Cobblr is a place to keep track of your own things. The data in it is yours, it is stored so only your workspace can read it, and we do not sell it, share it with advertisers, or use it to train anything. The one thing that leaves a hosted workspace is product information for the shared barcode network, described below. This page says exactly what is kept and what happens to it, in plain words.
Self-hosting
If you run Cobblr on your own machine, nothing on this page applies: your data never touches our servers. The source is public, and the self-host guide is at docs.cobblr.xyz.
What the hosted service stores
- Your account: your email address, a display name, a password hash or sign-in token, and when you last signed in. A Discord account you link is kept as its id and username so notifications can reach you.
- Your workspace: whatever you put in it: items, photos, receipts, locations, notes, orders, parcels, and the structure you build. Each workspace lives in its own database.
- Operational records: an activity log of changes in your workspace (so you can see who did what), notifications you were sent, and enough request logging to keep the service running and find abuse.
- Backups: nightly, kept for a limited time, so a mistake or an outage does not lose your work.
The shared barcode network
Every hosted workspace is part of Cobblr's shared barcode network. It is not a setting you can turn off: it is how the hosted service offers free product identification, and everyone who uses it helps it get better.
- Looking a barcode up: when you scan a barcode, our server (not your phone) sends the number to Cobblr's shared product database. That database answers from public product databases such as Open Food Facts, Open Library and MusicBrainz, and from other product catalogues. When none of them knows the item, its name and barcode may also be used for a web and picture search.
- Giving back: when you name, correct or identify a product that has a barcode, what you settled on is added to the shared database: the barcode, the product's name, brand and category, the address of a public catalogue picture, where each came from (a catalogue, the AI or a web search, or you), and whether you confirmed or changed it.
- Products without a barcode: when you file a product that has no barcode, the words the AI read off its label that also appear in what you filed (such as the brand, the product name, a colour or a size) are added to the shared database in scrambled form, with the name, brand and category you settled on, so the next photo of that product can be named from them. The words travel to the shared database over an encrypted connection and are scrambled there, with a key only it holds, before anything is stored or compared: it keeps only the scrambled form, never the words, and a new photo is matched by scrambling its words the same way. The photo itself is not sent.
- Who it comes from: not your name, email address or workspace. Each contribution carries a pseudonymous code worked out one way from your account, so one person's corrections count once; it cannot be turned back into your name or email. When Cobblr reports on its own that a barcode looks wrong, that report carries a similar code for the workspace instead. The database sees our server, not your device or address.
- What it never includes: your own photos or anything cut from them; any other text on a photo (only product words that also appear in what you filed, and only for items you file, never receipts or documents); where you keep things, how many you have, prices, notes, or anything else in your workspace. A store's in-house labels (the price-embedded codes on deli or meat counters) are never sent.
Self-hosted Cobblr is not part of the network unless whoever runs it connects it; once connected, it looks barcodes up and gives back the same way.
Photos, receipts and AI
When you photograph an item or a receipt, the picture and its text are sent to an AI provider to be read. On the hosted service that provider is one we run or contract; if you connect your own AI key under Connections, it is yours. The result (what the thing is, the line items) is stored in your workspace; the provider processes it under terms that do not allow training on it. You can turn AI off per workspace.
A mailbox you connect (Gmail)
You can connect your Gmail so that orders, parcels, returns and cancellations track themselves from the emails stores and carriers send you. Here is precisely what that does.
- Read-only. Cobblr asks Google for the
gmail.readonlypermission and nothing wider. It cannot label, move, delete or send mail. - Stores and carriers only. Cobblr asks Gmail for mail from an allowlist of sender domains (Amazon, UPS, FedEx, USPS, DHL, OnTrac, and any store you add on the card). The filtering happens at Google; Cobblr never receives the identity of a message outside that list.
- No message body is kept. Each matching message is read once, in memory, to find the order number, the parcel's state, the tracking number and the like. What is stored is the subject line, the sender, the date, the Message-ID and Gmail's id for the message (so it is never read twice and can be read again if a parse needs redoing), plus the result on your parcel or order. A receipt attached as a PDF or image is saved in your workspace as your receipt, the same as if you had uploaded it.
- The grant is encrypted and yours to revoke. The refresh token is stored encrypted, never shown, and used only to read your mailbox on a five-minute cycle. Disconnect on the Connections page revokes it at Google first, then deletes it here. You can also revoke it from your Google account at any time.
- Limited Use. Cobblr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: Google user data is used only to provide the parcel- and order-tracking feature you see on screen; it is never used for advertising, never sold or transferred to data brokers, and never read by a person except with your explicit consent, for security, or to comply with the law. It is not used to train AI models.
Emails Cobblr sends you
Sign-in links, notifications you have asked for, and replies to feedback you sent. Every notification channel can be turned off under Account → Communication.
Who can see your workspace
The people you invite to it, with the role you give them. Cobblr operators do not open workspaces. When support needs to look at a problem you reported, an operator uses a read-only, time-limited view that is recorded in the operator log.
Deleting things
Delete a workspace and its database is dropped after a short grace period; delete your account and the same happens to everything it owned. Backups age out on their own schedule. Export is available at any time, as a full backup you can restore into a self-hosted Cobblr.
Cookies and analytics
The app keeps a sign-in token in your browser so you stay signed in, and nothing else. This website has no analytics scripts and no trackers; its fonts load from Google Fonts.
Changes and contact
If this page changes in a way that matters, the date above moves and the change is noted in the changelog. Questions or requests about your data: hello@cobblr.xyz.