Credits
and third-party licenses.
Cryptocurrency Tracker is built on open-source packages, the ad networks' SDK plugins and public data sources. Each keeps its own license or terms. The full list of resolved packages is in THIRD-PARTY-LICENSES.md.
01Summary
The open-source packages in the app, the Cloud Functions and the console are under permissive licenses (MIT, BSD, Apache-2.0, ISC, 0BSD, Unlicense), with one exception under MPL-2.0, below. There are no GPL packages. The full list with versions, and the license texts of the components bundled in the console: THIRD-PARTY-LICENSES.md.
dbus 0.8.0 (MPL-2.0) is resolved by flutter pub get as a transitive dependency of file_picker, through its Linux implementation file_picker_linux (app/pubspec.lock). It is not compiled into the Android, iOS or web builds of this app and is used unmodified. MPL-2.0 is a file-level copyleft: if you modify that package's files and distribute them, you must publish those modified files under MPL-2.0.
The app bundles no third-party images or fonts; its icons are Flutter's Material Icons (Apache-2.0), and the cupertino_icons font package (MIT) is a dependency. The app logo is our own. The operator console ships the Geist and Geist Mono fonts (SIL Open Font License 1.1; the license texts are next to the fonts as Geist-OFL.txt and GeistMono-OFL.txt) and a prebuilt UI bundle with React and React DOM (MIT), cmdk (MIT) and Lucide icons (ISC) in admin/vendor/mikodes-admin/ui/assets/.
02App (Flutter, from pub.dev)
| Package | Version | License |
|---|---|---|
| firebase_core, firebase_auth, cloud_firestore, firebase_messaging | 4.15.0, 6.7.0, 6.10.0, 16.7.0 | BSD |
| google_mobile_ads | 9.0.0 | Apache-2.0 |
| applovin_max | 4.6.4 | MIT (AppLovin Corporation) |
| unity_ads_plugin | 0.5.0 | MIT (community plugin) |
| unity_levelplay_mediation | 9.3.0 | Unity Advertising Terms, see below |
| in_app_purchase | 3.3.1 | BSD |
| home_widget | 0.10.0 | BSD |
| fl_chart | 1.2.0 | MIT |
| cached_network_image | 3.4.1 | MIT |
| file_picker | 13.1.0 | MIT |
| csv | 8.0.0 | MIT |
| provider | 6.1.5+1 | MIT |
| http, shared_preferences, url_launcher, share_plus, package_info_plus, intl | 1.6.0, 2.5.6, 6.3.3, 13.3.1, 10.2.2, 0.20.2 | BSD |
| flutter_localizations | Flutter SDK | BSD-3-Clause (part of Flutter) |
| cupertino_icons | 1.0.9 | MIT |
03Ad network SDKs
unity_levelplay_mediation is © ironSource Ltd. and is made available under the Unity Advertising Terms of Service as a "Service Asset". It is not included in the download: app/pubspec.yaml declares it and flutter pub get fetches it from pub.dev, so you accept Unity's terms directly when you use it.
The native SDKs the Flutter plugins pull in when you build (Google Mobile Ads with the User Messaging Platform, AppLovin, Unity Ads, ironSource) come under each network's own terms. Opening an account with a network means accepting its publisher terms.
04Cloud Functions and console (from npm)
| Package | Version | License | Used in |
|---|---|---|---|
| firebase-admin | 13.10.0 | Apache-2.0 | Functions, console |
| firebase-functions | 7.4.0 | MIT | Functions |
| google-auth-library | 10.9.1 | Apache-2.0 | Functions (Google Play verification) |
| jose | 6.2.12 | MIT | Functions (App Store verification) |
| fast-xml-parser | 5.11.2 | MIT | Functions (RSS) |
| @anthropic-ai/sdk | 0.131.0 | MIT | Functions, console (AI key test) |
| hono, @hono/node-server | 4.13.13, 2.1.3 | MIT | Functions, console |
| better-sqlite3, pg, tsx | 13.0.3, 8.23.1, 4.23.15 | MIT | Console |
The operator console is built on the MIKODES Admin Kit 0.4.0, vendored in admin/vendor/mikodes-admin/ as part of this item.
05Data sources
These are services the backend calls, not code in the package. Each has its own terms, limits and attribution rules, which you accept when you use it.
| Source | Used for |
|---|---|
| CoinGecko API | Market data, charts, coin details, exchange tickers, trending, fiat rates, token contract list. Coin images from CoinGecko's image host. |
| CoinMarketCap API | Failover market data; coin images from CoinMarketCap's image host for failover rows. |
| RSS feeds of CoinDesk, Decrypt, Cointelegraph and The Block | Headlines and links to the publishers' articles. The names and content belong to the publishers. |
| publicnode.com, Solana mainnet-beta, mempool.space | Read-only wallet balances. |
| Anthropic, OpenAI or a compatible provider (optional) | AI brief and coin reports, with your own key. |
Exchange and coin names, tickers and logos shown in the app belong to their owners. Their display does not imply endorsement.