Privacy & data
Privacy Policy
This policy explains how Cribbo keeps your HomeKit and Matter setup information local by default, and what optional services you can enable.
1. Introduction and scope
One Thirteen (“Operator,” “we,” “us,” or “our”), located in the United States, operates Cribbo and is responsible for the processing described in this policy where applicable.
Cribbo is a local-first app for managing HomeKit and Matter setup codes. This policy covers the Cribbo app and related Cribbo pages on the One Thirteen website.
2. Privacy summary
- Your setup codes stay under your control.
- Cribbo does not require an account or operate a Cribbo user database.
- Analytics are optional and off by default.
- iCloud sync is optional and controlled through Apple.
- Secure Wipe can remove local Cribbo data.
- We do not sell personal information or use third-party advertising.
3. Data stored in Cribbo
Cribbo stores app data on your device so you can manage your setup-code vault, including:
- HomeKit setup codes, HomeKit QR payloads, and Matter setup codes
- Device metadata such as name, category, location, notes, manufacturer, and model
- App preferences and organization settings
4. Local-first handling
By default, Cribbo stores your data locally on your device. We do not transmit your setup codes to our servers and do not operate a database for Cribbo vault records.
5. Optional iCloud sync
If you enable iCloud sync, data syncs through Apple’s iCloud infrastructure using your Apple account. Sync is optional and can be disabled in app settings. We do not host, access, or read your iCloud sync data on our own servers. Apple processes information under its own Privacy Policy.
6. Optional analytics
Cribbo can send anonymous product analytics through PostHog only if you opt in through Settings. Analytics are off by default. When enabled, events may include signals such as onboarding completed, device added, or encrypted backup exported.
Cribbo does not send setup-code values, QR payloads, passphrases, device names, locations, notes, or other sensitive content for analytics. You can disable analytics at any time. Historical anonymous events may remain with the provider under its retention policy. See PostHog’s Privacy Notice.
7. Encrypted backups and import/export
Cribbo supports encrypted exports protected with your passphrase. Encryption and decryption happen on your device. Your passphrase is never stored by us, and we cannot recover it.
You can export JSON for backup or transfer and import JSON to restore or merge data. You are responsible for protecting exported files, passphrases, and any devices or services where you store a backup.
8. Third-party services
- Apple iCloud: optional user-controlled sync.
- PostHog: optional anonymous analytics, only after opt-in.
- Apple: platform services, App Store distribution, and payment processing.
These providers process information under their own terms and privacy notices.
9. Security, retention, and deletion
Cribbo uses local-first storage and encrypted exports to help protect your records. No storage or transmission method is perfectly secure.
- Local records remain until you delete them, use Secure Wipe, or remove Cribbo.
- Disabling iCloud sync stops future sync operations; Apple may retain records under its policies.
- Analytics data is retained for 24 months.
- Exported backups remain wherever you choose to store them until you delete them.
10. Children, changes, and contact
Cribbo is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have received such information, we will take reasonable steps to delete it.
We may update this policy as Cribbo or applicable requirements change. We will post revisions here and update the “Last updated” date.