Privacy Policy

Crumbs DNS / crumbs.com / Crumbs for Android | Effective date: 04/09/2026

We built Crumbs because we believe privacy is a human right, not a feature we bolt on. A privacy product’s privacy policy should be readable — so this one is written to be read, not skimmed and feared.

This policy covers the Crumbs products offered via crumbs.com, the Crumbs Android app, and Crumbs DNS, by eyeo GmbH (“eyeo”, “we”, “us”).

The short version

We collect the minimum data needed to run Crumbs: to block trackers and online threats, and — only where you’ve said yes — to measure ads or match them to broad interest groups. To do that, we handle your IP address, a random ID assigned to your device, and the DNS requests. Ad event data, where you’ve opted in, is deleted within 30 days.

We pseudonymize what we can and we don’t store your DNS requests — requests are processed, then only aggregate counts and anonymous aggregate data structures remain.

We never sell your personal data. The most an advertiser ever sees is a group ID protected by differential privacy that includes at least 100 other people and often more — never your identity.

We have strict contracts with the service providers who help us run Crumbs. You can access, correct, restrict, or delete your data, and withdraw any consent, at any time by emailing privacy@eyeo.com.

Everything below is the same facts, in full detail. We follow the EU General Data Protection Regulation (GDPR) and applicable US, EU, German, and UK data protection laws, as well as applicable laws outside these regions.

What we don’t do

  • We don’t sell your identity — advertisers never learn who you are.
  • We don’t tailor your ads or measure ad performance without your consent.
  • We don’t build rich advertising profiles — you’re only ever part of groups of at least 100 people, with random noise added.
  • We don’t keep your browsing history — DNS requests are answered and deleted within 24 hours, and no URLs, page titles, or search terms are ever stored.

Who is responsible for your data

eyeo GmbH, Kunibertsgasse 10, 50668 Cologne, Germany is the “controller” — the legal term for the company responsible for how your personal data is handled.

Questions? Our Data Protection Officer is Carlo Piltz: privacy@eyeo.com.

What we collect, and why

1. Running the blocking service and optional ad features

Crumbs works by rerouting your device’s DNS requests (the lookups that translate a web address into a location) through the Crumbs DNS servers, provided by our Cloud DNS Provider Whalebone. Two optional features — measuring ad performance (“attribution”) and seeing relevant ads matched to broad interest groups — run only if you opt in, and you can opt out at any time. Everything marked “with your consent” below happens only if you’ve opted in.

Our golden rule: advertisers only ever receive anonymous, aggregated statistics with mathematical noise added.

Your IP address. Your internet requests contain it; our Cloud DNS Provider needs it to answer your requests and provide the blocking service. Where Crumbs is set up without an app, our systems process IP addresses transiently to create your unique ID, and our Cloud DNS Provider keeps it for up to 24 hours for security purposes before deleting it. We never pass your IP address to advertisers.

A Crumbs ID for your device. A random, pseudonymous identifier — not your name, nothing personal. It applies the blocking protection you choose and counts how many trackers and malware domains were blocked on your device (the statistics shown in the app or in your Crumbs DNS dashboard) and — with your consent — is stored by us as part of the ad events listed below. It is never disclosed to advertisers.

DNS request data — for blocking or with your consent. As a DNS resolver that provides a tracker and threat blocking service, we have to process all DNS requests (your DNS query, and the resolver’s response). When our infrastructure handles a request — typically within one second — the individual request data is deleted within 24 hours; only aggregate counts of domains and anonymous aggregate data structures remain. With your consent, our Cloud DNS Provider also filters DNS requests to domains carrying ad beacons, registered conversion pages and domains we use to create a minimized pattern of numbers to work out which broad interest groups you belong to — all other traffic is ignored for the ad features. Stored ad events contain only an opaque campaign identifier, the event type, random mathematical noise, a timestamp, and your Crumbs ID — never URLs, page titles, or search terms. They’re deleted within 30 days.

Impression and conversion IDs — with your consent. Random identifiers created for each ad event so we can count events and prevent duplicates. They carry nothing about you or your device. It’s how we link an ad “impression” (an ad was seen) to a “conversion” (an action taken afterwards, like visiting a site or buying something), and how you’re placed in interest-based groups.

A minimized interest record — with your consent. A short list of yes/no flags, to place you in an interest group, each recording whether your device looked up one of the domains we track for this purpose. Nothing else is kept — no URLs, no page titles, no search terms, no record of when a lookup happened, and no ordering. It never leaves us — not to advertisers, not to ad platforms, not to anyone — and it is deleted within 30 days.

An interest-based group ID — with your consent. Advertisers define a broad interest (say, “car enthusiasts”). An automated, encrypted system with limited access places you in a group of at least 100 people matching it, with random people added as noise. Advertisers can show ads to that group without ever knowing who’s in it — they never see which sites you visited. It’s derived from a pattern of minimized numbers (yes/no flags) which means no domain history and no other DNS information. As described under “Who we share your data with” below, this group ID is the only piece of this data we ever share with advertisers.

We also use our own ad-measurement technology on our own websites: when we run campaigns for Crumbs, we measure them with the same system described above, under the same rules.

2. Communicating with you, and user support

If you choose to join our feedback community or early access waitlist on our website, we collect your email address so we can invite you to feedback sessions or testing and sign you into the community.

If you email us for help, we collect what we need to solve your issue: your email address, device information, your Crumbs version and relevant technical specs, any URLs you’re having trouble with, and a description of the issue.

3. Security

We also process some of the data above to keep Crumbs secure — detecting and preventing cyberattacks, fraud, and other harmful activity.

4. Evaluating and improving our products

We also process some of the data above, along with basic technical information we automatically receive (such as your browser user-agent string), to understand, evaluate and improve our products and services and the user experience. For instance, we may use the data to identify and repair errors, verify the quality or safety of our products, act on feedback you give us, or perform testing.

5. Legal obligations

Like every company, we process some data because the law requires it, such as keeping accounting and tax records, responding to lawful requests from courts and authorities, remembering and managing your privacy settings, handling your privacy rights requests, defending against legal claims, and complying with and enforcing our rights.

Why the law lets us process this

The GDPR requires a legal basis for each purpose above. Ours are:

  • The blocking service, communications, and support (sections 1–2): performing our contract with you — delivering what you signed up for, including steps you request before the contract, like downloading the app or setting up Crumbs on your device or router. We also rely on our legitimate interests and complying with our legal obligations in providing the services.
  • The optional ad features in section 1: your consent — one opt-in covering ad measurement (attribution) and relevant interest-group ads. You can withdraw it at any time: in the app’s settings, by removing the DNS from your device, or by following the instructions at my.crumbs.com.
  • Security, evaluation and improvement (sections 3–4): our legitimate interests in keeping Crumbs secure and making it better, and complying with our legal obligations.
  • Legal obligations (section 5): compliance with our legal obligations.

Who we share your data with

When we say share your data, we don’t always mean who we give your data to. This also may mean someone who we hire to run parts of Crumbs or provide a service to us and thus has access to your data or processes it on our behalf.

Service providers. We share data with companies that run parts of Crumbs on our behalf or provide services to us so that we can provide Crumbs to you — listed in our service providers list. They may only use your data to help us provide Crumbs to you, and for no other purpose. The most important one: Whalebone s.r.o., an EU-based DNS cybersecurity company, runs our cloud DNS infrastructure under a GDPR data processing agreement so processes data on our behalf. If we add or change service providers, we’ll update the list and put similar protections in place.

Advertisers and ad platforms — only with your consent. If you’ve consented to relevant interest-group ads, we share group IDs, protected by differential privacy that includes at least 100 other people and often more, with advertisers and the ad-buying platforms they use (sometimes called supply-side and demand-side platforms); no personal data is shared with advertisers.

Legal reasons. We may share data with our legal and tax advisors, insurers, law enforcement, courts, government bodies and others when we believe it’s necessary to comply with the law or legal process, get professional advice, respond to legal claims, or protect the rights and safety of our users, employees, or the public.

Corporate transactions. If eyeo’s structure changes — such as through a merger, sale, restructuring, or transfer of business units — we may share the data described above with a potential or actual purchaser (or other corporate transaction counterparty) of eyeo and their advisors. Any such transfer will honor this privacy policy and the GDPR and applicable data protection laws.

Our Company. We may share data within the eyeo group of companies to run parts of Crumbs and provide the products and services to you.

Does my data leave the EU?

Today, all Crumbs data is stored on servers in the EU. We will only transfer data outside the EU using European Commission-recognized measures to ensure an adequate level of protection.

Your rights

Under the GDPR and applicable data protection laws, you have the right to:

  • Know whether and how we process data about you
  • Access a copy of the data we hold about you, with details of how we process it
  • Correct inaccurate data, or complete incomplete data
  • Delete data we hold about you
  • Object to or restrict our processing of your data
  • Withdraw consent at any time, where our processing is based on your consent
  • Complain to a data protection authority — in particular where you live, work, or where you believe the infringement happened
 

To exercise any of these, email our Data Protection Officer at privacy@eyeo.com or write to eyeo GmbH, Kunibertsgasse 10, 50668 Cologne, Germany. We may also provide you the ability to exercise certain rights directly. For example, to withdraw your consent to ad measurement and relevant interest-group ads as a Crumbs user, you may do so in settings on the Android mobile application or by going to my.crumbs.com as a DNS user.

Before we act on a request, we may need to verify your identity (usually by email) so we don’t hand your data to someone pretending to be you. In some countries and in some U.S. states, you are permitted to have an authorized agent or representative contact us with the request on your behalf — if so, we may need proof they’re authorized by you and ask for your written confirmation. We’ll respond within the legally required time. Your specific rights may vary depending on where you live and local law.

How long we keep data

Only as long as reasonably necessary for the purposes above, unless the law requires or permits longer. For example, we retain user support data for one year after the case is closed, feedback and waitlist emails until you unsubscribe or ask us to delete your data whichever happens first, and blocked domain stats data for 30 days, after which it is auto-deleted. Ad event data is deleted within 30 days. We may also retain data longer where required to comply with record-keeping or other legal obligations, defend legal claims, or prevent fraud, or if we anonymize the data.

How we protect it

We’ve implemented commercially reasonable technical, administrative, and physical security measures designed to protect your data from loss, misuse, unauthorized access, and alteration. Ad event data is stored encrypted.

When this policy changes

The current version always lives at https://crumbs.com/privacy-policy. As Crumbs evolves and laws change, we may update this policy by posting the new version there. Where the law requires it, we’ll notify you before a new version takes effect — in the app or by other means where possible. If you don’t object by the effective date, the updated policy applies to you.

Additional rights for U.S. residents

If you reside in the U.S., depending on your state, you may also have the right to:

  • Opt out of “sale,” “sharing,” and targeted-advertising uses of your personal information. If you opt out, you may still see ads — they’ll just be less relevant — and you may need to opt out separately on each device and product.
  • Not be discriminated against for exercising any privacy right.
  • Appeal a decision if you believe we didn’t adequately address your privacy request — reply in your original request, or open a new one saying you’re appealing our response.
  • Know more about the categories of, or specific, third parties we might share your personal information with.
 

For requests made by an authorized agent, see “Your rights” above.

To exercise any of the above rights, or if you have questions about these rights, please contact privacy@eyeo.com.

Relevant interest-group ads and the legal definition of “sale”

We may process your interest-based group ID for relevant interest-group ads. Under some U.S. state laws, this can count as a “sale” or “sharing for cross-context behavioral advertising” of personal information, or processing of your personal information for “targeted advertising” — even though, as described above, advertisers never learn who is in that group. Where this applies, we will provide you the ability to opt out — in the Crumbs app’s settings menu, or for manual DNS setups at my.crumbs.com.

We have not “sold” or “shared” interest-based group IDs in the 12 months before this privacy policy’s effective date, but we may begin doing so afterward. We do not have actual knowledge that we “sell” or “share” interest-based group IDs relating to anyone under the age of 16.