Why do we care more about privacy than you do? Unveiling Crackercrack's "Privacy by Design" technical architecture
Why do we care more about privacy than you do? Unveiling Crackercrack's "Privacy by Design" technical architecture
From local hash matching to zero-knowledge proofs, here is how we build a security tool that 'protects you without seeing you.'
From local hash matching to zero-knowledge proofs, here is how we build a security tool that 'protects you without seeing you.'

Core Technology — Edge Computing and "Asymmetric" Information Matching
At Crackercrack, our core development principle is Privacy by Design. We believe that scam prevention should not come at the expense of browsing freedom. To achieve this goal, we adopt a hybrid architecture of "Edge (on-device) + Cloud":
1. Memory-Level Local Filtering: Bloom Filter
We have built highly efficient Bloom Filters into our Apps and browser extensions. This system includes:
Tranco 1M Global Million Whitelist: Ensures that when you visit mainstream legitimate websites, absolutely no external requests are triggered.
Dynamic Blacklist: Contains the latest malicious advertising domains and tracker intelligence, kept synchronized in real time.
Advantage: 99% of website matching is completed locally on your device, without the need to upload any URLs.
2. Professional Mode (Strict Mode) & Defense in Depth
Tailored for advanced users, we designed "Professional Mode" to achieve complete path analysis through different system permissions:
iOS: Achieves precise browser-level filtering through Web Extensions.
Android: Detects hidden links inside Apps (such as LINE, FB) through Accessibility features.
Anonymous Hash Matching: Borrowing the logic of Google Safe Browsing, we only match the prefix (first 4 characters) of the URL hash locally. Only when these 4 characters hit our risk database does it query the cloud. This means we never know your complete browsing history.
Data Processing Principles—"Burn After Reading" and Transparency Commitments
1. Cloud Heuristic Analysis: De-identification and Ephemeral Processing
When a URL cannot be evaluated locally and the platform's "heuristic analysis" function must be triggered:
Burn After Reading: We only record the characteristic values of the URL itself. All metadata related to personal identity adopts a "burn after reading" mechanism and is erased immediately after the analysis concludes.
Active Reporting Mechanism: Unless you click "Active Report" to participate in our reputation score and leaderboard mechanism, we will not record your name. Other than that, you are just a protected, anonymous node on the map.
2. Code Transparency: Trust, but Verify
We deeply understand that "trust" cannot rely solely on verbal promises. Therefore, we make the following commitments:
Open Source Code: In the future, the source code of all endpoint applications (Apps and Extensions) will be hosted on GitLab/GitHub for public review. Anyone can verify exactly what information our APIs collect.
Platform Regulation: Our applications will strictly comply with Google and Apple developer guidelines and undergo privacy reviews and permission monitoring by the platforms.
3. Saying No to the Hotbed of Commercial Advertising
Crackercrack is dedicated to blocking malicious trackers and advertising networks; therefore, we have decided to never display any form of advertising permanently. We do not want to become a penetration pathway for hackers and advertisers.
4. Conclusion:
Crackercrack's goal is to achieve a state of "Zero-Knowledge Proof": "I know this URL is malicious, but I do not know who visited it." This is our highest commitment to all users.

Core Technology — Edge Computing and "Asymmetric" Information Matching
At Crackercrack, our core development principle is Privacy by Design. We believe that scam prevention should not come at the expense of browsing freedom. To achieve this goal, we adopt a hybrid architecture of "Edge (on-device) + Cloud":
1. Memory-Level Local Filtering: Bloom Filter
We have built highly efficient Bloom Filters into our Apps and browser extensions. This system includes:
Tranco 1M Global Million Whitelist: Ensures that when you visit mainstream legitimate websites, absolutely no external requests are triggered.
Dynamic Blacklist: Contains the latest malicious advertising domains and tracker intelligence, kept synchronized in real time.
Advantage: 99% of website matching is completed locally on your device, without the need to upload any URLs.
2. Professional Mode (Strict Mode) & Defense in Depth
Tailored for advanced users, we designed "Professional Mode" to achieve complete path analysis through different system permissions:
iOS: Achieves precise browser-level filtering through Web Extensions.
Android: Detects hidden links inside Apps (such as LINE, FB) through Accessibility features.
Anonymous Hash Matching: Borrowing the logic of Google Safe Browsing, we only match the prefix (first 4 characters) of the URL hash locally. Only when these 4 characters hit our risk database does it query the cloud. This means we never know your complete browsing history.
Data Processing Principles—"Burn After Reading" and Transparency Commitments
1. Cloud Heuristic Analysis: De-identification and Ephemeral Processing
When a URL cannot be evaluated locally and the platform's "heuristic analysis" function must be triggered:
Burn After Reading: We only record the characteristic values of the URL itself. All metadata related to personal identity adopts a "burn after reading" mechanism and is erased immediately after the analysis concludes.
Active Reporting Mechanism: Unless you click "Active Report" to participate in our reputation score and leaderboard mechanism, we will not record your name. Other than that, you are just a protected, anonymous node on the map.
2. Code Transparency: Trust, but Verify
We deeply understand that "trust" cannot rely solely on verbal promises. Therefore, we make the following commitments:
Open Source Code: In the future, the source code of all endpoint applications (Apps and Extensions) will be hosted on GitLab/GitHub for public review. Anyone can verify exactly what information our APIs collect.
Platform Regulation: Our applications will strictly comply with Google and Apple developer guidelines and undergo privacy reviews and permission monitoring by the platforms.
3. Saying No to the Hotbed of Commercial Advertising
Crackercrack is dedicated to blocking malicious trackers and advertising networks; therefore, we have decided to never display any form of advertising permanently. We do not want to become a penetration pathway for hackers and advertisers.
4. Conclusion:
Crackercrack's goal is to achieve a state of "Zero-Knowledge Proof": "I know this URL is malicious, but I do not know who visited it." This is our highest commitment to all users.
Recent Posts
Popular Posts
Recent Posts
Popular Posts
More In-Depth Features
More In-Depth Features
More In-Depth Features

Crackercrack Founding Partner Program
The first 100 individual users will enjoy the 'Family Edition free forever'.
Enterprise partners participating in the POC will enjoy a completely free trial period and a "50% off for life" discount. Join us in defining the future of frictionless cybersecurity.



Crackercrack
Founding Partner Program
The first 100 individual users will enjoy the 'Family Edition free forever'.
Enterprise partners participating in the POC will enjoy a completely free trial period and a "50% off for life" discount. Join us in defining the future of frictionless cybersecurity.



Crackercrack Founding Partner Program
The first 100 individual users
will enjoy "Lifetime Free Family Edition".
Enterprise partners participating in the POC will enjoy a completely free trial period and a "50% off for life" discount. Join us in defining the future of frictionless cybersecurity.









