs, and expert witness fees) arising out of, resulting from, or relating to: (a) the User's failure to comply with any provision of these Terms or applicable laws; (b) the User's User Content, including any claim that it infringes copyright, trademark, patent, or violates privacy or publicity rights; (c) the User's misuse of the Developer API; (d) the User's domain or DNS configuration; or (e) the User's tax liabilities or failure to remit VAT/sales tax.
Reservation of Right to Assume Defense
The Operator reserves the right, at its own expense, to assume the exclusive defense and control of any matter otherwise subject to indemnification by the User. In such an event, the User shall provide full cooperation and reasonable assistance to the Operator in the defense and shall not settle or compromise any claim without the Operator's prior written consent.
Third-Party Services, Integrations, and External Providers
Reliance on Subcontractors and Infrastructure
The Operator relies on a complex chain of third-party subcontractors and technology providers to operate the Services, including Amazon Web Services for cloud hosting, SendGrid or similar for transactional email delivery, and open-source libraries. The Operator shall be responsible for the performance of its subcontractors to the same extent as its own performance under these Terms, but the Operator disclaims any liability for outages or data loss attributable to force majeure events affecting these providers (e.g., global AWS outages).
Embedded Social and Payment Plugins
The Services may integrate social sharing plugins (e.g., Twitter/X, Facebook, LinkedIn) and payment interfaces. The User acknowledges that these integrations are governed by the privacy policies and terms of service of the respective external providers, and the Operator does not assume any responsibility for the processing of User data by those external platforms during such interactions.
Data Protection and Privacy (gdpr, Ccpa, Coppa)
Lawful Basis and Processing Principles
The Operator processes Personal Data of Users strictly in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality as mandated by Art. 5 of the GDPR. For Bookmer Core Users, the lawful basis for processing is predominantly the performance of the contract (Art. 6(1)(b) GDPR) and the legitimate interest in improving platform security (Art. 6(1)(f) GDPR). For Visitors, processing is based on legitimate interest or consent (e.g., for cookies).
Data Controller vs
Data Processor Frameworks.
Bookmer Core & Bookmer ID Account Data: The Operator acts as the Data Controller for the User's profile information, authentication logs, billing data, and all internal analytics generated by the User's interaction with the platform.
Developer/End-User Relationship (OAuth): The Operator acts as a Data Controller for the Bookmer ID profile data it holds. The Developer Application acts as an Independent Data Controller for the data it collects via the OAuth flow. The Operator does not act as a processor for the Developer.
Enterprise Customers (Team/ Business): Where a corporate customer expressly enters into a DPA with the Operator, the Operator may act as a Data Processor for the specific business data (e.g., proprietary team bookmarks). In such cases, the Standard Contractual Clauses (2021/914/EU) shall apply.
CCPA/CPRA Compliance (California Residents)
If the User resides in California, the User is entitled to the specific rights under the California Consumer Privacy Act, as amended. The Operator does not "sell" Personal Data in the traditional commercial sense (i.e., exchanging it for monetary compensation), but to the extent "selling" or "sharing" under the CPRA includes cross-context behavioral advertising, the User has the right to opt-out via the "Do Not Sell or Share My Personal Information" link in the account settings. The User also has the right to request access, deletion, correction, and to non-discrimination for exercising these rights.
International Transfers (Schrems II/SCCs)
Given that the Operator utilizes global hosting and support services, User Personal Data may be transferred to, stored on, and processed in servers located outside the EEA, including in the United States. For such international transfers, the Operator relies upon the EU Commission's Standard Contractual Clauses (SCCs), augmented by appropriate supplementary technical measures (including advanced encryption and pseudonymization), to ensure an adequate level of data protection in compliance with the ruling in Case C-311/18 (Schrems II).
Governing Law, Jurisdiction, and Dispute Resolution
Exhaustive Governing Law
These Terms, their legal nature, formation, validity, interpretation, performance, and enforcement, together with any non-contractual obligations arising from or connected to them, shall be governed by, construed, and enforced in accordance with the substantive laws of the Federal Republic of Germany, to the absolute exclusion of the United Nations Convention on Contracts for the International Sale of Goods (CISG) and without regard to the conflict-of-law provisions of the German Introductory Act to the Civil Code (EGBGB).
Exclusive Place of Jurisdiction for Commercial and Developer Users
If the User is a legal entity, a commercial enterprise, a trader, or a Developer acting within the scope of their professional or business activity (kaufmännischer Verkehr), the User hereby irrevocably accepts and submits to the exclusive jurisdiction of the competent courts located in Stuttgart, Germany, for the resolution of any and all disputes, controversies, or claims arising out of or in connection with this Agreement, thereby waiving any objection based on forum non conveniens or improper venue.
Consumer Forum (B2C)
If the User is a natural person acting exclusively for non-business, private purposes, the above exclusive jurisdiction clause shall not restrict the User's statutory right to bring proceedings before the courts of the User's own domicile. The Operator shall not invoke the exclusive jurisdiction against a Consumer to force litigation away from the Consumer's home jurisdiction unless permitted by applicable procedural rules.
Alternative Dispute Resolution (EU ODR)
The European Commission provides an Online Dispute Resolution (ODR) platform accessible at https://ec.europa.eu/odr. The Operator is neither obliged nor willing to participate in a dispute resolution procedure before a consumer arbitration board (Verbraucherschlichtungsstelle). However, the Operator commits to resolving user complaints directly and amicably through its internal support and legal team.
Force Majeure, Severability, and Waiver
Excused Performance Under Force Majeure
Neither party shall be held liable for any delay or failure in performance of its obligations under this Agreement (excluding the obligation to pay outstanding fees) if such delay or failure is due to causes, circumstances, or events that are beyond the reasonable control of the affected party and which could not have been prevented or mitigated through the exercise of reasonable care. Such force majeure events shall include, but are not limited to: acts of God, earthquakes, floods, fires, pandemics (including COVID-19), government-imposed lockdowns, war, armed hostilities, terrorist attacks, cyberwarfare, denial-of-service attacks targeting internet infrastructure, general internet backbone outages, power grid failures, and labor strikes. The affected party shall provide prompt written notice to the other party and shall take commercially reasonable steps to resume performance as soon as is practicable.
Partial Invalidity and Salvatorian Clause
In the event that any provision of these Terms is determined to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the parties agree that the remaining provisions shall continue in full force and effect. The invalid provision shall be replaced, by operation of law, by a valid, enforceable provision that most closely approximates the commercial, economic, and legal intent of the invalid provision, as permitted under Section 139 BGB and consistent with the principle of "geltungserhaltende Reduktion."
Waiver of Defaults
No failure or delay by the Operator in exercising any right, power, or privilege under these Terms shall be deemed to be a waiver of such right, power, or privilege, nor shall any single or partial exercise thereof preclude any further exercise thereof or the exercise of any other right. A written waiver shall be required for the Operator's waiver to be legally effective.
Notices, Legal Correspondence, and Contact (embedded)
Form of Notices and Delivery
Unless expressly otherwise provided in these Terms, all legal notices, demands, requests, or other formal communications required to be given by the User to the Operator shall be in writing and shall be delivered either: (a) by physical, registered mail with proof of delivery to the Operator's principal place of business; or (b) via electronic mail to the Operator's designated legal and support address. Conversely, the Operator may provide official legal notices to the User by sending an electronic mail to the email address associated with the User's active account, which shall constitute effective delivery regardless of whether the User accesses the message.
Designated Representative and Contact for Legal Matters (DSA/TMG)
The User's primary point of contact for all formal legal matters, including but not limited to the submission of copyright takedown notices under the DMCA, complaints regarding illegal content under the Digital Services Act (DSA), withdrawal requests, consumer law inquiries, data protection subject access requests, and service of process, shall be directed to the Operator's internal legal handling department via the electronic contact support@mail.bookmer.com. This specific contact address serves as the Operator's official designated representative for the purposes of the German Telemedia Act (TMG § 5) and as the legal point of contact for regulatory authorities. The Operator endeavors to acknowledge receipt of all formal legal communications within forty-eight (48) hours and to provide a substantive response within the statutory periods mandated by the relevant regulatory framework (e.g., 30 days for GDPR requests, 15 days for DSA complaints).
User's Duty to Maintain Functional Communication Channel
The User affirmatively agrees and acknowledges that their active, functioning, verified email address is the primary, legally recognized channel for all official communications. The User bears the sole, undivided risk of failing to receive critical legal notifications (including modification notices and account suspension warnings) if they neglect to update their email address, fail to check their spam or junk folders, or allow their mailbox to exceed storage capacity, rendering it incapable of receiving messages. The Operator shall be deemed to have fulfilled its notification obligations upon the successful, non-bounce transmission of an email to the address last provided by the User in their account settings.
BY ACCESSING, BROWSING, REGISTERING, OR OTHERWISE UTILIZING THE BOOKMER ECOSYSTEM, THE USER ACKNOWLEDGES, WITHOUT RESERVATION, THAT THEY HAVE READ, COMPREHENDED, AND UNEQUIVOCALLY CONSENT TO BE BOUND BY THE FOREGOING TERMS, CONDITIONS, AND LEGAL OBLIGATIONS.