Privacy: what leaves the box
Cobblr makes no unsolicited phone-home. There's no telemetry, no analytics, no
error reporting, and no update check. Your data stays in your Postgres. A few
features reach third-party services only when you use them, and each has an
off-switch in .env:
| Feature | Contacts | Turn off |
|---|---|---|
| Barcode lookups | product catalogs (upcitemdb, Open Facts, DuckDuckGo, and go-upc if you opt in) | COBBLR_SCAN_EXTERNAL_LOOKUPS=false |
| Item image search | DuckDuckGo image search, when you fetch a catalog photo for an item | no dedicated switch yet, but it only fires when you use the image picker or photo enrichment |
| AI features | your chosen LLM provider (needs your own key) | COBBLR_AI_ENABLED=false |
| Marketplace bundles | nothing. The bundle catalog is built on your own instance from the bundle files it already ships | nothing to turn off |
| Sandboxed module install | the module registry, which defaults to a public index on GitHub | point COBBLR_REGISTRY_URL at your own index, or don't install sandboxed modules |
Each barcode provider is switchable on its own, and you can supply your own API
key where one exists (for example COBBLR_SCAN_GOUPC_API_KEY).
Running fully air-gapped
- Set
COBBLR_AI_ENABLED=falseandCOBBLR_SCAN_EXTERNAL_LOOKUPS=false. - Use the offline TLS option.
- Skip the image-picker features, and don't install sandboxed modules.
With no outbound network those calls simply fail quietly rather than leaking. Bundles keep working air-gapped, since they never needed the network.
The one feature that sends
The barcode network is the one scanning feature that sends something out rather than only fetching.
- It does nothing until you give it a key. The setup builder asks for one during install with joining as the suggested answer, so it is worth knowing what joining means before you say yes.
- What leaves is a correction you made: the corrected value, the barcode, which field it fixed, and an opaque account id. Not your email, not your workspace contents, not the rest of what you scanned.
The "marketplace": which half actually leaves the box
Two things often get lumped together as "the marketplace", and only one of them
leaves the box. Browsing and installing bundles makes no outbound call at
all: the catalog is assembled locally from the instance's own bundle files.
Installing a sandboxed module is the one that reaches out, because the module
code comes from a registry index, and COBBLR_REGISTRY_URL is the knob that
points it somewhere else. (COBBLR_EXTENSIONS_URL only matters if you
deliberately point the bundle catalog at an external index, and left alone it
stays local.)
The repo's root SELF_HOSTING.md carries the deepest version of all this: the
per-provider barcode knobs and the full air-gap recipe.