Privacy Policy

Crumbs for iOS & iPadOS Effective date: 31/07/2026  |  Version: 1.0

We built Crumbs because we believe privacy is a human right. A privacy product’s privacy policy should be readable, so this one is written to be read – not skimmed and feared. It covers the Crumbs iOS & iPadOS apps and services offered by eyeo GmbH (“eyeo”, “we”, “us”).

The short version

Crumbs blocks trackers and malware by filtering your device’s DNS requests. To do that, we handle three things: your IP address, a random ID assigned to your device, and the DNS requests. We don’t store your DNS requests — requests are processed, then only aggregate counts remain for the ones that get blocked (that’s what powers the blocking statistics you see in the app).

We collect as little as possible, anonymize what we can, and delete data when we no longer need it. We never sell your personal data. We have strict contracts with the service providers who help us run Crumbs. You can access, correct, delete, or object to our use of your data at any time by emailing privacy@eyeo.com.

Everything below is the same facts, in full detail. We follow the EU General Data Protection Regulation (GDPR) and applicable EU, German, and UK data protection laws, as well as applicable laws outside the EU and UK.

Who is responsible for your data

eyeo GmbH, Kunibertsgasse 10, 50668 Cologne, Germany is the “controller” — the legal term for the company responsible for how your personal data is handled.

Questions? Our Data Protection Officer is Carlo Piltz: privacy@eyeo.com.

What we collect, and why

1. Running the blocking service

Crumbs works by routing your device’s DNS requests through the Crumbs DNS servers, which intercept and block requests to tracking and malicious domains. To do this, we process:

Your IP address. Your internet requests carry it, so we need it to answer them as your DNS resolver and provide the blocking service.

A unique ID for your device. A random, pseudonymous identifier — not your name or Apple ID. It allows us to apply the blocking protection you choose, and it lets us count how many trackers and malware domains were blocked on your device (the statistics shown in the app).

DNS requests data. As a DNS resolver that provides a tracker and threat blocking service, we have to process all DNS requests (your DNS query, and the resolver’s response). When our infrastructure handles a request — typically within one second — the individual request data is deleted within 24 hours; only an aggregate count of blocked domains remains.

Why the law permits this (our legal basis): this processing is necessary to perform our contract with you — delivering the service you signed up for — and to take steps you request before that contract, such as when you download and install the app. We also rely on our legitimate interests and on compliance with our legal obligations in providing the services to you.

2. Communicating with you, and user support

If you choose to join our feedback community, we collect your email address to create an account so we can invite you to feedback sessions or testing.

If you email us for help, we collect what we need to solve your issue: your email address, device OS version, your Crumbs version, the URL or app that you tell us you’re having a problem with and a description of the problem. You can optionally share the trackers that Crumbs blocked in the last hour so we can further identify the cause of the issue.

Why the law permits this (our legal basis): sending these communications and providing support is necessary to perform our contract with you — it’s part of the service you signed up for. We also rely on our legitimate interests and on compliance with our legal obligations.

3. Security 

We also process some of the data above to keep Crumbs secure — detecting and preventing cyberattacks, fraud, and other harmful activity.

Why the law permits this (our legal basis): we have a legitimate interest in keeping the service secure and working well, and some security processing is also needed to comply with our legal obligations.

4. Evaluating and Improving Our Products

We also process some of the data above to understand, evaluate, assess the effectiveness of and improve our products and services and the user experience. For instance, we may use the data to identify and repair errors or to verify the quality or safety of our products, or to act on feedback you give us.

Why the law permits this (our legal basis): we have a legitimate interest in understanding how our users interact with our products so we can improve them, and we also process this data to comply with our legal obligations.

5. Legal obligations

Like every company, we process some data because the law requires it such as keeping accounting and tax records, responding to lawful requests from courts and authorities, handling your privacy rights requests, defending against legal claims and complying with or enforcing our rights.

Why the law permits this (our legal basis): compliance with our legal, regulatory, and other obligations under applicable laws.

Who we share your data with

When we say share your data, we don’t always mean who we give your data to.  This also may mean someone who we hire to run parts of Crumbs or provide a service to us and thus has access to your data or processes it on our behalf.  

Service providers. We share data with companies that run parts of Crumbs on our behalf or provide services to us so that we can provide Crumbs to you — listed in our processor list [link]. They may only use your data to help us provide Crumbs to you, for no other purpose. The most important one: Whalebone s.r.o., an EU-based DNS cybersecurity company, runs our cloud DNS infrastructure under a GDPR data processing agreement so processes data on our behalf. If we add or change service providers, we’ll update the list and put similar protections in place.

Legal reasons. We may share data with our legal and tax advisors, insurers, law enforcement, courts, government bodies and others when we believe it’s necessary to comply with the law or legal process, get professional advice, respond to legal claims, or protect the rights and safety of our users, employees, or the public. 

Corporate transactions. If eyeo’s structure changes — such as through a merger, sale, restructuring, or transfer of business units — we may share the data described above with a potential or actual purchaser (or other corporate transaction counterparty) of eyeo and their advisors. Any such transfer will honor this privacy policy and the GDPR and applicable data protection laws.

Our Company.  We may share data within the eyeo group of companies to run parts of Crumbs and provide the products and services to you.  

Does my data leave the EU?

Today, all Crumbs data is stored on servers in the EU. We will only transfer data outside the EU using European Commission-recognized measures to ensure an adequate level of protection.

Your rights

Under the GDPR and applicable EU, German, and UK laws, you have the right to:

  • Know whether and how we process data about you
  • Access a copy of the data we hold about you, with details of how we process it
  • Correct inaccurate data, or complete incomplete data
  • Delete data we hold about you
  • Object to or restrict our processing of your data
  • Complain to a data protection authority — in particular where you live, work, or where you believe the infringement happened
 

To exercise any of these, email our Data Protection Officer at privacy@eyeo.com or write to eyeo GmbH, Kunibertsgasse 10, 50668 Cologne, Germany.

Before we act on a request, we may need to verify your identity (usually by email) so we don’t hand your data to someone pretending to be you. In some countries and in some U.S. states, you are permitted to have an authorized agent or representative contact us with the request on your behalf – if so, we may need proof they’re authorized by you and ask for your written  confirmation. We’ll respond within the legally required time. Your specific rights may vary depending on where you live and local law.

How long we keep data

Only as long as reasonably necessary for the purposes above, unless the law requires or permits longer. For example, we retain user support data for one year after the case is closed, feedback emails until you withdraw from the community, and blocking stats data for 30 days, or until you turn off the blocking service. We may also retain data longer where required to comply with record-keeping or other legal obligations, defend legal claims, or prevent fraud, or if we anonymize the data.  

How we protect it

We’ve implemented commercially reasonable technical, administrative, and physical security measures designed to protect your data from loss, misuse, unauthorized access, and alteration.

When this policy changes

The current version always lives at https://crumbs.com/privacy-policy-ios. As Crumbs evolves and laws change, we may update this policy by posting the new version there. Where the law requires it, we’ll notify you before a new version takes effect — in the app or by other means. If you don’t object by the effective date, the updated policy applies to you.

Additional rights for U.S. residents

We do not “sell” or “share” your personal information, as those terms are defined under U.S. state privacy laws.

Depending on your state, you may also have the right to:

  • Not be discriminated against for exercising any privacy right.
  • Appeal a decision if you believe we didn’t adequately address your privacy request.
  • Know additional information about third parties such as categories of, or specific, third parties we might share your personal information with.

For requests made by an authorized agent, see “Your rights” above.

To exercise any of the above rights or if you have questions about these rights, please contact: privacy@eyeo.com.