Privacy Policy
Who We Are
Cribble ("we", "us", "our") is an AI-powered search engine built for Filipino users and the Filipino diaspora worldwide, operated under the domain cribble.ph. Cribble is headquartered in the Philippines and is committed to complying with the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations, as administered by the National Privacy Commission (NPC).
This Privacy Policy describes how we collect, use, store, share, and protect personal information when you use our website, mobile application, API, and related services (collectively, the "Service"). By accessing or using our Service, you acknowledge that you have read, understood, and agree to the practices described in this Policy.
For purposes of Philippine data privacy law, Cribble acts as the Personal Information Controller (PIC) with respect to data collected through the Service.
Information We Collect
2.1 Information You Provide Directly
- Account registration details (email address, display name) if you choose to create an account
- Feedback, bug reports, and support messages you submit
- Content you voluntarily submit, such as ratings or reviews of search results
- Communications with our team via email or social media
2.2 Information Collected Automatically
- Search queries you submit through Cribble, including language, filters, and result interactions
- IP address and approximate geolocation (city/region level, not precise GPS)
- Browser type, version, and operating system
- Device type (mobile, desktop, tablet) and screen resolution
- Referring URL and exit URL
- Pages viewed, features used, and session duration
- Error logs and performance diagnostics
- HTTP headers and standard web request metadata
2.3 Wallet Information
- Solana wallet public key (address) when you connect your wallet
- On-chain transaction hashes related to $CRIB token interactions initiated through the Service
- Subscription status derived from on-chain staking or payment data
2.4 Information from Third Parties
- Public blockchain data from the Solana network visible at your wallet address
- Analytics data from service providers such as Vercel Analytics or similar tools
- Token pricing data from decentralized exchanges (DEXes) and aggregators
How We Use Your Data
We use the information we collect for the following purposes, always limited to what is necessary, proportionate, and legitimate under Philippine law:
| Purpose | Legal Basis |
|---|---|
| Provide, operate, and improve the search engine and AI features | Contract performance / Legitimate interest |
| Personalize search results based on language and region | Legitimate interest / Consent |
| Process $CRIB token subscriptions and verify Pro access | Contract performance |
| Send transactional emails (account alerts, subscription confirmations) | Contract performance |
| Send product updates and announcements (opt-in only) | Consent |
| Detect fraud, abuse, spam, and security threats | Legitimate interest / Legal obligation |
| Analyze aggregate usage to improve product quality and relevance | Legitimate interest |
| Comply with legal obligations, court orders, or NPC directives | Legal obligation |
| Train and improve AI and NLP models (anonymized/aggregated data only) | Legitimate interest |
Cookies & Tracking
Cribble uses cookies and similar technologies (local storage, session storage, browser fingerprinting for fraud prevention) to operate and improve the Service. Below is a summary of the categories of cookies we use:
| Category | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Authentication, session management, CSRF protection | Session |
| Functional | User preferences (language, theme, search settings) | 1 year |
| Analytics | Aggregate usage statistics (no cross-site tracking) | 30 days |
| Performance | Error monitoring and latency diagnostics | Session |
We do not use advertising cookies or third-party retargeting pixels. You can control or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent certain features from functioning correctly.
Cribble products are ad-free. We do not allow advertisers to place tracking technologies on our platform.
Solana Wallet Data
Cribble integrates with Solana-compatible wallets (Phantom, Backpack, Solflare, and others) to enable $CRIB token-gated features and staking. When you connect a wallet:
- We read your public wallet address to verify token holdings and subscription status
- We query on-chain data from the Solana blockchain, which is publicly accessible to anyone
- We store your wallet address linked to your Cribble session to maintain Pro access across visits
- We do not store private keys, seed phrases, or any credentials that control your wallet
- We do not initiate any on-chain transactions without your explicit approval through your wallet interface
Blockchain transactions are irreversible and publicly recorded. Once you execute a transaction on Solana, that record is permanent and visible to the public. Cribble is not responsible for on-chain data visibility.
Third-Party Services
We use a limited number of trusted third-party service providers to operate Cribble. These providers are contractually bound to process your data only on our instructions and in accordance with applicable privacy law:
- Vercel — Hosting and edge deployment (United States)
- Supabase — Database, authentication, and session management
- Solana RPC providers — Blockchain data queries (public network)
- Cloudflare — DNS, DDoS protection, and CDN
- OpenAI / Anthropic / other LLM providers — AI generation pipeline (queries processed under their respective data processing agreements)
We do not integrate Facebook Pixel, Google Ads, TikTok Pixel, or any other advertising network tracking. We do not share your personal data with social media platforms.
Links on Cribble search results point to third-party websites. We are not responsible for the privacy practices of those websites. We encourage you to review their privacy policies before sharing personal information with them.
Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements.
- Search query logs — Retained for up to 90 days for quality improvement, then anonymized or deleted
- Account data — Retained for the life of your account plus 30 days after deletion request
- Session logs and analytics — Retained for up to 90 days
- Wallet association records — Retained for the duration of active subscription plus 6 months
- Support correspondence — Retained for up to 2 years
- Legal compliance records — As required by Philippine law (typically 5-10 years for financial records)
When retention periods expire, we securely delete or irreversibly anonymize the data. Anonymized, aggregated data (from which you cannot be identified) may be retained indefinitely for research and product improvement.
Your Rights
Under the Data Privacy Act of 2012 (RA 10173) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the following rights with respect to your personal data:
- Right to be Informed — You have the right to know that your data is being collected and how it is being used. This Privacy Policy fulfills that obligation.
- Right to Access — You may request a copy of all personal data we hold about you, including the source, recipients, and purposes of processing.
- Right to Correction / Rectification — You may request correction of inaccurate or incomplete personal data.
- Right to Erasure / Right to be Forgotten — You may request deletion of your personal data, subject to legal retention obligations.
- Right to Data Portability — You may request your data in a structured, commonly used, machine-readable format.
- Right to Object — You may object to the processing of your data for direct marketing, automated decision-making, or profiling.
- Right to Lodge a Complaint — You have the right to file a complaint with the National Privacy Commission (NPC) at privacy.gov.ph if you believe your rights have been violated.
- Right to Withdraw Consent — Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact our Data Protection Officer at privacy@cribble.ph. We will respond to all verified requests within 15 business days as required by Philippine law.
International Data Transfers
Cribble operates infrastructure across multiple countries, including the United States, Singapore, and the Philippines. When your data is processed or stored outside the Philippines, we ensure that adequate safeguards are in place consistent with the Data Privacy Act and NPC guidelines, including:
- Standard contractual clauses (SCCs) with processors in jurisdictions without adequacy decisions
- Data processing agreements (DPAs) with all third-party sub-processors
- Technical and organizational security measures appropriate to the risk level
- Onward transfer restrictions ensuring your data is not further disclosed without authorization
Children's Privacy
Cribble is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided personal information to us without your consent, please contact us immediately at privacy@cribble.ph and we will take prompt steps to delete that information.
Users between 13 and 18 years of age should only use Cribble with parental or guardian consent. We encourage parents to supervise their children's internet activity and use of AI tools.
Security
We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, and destruction. These include:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of sensitive data at rest using AES-256
- Access controls and role-based permissions limiting data access to authorized personnel only
- Regular security audits and vulnerability assessments
- Incident response procedures and breach notification protocols in accordance with RA 10173
- Multi-factor authentication for administrative access
- Dependency monitoring and regular security patching
Despite these measures, no system is perfectly secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected users and the NPC within 72 hours of becoming aware of the breach, as required by Philippine law.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Post a notice on the Cribble homepage or within the Service
- Send an email notification to registered users with an active account
- For significant changes affecting your rights, provide at least 30 days' notice before the changes take effect
Your continued use of Cribble after the effective date of any update constitutes your acceptance of the revised Policy. If you do not agree to the revised Policy, you should stop using the Service and request deletion of your data.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to our Data Protection Officer:
Cribble Data Protection Officer
For complaints, you may also contact the National Privacy Commission of the Philippines at privacy.gov.ph.