AnimeBookmarkTracker

ANIMEBOOKMARK / Privacy Policy

AnimeBookmark Tracker Privacy Policy

This policy explains how 18212520 Canada Inc., operating as AnimeBookmark, handles information when you use AnimeBookmark, AnimeBookmark Tracker, its connected account and API features, and AnimeBookmark Tracker Premium billing.

This policy covers the extension, its sign-in flows, the dedicated https://animebookmark.com/extension-signup/ account-setup page, optional access to supported streaming services, the AnimeBookmark account and API activity the extension creates, and subscription checkout, fulfillment, billing, refunds, and account-management records.

Privacy at a glance

  • Tracking is off by default. You must sign in, review the disclosure, grant optional access to a tracking-ready service, and enable that provider before playback inspection begins.
  • Playback tracking is currently available for eligible anime episodes on Crunchyroll, Netflix, Amazon Prime Video, Disney+, HIDIVE, and Tubi. Every service remains separately optional and off until you enable it.
  • Qualified watch evidence and an account-scoped episode match can update your AnimeBookmark Bookmarks and watched-episode progress only after the viewing session ends and final checks pass.
  • The extension does not request broad browser-history access, Chrome's broad tabs permission, access to every website, or Incognito access.
  • You can disable one provider without disabling another, disable reminders, correct a match, sign out, uninstall, or contact the AnimeBookmark Privacy Officer about access, correction, or deletion.
  • Premium checkout uses Stripe Managed Payments, where customers buy through Link as Merchant of Record. Payment-card details stay with the checkout provider; AnimeBookmark receives and retains the billing identifiers, status, amounts, currency, catalog references, and timing needed to fulfill and administer the subscription.
  • AnimeBookmark does not sell Tracker user data or transfer it to advertising platforms, data brokers, or information resellers.

Identity and scope

18212520 Canada Inc., operating as AnimeBookmark, operates AnimeBookmark, AnimeBookmark Tracker, and AnimeBookmark Tracker Premium. The responsible contact for this policy is the AnimeBookmark Privacy Officer at support@animebookmark.com.

This policy applies when the Tracker signs you in to AnimeBookmark, sends you to its dedicated extension account-setup page, stores extension settings, accesses an enabled tracking-ready streaming-service page, records eligible playback evidence, asks you to confirm an anime or episode, requests the resulting Bookmark and watched-episode update from the AnimeBookmark API, or when you view pricing, begin checkout, manage billing, cancel, or request a refund.

The Tracker's single purpose

The extension does not use this data for general browsing analytics, advertising, profiling, market research, credit decisions, or an unrelated product purpose.

Current streaming-service capabilities

This table is the authoritative public list of provider-specific behavior for this policy. Tracking available means the provider can inspect an eligible anime episode page and create the evidence flow described below only after provider-specific opt-in. A future service does not receive site access or tracking authority merely because it is added to the interface; AnimeBookmark will update the disclosure and require a new user action before a newly supported provider can begin tracking.

Streaming-service availability, optional access, and provider-specific behavior
ServiceStatus in this releaseOptional originProvider-specific behavior
CrunchyrollTracking availablehttps://crunchyroll.com/* and https://www.crunchyroll.com/*After explicit provider consent and access, the packaged bundle is registered across the two exact Crunchyroll origins so it can follow provider navigation. On non-watch routes it can perform passive video and DOM lifecycle checks, but exact watch-route validation prevents metadata collection, a watch session, local evidence, matching, or AnimeBookmark tracking API traffic. On an eligible watch route it can inspect the bounded title, episode, and HTML video fields described in this policy.
NetflixTracking available for anime episodeshttps://www.netflix.com/*After explicit provider consent and access, a URL-only route bootstrap can recognize a transition to an exact numeric /watch/<id> route. The full tracker bundle is injected only on an authorized exact watch route. Episode metadata normally comes from one unambiguous active-player title structure. If same-document navigation removes that structure before guarded injection, the bounded credential-free title-page response described below may recover the exact current Episode-to-Season-to-Show graph with a compatible runtime. Credited playback tracking begins only after one eligible episodic player, explicit anime taxonomy, and unambiguous current-episode metadata pass; conflicts fail closed.
Amazon Prime VideoTracking available for explicitly classified anime episodeshttps://www.primevideo.com/*After explicit provider consent and access, a URL-only bootstrap can wake the authorized tracker on a guarded detail/player route. Because Prime Video's visible URL can remain on a series or previous episode, the adapter derives one exact compact title identity from the active episodic player and bounded title-scoped data rather than trusting the URL. It normally uses current page hydration and, when that hydration is missing, unreadable, or stale and therefore does not support the current playback route, can make one bounded credential-free request to the exact public Prime Video detail page per unchanged eligible live-playback boundary. Tracking begins only when the joined title scope contains either Prime Video's exact Anime genre entry or the exact paired Top anime and #N in Anime TV Shows badges, and all episodic, player, duration, advertisement, live-state, and ambiguity checks pass.
Disney+Tracking available for explicitly classified anime episodeshttps://www.disneyplus.com/*After explicit provider consent and access, the tracker accepts only an exact episode play route whose route, deeplink, series, season, episode, and player fields agree. Exact play-bound taxonomy supplies immediate anime or other classification; only a play response without usable taxonomy may fall back to the bounded, account-scoped exact same-series cache populated by a matching Disney+ series page. A disagreement fails closed. A consent-gated page bridge observes only the bounded structured responses and player Timeline needed for this classification and playback calculation, with exact pre-route response and player-root references retained for at most 10 seconds during same-document Home-to-Play navigation.
HIDIVETracking available for explicitly classified anime episodeshttps://www.hidive.com/*After explicit provider consent and access, the tracker requires an exact numeric /video/<id> route and an exact same-ID episodic VOD response containing the Anime genre value. During same-document navigation from Home, a season page, or a different episode into the requested video, a short-lived page bridge may retain at most eight exact unread response references for up to 10 seconds from settlement, then inspect one only after the exact target route, current lease, and expected single route transition agree. It observes only the bounded VOD response HIDIVE's page already receives, sanitizes the required episode context, and does not make a replacement request or request Chrome access to HIDIVE's API hostname.
TubiTracking available for explicitly classified anime episodeshttps://tubitv.com/*After explicit provider consent and access, a URL-only bootstrap recognizes an exact numeric /tv-shows/<id> episode route. The isolated adapter requires one English episode context, one matching canonical link, one exact Anime category link, and one eligible finite video. It reads only bounded visible page metadata and native playback state; it does not use a page bridge, page hydration state, provider API, cookies, web storage, account data, or media URLs.

AnimeBookmark Tracker is an independent service and is not affiliated with, endorsed by, or sponsored by any streaming service listed in this policy.

Your choices before and during tracking

  • An AnimeBookmark account and sign-in are required before information can synchronize with your account.
  • Provider access is optional and provider-specific. No streaming-service origin is granted at installation.
  • Each tracking-ready provider stays off until you review the in-extension disclosure, affirmatively accept it, grant that provider's exact optional site permission, and enable it.
  • Enable All Tracking requests only the exact current provider options—Crunchyroll, Netflix, Amazon Prime Video, Disney+, HIDIVE, and Tubi—and optional generic desktop reminders in one direct gesture. It creates no wildcard or authority for an unnamed future provider. A provider added in a later release remains off until you take a new action.
  • Choose specific tracking options lets you enable or disable Crunchyroll, Netflix, Amazon Prime Video, Disney+, HIDIVE, Tubi, and desktop reminders independently.
  • Desktop match reminders are optional, require separate Chrome notification access, contain no anime or episode title, and are off by default.
  • Disabling tracking, signing out, or uninstalling clears the applicable local state described below, but it is not a request to delete data already accepted by the AnimeBookmark server.

Data categories handled

The Chrome Web Store treats data as handled when it is collected, transmitted, used, shared, or stored locally. The table therefore includes local-only processing as well as information sent to AnimeBookmark.

Tracker data categories, sources, purposes, and locations
CategorySpecific dataSourcePurposeLocation
Account identityAnimeBookmark user ID, email, display name, and selected avatar URL/sourceYou, your AnimeBookmark account, or your Google basic profileIdentify the correct account, show the profile, and isolate consent, evidence, and matches by accountAnimeBookmark server and restricted extension storage
Subscription and billing recordsAnimeBookmark account ID and email; Stripe Checkout Session, customer, subscription, invoice, payment, refund, and dispute identifiers; status and event timestamps; billed or adjusted amount and currency; product and price catalog references; accepted policy versions and acceptance time; and server-generated internal checkout referencesYou, the AnimeBookmark account and checkout service, and verified Stripe notificationsCreate and secure checkout, associate a purchase with the correct account, provision or revoke Premium access, prevent duplicate fulfillment, provide billing support, process cancellations and refunds, reconcile payments, and meet financial, tax, fraud-prevention, audit, and legal obligationsAnimeBookmark server and Stripe / Link systems. Stripe checkout receives a server-generated internal intent reference to bind the resulting subscription to the correct account; the browser receives only the hosted checkout URL and expiry
AuthenticationPassword submitted for password login; selected sign-in method (password or Google); AnimeBookmark access and refresh tokens; Google subject, email/profile, transient Google token or one-time chooser handoff; session IP and user agentYou, Chrome Identity/Google, and request metadataSign in, maintain sessions, prevent abuse, and protect account accessExtension session/local storage and AnimeBookmark server
Streaming-service browsing contextEnabled provider hostname, provider media ID, sanitized canonical watch URL, and relevant timestampsThe current enabled tracking-ready provider pageIdentify the episode being tracked, bind the correct page, and deduplicate evidenceLocally and, for consented evidence, the AnimeBookmark server
Website and episode contentBounded provider-specific series, season, episode-number, episode-title, document or page title, metadata-confidence label, structured metadata, and safe AnimeBookmark catalog presentationThe current enabled tracking-ready provider page and AnimeBookmark catalogDetermine whether the content is eligible and help the user confirm the correct matchLocally and on the AnimeBookmark server as needed
Netflix anime eligibilityOne consistent title identity, its eligible or ineligible result, the Genres and This show is ... taxonomy labels used to derive that result, optional strict normalized Episode-to-Season-to-Show playback metadata, and an optional title-wide episode scope and count of at most 512; raw HTML, taxonomy groups, and graph data are not persisted or uploadedA credential-free request to the matching Netflix title pageFail closed unless Netflix explicitly classifies the episodic title as anime, and recover strict current-episode or title-scope context when the live player labels are unavailableBounded tab memory for taxonomy and graph processing; normalized recovered episode metadata can enter consented watch evidence and matching, while the optional scope and count enter matching only
Amazon Prime Video anime eligibilityActive episodic player labels, exact compact title identity, title type, episode number, duration corroboration, and either the exact title-scoped Anime genre entry or the exact paired Top anime and #N in Anime TV Shows badges; fetched HTML and full page hydration data are not persisted or uploadedThe enabled Prime Video detail/player page and its already-loaded, size-bounded title data or, when current-route hydration is missing, unreadable, or stale, one credential-free request to the exact public Prime Video detail pageFail closed unless the exact joined episodic title has one of Prime Video's two exact title-scoped anime classificationsBounded tab memory for eligibility; only the resulting bounded episode metadata can enter the consented AnimeBookmark matching and evidence flows
Disney+ anime eligibility and playback contextExact play-route UUID, matching series entity ID, bounded series/season/episode labels, program and stream type, runtime, exact Anime taxonomy classification, ad state, and bounded player TimelineThe enabled Disney+ play response and, only as a fallback, the matching series details classification cache through a consent-gated bounded bridgeFail closed unless exact play-bound Anime taxonomy or its exact same-series cache fallback agrees with the episodic player identities; a disagreement between those classification sources also fails closed. Playback is calculated without treating Disney+'s rolling native video clock as episode progressRestricted account-scoped local fallback cache and bounded tab memory; cache entries expire within 24 hours, may survive an extension reload or update, and are purged at browser startup while the extension is enabled and at the authority boundaries described below. Exact pre-route response and player-root references expire after at most 10 seconds, and full responses, shadow DOM, and player objects are not persisted or uploaded
HIDIVE anime eligibilityExact numeric route and VOD identity, bounded series/season/episode fields, duration, program and stream type, and exact Anime genre classificationThe enabled HIDIVE origin and the exact VOD response its page already receivesFail closed unless the response identity agrees with the exact numeric video route and identifies an eligible episodic anime VODBounded tab memory; at most eight exact unread response references may remain for 10 seconds during same-document navigation. The full response is not persisted or uploaded, while only sanitized episode metadata can enter the consented AnimeBookmark flows
Tubi anime eligibilityExact numeric episode route, matching canonical link, bounded English series and episode headings, exact Anime category link, and one eligible finite videoThe enabled Tubi episode pageFail closed for non-anime, movies, live content, malformed or conflicting metadata, or ambiguous players; suspend credited coverage while a visible advertisement is detectedBounded tab memory; Tubi hydration state, provider API data, cookies, web storage, account data, and media URLs are not read
Playback activityDuration, watched timeline ranges, credited playback time, visible/hidden time, maximum position, bounded seek/pause/stall counts, and session/observation timesThe eligible provider player on the enabled page, including its native HTML video element and, for Disney+, the bounded provider Timeline described in this policyCalculate tracked coverage, reject implausible evidence, and determine whether final checks passLocal journal and AnimeBookmark server after consent
Match activitySuggested candidates, a bounded user-entered anime-title search query, prompt/candidate challenges, confirmation, correction, presentation, retry, and expiry stateYour actions and the AnimeBookmark APISave or correct the account-scoped anime and episode matchLocally and on the AnimeBookmark server as applicable
Bookmark and progress stateProjection status and the resulting Bookmark creation or exact episode watched updateAnimeBookmark APIShow whether a qualified exact match updated your BookmarksAnimeBookmark server and short-lived status locally
Extension settingsTracking-ready provider-enabled choice, consent version/time, setup state, notification preference, activation binding, permission intent, and retry metadataYour choices and the extensionEnforce consent and operate the Tracker safelyRestricted Chrome storage
Network and security dataRequest IP, user agent, timestamps, rate-limit/session/security data, and sanitized error diagnostics when enabledHTTP requests, infrastructure, and backend errorsAuthentication, abuse prevention, security, reliability, and troubleshootingAnimeBookmark server and the service providers listed below

Google Sign-In

  • The extension requests only the openid, email, and profile OAuth scopes.
  • The basic profile information used can include Google's stable subject identifier, email address, display name, and profile image.
  • AnimeBookmark uses this information only to create, identify, link, and authenticate the correct AnimeBookmark account and show the safe account summary.
  • The fast sign-in path can send a short-lived Google access token to AnimeBookmark for validation. The extension and backend do not persist that Google access token.
  • The explicit account chooser uses Google's hosted authorization-code flow with PKCE. The extension receives only a short-lived, single-use AnimeBookmark handoff code. It does not store Google's authorization code, PKCE verifier, access token, or the Web OAuth client secret.
  • Pending OAuth handoff records become eligible for deletion after approximately 10 minutes, ready handoffs after approximately 2 minutes, and consumed handoffs immediately.
  • The extension does not request Gmail, Drive, Calendar, Contacts, or other Google-service content.
  • A Google-hosted avatar can cause a standard image request to Google. This does not grant the extension general browsing access to Google.

Optional streaming-service access and page inspection

Only a supported provider that the signed-in user explicitly enables can run a playback tracker. Packaged provider-specific scripts inspect only the route, lifecycle, bounded page or response data, and playback fields described in this policy. Disney+ and HIDIVE use narrowly bounded page bridges for information their isolated trackers cannot otherwise receive. To start an enabled tracker, the extension can query tabs matching that provider. To stop a provider robustly—including during normal disable, logout, cleanup, or after external permission removal—it transiently enumerates open tab IDs solely to broadcast a provider-qualified stop command. It does not read or retain other tabs' URLs, titles, or content, and it keeps no retained general tab inventory. Incognito operation is not allowed.

The Tracker rejects episode runtimes shorter than five minutes or longer than six hours. Crossing its displayed 80% coverage target is not an automatic watched result; the viewing session must end, every timeline and plausibility check must pass, and an exact account-scoped match must exist before Bookmarks can update.

A detected visible advertisement does not permanently reject an otherwise validated episode. It preserves that exact episode identity only in memory, resets playback continuity, and credits no coverage until eligible content resumes.

Crunchyroll

After Crunchyroll is enabled, its packaged tracker bundle is dynamically registered across only https://crunchyroll.com/* and https://www.crunchyroll.com/* so it can follow the site's navigation lifecycle. On a non-watch route, the bundle can scan for candidate video elements, attach passive video listeners, and observe DOM mutations to detect route or player changes. Exact watch-route validation prevents those lifecycle checks from reading or storing episode metadata, starting a coverage session, creating local evidence or match state, or contacting an AnimeBookmark tracking or mapping API.

On an eligible Crunchyroll watch route, evidence uses a provider media ID and a sanitized canonical watch URL. Query parameters, fragments, credentials, locale, and title slugs are removed. The adapter can read bounded page and Open Graph titles plus series, season, and episode fields exposed in JSON-LD metadata. For matching only, it can derive at most three normalized numeric episode hints from those bounded labels. These hints do not enter the watch-evidence journal.

Netflix route handling

Netflix can change from Browse to Watch without loading a new document. After Netflix is enabled, a small isolated route bootstrap on the exact Netflix origin reads only location.href in memory to distinguish an exact numeric /watch/<id> path from every other route. It ignores query parameters and fragments and sends the service worker only a fixed provider/version wake-up. It does not send the URL or media ID and does not inspect the Browse-page DOM, title, video, profile, account data, cookies, or other page content.

The service worker independently rechecks the signed-in account, Netflix consent and activation, optional site grant, top-level non-Incognito sender, and current exact watch route before it can inject or repair the full tracker. Leaving the watch route, disabling Netflix, signing out, removing permission, or provider cleanup stops or resets that route handling.

Netflix anime eligibility request

An exact Netflix watch route alone is not enough to start tracking. Episode metadata normally comes from one unambiguous active-player title structure. The Netflix adapter also makes a bounded HTTPS GET request to https://www.netflix.com/title/<watch-id> and follows only a consistent Netflix title identity.

The Netflix eligibility request

  • Omits cookies and other credentials
  • Sends no referrer
  • Bypasses the browser cache
  • Asks only for HTML
  • Is time-bounded and size-bounded
  • Is processed locally to read one consistent title-metadata group containing Netflix's Genres and This show is ... taxonomy labels and, when available, one strictly bounded public Episode-to-Season-to-Show graph

Tracking starts only when that taxonomy explicitly classifies the title as anime. The bounded title response may also recover normalized current-episode metadata from one exact Episode-to-Season-to-Show graph when visible player labels are unavailable, and it may prove a title-wide episode scope and count only from one complete, conflict-free 1-through-N enumeration with no season or part controls. Raw HTML, taxonomy groups, and graph data are discarded and are not uploaded. Only normalized episode metadata may enter watch evidence and matching; the optional scope and count enter matching only. Bounded normalized records remain in tab memory. An unresolved lookup or graph recovery may retry no sooner than 30 seconds, while pending, malformed, oversized, ambiguous, conflicting, or explicit non-anime results fail closed. No playback card, credited coverage, match request, local watch journal entry, or AnimeBookmark watch API traffic is created for a rejected interval, and time observed while classification is pending is not backfilled.

Because this is a direct request to Netflix, Netflix necessarily receives the requested title-page path and ordinary network information such as the device's IP address and user agent. The request does not include an AnimeBookmark account identifier, AnimeBookmark token, watch evidence, match choice, or referrer.

Netflix tracking additionally requires one eligible player and unambiguous current-episode metadata from either the active-player title structure or the exact recovered graph. It rejects movies, live playback, previews, trailers, explicit non-anime titles, incompatible runtimes, and ambiguous or multiple-player states, and suspends evidence credit while a visible advertisement is identified.

Amazon Prime Video

After Prime Video is enabled, a URL-only bootstrap on the exact Prime Video origin can recognize a guarded detail/player route and wake the trusted service worker without sending the URL or media identity. The service worker rechecks the account, consent, activation, optional host grant, sender, and current route before injecting or repairing the full tracker.

Prime Video's single-page application can leave the visible URL on a series or previous episode. The adapter therefore selects one exact active episodic player, joins its bounded visible labels to one exact title-scoped hydration entry, and derives the compact provider media identity from that join. Anime classification requires either an exact Anime genre entry or the exact paired Top anime and #N in Anime TV Shows badges within that same title scope. Generic animation labels, incomplete or unrelated ranking text, recommendation data, movies, live titles, trailers, previews, specials, unresolved joins, conflicting classifications, and ambiguous players fail closed.

The adapter normally uses bounded hydration already loaded on the page. If current-route hydration is missing, unreadable, or stale and therefore does not support the current playback route, it may make at most one HTTPS GET request to the exact public https://www.primevideo.com/detail/<id> page for that unchanged eligible live-playback boundary. That boundary includes the route, document, player, video, duration, visible metadata, advertisement state, and live-status evidence. The request omits credentials and cookies, sends no referrer, bypasses stored caches, rejects redirects, stops after eight seconds, and accepts no more than 10 MiB. It requires the byte-exact response URL, HTML content, one inert JSON hydration script, and the same strict player, episode, duration, type, advertisement, identity, and anime-classification agreement. Fetched markup is never executed. The raw HTML and parsed hydration are discarded after local evaluation, and a success or failure cannot start another request until one of those eligible live-playback boundary components changes.

Because this recovery is a direct request to Prime Video, Prime Video necessarily receives the requested public detail-page path and ordinary network information such as the device's IP address and user agent. The request does not include an AnimeBookmark account identifier, AnimeBookmark token, watch evidence, match choice, cookies, credentials, or referrer.

Disney+

After Disney+ is enabled, a packaged route bootstrap and consent-gated page bridge operate only on the exact Disney+ origin. Playback can qualify only on a lowercase UUID /play/<id> route whose ID matches the deeplink action, whose deeplink and player records agree on the series title and structured season and episode labels, and whose program type, stream type, and runtime independently pass the eligibility checks. Exact play-bound taxonomy supplies immediate anime or other classification; the matching series cache is used only when that play response has no usable taxonomy, and disagreement between both sources fails closed. The bridge observes only bounded structured Disney+ responses and the exact player Timeline, ad, and progress components needed for eligibility and credited coverage. For same-document Home-to-Play ordering, only exact allowlisted response and player-root references may cross into the exact play route, and they expire after at most 10 seconds. Full responses, shadow DOM, and player objects are not persisted or uploaded.

A supported play-bound genre list containing the exact case-sensitive Anime value is immediate anime authority; the same supported shape without Anime is other. When that play response has no usable taxonomy, the adapter may fall back only to a restricted account-scoped cache populated by the enabled exact same-series Disney+ page. The cache holds at most 32 series classifications for up to 24 hours in restricted account-scoped local storage. It may survive an extension reload or update during the same Chrome run, but is purged at browser startup while the extension is enabled and is also cleared on Disney+ disable or permission loss, logout or account replacement, migration, or environment reset. A series-page visit is therefore an optional fallback rather than a direct or Continue Watching prerequisite. Missing classification, a play/cache conflict, unsupported locale or label shapes, movies, live content, stale data, and ambiguous players fail closed.

HIDIVE

After HIDIVE is enabled, a URL-only bootstrap recognizes only an exact numeric /video/<id> route. A short-lived consent- and activation-gated page bridge observes only the exact VOD response HIDIVE's page already receives. During same-document navigation from Home, a season page, or a different episode into the requested video, it may retain at most eight exact response references for 10 seconds from settlement without reading their bodies off-route, and inspect one only after its numeric media ID matches the exact target video route under the current lease and expected single route-generation transition. Wrong-target, churned, expired, overflowing, stopped, or lease-invalid references are discarded. The extension does not request Chrome host access to HIDIVE's API hostname and does not issue a replacement request.

The inspected response is size- and traversal-bounded and must identify an on-demand episode at least five minutes long with exact Anime genre classification. Only a fixed sanitized episode context crosses to the isolated tracker; the full response is not persisted or uploaded. If HIDIVE tracking is enabled only after an episode has already loaded, the user may still need to reload the episode or reopen it from its season page because the bridge does not refetch a response it missed before installation. Non-anime, movies, live content, previews, stale routes, malformed responses, and ambiguous players fail closed.

Tubi

After Tubi is enabled, a URL-only bootstrap on https://tubitv.com/* recognizes only an exact numeric /tv-shows/<id> episode route and sends a fixed provider/version wake-up without sending the URL or media ID. The service worker rechecks the current account, consent, activation, permission, sender, and route before injecting or repairing the full tracker.

The Tubi adapter requires one exact English episode context: a unique series heading, an exact season-and-episode heading, a matching canonical link, an exact same-origin Anime category link, and one visible finite video from five minutes through six hours. It does not read page hydration globals, cookies, browser storage, provider account data, request or response bodies, provider APIs, or media URLs. Series landing pages, movies, live channels, missing or non-Anime classification, malformed or conflicting headings, multiple plausible videos, and short videos fail closed.

Data not read from provider pages

The Tracker does not read provider login credentials, cookies, form values, DRM data, CDN or media-resource URLs, advertising identifiers, or unrelated browsing history or website content. It does not capture, persist, or upload full DOM snapshots from signed-in provider pages. As disclosed above, Netflix transiently parses bounded credential-free title-page response data for taxonomy and a strictly bounded public graph, with unresolved recovery requests separated by at least 30 seconds; Prime Video reads bounded title-scoped data already loaded in its page or, when current-route hydration is missing, unreadable, or stale, transiently parses one bounded credential-free public detail-page HTML response; Disney+ observes bounded classification and player data; and HIDIVE observes one exact bounded VOD response the page already receives. The full source responses and unbounded page data are not persisted or uploaded; only the bounded derived fields disclosed in the storage and transmission sections may be retained or sent. Tubi uses bounded DOM and native playback state without a provider response or API request.

Data stored by the extension

Trusted extension contexts use chrome.storage.session and restricted chrome.storage.local. Passwords are never stored in extension storage. Chrome local storage is not described as end-to-end encrypted or automatically encrypted at rest.

Local extension retention and capacity bounds
Local itemRetention or bound
AnimeBookmark access tokenBrowser session in chrome.storage.session
Rotating refresh tokenRestricted local storage until logout, revocation, expiry, account replacement, or environment reset
Minimal account summary and selected sign-in methodRestricted local storage until logout, account replacement, or environment reset
Tracking-ready provider enable intentHeld in trusted session storage for up to 5 minutes and bound to the exact account, environment, and requested provider; cleared on success, denial cleanup, failure, disable, logout/account change, migration, or expiry
Desktop reminder preference and enable intentAccount-scoped restricted local storage. The enable intent expires after 5 minutes. The preference remains until reminders are disabled, notification permission or state is cleaned up, all tracking is disabled, logout or account cleanup, environment reset, Chrome clears extension data, or the extension is uninstalled
Tracking-ready provider choice and consentAccount/provider scoped until disable, logout/account change, re-consent/reset, or environment reset as applicable
Activation IDRecreated for each enablement and used to reject stale trackers. A content tracker receives only its opaque provider activation binding and never the AnimeBookmark account ID
Disney+ fallback classification cacheRestricted account-scoped local storage; maximum 32 exact series entries and 24 hours. Each entry contains only a Disney series entity UUID, bounded series title, anime or other classification, and observation time. It may survive an extension reload or update, is purged at browser startup while the extension is enabled, and is cleared on Disney+ disable or permission loss, logout or account replacement, migration, or environment reset
Unsent watch-evidence journalUp to 7 days; maximum 25 live sessions and 1 MiB serialized data
Last successful watch-evidence sync timeOne account-scoped timestamp in restricted local storage, used only for the popup's Last synced status. It remains until the last tracking-ready provider is disabled or shared watch-session state is otherwise cleared by all-tracking, logout or account, or environment cleanup, Chrome data clearing, or uninstall
Legacy local completion display records from version 0.2 upgradesAn upgraded installation may retain at most one last-activity record and up to 50 pending completion records. A record can include an opaque random activity ID, provider ID and service label, source URL, bounded series, episode and document titles, metadata-confidence label, duration, completion ratio, detection time and status, and a derived deduplication fingerprint. Current versions do not append or upload these records and use only the most recent retained record for legacy activity display. They have no automatic time-to-live while their provider remains supported and can remain after provider disable or sign-out; they are removed when the provider is retired or explicitly reset, when Chrome clears the extension's data, or when the extension is uninstalled
Match and prompt stateMaximum 80 media records plus 160 displayed-session markers, with a combined 256 KiB limit. A pending or recoverable lookup record may retain at most three normalized mapping-only episode-number hints with fixed source categories. For Netflix, a short-lived pending prompt may also retain the fixed title-wide scope with a count from 1 to 512 and/or the fixed repeated-series active-overlay attestation. These mapping-only fields never enter the watch-session journal or confirmed mapping. A user-entered anime-title search query of 2 to 80 characters is retained only with that short-lived prompt state. A display marker contains only the provider, provider media ID, random playback-session ID, display timestamp, and a Boolean indicating whether that session finished the prompt and may show Manage episode match. The Boolean contains no match choice. Match records and markers are pruned after 30 days; short-lived prompt data, search query, and candidate challenges expire after 20 minutes
Projection-status presentation cacheUp to 15 minutes; maximum 25 records. The popup receives only the fixed version and status, not internal account, session, catalog, mapping, or source-URL identifiers
Popup setup completionAn account-scoped version number and completion timestamp in restricted local storage. It can remain across ordinary provider disable, provider migration, and sign-out so the same account does not repeat setup, until environment reset, Chrome data clearing, or uninstall
Enable All Tracking aggregateNo global enableAll choice or future-provider authority is stored; the aggregate button is derived from current tracking-ready provider and reminder choices

Chrome storage is limited to trusted extension contexts. Rebuilding the same installation for a different API environment triggers a fail-closed reset that removes authentication, provider consent, optional site access, and unsent evidence before the new environment is trusted.

Data sent to AnimeBookmark

Authentication and profile

  • The extension's Create account link opens https://animebookmark.com/extension-signup/ in a separate browser tab. Registration remains a first-party AnimeBookmark website flow rather than collecting a new password inside the extension.
  • That dedicated page and its password-registration, email-verification, and Google account-creation requests do not initialize or send events through AnimeBookmark's Google Analytics, Reddit, or X marketing integrations; do not create or update AnimeBookmark marketing-analytics or ad-attribution identifiers; do not call AnimeBookmark's site-event endpoint; and suppress backend advertising auth-conversion events. This suppression remains tied to a pending password registration through email verification.
  • Google's operational identity resources may still load when you choose Continue with Google, and Resend processes the verification email when password registration requires verification. These providers are used only for the account functions described in this policy.
  • Password login sends the email address and password to the AnimeBookmark API over HTTPS solely to authenticate. The extension does not store the password, and the backend stores a salted one-way password hash instead of plaintext.
  • Google login sends only the transient authentication material and basic profile identity described above.
  • AnimeBookmark issues its own session tokens and may store a hashed refresh-token record with session IP address and user agent for session security.
  • The popup can request the current safe profile summary and selected avatar.

Watch evidence

  • Only after the current tracking-ready provider's disclosure is accepted can the extension create or send cumulative checkpoint and finalization snapshots.
  • No watch snapshot is journaled before 30 credited playback seconds.
  • The ordinary first checkpoint is at 60 credited seconds; a qualifying lifecycle finalization may be journaled after the 30-second floor. Later cumulative checkpoints may follow.
  • Uploads can contain schema, qualification-policy, and tracker versions; provider, provider-media, playback-session, and revision identity; the sanitized canonical watch URL; duration and exact watched ranges; bounded series, season, episode-number, episode-title, document-title, and metadata-confidence fields; visible and hidden playback totals; maximum position; bounded seek, pause, and stall counts; session and observation timestamps; and, for terminal snapshots, a bounded finalization reason.
  • The API binds each request to the authenticated AnimeBookmark account and independently calculates qualification. The extension never sends a completed Boolean, client-selected catalog IDs, or a command to toggle a Bookmark.
  • Raw playback-rate samples, cookies, form values, DRM data, and unrelated page content are not uploaded.
  • Uploads are authenticated and account-linked. Failed deliveries can remain in the bounded local journal and retry with controlled backoff until success, expiry, or a permanent rejection.

Episode matching

  • After 30 seconds of unique credited coverage, the extension can request an account-scoped mapping suggestion independently of its watch-evidence checkpoints.
  • The suggestion request contains provider, media, and session identity, duration, and bounded provider-detected episode metadata. Crunchyroll can include at most three normalized mapping-only episode-number hints with fixed source categories. Netflix can include one normalized mapping-only episode-number hint from its bounded current-episode metadata, whether proven by the active-player title structure or the exact recovered graph. After strict live proof, Netflix can additionally include a fixed title-wide episode scope with a count from 1 to 512 and/or a fixed repeated-series active-overlay context; those Netflix fields are used only for matching and never enter the watch-session journal. Netflix, Amazon Prime Video, Disney+, HIDIVE, and Tubi are accepted only after their strict provider-specific episodic and anime gates pass. The request does not contain raw watched ranges, coverage metrics, the source URL, cookies, raw Netflix or Prime Video HTML or full hydration data, Disney+ classification-cache entries, raw HIDIVE responses, raw or unbounded Tubi page content or Tubi account data, or client-supplied catalog IDs.
  • You can send a 2-to-80-character anime-title query to search for alternatives; the extension keeps it only with the short-lived prompt state. You can confirm a match, correct a match later, or close the prompt without sending a decision. Closing does not stop tracking or watch-data delivery, and the extension does not use prompt-frequency or per-episode snooze timers.
  • After you finish the displayed prompt, Manage episode match appears separately below the tracking card for that exact playback session. Clicking it opens the side-panel manager. If the short-lived review challenge has expired, that click can request a fresh passive challenge only after the extension revalidates the same account, activation, document, provider media, and playback session; popup polling does not refresh it.
  • An exact confirmation saves the selected anime and episode for your account.
  • If the anime is known but the exact episode is absent, the server stores a catalog-pending anime identity. It does not fabricate an episode or update your Bookmarks until an exact episode can be verified.
  • Your choice remains account-scoped. It does not become a global provider mapping or change another user's data.

Bookmark and watched-episode actions

Only new, consented, finalized evidence that passes server qualification and has an exact account-scoped match is eligible for library projection. The backend can idempotently add the anime to your AnimeBookmark Bookmarks if needed and mark only the exactly matched episode as watched. Rewatch evidence remains distinct while the canonical Bookmark and watched state stay deduplicated. The extension does not send an unrestricted client command to toggle arbitrary Bookmarks or watched state.

Optional desktop notification

Desktop match reminders are optional, off by default, and require separate Chrome notification permission. The desktop notification is generic and does not contain the anime or episode title; those details appear only after you open the extension's review interface. Your operating system may display a notification on the lock screen.

Data the Tracker does not handle

  • Broad Chrome browsing history, other tabs' URLs, titles, or content, or a retained general tab inventory
  • Incognito activity
  • Provider or Google passwords read from web pages
  • Captured, persisted, or uploaded full DOM snapshots from signed-in provider pages, or unrelated provider content; the separately disclosed Netflix title-page HTML, Prime Video title-scoped page data and public detail-page HTML, Disney+ bounded response/player data, and HIDIVE VOD response are handled only within their stated local bounds and are not uploaded as full responses
  • Gmail, Drive, Calendar, Contacts, or other Google-service content
  • Precise GPS location, payment-card details handled by AnimeBookmark, health information, or personal communications; card and payment-instrument details entered during checkout are sent directly to the checkout provider, Stripe
  • Personalized advertising profiles or data-broker transfers
  • Remote executable code

Password login does transmit the password you enter to AnimeBookmark over HTTPS for authentication. The extension does not store it and does not read passwords from supported streaming-service pages.

Permissions and host access

Why the extension requests each permission or host
Permission or accessReason
storageStores the AnimeBookmark session, account-scoped supported-provider choices and consent, the bounded Disney+ classification cache, bounded unsent evidence, match state, and small setup, retry, and presentation records
identitySupports Google authentication using only openid, email, and profile
scriptingRegisters or injects only packaged provider-specific tracking scripts after a supported provider is enabled, consented, and granted exact site access; fetched provider HTML is parsed only as inert data and never executed, while Disney+ and HIDIVE also use the bounded packaged page bridges described in this policy
alarmsSchedules bounded delivery, retry, expiry pruning, registration recovery, match maintenance, and short progress-status follow-ups
sidePanelShows user-invoked alternate candidates and match-correction controls bound to the currently detected episode
https://api.animebookmark.com/*Supports AnimeBookmark authentication, profile, watch evidence, matching, and Bookmark-update status
Exact optional streaming originsIncludes only https://crunchyroll.com/*, https://www.crunchyroll.com/*, https://www.netflix.com/*, https://www.primevideo.com/*, https://www.disneyplus.com/*, https://www.hidive.com/*, and https://tubitv.com/*. Each exact origin supports only the explicitly enabled provider behavior described in the capability table, including the bounded same-origin Netflix and Prime Video public-page requests disclosed above. No origin is granted at installation, and no wildcard access to unrelated websites is requested.
Optional notificationsShows a generic match-ready reminder after separate opt-in; off by default

You can remove optional site and notification access through the extension controls or Chrome's extension settings. Removing access stops the corresponding local feature but does not delete server data already accepted by AnimeBookmark.

Sharing and service providers

Organizations that may process Tracker-related data
Recipient or providerLimited purpose
AnimeBookmark APIFirst-party account, authentication, watch-evidence, matching, Bookmark-update, support, security, and operations processing
VultrVPS hosting for the API, background workers, and self-hosted MongoDB
CloudflareDNS, API proxy and security services, Cloudflare Pages, R2 object storage/CDN, and associated edge request/security metadata
GoogleGoogle Sign-In, OAuth identity services, and optionally hosted profile-image delivery
Google WorkspaceDelivery and handling of support, privacy, and deletion-request email sent to support@animebookmark.com
ResendAccount-verification and password-reset email delivery
Stripe Managed Payments / LinkManaged Payments checkout and Merchant of Record services through Link, including payment instruments, applicable tax, receipts, recurring billing, transaction support, cancellations, disputes, and returns; Stripe sends verified billing updates needed to connect purchases to an AnimeBookmark account and administer Premium access
SentrySanitized application-error monitoring, including error details, stack traces, query-free routes, runtime information, response status, and an internal account identifier
NetflixServes the credential-free title-page request or bounded recovery retries used locally for anime eligibility and strict current-episode or title-scope recovery; receives the title-page path and ordinary network metadata, but no AnimeBookmark account data, token, watch evidence, match choice, cookies, credentials, or referrer
Amazon Prime VideoServes the credential-free public detail-page recovery used locally when Prime Video's current-route hydration is missing, unreadable, or stale; receives the requested detail-page path and ordinary network metadata, but no AnimeBookmark account data, token, watch evidence, match choice, cookies, credentials, or referrer
Legal or security recipientsDisclosure only when required by law or reasonably necessary to investigate abuse or security incidents

MongoDB is self-hosted on Vultr, so MongoDB Inc. is not a separate data recipient for the production application database. The selected billing provider receives the account email and checkout information needed for the purchase. Payment-card details stay with Stripe and are not stored by AnimeBookmark. Streaming services do not receive the watch evidence sent to AnimeBookmark. The direct Netflix eligibility and strict metadata-recovery request or bounded retries, and the Prime Video missing, unreadable, or stale current-route hydration recovery request, are limited to the credential-free behaviors described above. Disney+ and HIDIVE bridges observe only bounded responses their pages already receive, and Tubi makes no provider classification request. None of these mechanisms sends AnimeBookmark account data, match choices, or watch evidence to those streaming services.

Limited Use commitments

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
AnimeBookmark Tracker's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • User data is used only to provide, maintain, secure, or improve the Tracker's single purpose.
  • Transfers occur only when necessary for that purpose, security or abuse prevention, legal compliance, or a merger or acquisition with consent required by Chrome policy.
  • User data is not sold or transferred to advertising platforms, data brokers, or information resellers.
  • User data is not used for personalized, retargeted, or interest-based advertising.
  • User data is not used for creditworthiness or lending.
  • Humans do not read user data except with your specific consent for support, for security or abuse investigation, to comply with law, or in permitted aggregated or anonymized internal operations.

Security safeguards

  • HTTPS/TLS protects user-data transmission in transit.
  • Passwords are not stored in the extension, and backend password records use a salted one-way hash.
  • AnimeBookmark access and refresh tokens are separated between session and restricted local Chrome storage.
  • Refresh-token records are hashed on the server.
  • Stripe Checkout Session identifiers and internal checkout references are retained server-side to verify ownership and reconcile billing events. Payment-card and payment-instrument details are collected and secured by Stripe rather than AnimeBookmark.
  • Account, provider, consent, environment, activation, and request-sender checks help prevent cross-account or stale-context use.
  • Local journals and caches have capacity and time bounds.
  • Streaming-site access is optional, exact, and provider-specific; the extension does not request <all_urls>.
  • Canonical evidence URLs are reduced to each provider's strict watch identity: Crunchyroll removes query strings, fragments, credentials, locale, and title slugs; Netflix uses only a numeric https://www.netflix.com/watch/<id> URL; Prime Video uses only an exact compact title identity at https://www.primevideo.com/detail/<id>; Disney+ uses only a lowercase UUID at https://www.disneyplus.com/play/<id>; HIDIVE uses only a numeric https://www.hidive.com/video/<id> URL; and Tubi uses only a numeric https://tubitv.com/tv-shows/<id> URL without its live slug, query, or fragment.
  • The Netflix title-page eligibility and strict metadata-recovery request is HTTPS, credential-free, no-referrer, cache-bypassing, time-bounded, and size-bounded. Taxonomy and one strictly bounded public graph are parsed only as inert data and never executed; unresolved recovery retries are separated by at least 30 seconds.
  • The Prime Video missing, unreadable, or stale current-route hydration request is HTTPS, credential-free, no-referrer, no-store, redirect-rejecting, limited to one attempt per unchanged eligible live-playback boundary—including route, document, player, video, duration, visible metadata, advertisement state, and live-status evidence—and bounded to eight seconds and 10 MiB; it accepts one inert JSON hydration script from the exact public detail response and never executes fetched markup.
  • Prime Video title-scoped page data, Disney+ structured responses and player Timeline, and the HIDIVE VOD response are size- or traversal-bounded and processed locally without uploading the full source data. Disney+ same-document pre-route handoff retains only exact allowlisted response and player-root references for at most 10 seconds. HIDIVE may retain at most eight exact unread VOD response references for 10 seconds from settlement and inspect one only after the exact same-ID target video route, current lease, and expected single route transition agree. Tubi uses bounded visible DOM metadata and no provider API or page bridge.
  • Executable JavaScript is packaged with the extension. Remote responses are processed only as data and are not executed as code.
  • API authorization controls associate Tracker data with the authenticated account.
  • Sentry reporting is configured to exclude or scrub request bodies, headers, cookies, query strings, IP addresses, emails, usernames, and credential-shaped fields.

No storage or transmission system is perfectly secure. AnimeBookmark does not claim end-to-end encryption, verified encryption at rest, absolute security, or anonymous watch evidence.

Retention

Local extension retention

The local limits in Data stored by the extension apply. Disabling a supported provider clears that provider's current local consent, activation, unsent watch-evidence journal, match, projection, and presentation state for the account; Disney+ disable also clears its bounded account-scoped local classification cache. Signing out clears the local AnimeBookmark session and applicable current account-scoped tracking state. As separately disclosed above, version 0.2 completion-display records already present on an upgraded installation can remain locally after provider disable or sign-out; current versions do not append or upload them.

Server and infrastructure retention

  • Account-linked watch evidence, quota counters, confirmed and pending episode mappings, library-projection records, refresh-session security records, and related operational records currently have no automatic expiration. They remain until the account is permanently deleted or AnimeBookmark adopts a different verified retention rule.
  • Customer, subscription, transaction, adjustment, refund, checkout-intent, webhook-delivery, reconciliation, and related billing records may be retained for the period reasonably required for subscription administration and applicable financial, tax, fraud-prevention, dispute, audit, security, and legal obligations. Some records cannot be deleted on request while those obligations apply.
  • Application, PM2, Nginx, Cloudflare, and Sentry records do not currently share one fixed automatic expiration period. They may remain until infrastructure rotation, provider-configured expiration, or manual deletion.
  • Technical logs may include IP address and user-agent information, request time, method, query-free route or URL, response status/size/time, rate-limit and security events, error messages, and stack traces.
  • Manual MongoDB backups do not follow a fixed schedule or guaranteed automatic deletion period. Backup data remains until the applicable archive is manually deleted or replaced.
  • Disabling tracking, signing out, or uninstalling is not a server deletion request. A Bookmark update already authorized by uploaded finalized evidence may finish after local tracking is disabled.

User controls, access, correction, and deletion

Tracker controls and their effects
ControlEffect
Disable a tracking-ready providerStops that provider's trackers, unregisters its scripts, attempts to remove its optional site permission, and clears its current consent plus unsent watch-evidence and match state for that account without disabling another provider. It does not delete uploaded server records or pre-existing version 0.2 legacy completion-display records.
Disable all trackingAttempts each tracking-ready provider's normal cleanup and reminder cleanup, preserving authentication, server-acknowledged evidence, confirmed mappings, and completed Bookmark and watched updates.
Disable desktop remindersClears the preference and reminder state. Chrome permission removal is best effort.
Correct a matchFuture eligible Bookmark updates use the confirmed replacement. Already-saved watched progress is not automatically undone.
Sign outClears the local AnimeBookmark session and current account tracking state and attempts backend token revocation. It does not delete uploaded watch evidence or mappings, and pre-existing version 0.2 legacy completion-display records can remain locally as disclosed above.
UninstallRemoves the extension from Chrome but does not send a server-deletion request.
Request access, correction, or deletionEmail support@animebookmark.com from the address associated with your account. AnimeBookmark may request additional information to verify ownership.

Permanent account deletion is completed administratively rather than through a self-service account button. Verified deletion removes the live AnimeBookmark account, refresh sessions, Bookmarks and sharing state, watched progress, pending Bookmark imports, announcement-read receipts, extension watch evidence and quotas, confirmed and pending mappings, and library-projection records, subject to the billing, security, audit, backup, and legal exceptions below.

Deletion exceptions

  • A limited administrative deletion or audit record containing the deleted account ID and email may remain for security and accountability and currently has no automatic expiration.
  • Customer, subscription, checkout, transaction, adjustment, refund, webhook, tax, fraud-prevention, dispute, and other financial or audit records may remain when AnimeBookmark or the applicable billing provider must retain them for legitimate business or legal obligations; deletion of an AnimeBookmark account does not require Stripe or Link to erase records they independently must keep.
  • Request, security, diagnostic, provider-email, and support records may remain according to their applicable retention.
  • Manual backups may retain deleted data until the applicable archive is manually deleted or replaced.
  • A separately created newsletter subscription is not automatically removed by account deletion and requires its own unsubscribe or removal action.

Revoke Google authorization

You can review and revoke AnimeBookmark's Google connection from your Google Account's third-party connections page. Signing out of the extension is not necessarily the same as revoking Google authorization, and revoking Google authorization does not delete AnimeBookmark server data.

Children and audience

AnimeBookmark Tracker is not directed to children under 13, and AnimeBookmark does not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information through the Tracker, contact the AnimeBookmark Privacy Officer so the situation can be reviewed.

Changes to this policy

This page shows the current Last updated date. Material changes will be described or communicated before a new use begins where required. If extension data use changes, AnimeBookmark will update the in-extension prominent disclosure and consent version before collecting or using data under the changed practice.

AnimeBookmark works to keep this policy, the extension interface, Chrome Web Store listing and privacy declarations, Google OAuth consent configuration, and runtime behavior consistent.

Contact