Privacy: what leaves the box
Cobblr makes no unsolicited phone-home. There's no telemetry, no analytics, no
error reporting, and no update check. Your data stays in your Postgres. A few
features reach third-party services only when you use them, and each has an
off-switch in .env:
| Feature | Contacts | Turn off |
|---|---|---|
| Barcode lookups | product catalogs (upcitemdb, Open Facts, DuckDuckGo, and go-upc if you opt in) | COBBLR_SCAN_EXTERNAL_LOOKUPS=false |
| Item image search | DuckDuckGo image search, when you fetch a catalog photo for an item | no dedicated switch yet. It only fires when you use the image picker or photo enrichment |
| AI features | your chosen LLM provider (needs your own key) | COBBLR_AI_ENABLED=false |
| Marketplace bundles | nothing. The bundle catalog is built on your own instance from the bundle files it already ships | nothing to turn off |
| Sandboxed module install | the module registry, which defaults to a public index on GitHub | point COBBLR_REGISTRY_URL at your own index, or don't install sandboxed modules |
A fully air-gapped install
- Set
COBBLR_AI_ENABLED=falseandCOBBLR_SCAN_EXTERNAL_LOOKUPS=false. - Use the offline TLS option.
- Skip the image-picker features, and don't install sandboxed modules.
With no outbound network those calls simply fail quietly rather than leaking. Bundles keep working air-gapped, since they never needed the network.
Barcode lookups
- Each barcode provider is switchable on its own, and you can supply your
own API key where one exists (for example
COBBLR_SCAN_GOUPC_API_KEY). - The barcode network is the one scanning feature that sends something out rather than only fetching. It does nothing until you give it a key.
- The setup builder asks for a key during install, with joining as the suggested answer, so it is worth knowing what joining means before you say yes.
- What leaves is a correction you made: the corrected value, the barcode, which field it fixed, and an opaque account id. Not your email, not your workspace contents, not the rest of what you scanned.
The marketplace
Two things often get lumped together as "the marketplace", and only one of them leaves the box.
- Browsing and installing bundles makes no outbound call at all. The catalog is assembled locally from the instance's own bundle files.
- Installing a sandboxed module is the one that reaches out, because the
module code comes from a registry index.
COBBLR_REGISTRY_URLis the knob that points it somewhere else.
The other index variable
COBBLR_EXTENSIONS_URL only matters if you deliberately point the bundle
catalog at an external index. Left alone it stays local.
The deepest version
The repo's root SELF_HOSTING.md carries the deepest version of all this: the
per-provider barcode knobs and the full air-gap recipe.