Version 1.14, 27 September 2026. Applies to Crib 1.28.10.
Crib runs on your machine. There is no Crib server, no account, no sign-up, no analytics, no advertising, and no telemetry. We — Iron Kennel, the publisher — receive nothing from your copy of Crib. Not your holdings, not your addresses, not a crash report, not a count of how often you open it.
With one exception, and it only happens if you ask for it: if you press Updates, Crib asks where the installer is published whether a newer version exists. That request tells that host a copy of Crib is running at your address, right now, at your version — the same thing any download tells any website. Nothing about your holdings is sent, and it never happens on a schedule. You are asked before the first check, the host is named at the time, and you can withdraw it. If you never press it, we still have no way to know you are using Crib.
This document says exactly what that does and does not cover, because "local only" on its own would be a slogan rather than a disclosure.
What never leaves your machine
- Your holdings, quantities, costs, lots, sales and transfers.
- Your notes, tags, drawers, targets and card arrangement.
- Your realised and unrealised profit and loss.
- Any CSV you import.
- Your backups.
None of this is transmitted anywhere by Crib, with the single exception of Telegram alerts if you turn them on — see below.
Crib never asks for, and cannot store, a private key or a seed phrase. It has no ability to move funds or place an order. It reads public information only.
What does leave your machine, and when
Crib is a price and blockchain reader, so it makes requests to public services. Every one of them is listed here.
Price lookups — always, whenever prices refresh
| Host | What is sent | Why |
|---|---|---|
api.coingecko.com |
coin identifiers (e.g. ethereum) |
prices for listed coins |
api.geckoterminal.com |
token contract addresses | prices for on-chain tokens |
api.dexscreener.com |
token contract addresses | ranking and pool data |
coins.llama.fi |
contract addresses, and dates for past prices | what a token was worth on a past date, and a second opinion on what it is worth now |
api.frankfurter.dev |
nothing about you — asks what a dollar is worth | converting the desk into your own currency |
These requests carry which coins you are interested in, but not your wallet address, not your quantities, and not what you paid. Be aware that the set of coins you hold is itself distinctive — a service that sees it repeatedly could in principle treat it as a fingerprint.
Wallet reads — only when you ask, or when you open Crib with that setting on
If you add a watched wallet, Crib sends that wallet address to the services for its chain. Crib asks for your agreement before the first such request, and names the hosts at the time. You can withdraw that agreement, which stops all of it.
| Chain | Hosts that receive your address |
|---|---|
| Ethereum, Base, Arbitrum, Polygon, Unichain | *.blockscout.com, *-rpc.publicnode.com |
| Optimism | explorer.optimism.io (Optimism's Blockscout, on its own domain), optimism-rpc.publicnode.com |
| zkSync Era | zksync.blockscout.com, mainnet.era.zksync.io |
| Scroll | scrollscan.com, scroll-rpc.publicnode.com |
| Avalanche, Blast | api.routescan.io, *-rpc.publicnode.com |
| BNB Chain, Linea, Berachain (coin, and coins already on your desk) | bsc-rpc.publicnode.com, linea-rpc.publicnode.com, berachain-rpc.publicnode.com |
| Robinhood Chain (coin, every coin sent to the address, and history) | robinhood-rpc.publicnode.com, rpc.mainnet.chain.robinhood.com (Robinhood's own public node, for the coins sent to the address and for history) |
| PulseChain | api.scan.pulsechain.com, pulsechain-rpc.publicnode.com |
| Solana | api.mainnet-beta.solana.com |
| Tron | api.trongrid.io |
| Sui | sui-rpc.publicnode.com |
| TON | tonapi.io |
| Bitcoin | blockstream.info, mempool.space |
| Litecoin | litecoinspace.org |
| Dogecoin | api.blockcypher.com |
| XRP | xrplcluster.com, s1.ripple.com |
| Cardano (coin only) | api.koios.rest |
"Check every chain" asks all of the EVM rows above at once, so one press sends your address to every host in them. That is a bigger disclosure than watching a single chain, and it is why the consent screen names all of them rather than only the chains you already watch.
Reading a wallet's contents also prices what it finds, so api.dexscreener.com
and api.geckoterminal.com receive the contract addresses of tokens in it.
On BNB Chain, Linea and Berachain nothing free can list an address's tokens, so Crib asks that chain's node about each coin already on your desk for that chain, one contract at a time, alongside your address. The node learns which of those coins you are checking, which it could see anyway from the balances.
On Robinhood Chain, Crib asks Robinhood's own public node for every token
transfer ever sent to your address -- the only free way to find the coins it
holds -- and then asks robinhood-rpc.publicnode.com for your balance of each.
Past prices for coins on that chain come from api.geckoterminal.com (which
receives the coin's contract address, never yours).
Crib does not poll. It does not read your wallets on a timer. It reads them when you press the button, and — only if you switch this on — when you open the app. That setting is off by default and can be turned off again at any time. The reasoning is that opening the app is a moment you chose; a schedule is not.
The Yard — your NFTs and game items, only when you press "Read my wallets"
The Yard reads the same watched wallets from the same hosts in the table above, so no new service learns your address. Two things are new:
- Star Atlas's item list, from
galaxy.staratlas.com. It is one public file, the same for everyone, and Crib sends nothing about you to get it — only the request itself, which reveals your IP address. - Pictures of your items. Each item keeps its picture wherever its maker
put it — Star Atlas on Google's storage, many NFTs on IPFS (fetched through
ipfs.filebase.io, or4everland.ioorgateway.pinata.cloudwhen that one does not answer) or Arweave (arweave.net), some on the maker's own server. Crib fetches each picture once and keeps it on this computer. The host that serves a picture sees your IP address and which picture was asked for, not your wallet address. Pictures of items Crib judges to be junk are never fetched, because a scam item's picture sits on the scammer's own server, and loading it would tell them the wallet is watched and from where.
Guard Dog — the permissions your wallets have given apps, only when you press "Check my wallets"
Guard Dog asks the same explorers and public nodes in the table above about the same watched addresses, so no new service learns your address: the explorer lists the permission events your address signed, the chain's public node says what each permission still allows, and the explorer names the app each one was given to.
Crib never contacts revoke.cash. A "Revoke" button is a link: it opens
revoke.cash in your browser only when you press it, with that wallet's
address and chain in the link, so revoke.cash learns the address the moment
you choose to go there. Revoking happens there, with your own wallet.
"Sent at you" — no requests of its own, ever
The warnings about poisoned addresses, impostor tokens and bait names are worked out from a wallet history you already asked Crib to read. It sends nothing: no new service is contacted, nothing extra is fetched, and the findings are kept in your own database file. Crib never loads a page, an image or a link belonging to any of the junk it names — doing so would tell whoever sent it that the address is watched, and from where.
"Where to go" — a list, not a connection
The Where to go page shows the real web addresses of wallets, exchanges, swap sites, explorers and lookup tools, together with a box for testing a link you were about to click.
Crib never visits any of them. The list ships inside the app, the page makes no requests at all, and the link checker answers from that list alone — it does not fetch the address you paste, which is the one thing you must not do with a link you are unsure about. Opening the page, searching it, or checking a link sends nothing to anybody, and nobody learns what you looked at.
An address is contacted only when you click it, and then it is your browser that goes there, exactly as if you had typed it — so that site sees your IP address and whatever your browser normally sends, and Crib is no longer involved. Nothing about your holdings is passed in the link, with one exception you choose: the links offered for a particular coin contain that coin's public contract address, because that is what makes them open on the right page.
The page exists because the alternative is worse. Searching for these sites sends the search to a search engine that sells the top position, and the fake version of a site is usually the advert above the real one.
Checking a price against a second source — no new service
Crib compares the price it is showing against coins.llama.fi, which is
already in the table above and already receives the same contract addresses for
historical prices. No new service is contacted and nothing new is sent: it
is one request covering the whole desk, for coins worth more than $25, and no
more often than once every three hours per coin. It asks by chain and contract,
exactly as a past-price lookup does, and it is not told that the answer is
being used to check anybody else.
The rewards and airdrop log — the same price sources, nothing new
Working out what a coin was worth the day it arrived uses the same historical price sources listed in the table above, asked by token and date, exactly as importing a wallet's history does. No new service is contacted and no service is told that the figure is for you, for tax, or for anything else. A price Crib already has is never re-asked.
What it would really sell for — no new request, no new service
Crib now keeps the size of the pool behind each on-chain coin, so it can say whether a position could actually be sold for what the desk says it is worth.
Nothing new is asked of anybody. That figure already arrives in the same answer as the price, from the same service, in the same request — Crib was reading past it and throwing it away. Keeping it adds no call, no host and no new disclosure. It is a number about a market, not about you, and like everything else it stays on your machine.
The share card — drawn here, uploaded nowhere
A share card is a picture of one holding that you can post. It is the only thing in Crib designed to leave your machine, so it is the one place these rules are strictest.
Crib does not upload it, and has nowhere to upload it to. The image is drawn in your own browser and saved to your own disk. What you do with the file afterwards is entirely yours.
Your wallet address, your wallet names, your note and how many coins you own are never on it — and there is no setting that puts them there. The card is built by naming each thing that may appear, so a figure added to Crib later does not become shareable by accident.
What it is worth is off unless you turn it on, one card at a time, and it is never remembered: the next card starts with the money hidden again. The headline is a multiple and a percentage, because a ratio says how a holding went without saying how much of it there is.
Crib also refuses to draw a price two sources disagree about. A picture outlives the doubt that produced it.
What else is out there — written down, never asked about
When Crib reads a wallet's history it sees the other side of every transfer: the addresses your coins went to, and the ones they came from. It now keeps those addresses on your machine, with a count of how many times and which coins, so it can show you places you have moved coins to and forgotten.
No request is made for this, and none could be. The page adds up what previous history reads already saw; opening it contacts nobody. No address is ever sent anywhere to be identified — asking an outside service "whose wallet is this?" about a list of addresses one person owns is exactly the thing that would tie them all together, so Crib does not have that feature and will not get one.
What is stored is a tally, not a copy of your history: an address, how many
transactions went each way, which coins, and the first and last dates. It is
removed with the wallet it came from, and it goes wherever your crib.sqlite3
goes — see What is stored on your machine below.
Desk Health — arithmetic over what Crib already wrote down
Desk Health says how much of your desk rests on figures that need nothing from you, and lists what would improve the rest. It contacts nothing. Every fact it uses was written down at the moment each figure was made — which source priced a lot, which day it was priced on, whether a cost was read or worked out — and the page only adds those up. No service is asked anything, and nothing is told that your record has a gap in it.
The Legacy Kit — printed here, sent nowhere
The Legacy Kit is a page built on your machine from your own desk and opened in your own browser. It is not uploaded, not generated by a server, and not seen by anyone but you until you print it and hand it to somebody.
It cannot contain a secret. Crib has never held a recovery phrase, a private key, a passphrase or a password — there is no field anywhere in the database that could hold one — so the sheet has nothing of that kind to print. The few things only you know are printed as ruled lines to fill in by hand, and Crib refuses to store something typed into its note that looks like a recovery phrase or a key. The finished sheet does list what you hold and your public addresses, so treat the paper the way you would treat a will: a public address cannot be spent from, but it does show what is there.
Your IP address
Any request reveals your IP address to the service receiving it. That is how the internet works, and Crib cannot prevent it. It matters here because a wallet address and an IP address seen together are a real correlation: those services could, in principle, associate your network location with the wallets you asked about. If that concerns you, use Crib behind a VPN or Tor, or do not add watched wallets and enter holdings by hand instead.
Telegram alerts — off by default, opt-in
If you set up Telegram alerts, Crib sends your portfolio figures — totals,
positions and targets reached, at the level of detail you choose — to
api.telegram.org, for delivery to the chat you nominated. Telegram then holds
that message under its own privacy policy, not this one. A watchlist token that
reaches your price is named in that message too, with its price.
If you turn on "message me the moment a target is reached", Crib checks prices every 5 minutes while any target is still waiting, whether or not the page is open, so the message can reach you when you are away. These are the price lookups listed above and nothing else — it never reads your wallets on a timer. It stops as soon as that setting is off, Telegram is removed, or no target is left waiting.
Your Telegram bot token and chat ID are stored in plain text in Crib's local database. They are not encrypted. Anyone with access to that file, or to a backup of it, can read them and could send messages as your bot. If that is not acceptable to you, do not configure Telegram alerts. You can remove the link at any time, which deletes the token from the database.
Crib's window — Microsoft Edge, signed out
Crib opens in a window of its own: Microsoft Edge, which comes with Windows,
started as an app window with its own settings folder beside your desk
(%USERPROFILE%\crib\window\). It is started signed out, with sync off, so
nothing in it is tied to a Microsoft account or copied anywhere, and your
browser extensions do not run in it. Crib sends Edge nothing but its own page
on this computer. Edge itself behaves as it does for any window, under
Microsoft's own privacy terms, not these. If Edge is not there, Crib opens in
your default browser instead.
Checking for updates — off until you ask
Crib does not check for updates on its own. Pressing Updates fetches one small file from wherever the installer is published, containing the newest version number and a link. That is all it reads: Crib never downloads or runs an installer for you — it hands you a link and you decide.
You are asked before the first check and told which host will be contacted. There is an option to check when you open Crib, which is off unless you turn it on; opening the app is a moment you chose, and a schedule is not.
The Microsoft Store version never checks at all. The Store keeps it up to date, so its Updates button just says so and contacts no one.
An optional API key
Crib works with no API key of any kind. If the environment variable
CRIB_CG_KEY is set, Crib will send that key to CoinGecko with its price
requests. It is read from the environment and is never written to Crib's
database. This is optional and off unless you set it yourself.
A problem report — only if you copy it and send it yourself
Report a problem shows a short plain-text report: your Crib version, your Windows and Python versions, how many holdings, buys, sales, watches and backups you have, which chains your watched wallets are on (not their addresses), your settings (on or off), your licence tier (not the key), and the problems Crib has hit since it last started. Wallet addresses, keys, tokens, hashes and your Windows user name are removed from those problems before they are kept. It contains no holdings, quantities, prices or values.
Crib does not send it. It sits on the screen for you to read; copying it and pasting it into an email is up to you. The problems it lists are kept in memory only, and are gone when Crib closes.
What Crib never sends anywhere
Your quantities, your costs, your profit and loss, your notes, and your CSV imports. Price and blockchain services are told what to look up, never how much of it you own.
What is stored on your machine, and where
| What | Where |
|---|---|
| Everything you own and everything you typed | %USERPROFILE%\crib\crib.sqlite3 |
| Backups you create | %USERPROFILE%\crib\backups\ |
| Cached prices, so Crib is not re-asking constantly | the same database file |
| A second source's price for the same coin, and when it was asked | the same database file |
| The Yard's items, your "mine"/"junk" answers | the same database file |
| Coins you received rather than bought, and what they were worth that day | the same database file |
| What the last history read found being sent at your wallets | the same database file |
| The name and note for the Legacy Kit, if you set them | the same database file |
| Solana transactions already read for a watched wallet, so a long history is not fetched twice (removed with the wallet) | the same database file |
| The Yard's pictures, and a copy of Star Atlas's item list | %USERPROFILE%\crib\yard\ |
| Settings, consents, and Telegram credentials if set | the same database file |
| A desk file you save to move to another computer | wherever you choose to save it |
A saved desk file is a complete copy of the database — every holding, sale, watched wallet address, your licence, and Telegram credentials if set. Crib never sends it anywhere; it goes only where you put it. Treat it like the database itself.
The database is not encrypted. It is protected by your operating system account and nothing more. Anyone who can read that file can see your positions. If your machine is shared or unencrypted, consider full-disk encryption.
To delete everything Crib knows about you: uninstall Crib and delete the
crib folder in your user directory. There is nothing held anywhere else,
because there is nowhere else. We cannot delete it for you, and we cannot
recover it for you.
Children
Crib is not intended for anyone under 18 and is not directed at children.
Changes to this document
If what Crib sends changes, this document changes in the same release, and the version and date at the top change with it. Adding a new blockchain means adding its hosts to the table above and to the consent screen in the app.
Contact
Iron Kennel — woof@getcrib.app
Where Crib is sold
Crib is sold only in the United States. If that changes, this document changes with it: selling to people in the EU or UK brings GDPR and UK-GDPR obligations that would need naming here, and possibly a representative, even though Crib holds no data centrally.
This document describes Crib 1.28.10 as built. Every host named above appears in the source; every claim about what is not sent was checked against it.